Skip to content
Change the repository type filter

All

    Repositories list

    • C
      8156400Updated Jul 21, 2025Jul 21, 2025
    • TrustedSec Sysinternals Sysmon Community Guide
      Shell
      1741.2k50Updated Jul 18, 2025Jul 18, 2025
    • Situational Awareness commands implemented using Beacon Object Files
      C
      2421.5k10Updated Jul 16, 2025Jul 16, 2025
    • specula

      Public
      Python
      2320300Updated Jun 10, 2025Jun 10, 2025
    • orpheus

      Public
      Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types
      Python
      4939700Updated Mar 21, 2025Mar 21, 2025
    • Tool for viewing NTDS.dit
      C#
      1417470Updated Mar 14, 2025Mar 14, 2025
    • C
      1541k10Updated Feb 26, 2025Feb 26, 2025
    • A tool for automating cracking methodologies through Hashcat from the TrustedSec team.
      Python
      2731.8k21Updated Jan 30, 2025Jan 30, 2025
    • The_Shelf

      Public
      Retired TrustedSec Capabilities
      Python
      1424800Updated Nov 25, 2024Nov 25, 2024
    • The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
      Python
      3k12k3315Updated Oct 21, 2024Oct 21, 2024
    • ptf

      Public
      The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
      Python
      1.3k5.4k61Updated Sep 22, 2024Sep 22, 2024
    • Egressbuster is a method to check egress filtering and identify if ports are allowed. If they are, you can automatically spawn a shell.
      Python
      10936712Updated Jul 30, 2024Jul 30, 2024
    • ridenum

      Public
      Rid_enum is a null session RID cycle attack for brute forcing domain controllers.
      Python
      8528711Updated Jul 28, 2024Jul 28, 2024
    • C
      21400Updated May 22, 2024May 22, 2024
    • VerifyELF

      Public
      C
      42600Updated May 6, 2024May 6, 2024
    • unicorn

      Public
      Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
      Python
      8223.9k12Updated Jan 24, 2024Jan 24, 2024
    • Windows RPC example calling stubs generated from MS-LSAT and MS-LSAD
      C
      62600Updated Jan 4, 2024Jan 4, 2024
    • C#
      2112910Updated Dec 4, 2023Dec 4, 2023
    • This script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several different sources. Written by Larry Spohn (@Spoonman1091) Payload written by Ben Mauch (@Ben0xA) aka dirty_ben
      Python
      12344541Updated Nov 30, 2023Nov 30, 2023
    • Python
      2314011Updated Oct 31, 2023Oct 31, 2023
    • C
      71610Updated Oct 11, 2023Oct 11, 2023
    • C++
      4416511Updated Sep 22, 2023Sep 22, 2023
    • Python
      2316400Updated Aug 22, 2023Aug 22, 2023
    • spoonmap

      Public
      Python
      3915012Updated Aug 1, 2023Aug 1, 2023
    • C
      1114200Updated May 17, 2023May 17, 2023
    • HTML
      3619011Updated May 11, 2023May 11, 2023
    • 5425041Updated Mar 8, 2023Mar 8, 2023
    • PowerShell
      144600Updated Jan 19, 2023Jan 19, 2023
    • tap

      Public
      The TrustedSec Attack Platform is a reliable method for droppers on an infrastructure in order to ensure established connections to an organization.
      Python
      11743010Updated Nov 17, 2022Nov 17, 2022
    • Zoinks

      Public
      Manage Engine Decrypter
      Python
      82300Updated Oct 17, 2022Oct 17, 2022