Home

Awesome

PurpleTeam

PurpleTeam - Tools and more..


Emergency Response Tool

Project Descriptionproject addressproject name
Automatic and comprehensive detection script of the host-side Checklisthttps://github.com/grayddq/GScanGscan
Practical notes on emergency response, self-cultivation of a safety engineerhttps://github.com/Bypass007/Emergency-Response-NotesBypass007
Linux information collection/emergency response/common backdoor/mining detection/webshell detection scripthttps://github.com/al0ne/LinuxCheckLinuxCheck
APT-Hunter Windows log event emergency toolhttps://github.com/ahmedkhlief/APT-HunterAPT-Hunter
uroboros – A GNU/Linux monitoring and profiling tool that focuses on a single processhttps://github.com/evilsocket/uroborosuroboros
A powerful emergency response tool under whohk linuxhttps://github.com/heikanet/whohkwhohk
Malwoverview is a first responder tool for threat huntinghttps://github.com/alexandreborges/malwoverviewmalwoverview
Attack Surface Analyzer can help you analyze the security configuration of your operating systemhttps://github.com/Microsoft/AttackSurfaceAnalyzerAttackSurfaceAnalyzer
A tool for real-time detection of malicious web traffic based on IP reputation informationhttps://github.com/CRED-CLUB/ARTIFARTIF
Rootkit Hunter Rootkit Hunterhttp://rkhunter.sourceforge.net/Rootkit
SHELPUB.COM focuses on killing hippo webshell killinghttps://www.shellpub.com/hippo webshell
Fire Kylin-Network Security Emergency Response Tool (System Trace Collection)https://github.com/MountCloud/FireKylinFireKylin
Log analysis library, another usage of nucleihttps://github.com/ffffffff0x/LOG-HUBLOG-HUB

Tunnel proxy tool

Project Descriptionproject addressproject name
A full-platform proxy tool that supports a variety of socks protocolshttps://www.proxifier.com/proxifier
High-performance reverse proxy application focusing on intranet penetrationhttps://github.com/fatedier/frpfrp
Lightweight, high-performance, powerful intranet penetration proxy serverhttps://github.com/ehang-io/npsnps
Improved reGeorg versionhttps://github.com/L-codes/Neo-reGeorgNeo-reGeorg
It is a tool that uses the dns protocol to transmit tcp datahttps://github.com/alex-sector/dns2tcpdns2tcp
is a DNS tunneling toolhttps://github.com/iagox86/dnscat2dnscat2
Intranet penetration proxy, port forwarding toolhttp://rootkiter.com/Termite/Termite
A simple reverse ICMP shellhttps://github.com/inquisb/icmpshicmpsh
Forward/reverse proxy, intranet penetration, port forwardinghttps://github.com/inconshreveable/ngrokskirt
Pingtunnel is a tool for forwarding tcp/udp/sock5 traffic disguised as icmp traffichttps://github.com/esrrhs/pingtunnelping tunnel
pystinger – An out-of-network tool that uses webshell for traffic forwardinghttps://github.com/FunnyWolf/pystingerpystinger
goproxy is a lightweight, powerful, high-performance proxy toolhttps://github.com/snail007/goproxygoproxy
A tool that can perform reverse proxy and cs online without going onlinehttps://github.com/Daybr4ak/C2ReverseProxyC2ReverseProxy

Lateral movement tool

Project Descriptionproject addressproject name
Mimikatz Windows Password Grabberhttps://github.com/gentilkiwi/mimikatzmimikatz
sharpwmi rpc-based lateral movement tool with upload and execute command functionshttps://github.com/QAX-A-Team/sharpwmisharpwmi
File download command is generated quicklyhttps://forum.ywhack.com/bountytips.php?downloadshortcut command
One-click generation of rebound shell commandshttps://forum.ywhack.com/shell.phpbounce shell
ATT&CK Lateral Movement Summary Tipshttps://attack.mitre.org/tactics/TA0008/attack
Pass hash to named pipe for token impersonationhttps://github.com/S3cur3Th1sSh1t/NamedPipePTHNamedPipePTH
Common lateral movement and domain control authority maintenance methodshttps://xz.aliyun.com/t/9382Methodology

Password Extraction Tool

Project Descriptionproject addressproject name
Various password extractionhttps://github.com/kerbyj/goLazagnegoLazagne
Used to read common program passwords, such as Navicat, TeamViewer, FileZilla, WinSCP, etc.https://github.com/RowTeam/SharpDecryptPwdSharpDecryptPwd
Xshell, Xftp password decryption toolhttps://github.com/JDArmy/SharpXDecryptSharpXDecrypt
An export tool for decrypting browser data (password|history|cookie|bookmark|credit card|download record), supporting mainstream browsers on all platforms.https://github.com/moonD4rk/HackBrowserData/HackBrowserData
An identification code and verification code extraction tool for sunflowerhttps://github.com/wafinfo/Sunflower_get_PasswordSunflower_get_Password
One-click CobaltStrike script to assist in grabbing 360 secure browser passwords and decryption gadgetshttps://github.com/hayasec/360SafeBrowsergetpass360SafeBrowsergetpass
BrowserGhost tool to grab browser passwordshttps://github.com/QAX-A-Team/BrowserGhostBrowserGhost
win-brute-logon cracks any Microsoft Windows user password without permissionhttps://github.com/DarkCoderSc/win-brute-logonwin-brute-logon
TeamViewer: Bypass anti-software tool to obtain Teamview passwordhttps://github.com/wafinfo/TeamViewerTeamViewer
Xdecrypt Xshell Xftp password decryptionhttps://github.com/dzxs/XdecryptXdecrypt

https://reconshell.com/all-defense-tool/