Skip to content

Red Team Toolkit

The Red Team Toolkit is a field reference for offensive security work: methodology, reconnaissance, initial access, discovery, privilege escalation, lateral movement, and collection. It is maintained by @EvolvingSysadmin.

The content comes from hands-on lab work, penetration testing methodology, and training including TryHackMe paths. It is intended for authorized testing, education, and capture-the-flag practice.

Authorized use only

Everything here is for systems you own or have explicit written permission to test. Unauthorized access, scanning, or exploitation is illegal. Confirm the scope and rules of engagement before you start.

Sections

Section What's Inside
Methodology Frameworks that structure an engagement: MITRE ATT&CK, PTES, OWASP, NIST, SANS
Reconnaissance OSINT, DNS recon, and web application recon
Initial Access Phishing, web exploitation, network service attacks, and supporting tools
Discovery Enumeration and post-exploitation discovery on Windows, Linux, and Active Directory
Privilege Escalation Local and domain privilege escalation, credential access
Movement Lateral movement and defense evasion
Collection Persistence and exfiltration
Other Operational security and reference bookmarks

How Pages Are Organized

  • Reference pages explain why a topic matters, give the reference data in tables, and describe how I approach it
  • Tool pages cover when I reach for the tool, installation, common commands, and how to read the output
  • Pages map to the phase of an engagement they belong to

The source is on GitHub.

Happy Hacking!