操作系统持久化 ======================================== Windows ---------------------------------------- 凭证获取 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `mimikatz `_ - `RdpThief `_ Extracting Clear Text Passwords from mstsc.exe using API Hooking - `quarkspwdump `_ Dump various types of Windows credentials without injecting in any process - `SharpDump `_ C# port of PowerSploit's Out-Minidump.ps1 functionality 权限提升 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `WindowsExploits `_ - `GTFOBins `_ Curated list of Unix binaries that can be exploited to bypass system security restrictions - `JAWS `_ Just Another Windows (Enum) Script UAC Bypass ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `WinPwnage `_ UAC bypass, Elevate, Persistence and Execution methods - `UACME `_ Defeating Windows User Account Control - `UAC Bypass In The Wild `_ 隐藏 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `ProcessHider `_ Post-exploitation tool for hiding processes from monitoring applications Linux ---------------------------------------- 权限提升 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `linux exploit suggester `_ - `LinEnum `_ Scripted Local Linux Enumeration & Privilege Escalation Checks - `AutoLocalPrivilegeEscalation `_ 综合 ---------------------------------------- 凭证获取 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `sshLooterC `_ program to steal passwords from ssh - `keychaindump `_ A proof-of-concept tool for reading OS X keychain passwords - `LaZagne `_ Credentials recovery project 权限提升 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `BeRoot `_ Privilege Escalation Project - Windows / Linux / Mac RAT ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `QuasarRAT `_ C2 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `cobalt strike `_ - `Empire `_ - `pupy `_ 日志清除 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Log killer `_ Clear all logs in [linux/windows] servers Botnet ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `byob `_ Build Your Own Botnet