🔴 Red Team & Offensive Security
Red Team Tools for
Indian Pentesters
Free offensive security references — C2 frameworks, Active Directory attacks, payload obfuscation, OPSEC, web application attacks, and India-context phishing simulations.
8
Red Team Tools
43
AD Attack Paths
6
Assume-Breach Scenarios
7
India Phishing Pretexts
⚠️ All tools on this page are intended for authorised penetration testing, red team engagements, and security education only. Unauthorised use against systems you do not own or have explicit permission to test is illegal under the IT Act 2000 and IPC. Always obtain written authorisation before any offensive testing.
Attack Lifecycle — Tools by Phase
🔴
Core Red Team References
C2 Framework Reference
Cobalt Strike, Sliver, Havoc, Metasploit, Brute Ratel — capabilities, detection signatures, OPSEC notes, protocol reference, and redirector architecture.
Active Directory Attack Reference
Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash, LSASS dump, Golden Ticket, BloodHound, lateral movement — technique, commands, detection, and mitigation.
Payload Obfuscation Reference
PowerShell (-enc, IEX, gzip, reflection), .NET (reflective PE, injection), VBA (Chr arrays, WScript COM), JavaScript, and AMSI bypass techniques with detection for each.
Red Team OPSEC Reference
Artifact types, log sources (what sees you), infrastructure tradecraft, LOL binary reference, C2 redirector architecture, and 10 most common OPSEC failures.
🎯
Scenarios & Application Testing
Assume Breach Scenarios
6 India-context scenarios: Endpoint Foothold, Cloud Credential Compromise, Insider Threat, Ransomware Simulation, BFSI Payment System Attack, Supply Chain Compromise. Each with phases, detection opportunities, Blue Team scoring.
Web Application Attack Reference
SQLi (union, blind, time-based, WAF bypass), XSS, SSRF→cloud IMDS (AWS/Azure/GCP), IDOR/BAC, JWT (alg confusion, none), XXE, GraphQL with payloads and bypass techniques.
Phishing Simulation Reference
7 India-specific pretexts (RBI, CERT-In, GST, IT helpdesk, salary), GoPhish setup and configuration, SMTP relay options, campaign metrics benchmarks, and post-campaign awareness training.