Skip to content

Popular repositories Loading

  1. malleable-c2 malleable-c2 Public

    Cobalt Strike Malleable C2 Design and Reference Guide

    1.8k 299

  2. domainhunter domainhunter Public

    Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

    Python 1.7k 289

  3. red-team-scripts red-team-scripts Public

    A collection of Red Team focused tools, scripts, and notes

    PowerShell 1.1k 196

  4. random_c2_profile random_c2_profile Public

    Cobalt Strike random C2 Profile generator

    Python 690 90

  5. cs2modrewrite cs2modrewrite Public

    Convert Cobalt Strike profiles to modrewrite scripts

    Python 608 116

  6. metatwin metatwin Public

    The project is designed as a file resource cloner. Metadata, including digital signature, is extracted from one file and injected into another.

    HTML 374 77

Repositories

Showing 10 of 22 repositories
  • threatexpress/redteamguide's past year of commit activity
    HTML 15 8 0 0 Updated Aug 17, 2026
  • threat-mitigation Public

    Threat Mitigation Strategies

    threatexpress/threat-mitigation's past year of commit activity
    29 9 0 0 Updated Aug 11, 2026
  • edc Public

    Event Data Collector

    threatexpress/edc's past year of commit activity
    Python 40 MIT 6 0 7 Updated Mar 23, 2026
  • procdot_sandbox Public

    ProcDot Malware Sandbox

    threatexpress/procdot_sandbox's past year of commit activity
    Python 28 MIT 6 0 0 Updated Jul 28, 2025
  • threatexpress Public
    threatexpress/threatexpress's past year of commit activity
    HTML 14 4 0 0 Updated Apr 6, 2025
  • portplow Public

    PortPlow is a distributed port and system scanning & enumeration service. It enables the quick and automated enumeration of ports and services from multiple systems managed by a central console.

    threatexpress/portplow's past year of commit activity
    JavaScript 57 MIT 10 0 0 Updated Nov 19, 2024
  • threatbox Public

    ThreatBox is a standard and controlled Linux based attack platform. I've used a version of this for years. It started as a collection of scripts, lived as a rolling virtual machine, existed as code to build a Linux ISO, and has now been converted to a set of ansible playbooks. Why Ansible? Why not? This seemed a natural evolution.

    threatexpress/threatbox's past year of commit activity
    Smarty 77 MIT 14 1 0 Updated Nov 19, 2024
  • pasties Public

    A collection of random bits of information common to many individual penetration tests, red teams, and other assessments

    threatexpress/pasties's past year of commit activity
    Shell 114 MIT 33 0 0 Updated Nov 19, 2024
  • aggressor-scripts Public

    Cobalt Strike Aggressor Scripts

    threatexpress/aggressor-scripts's past year of commit activity
    JavaScript 142 MIT 19 0 0 Updated Nov 19, 2024
  • metatwin Public

    The project is designed as a file resource cloner. Metadata, including digital signature, is extracted from one file and injected into another.

    threatexpress/metatwin's past year of commit activity
    HTML 374 MIT 77 2 1 Updated Nov 19, 2024

Top languages

Loading…

Most used topics

Loading…