This is your work, valued
Cybersecurity Engineer.
badusb_botnet. :busts_in_silhouette::smiling_imp: Infect a pc with badusb and establish a connection through telegram.
★ 191A-Detector. :star: An anomaly-based intrusion detection system.
★ 85offensive-vlang. POCs to test Vlang in cybersecurity aspects.
★ 37CVE-Search. CVE-Search (name still in alpha), is a Machine Learning tool focused on the detection of exploits or proofs of concept in social networks such as Twitter, Github. It is also capable of doing related searches on Google, Yandex, DuckDuckGo on CVEs and detecting if the content may be a functional exploit, a proof of concept or simply information about the vulnerability.
★ 26iSOC. :bar_chart: Deploy an "illegal" SOC to manage vulnerabilities on your city servers in minutes.
★ 20CVE-2020-7200. CVE-2020-7200: HPE Systems Insight Manager (SIM) RCE PoC
★ 6gomitm. :construction: An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers written in go.
★ 5happy_iqy. :email::smiling_imp: Example of spread phishing with '.iqy' files with ruby on rails server.
★ 5C-SAST. An automated web application source code vulnerability detection application with machine learning.
★ 4docker-responder. Docker-based platform for conducting MultiRelay attacks using Responder.
★ 3CMS_version_detector_PoC. A Machine Learning application that detects versions of WordPress with Multi-Class classification algorithms.
★ 3Exploits. Ruby
★ 2yaxss. Yet another XSS fuzzer.
★ 2nessrest. A python library for using the new Nessus REST API.
★ 1HACKtheCITY. :city_sunset: Hack the city with one click. *Include script kiddie protection
★ 1PAScanner. :warning: **OUTDATED** Scanner that analyzes WebApps coming from a zip code.
★ 1SysWhispers4. AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64
★ 544osed-scripts. bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)
★ 622Voidmaw. A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders implemented by C2 beacons) or other problematic executables that will be flagged by the antimalware programs(such as mimikatz).
★ 361Kaonashi. Wordlist, rules and masks from Kaonashi project (RootedCON 2019)
★ 1.1ksliver. Adversary Emulation Framework
★ 12kMythic. A collaborative, multi-platform, red teaming framework
★ 4.7kRedWarden. Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation
★ 997Ghost. Evasive shellcode loader
★ 403RemoteShellcodeExec. Execute shellcode from a remote-hosted bin file using Winhttp.
★ 235Kraken. Kraken, a modular multi-language webshell coded by @secu_x11
★ 555PPLSystem. Rust
★ 209ThreatHunting-Keywords. Awesome list of keywords and artifacts for Threat Hunting sessions
★ 670FindFrontableDomains. Search for potential frontable domains
★ 649deepdarkCTI. Collection of Cyber Threat Intelligence sources from the deep and dark web
★ 7.1kClear-NDR-ISO. A Suricata based NDR distribution
★ 1.6kDefaultCreds-cheat-sheet. One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
★ 6.7kFreeze. Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods
★ 1.5kuncover. Quickly discover exposed hosts on the internet using multiple search engines.
★ 3kdot. The Deepfake Offensive Toolkit
★ 4.6kshennina. Automating Host Exploitation with AI
★ 557AmsiScanBufferBypass. Bypass AMSI by patching AmsiScanBuffer
★ 284HelloWord-Keyboard. C
★ 6.6kcloud-gpus. This repository contains information about Cloud GPU offerings for Machine Learning practitioners.
★ 469GoBypassAV. 整理了基于Go的16种API免杀测试、8种加密测试、反沙盒测试、编译混淆、加壳、资源修改等免杀技术,并搜集汇总了一些资料和工具。
★ 1.2kPyramid. a tool to help operate in EDRs' blind spots
★ 772attack_data. A repository of curated datasets from various attacks
★ 795wardriver_rev3. A portable ESP32-based WiFi/Bluetooth scanner for Wigle.net.
★ 360Focaccia-Board. Multipurpose Breakout for the FT232H
★ 96websitesVulnerableToSSTI. Simple websites vulnerable to Server Side Template Injections(SSTI)
★ 425OSWE. OSWE Preparation
★ 686SonarSearch. A rapid API for the Project Sonar dataset
★ 653Meross. Investigating the Meross / Refoss MSS310 Smart Plug and getting these devices to communicate with our private MQTT brokers
★ 140mss310-kontrol. Meros MSS310 Control and Information of API operations
★ 7b-parasite. 🌱💧 An open source DIY soil moisture sensor
★ 2.4kMerossIot. Async Python library for controlling Meross devices
★ 533flower. DIY Zigbee flower sensor
★ 430echidna. Ethereum smart contract fuzzer
★ 3.2kunredacter. Never ever ever use pixelation as a redaction technique
★ 8.4kpowerlevel10k. A Zsh theme
★ 55kethersplay. EVM dissassembler
★ 858generative-art-nft. A generative art library for NFT avatar and collectible projects.
★ 755nft-mix. Solidity
★ 807Sensor-Watch. A board replacement for the classic Casio F-91W wristwatch
★ 2ksigma_to_wazuh. Convert Sigma rules to Wazuh rules
★ 77nft-minting-website-example. Example website with NFT Minting Features
★ 51chipshouter-picoemp. Why not run micropython on your EMFI tool?
★ 752ZipExec. A unique technique to execute binaries from a password protected zip
★ 1kRoomba980-Python. Python program and library to control iRobot Roomba 980 Vacuum Cleaner
★ 445ntlm_theft. A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)
★ 1.5kSharpShooter. Payload Generation Framework
★ 2kdocker-cuckoo. Cuckoo Sandbox Dockerfile
★ 332flare-vm. A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.
★ 8.9kmisp2elastalert. Convert MISP events to Elastalert rules
★ 12ShellcodeFluctuation. An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents
★ 1.1kk8s-security-elasticsearch. Kubernetes Elasticsearch Secure Cluster Example
★ 12elasticsearch-kubernetes. Deploy Elasticsearch cluster on Kubernetes
★ 8PR0CESS. some gadgets about windows process and ready to use :)
★ 616muraena. Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
★ 1.1kcommunity. Kubernetes Community Documentation
★ 13kS1EM. This project is a SIEM with SIRP and Threat Intel, all in one.
★ 463DetectionLab. Automate the creation of a lab environment complete with security tooling and logging best practices
★ 5kdockerfiles. 🌊 Dockerfiles for apps I use. Also take a look at https://github.com/security-dockerfiles
★ 25SigFlip. SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
★ 1.3kDigiBruteDroid. A 4-Digit PIN Brute Force attack for USB-OTG Android devices
★ 54Callback_Shellcode_Injection. POCs for Shellcode Injection via Callbacks
★ 415Active-Directory-Exploitation-Cheat-Sheet. A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
★ 6.7kPSBits. Simple (relatively) things allowing you to dig a bit deeper than usual.
★ 3.5kADTimeline. Timeline of Active Directory changes with replication metadata
★ 532sigma. Main Sigma Rule Repository
★ 11kawesome-threat-detection. ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
★ 4.7kERC.Xdbg. An Xdbg Plugin of the ERC Library.
★ 190OffensiveNim. My experiments in weaponizing Nim (https://nim-lang.org/)
★ 3.1kOneWordlistToListThemAll. OneWordlistToListThemAll is a huge mix of password wordlists, useful to provide some quick hits when cracking many hashes
★ 135CVE-2021-1675. Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
★ 1.1kRustScan. 🤖 The Modern Port Scanner 🤖
★ 20kkali-clean. my kali desktop setup
★ 330CVE-2021-1675. C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
★ 2kpwndoc. Pentest Report Generator
★ 2.9kRWCTF21-VirtualBox-61-escape. 0day VirtualBox 6.1.2 Escape for RealWorld CTF 2020/2021 CVE-2021-2119
★ 148tpotce. 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
★ 9.4kevtx. A Fast (and safe) parser for the Windows XML Event Log (EVTX) format
★ 941WiFi_CCC. Wi-Fi Covert Channel Chat demo application
★ 1WebShell. Webshell && Backdoor Collection
★ 2kPeerlyst-Articles-Collection.
★ 14Litmus_Test. Detecting ATT&CK techniques & tactics for Linux
★ 258python-vimrc. VIM Configuration for Python / Cython / C Development
★ 652flask-active-directory. Active Directory (LDAP) login with Flask
★ 7opencve. Vulnerability Intelligence Platform
★ 2.8kArduino-TouchScreen-Buttons. Library for drawing buttons to the Seeed Studio TFT touch screen
★ 5freedeck-hardware. all the stuff you need to build your own FreeDeck
★ 771colabcat. :smiley_cat: Running Hashcat on Google Colab with session backup and restore.
★ 743CVE-2020-16898-EXP-POC. CVE-2020-16898 Windows TCP/IP远程代码执行漏洞 EXP&POC
★ 5twint. An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.
★ 16kpractical-nlp-code. Official Repository for Code associated with 'Practical Natural Language Processing' book by O'Reilly Media
★ 1.5kGSoC-2020. This repo works on developing proof of concepts for some tasks.
★ 3cybersecurity_threat_severity_analysis. Code for "Analyzing the Perceived Severity of Cybersecurity Threats Reported on Social Media".
★ 25exploitdb. The legacy Exploit Database repository - New repo located at https://gitlab.com/exploit-database/exploitdb
★ 7.9kwindows_hardening. HardeningKitty and Windows Hardening Settings
★ 2.6kCheatsheets. Helped during my OSCP lab days.
★ 820local-cert-generator. 🚀 A set of scripts to quickly generate a HTTPS certificate for your local development environment.
★ 971CVE-2020-14882. CVE-2020–14882、CVE-2020–14883
★ 288gadgetinspector. A byte code analyzer for finding deserialization gadget chains in Java applications
★ 1.1kreact-native-whatsapp-ui. Pure javascript UI prototype of Whatsapp for React Native framework.
★ 161ThreatHunting. An informational repo about hunting for adversaries in your IT environment.
★ 1.9kwindows-BSOD.
★ 23hubble. Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event notifications, alerting, and reporting.
★ 385first-order-model. This repository contains the source code for the paper First Order Motion Model for Image Animation
★ 15kwebanalyze. Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.
★ 1.2kosquery-attck. Mapping the MITRE ATT&CK Matrix with Osquery
★ 811instagram_bot. Machine Learning Instagram Bot
★ 14user-behavior-anomaly-detector. User anomaly detector based on logs generated by Osquery framework and machine learning to process those logs.
★ 33nuclei. Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
★ 30kjaeles. The Swiss Army knife for automated Web Application Testing
★ 2.4kasync_flask. Test of asynchronous flask communication with web page.
★ 217NCTU_deep_learning_fall2019. my projects following nctu's deep learning course.
★ 3Real-Time-Voice-Cloning. Clone a voice in 5 seconds to generate arbitrary speech in real-time
★ 60kYelp_review_generation. How to generate realistic yelp restaurant reviews with Keras
★ 71deep-generation. I used in this project a reccurent neural network to generate c code based on a dataset of c files from the linux repository.
★ 109Win-PS2EXE. Graphical frontend to PS1-to-EXE-compiler PS2EXE.ps1
★ 378graudit. grep rough audit - source code auditing tool
★ 1.7kblindSQLi. A python based blind SQL injection exploitation script
★ 144proxmark3. Iceman Fork - Proxmark3
★ 5.9khoneybits-win. Windows version of honeybits - a PoC tool to create breadcrumbs and honeytokens, to lead the attackers to your honeypots!
★ 24honeybits. A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward your honeypots
★ 278WiFiKeylogger. Simple Wi-Fi Keylogger with multiple layout support.
★ 27xray. 一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档
★ 12kail-framework. AIL framework - Analysis Information Leak framework
★ 983uriDeep. Unicode encoding attacks with machine learning
★ 98openvasrun. This script can scan a large number of IP addresses with Openvas and allows throttling the maximum number of concurrent scans.
★ 5openvas. openvas 8 docker image compiled from source on debian 8
★ 1gpt-2. Code for the paper "Language Models are Unsupervised Multitask Learners"
★ 25krfid. Arduino RFID Library for MFRC522
★ 3kdocument. Dockerfile
★ 2docker-elk. The Elastic stack (ELK) powered by Docker and Compose.
★ 18kPHP-Vuln-test-suite-generator. PHP synthetic test cases generator
★ 10TAP. TAP: A Static Analysis Model for PHP Vulnerabilities Based on Token and Deep Learning Technology
★ 14SourceCodeClassification. Python
★ 6PEASS-ng. PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
★ 20kffuf. Fast web fuzzer written in Go
★ 16kNosql-MongoDB-injection-username-password-enumeration. Using this script, you can enumerate Usernames and passwords of Nosql(mongodb) injecion vulnerable web applications.
★ 174machine_learning_security. Source code about machine learning and security.
★ 2.1kvulnx. vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.
★ 2.1kHackingNeuralNetworks. A small course on exploiting and defending neural networks
★ 2.6kJava-Deserialization-Scanner. All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
★ 802blog-tutorials. :star: Codebase for various tutorials about Java, Spring Boot, AWS, Kotlin, and Testing
★ 809vulncode-db. Vulncode-DB project
★ 573pwnagotchi. (⌐■_■) - Deep Reinforcement Learning instrumenting bettercap for WiFi pwning.
★ 9.2kawesome-source-analysis. Source code understanding via Machine Learning techniques
★ 139SySeVR. HTML
★ 357coursera-deeplearning.ai-Sequence-Models-Course-5. Jupyter Notebook
★ 24Text-Classification. Text Classification through CNN, RNN & HAN using Keras
★ 237vulhub. Pre-Built Vulnerable Environments Based on Docker-Compose
★ 21kMulti-Class-Classification-Project-2-IRIS-DataSet. Jupyter Notebook
★ 1xss2png. PNG IDAT chunks XSS payload generator
★ 215gym-malware. Python
★ 637dostackbufferoverflowgood. C
★ 1.4kNetworkAttackSimulator. An environment for testing AI pentesting agents against a simulated network.
★ 209oscp. General Notes and files for OSCP Study
★ 9awesome-ml-for-cybersecurity. :octocat: Machine Learning for Cyber Security
★ 9.2kGyoiThon. GyoiThon is a growing penetration test tool using Machine Learning.
★ 18homemade-machine-learning. 🤖 Python examples of popular machine learning algorithms with interactive Jupyter demos and math being explained
★ 25kIntensio-Obfuscator. Obfuscate a python code 2.x and 3.x
★ 647Deep-Reinforcement-learning-Mountain-Car. Reinforcement Learning DQN - using OpenAI gym Mountain Car
★ 23GyoiThon. GyoiThon is a growing penetration test tool using Machine Learning.
★ 825ergo-pe-av. 🧠 🦠 An artificial neural network and API to detect Windows malware, based on Ergo and LIEF.
★ 182trivy. Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
★ 37kcdb. Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively monitor and intercept HTTP requests and responses.
★ 72lstm_lyrics. LSTM text generation by word. Used to generate lyrics from a corpus of a music genre.
★ 82linux-exploit-suggester. Linux privilege escalation auditing tool
★ 6.6ksonar-findbugs. SpotBugs plugin for SonarQube
★ 381examples. Home for Elasticsearch examples available to everyone. It's a great way to get started.
★ 2.7kkeras-rl. Deep Reinforcement Learning for Keras.
★ 5.5kchainerrl. ChainerRL is a deep reinforcement learning library built on top of Chainer.
★ 1.2kPixi. The Pixi module is a MEAN Stack web app with wildly insecure APIs!
★ 140API-fuzzer. API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities
★ 408API-Security-Checklist. Checklist of the most important security countermeasures when designing, testing, and releasing your API
★ 23kFacebook-Messenger-Bot. Facebook chatbot that I trained to talk like me using Seq2Seq
★ 709jekyll-jacman. A fresh looking and responsive theme for Jekyll
★ 92wavsep. The Web Application Vulnerability Scanner Evaluation Project
★ 238SAIVS. SAIVS (Spider Artificial Intelligence Vulnerability Scanner).
★ 54monitoring-analytics. R statistical computing and graphic tool for Zabbix monitoring metrics from data scientists
★ 29UltimateAppLockerByPassList. The goal of this repository is to document the most common techniques to bypass AppLocker.
★ 2.1kLinEnum. Scripted Local Linux Enumeration & Privilege Escalation Checks
★ 8kdirty_sock. Linux privilege escalation exploit via snapd (CVE-2019-7304)
★ 681PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kAPT_CyberCriminal_Campagin_Collections. APT & CyberCriminal Campaign Collection
★ 4.1kp0wny-shell. Single-file PHP shell
★ 2.8kQRLJacking. QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.
★ 1.6kspark-iforest. Isolation Forest on Spark
★ 237Stream4Flow. A framework for the real-time network traffic analysis based on world-leading technologies for distributed stream processing, network traffic monitoring, and visualization.
★ 103SILENTTRINITY. An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR
★ 2.3kInvoke-Obfuscation. PowerShell Obfuscator
★ 4.3kmacro_pack. macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
★ 2.3kflask-app-blueprint. Flask App Blueprint / Boilerplate including user registration/login, admin only section, CRUD on database, and more. Based on Python, Flask, PostgreSQL, et al. deployed on Heroku. The #1 starter project.
★ 220Flask-SimpleLogin. Simple Login - Login Extension for Flask
★ 204botnets. This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY
★ 3.3kjudas. Go
★ 274socialsentiment. Sentiment Analysis application created with Python and Dash, hosted at socialsentiment.net
★ 462go-sslterminator. SSL termination proxy
★ 28goenv. Isolated development environments for Go
★ 180