This is your work, valued
〉There's nothing more permanent than a temporary hack.
doxycannon. A poorman's proxycannon and botnet, using docker, ovpn files, tor nodes, and dante socks5 proxies
147passdb-frontend. Pivoting Frontend for Pre-Seeded Password Databases
134letsproxy. Quickly fetch Let's Encrypt certs and serve a reverse proxy
103passdb-backend. Password Breach API Server
88gorsh. A toy CTF Golang Reverse Shell w/ a Tmux-driven psuedo-C2 Interface
87hackthebox.vim. HackTheBox Vim Colorscheme
44dummyDLL. Utility for hunting UAC bypasses or COM/DLL hijacks that alerts on the exported function that was consumed.
38ino. In 'n Out - See what goes in and comes out of PEs
35DoubleTap. Password spraying on sites that require 2+ page loads and dynamic nonces
32sudophisher. A logging ASKPASS binary
29bothan. Is this IP a C2 server?
28holeysocks. Cross-Platform Reverse Socks Proxy in Go
27davil. leaking net-ntlm with webdav
25getsystem. Small utility package for manipulating Windows process tokens
24vpn_access_point. Script from VPN AP blog post
20xordump. Go
18kh. Keyhack - Golang API token/webhook validator
16msldapuac. A golang package for retrieving values from the Microsoft LDAP property, `UserAccountControl`
16sql-trainer. Practice your SQL query-fu
15dllexical. easy dll proxying in go
14amnesia. Takes unallocated memory and fills it with junk to mess with forensics tools.
13oscp_tools. A collection of scripts from around the web to be used with OSCP
11printntlm. Creates a localhost webDAV server and authenticates to it, capturing the Net-NTLM hash
11it-o. Hacky linux memory probe. Yara or Regex scan process memory
11git-ls. List (or plunder) private repos/gists to which a token has access, including those of other users
10bashynumb. Quick and Dirty Linux Enum Script from blog post -->
9interview-log. A collection of interview questions and their answers
7all-yar-secrets. Yara rules for finding secrets
7xbox-api. An API wrapper for xboxapi.com
7atreus-firmware. Firmware for the atreus keyboard
5nx. a tmux-driven, reverse shell manager with an identity crisis
5rpcls. List running processes that are acting as DCE/RPC servers or clients
5go-ntlm. Go
4exploit-database. The official Exploit Database repository
3meterpreter. WiFi Pineapple interface for persistent meterpreter sessions
3hera. Automated secure tunnels for services/containers via Cloudflare Argo
3pwnbox. ansible playbook for setting up my pwn dev env
3discover. For use with Kali Linux. Custom bash scripts used to automate various pentesting tasks.
3holepunch-client. Totally self-contained SSH reverse tunnel written in Go
3cryptoparty. Collection of outlines, walkthroughs, and talks about communicating securely in a surveillance state
3dllinquent. Search running process for a given dll/function. Exposes a bufio.Scanner-like interface for walking a process' PEB
2minbeacon. A work in progress of constructing a minimal http(s) beacon for Cobalt Strike.
2unifi_syslogd. Simple little syslog server I made for troubleshooting UniFi firewall rules
2mcpmap. List Resources, Tools, and Prompts. Execute Tools.
2go-clr. A PoC package for hosting the CLR and executing .NET from Go
2i3tab.nvim. super small, i3-like tabs. no buffers
2bamflags. Parse out values from which a Binary Alignment Map is comprised
2GitGot. Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.
2go-mimikatz. A wrapper around a pre-compiled version of the Mimikatz executable for the purpose of anti-virus evasion.
2rcas-server-node. toy roster app using sockets and react
2getsystem.rs. WIP
1logerr. flexible and convenient logging
1donloader. donLoader is a shellcode loader creation tool that uses donut to convert executable payloads into shellcode to evade detection on disk.
1go-sshclient. simple sshclient with go
1CVE-2024-20656. C++
1hearsay. Proxy-aware reverse HTTP proxy.
1