This is your work, valued

Christophe Tafani-Dereeper

Elite
@christophetd

CloudFlair. 🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

3k

log4shell-vulnerable-app. Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

1.1k

censys-subdomain-finder. ⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

840

Adaz. :wrench: Deploy customizable Active Directory labs in Azure - automatically.

429

spoofing-office-macro. :fish: PoC of a VBA macro spawning a process with a spoofed parent and command line.

383

duplicacy-autobackup. :floppy_disk: Painless automated backups to multiple storage providers with Docker and duplicacy.

251

mindmaps. :mag: Mindmaps for threat hunting - work in progress.

151

IPv6teal. :wave: Stealthy data exfiltration via IPv6 covert channel

102

firepwned. :pray: Checks Firefox saved passwords against known data leaks using the Have I Been Pwned API.

90

nextcloud-docker-compose. :cloud: Spin up a Nextcloud instance with automatied backups and SSL certificate issuance.

77

docker-python-sandbox. A Docker-powered NodeJS sandbox to execute untrusted python code.

66

nmap-nse-info. Browse and search through nmap's NSE scripts.

59

aws-sso-device-code-authentication. Python

39

geolocate-ips. Batch IP geolocation script.

21

code-execution-api-demo. JavaScript

17

abusing-cloudflare-workers. Abusing Cloudflare Workers to establish persistence and exfiltrate sensitive data at the edge.

15

fun-with-vpc-endpoints. HCL

14

telegram-downbot. A Telegram bot to monitor websites

5

polybot. CoffeeScript

4

unix-commands. Some useful UNIX commands

4

my-arsenal-of-aws-security-tools. List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

3

vulnerable-java-application. This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).

3

PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework

2

known_aws_accounts. List of known AWS accounts

2

powercoders-docker. Repository for Powercoders Docker presentation and workshop

2

falias. Shell

2

aws-security-cert-service-notes. Security aspects of AWS products for the Security Specialist certification

2

container-security-site. HTML

1

fun-with-aws-load-balancers. HCL

1

BloodHound. Six Degrees of Domain Admin

1

opennem. Energy market data access platform

1

manifesto. The OpenTF Manifesto expresses concern over HashiCorp's switch of the Terraform license from open-source to the Business Source License (BSL) and calls for the tool's return to a truly open-source license.

1

filezilla-passwords-revealer. JavaScript

1

fos2015.github.io. Website for the Foundations of Software course at EPFL in the Fall 2015 semester

1