100 Red Team Projects: 79 rows visible, 20 marked done, and a Level 3 that lists a botnet
Projects for security students
At a glance
- What is it?
- kurogai/100-redteam-projects is a reading list rather than a toolkit: five levels of numbered project ideas for security students, each row carrying a mark for whether the author built an example. The marks are more informative than the titles, because they show the composed offensive exercises left undone while their harmless components are ticked, and the visible list stops at row 78 with the row itself unmarked.
- Who is it for?
- Treat this as a syllabus rather than a toolchain, and use the first two levels for the parts worth doing on your own machine: sockets, ciphers, file transfer and a hand-written scanner against hosts you own. Two things to settle before anything else.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Activity is slowing. The repository last received commits 6 months ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The list is numbered from zero and graded by a mark column
The repository is a README table, an images directory and a Projects directory, described as projects for security students. The framing paragraph asks readers who want to learn how to create their own tools, on the argument that building them beats becoming a script kiddie, and it recommends doing the work in whatever language they are most comfortable with. The list is then divided into levels, described as ranging from very basic to advanced, and the author is explicit that the division is based solely on personal experience. Two mechanical details matter for reading it. The numbering starts at [0] rather than [1], and every row has an Example column whose value says whether the author built a working version of that project. So the list is doing two things at once: proposing exercises and reporting personal progress, and those two are not the same thing.
Level 1 ticks the components and leaves the combinations undone
The first level is eleven rows, from a plain TCP or UDP receiver through ciphers to a Netcat clone, and the marks form a pattern. Everything that is a building block is done: the TCP and UDP chat servers, the multi-threaded variant, the file transfer server, the Caesar cipher tool, ROT13, remote command execution and Netcat. The two rows that combine two of those are not done: a chat server whose messages are Caesar encoded is marked with an x, and a UDP chat server with ROT13 encoding is also marked with an x. So the mark column is not a difficulty rating. It records that the plain socket work is finished and the composed work is not, which means the order a reader follows does not have to match the numbering.
Level 2 is where the marks thin out sharply
The Essential level holds twenty rows and only eight of them are marked done. The finished ones are clustered at the start: the simple port scanner, the two fingerprinting variants that add OS detection through TTL values and protocol footprinting, the two threaded directory brute-forcers, the FTP and SSH login brute-forcers, and the collector that gathers information about a person through Google, Bing and Yahoo. Everything from the web login brute-forcer onwards is marked undone, including the web directory work sitting next to finished rows, the FTP and MySQL user footprinting, the Google web-scan bot, the automatic comment and message bots, the regex scraper, the SQL injection tester, the cross-site scripting tester, the WordPress brute-forcer, the database retriever and the spam creator. Two inconsistencies sit in that block: FTP and SSH login brute-forcers are ticked while the web one is not, and a people-search collector is ticked among scanners.
Level 3 lists a botnet, a worm, a trojan and ransomware by name
The third level is called Advanced Network Attacks, it holds fourteen rows, and exactly one of them is marked done: an application that encrypts a file. The rest carry an x, and their titles name offensive tooling directly. There is a payload for a reverse shell, a payload to capture screenshots, a botnet implementation, a passive web scanner, an ARP poisoning tool, an application that creates random shortcuts on screen, a ransomware application, a spam email sender, an HTTP server for phishing, a honeypot creator, a client that connects to the Tor network, an IRC server and a packet capture tool. Their titles are recorded here as the list records them, and none of their mechanics are described anywhere in the repository, so nothing here can be built from this page alone. What the level does show is the shape of the intended curriculum: detection and interception work alongside the offensive half.
Level 4 puts packet analysis beside payload generators and a DDoS server
The fourth level is the longest, twenty-six rows from [45] to [70], and one row is marked done. Analysis and tooling sit on one list: packet data analysis, packet image analysis with OpenCV, a process monitor for Windows and Linux, a Windows token privilege escalation tool, a disassembler, subnet and DNS enumerators, a BurpSuite extender, a simple firewall and a gateway. Alongside them sit rows whose titles describe payload delivery: one that moves the mouse cursor, one that starts automatically through Windows Regedit, one that starts as a daemon, one that retrieves browser information, a PowerShell payload generator, a Bash payload generator, a worm, a distributed denial of service server, a trojan and a man-in-the-browser tool. The single completed row in the level is the hexdump tool, which is the least ambiguous item on it.
One row uses a plain character where the rest use a shortcode
Small formatting tells you how a table is maintained. Nineteen of the twenty completed rows record their mark as the :heavy_check_mark: shortcode, which is how GitHub renders a check inside a table cell. Row [47], the hexdump tool, records its mark as a bare check character instead, so the rendered table shows one differently shaped mark among the shortcodes. That single divergence is the only visible sign of a table assembled by hand over time rather than generated. The rest of the table is consistent in the other direction: every unfinished row uses the same :x: shortcode, and no row carries any other annotation, so there is no third state such as skipped or in progress.
The visible list stops at row 78, with that row unmarked
The title promises a hundred projects, and the rows are numbered from zero, so the numbering and the title are not expected to line up one to one. What is visible here is narrower: 79 rows, from [0] through [78], with [78] Browser exploit appearing as the last line and carrying no Example cell before the table ends. Of the 78 rows that do carry a mark, 58 are marked undone and 20 are marked done. That leaves the gap between the visible rows and the hundred in the title unaccounted for in this table, so a reader looking for items [79] and above is looking past what is written here. The page also names a parent project, kurogai/100-mitre-attack-projects, which is where the MITRE-attack-derived version of a similar list lives.
No license file, no scope rule, and a last push in March
Three things about the repository itself are worth knowing before you build anything from the list. Licensing is unsettled: the repository's license field is empty and its tree holds only .gitignore, Projects/, README.md and images/, with no license file, so the terms for reuse are not stated anywhere. Scope guidance is absent: the page never says to run these against systems you own or are authorized to test, names no rule about which targets are acceptable, and describes no dry run, logging or abort approach for any row. And the last push is dated 2026-03-29, with 2918 stars, 411 forks and a single open issue, so the list has not moved in over half a year and its marks describe one author's progress up to that point.
Editorial conclusion
Treat this as a syllabus rather than a toolchain, and use the first two levels for the parts worth doing on your own machine: sockets, ciphers, file transfer and a hand-written scanner against hosts you own. Two things to settle before anything else. First, scope: the list itself draws no boundary between an exercise you can run on your own network and one aimed at a third party, so every row beyond the basic networking work needs an authorization decision you make yourself, and the entries naming a botnet, a worm, a trojan, ransomware or a phishing server are not things to implement casually. Second, provenance: the repository has an empty license field and no license file in its tree, the visible list ends at row 78 while the title promises a hundred, and the last push is dated 2026-03-29, so what you are reading is a snapshot rather than a maintained curriculum. The author's own framing is that the division into levels is based solely on personal experience, which is worth keeping in mind when a row's placement feels arbitrary.
Frequently asked questions
How is the kurogai/100-redteam-projects list organised?
It is divided into levels described as ranging from very basic to advanced, with rows numbered from [0], and the author notes the division is based solely on personal experience. Each row has an Example column marking whether the author built a working version, which makes the column a progress record rather than a difficulty rating.
How many projects on the 100 redteam projects list have examples?
Of the 79 rows visible, [0] through [78], twenty are marked done and fifty-eight are marked undone, with row [78] carrying no mark at all. The marks cluster in the first two levels, and the third level has exactly one completed row, an application that encrypts a file.
What does the 100-redteam-projects repository contain besides the list?
Its top level is .gitignore, Projects/, README.md and images/. No license file is present and the repository's license field is empty, so the terms for reuse are not stated. The last push is dated 2026-03-29 and there is one open issue.
Does the 100 redteam projects list say what you may test?
No. The framing text asks readers to implement or study the projects so they build their own tools rather than script-kittie, but it names no authorization boundary, no target rule, no dry run and no logging or abort approach. The rows in the later levels name a botnet, a worm, a trojan, ransomware and a phishing server, and none of their mechanics are described in the repository.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/kurogai-100-redteam-projects)