Red Team Toolkit¶
The Red Team Toolkit is a field reference for offensive security work: methodology, reconnaissance, initial access, discovery, privilege escalation, lateral movement, and collection. It is maintained by @EvolvingSysadmin.
The content comes from hands-on lab work, penetration testing methodology, and training including TryHackMe paths. It is intended for authorized testing, education, and capture-the-flag practice.
Authorized use only
Everything here is for systems you own or have explicit written permission to test. Unauthorized access, scanning, or exploitation is illegal. Confirm the scope and rules of engagement before you start.
Sections¶
| Section | What's Inside |
|---|---|
| Methodology | Frameworks that structure an engagement: MITRE ATT&CK, PTES, OWASP, NIST, SANS |
| Reconnaissance | OSINT, DNS recon, and web application recon |
| Initial Access | Phishing, web exploitation, network service attacks, and supporting tools |
| Discovery | Enumeration and post-exploitation discovery on Windows, Linux, and Active Directory |
| Privilege Escalation | Local and domain privilege escalation, credential access |
| Movement | Lateral movement and defense evasion |
| Collection | Persistence and exfiltration |
| Other | Operational security and reference bookmarks |
How Pages Are Organized¶
- Reference pages explain why a topic matters, give the reference data in tables, and describe how I approach it
- Tool pages cover when I reach for the tool, installation, common commands, and how to read the output
- Pages map to the phase of an engagement they belong to
The source is on GitHub.