Red Team Operations

Offensive Security
Tools & Techniques

7
Tool Modules
43
AD Attack Paths
6
Breach Scenarios
7
India Pretexts
MITRE
ATT&CK Mapped
⚠️ All content is for authorised penetration testing and security education only. Unauthorised use is illegal under IT Act 2000. Always obtain written authorisation before any offensive testing.
CRITKerberoasting → RC4 hash → offline crack → Domain Admin| HIGHLSASS dump via procdump → Mimikatz → Pass-the-Hash| CRITDCSync from non-DC account → all NTLM hashes extracted| HIGHADCS ESC1 → certificate request → Domain Admin impersonation| MEDSSRF → AWS IMDSv1 → IAM credentials → cloud pivot| CRITRBI circular phish → macro dropper → Sliver implant| HIGHBloodHound path: GenericAll → Shadow Credentials → DA| MEDAMSI bypass via AmsiScanBuffer patch → reflective load| CRITKerberoasting → RC4 hash → offline crack → Domain Admin| HIGHLSASS dump via procdump → Mimikatz → Pass-the-Hash| CRITDCSync from non-DC account → all NTLM hashes extracted| HIGHADCS ESC1 → certificate request → Domain Admin impersonation| MEDSSRF → AWS IMDSv1 → IAM credentials → cloud pivot| CRITRBI circular phish → macro dropper → Sliver implant| HIGHBloodHound path: GenericAll → Shadow Credentials → DA| MEDAMSI bypass via AmsiScanBuffer patch → reflective load|
Attack Phases
01
🎯
Recon & Phishing
India pretexts, GoPhish, SMTP relay, campaign metrics
02
🎭
Payloads & Evasion
PowerShell obfuscation, AMSI bypass, VBA macros, .NET injection
03
📡
C2 & Persistence
Cobalt Strike, Sliver, Havoc, redirectors, malleable profiles
04
🏰
Active Directory
Kerberoast, DCSync, BloodHound, 43 attack paths, KQL detections
05
🌐
Web, Cloud & OPSEC
SQLi, JWT, SSRF→IMDS, XXE, LOLBins, assume-breach scenarios
🎯

Reconnaissance & Phishing Simulation

India-specific pretexts, GoPhish setup, SMTP relay options, campaign benchmarks

Interactive📧

India Phishing Pretexts

7 India-specific pretexts: RBI, CERT-In, GST, TRAI, HR/Salary, MCA. GoPhish setup + SMTP relay options.

Interactive🔍

OSINT Target Profiler

Generate recon checklist for a target org — LinkedIn, Shodan, GitHub, DNS, email harvesting.

🎭

Payload Crafting & AV Evasion

PowerShell obfuscation, AMSI bypass, VBA macros, .NET injection techniques

Reference🎭

Payload Obfuscation

PowerShell base64, IEX cradles, AMSI bypass, VBA Chr() arrays, .NET reflection injection.

Interactive🕶

EDR Evasion Selector

Pick your target EDR and get recommended evasion techniques and detection gaps.

📡

C2 Frameworks & Persistence

Cobalt Strike, Sliver, Havoc, Brute Ratel — redirectors, malleable profiles, detection sigs

Reference📡

C2 Framework Comparison

Cobalt Strike vs Sliver vs Havoc vs Metasploit — protocols, evasion, detection signatures.

Reference🔒

Persistence Techniques

Registry run keys, scheduled tasks, WMI subscriptions, DLL hijacking, service installation.

🏰

Active Directory Attacks

Kerberoasting, DCSync, BloodHound, Pass-the-Hash, ADCS abuse — with KQL detections

Reference🏰

AD Attack Reference

8 core techniques with commands, Event IDs, KQL detections, and mitigations.

Interactive📊

Attack Path Simulator

Select your starting position and get the most likely path to Domain Admin.

MITRE ATT&CK — AD Techniques
T1558.003
Kerberoasting

TGS request for SPN accounts → offline crack

T1558.004
AS-REP Roasting

No pre-auth accounts → hash offline

T1003.006
DCSync

Mimic DC replication → all hashes

T1550.002
Pass-the-Hash

NTLM hash auth without cracking

T1558.001
Golden Ticket

Forge TGT with KRBTGT hash

T1003.001
LSASS Dump

Extract creds from LSASS memory

T1069.002
BloodHound

Graph-based AD attack path enum

T1557.001
NTLM Relay

Responder → ntlmrelayx pivot

T1649
ADCS ESC1

Cert template abuse → DA cert

T1484.001
GPO Abuse

Modify GPO → scheduled task exec

🌐

Web App, Cloud & OPSEC

SQLi, JWT attacks, SSRF→IMDS, XXE, GraphQL, LOLBins, assume-breach scenarios

Reference🌐

Web App Attack Reference

SQLi payloads, SSRF→cloud IMDS, JWT attacks, XXE, GraphQL abuse techniques.

Reference🕶

OPSEC Reference

Top 10 OPSEC failures, log sources that see you, LOLBins quick reference.

Interactive🎯

Assume Breach Scenarios

6 India-context scenarios: BFSI, IT sector, cloud, insider, supply chain, ransomware.

Interactive📊

Engagement Scorer

Score your red team engagement across detection, response, and coverage dimensions.

🔒

Tool