# ForbiddenProgrammer/conti-pentester-guide-leak

Leaked pentesting manuals given to Conti ransomware crooks

Repository: https://github.com/ForbiddenProgrammer/conti-pentester-guide-leak
Canonical: https://ross.abutalabs.com/products/conti-pentester-guide-leak
Language: Batchfile
License Family: other
Topics: cybersecurity, pentesting, infosec, offensive-security, redteaming, cobalt-strike, ransomware, ransomware-detection, mitigation, ioc, guide, pentesting-tools, pentest-scripts
Last push: 2021-08-17T20:28:41+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1853, "days_push": 1842, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1104, forks 260 (observed 2026-08-28T04:03:36.188212+00:00)

## What it is
An archive of leaked technical training manuals originally distributed to affiliates of the Conti ransomware gang, covering attack techniques like data exfiltration, domain takeover, and Cobalt Strike usage. It serves as educational material for pentesters and a source of detection knowledge for defenders.

## Use cases
- learn how ransomware operators conduct intrusions
- study real-world pentesting tradecraft from leaked manuals
- build detection rules and IOCs for Conti-style attacks
- improve red team skills with adversary techniques
- understand post-exploitation tactics like Kerberoasting and credential dumping
- research threat actor tooling such as Cobalt Strike and Rclone

## When to choose
- you want primary-source insight into ransomware operator playbooks
- you are a defender building detections for Conti TTPs
- you are a pentester studying adversary techniques for education

## When to avoid
- you need a maintained tool or framework rather than static documents
- you cannot read Russian-language materials
- you need legally clean, licensed content for commercial use
- you are looking for step-by-step beginner pentesting tutorials in English

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: penetration-testing, security, osint
- domain: security, penetration-testing, tutorials
- platform: cross-platform
- tags: conti-ransomware, leaked-documents, red-teaming, cobalt-strike, threat-intelligence, ransomware-detection, ioc, russian-language, educational-archive, cybercrime-research

## Member repositories
- ForbiddenProgrammer/conti-pentester-guide-leak (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:36.188212+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:44:36.450385+00:00, confidence not recorded.
  - readme: https://github.com/ForbiddenProgrammer/conti-pentester-guide-leak (fetched 2026-08-28T04:03:36.188212+00:00, sha b908e3f4cbdb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
