📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping #LSASS

📦 项目名称: Cloud-Native-Threat-Hunting
👤 项目作者: Spica581
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-24 18:23:49

📝 项目描述:
Cloud-native threat hunting case study using Splunk Cloud to detect MITRE ATT&CK T1003.001 (LSASS Memory Dumping). Features custom SPL and runtime regex (rex) log parsing of raw Sysmon telemetry to isolate credential theft.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping #LSASS #Mimikatz

📦 项目名称: Volatility3-Memory-Analysis-Playbook
👤 项目作者: ilyess-sellami
🛠 开发语言: Unknown
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-18 19:01:57

📝 项目描述:
A structured DFIR playbook for analyzing memory dumps using Volatility 3. This repository provides a question-driven workflow for investigating volatile memory artifacts, suspicious processes, network connections, persistence mechanisms, credential dumping activity, and attacker behavior during incident response and CTF investigations.

🔗 点击访问项目地址 GitHub - ilyess-sellami/Volatility3-Memory-Analysis-Playbook: A structured DFIR playbook for analyzing memory dumps using Volatility…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Enterprise-SOC-Homelab-Threat-Detection-Engineering-Project
👤 项目作者: Nourmohamed2
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-19 22:59:05

📝 项目描述:
Built an enterprise SOC homelab using ELK Stack, Active Directory, Sysmon, and Winlogbeat for centralized log monitoring and threat detection. Simulated real-world attacks including brute force, reverse shells, credential dumping, and lateral movement with custom detections mapped to MITRE ATT&CK.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Endpoint-Detection-and-Response-EDR-LimaCharlie
👤 项目作者: omcyber10
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-16 22:51:59

📝 项目描述:
Hands-on Endpoint Detection & Response (EDR) lab using LimaCharlie to simulate and investigate LSASS credential dumping activity, endpoint telemetry, and SOC investigation workflows.

🔗 点击访问项目地址 GitHub - omcyber10/Endpoint-Detection-and-Response-EDR-LimaCharlie: Hands-on Endpoint Detection & Response (EDR) lab using LimaCharlie…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Pentest-lab-project
👤 项目作者: JOHNNY210702
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-12 13:02:49

📝 项目描述:
Simulated internal Active Directory penetration test demonstrating enumeration, lateral movement, credential dumping, and full domain compromise in a VMware lab environment.

🔗 点击访问项目地址 JOHNNY210702/Pentest-lab-project
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: -Active-Directory-Kill-Chain-
👤 项目作者: vetementsvmnts
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-12 10:02:16

📝 项目描述:
Critical concepts demonstrated: Kerberoasting, AS-REP roasting, DCSync BloodHound attack path analysis Lateral movement (PSExec, WMI, WinRM) Credential dumping (LSASS, SAM)

🔗 点击访问项目地址 GitHub - vetementsvmnts/-Active-Directory-Kill-Chain-: Critical concepts demonstrated: Kerberoasting, AS-REP roasting, DCSync BloodHound…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Volatility-3-Memory-Analysis-Playbook
👤 项目作者: ilyess-sellami
🛠 开发语言: None
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-11 16:48:35

📝 项目描述:
A structured DFIR playbook for analyzing memory dumps using Volatility 3. This repository provides a question-driven workflow for investigating volatile memory artifacts, suspicious processes, network connections, persistence mechanisms, credential dumping activity, and attacker behavior during incident response and CTF investigations.

🔗 点击访问项目地址 GitHub - ilyess-sellami/Volatility-3-Memory-Analysis-Playbook: A structured DFIR playbook for analyzing memory dumps using Volatility…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Windows10-Privilege-Escalation-Lab
👤 项目作者: ajx77
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-06 07:02:02

📝 项目描述:
Windows 10 exploitation and privilege escalation lab using SMB enumeration, remote command execution, credential dumping, and NTLM hash cracking.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Incident-Response-lab
👤 项目作者: gaurav-koshti-CySA
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-04 03:56:06

📝 项目描述:
End-to-end incident response simulation: T1003.001 LSASS credential dumping detection & remediation with Wazuh SIEM and formal incident report

🔗 点击访问项目地址 GitHub - gaurav-koshti-CySA/Incident-Response-lab: End-to-end incident response simulation: T1003.001 LSASS credential dumping…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Windows-10-Crendential-Attack-Pentesting
👤 项目作者: KiMiRoTa
🛠 开发语言: None
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-02 07:12:03

📝 项目描述:
This repository is my university project about simulating credential dumping and privilege escalation in a Windows Active Directory environment

🔗 点击访问项目地址 GitHub - KiMiRoTa/Windows-10-Crendential-Attack-Pentesting: This repository is my university project about simulating credential…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Active-Directory-Pentest-Lab
👤 项目作者: ajx77
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-29 06:59:03

📝 项目描述:
Built and exploited a self-hosted Active Diretory Lab Simulation real-world attack scenarios including enumeration, lateral movement, and credential dumping.

🔗 点击访问项目地址 GitHub - ajx77/Active-Directory-Pentest-Lab: Built and exploited a self-hosted Active Diretory Lab Simulation real-world attack…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: slinger
👤 项目作者: FalconOpsLLC
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-28 01:31:32

📝 项目描述:
FalconOps fork of slinger: live-read SAM/LSA/DCC credential dumping over SMB with no hive file written on target.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Detection-of-Suspicious-LSASS-Dump-Activity-via-PowerShell-CMD-in-Splunk
👤 项目作者: KillerInstinct7
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-27 23:32:11

📝 项目描述:
Built and validated a Splunk detection for PowerShell or cmd activity executing from or referencing a temporary directory where the command line references an LSASS dump file (lsass.DMP). This behavior may indicate credential dumping or unauthorized access to sensitive system memory artifacts.

🔗 点击访问项目地址 GitHub - KillerInstinct7/Detection-of-Suspicious-LSASS-Dump-Activity-via-PowerShell-CMD-in-Splunk: Built and validated a Splunk…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Windows-10-Crendential-Attack-Lab
👤 项目作者: KiMiRoTa
🛠 开发语言: None
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-23 04:08:45

📝 项目描述:
This repository is my university project about simulating credential dumping and privilege escalation in a Windows Active Directory environment

🔗 点击访问项目地址 GitHub - KiMiRoTa/Windows-10-Crendential-Attack-Pentesting: This repository is my university project about simulating credential…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: WIndows-Crendential-Attack-Lab
👤 项目作者: KiMiRoTa
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-22 09:58:06

📝 项目描述:
This repository is my university project about simulating credential dumping and privilege escalation in a Windows Active Directory environment

🔗 点击访问项目地址 GitHub - KiMiRoTa/WIndows-Crendential-Attack-Lab: This repository is my university project about simulating credential dumping…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Wazuh-Splunk-SOC-Lab
👤 项目作者: Yelazhar
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-19 14:16:09

📝 项目描述:
Monitoring Windows (Sysmon) and Debian VMs. I use Wazuh to parse and filter telemetry before forwarding to Splunk, keeping the daily volume under the 500MB license limit. Focuses on efficient indexing and alert tuning. Tested via Atomic Red Team to verify detection logic for process injection and credential dumping.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Active-Directory-Breach-Investigation-EmberForge
👤 项目作者: jasonstokes1
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-18 13:24:42

📝 项目描述:
Full Active Directory breach investigation involving credential dumping, lateral movement, and data exfiltration using Microsoft Sentinel.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: Active-Directory-Penetration-Testing-PNPT-Study-Guide
👤 项目作者: jayshalwala
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-09 10:40:09

📝 项目描述:
It covers everything from initial network attacks like LLMNR poisoning and SMB relay, all the way through to post-compromise techniques including Kerberoasting, token impersonation, credential dumping, and Golden Ticket attacks. Every command has been tested in a home lab and the guide includes a full mitigation and defenses section as well.

🔗 点击访问项目地址 GitHub - jayshalwala/Active-Directory-Penetration-Testing-PNPT-Study-Guide: It covers everything from initial network attacks like…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: MITRE-ATT-CK-TTPs-Mapping-to-Active-Directory-AD-Attacks
👤 项目作者: d0midigi
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-07 18:15:54

📝 项目描述:
Comprehensive mapping of Active Directory (AD) attacks to the MITRE ATT&CK® framework. Covers TTPs for credential dumping, lateral movement, persistence, and privilege escalation with detection rules, attack simulations, and mitigation strategies for Windows/AD environments. Focuses on actionable threat intel.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping

📦 项目名称: soc-investigation-windows-compromise
👤 项目作者: Friendlyfoldman
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-04-07 16:00:47

📝 项目描述:
SOC-style investigation of a compromised Windows system (TryHackMe lab), identifying credential dumping (Mimikatz), attacker tooling, and post-exploitation activity.

🔗 点击访问项目地址 GitHub - Friendlyfoldman/soc-investigation-windows-compromise: SOC-style investigation of a compromised Windows system (TryHackMe…
 
 
Back to Top