This is your work, valued
CloudFlair. 🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
3klog4shell-vulnerable-app. Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
1.1kcensys-subdomain-finder. ⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.
840Adaz. :wrench: Deploy customizable Active Directory labs in Azure - automatically.
429spoofing-office-macro. :fish: PoC of a VBA macro spawning a process with a spoofed parent and command line.
383duplicacy-autobackup. :floppy_disk: Painless automated backups to multiple storage providers with Docker and duplicacy.
251mindmaps. :mag: Mindmaps for threat hunting - work in progress.
151IPv6teal. :wave: Stealthy data exfiltration via IPv6 covert channel
102firepwned. :pray: Checks Firefox saved passwords against known data leaks using the Have I Been Pwned API.
90nextcloud-docker-compose. :cloud: Spin up a Nextcloud instance with automatied backups and SSL certificate issuance.
77docker-python-sandbox. A Docker-powered NodeJS sandbox to execute untrusted python code.
66nmap-nse-info. Browse and search through nmap's NSE scripts.
59aws-sso-device-code-authentication. Python
39geolocate-ips. Batch IP geolocation script.
21code-execution-api-demo. JavaScript
17abusing-cloudflare-workers. Abusing Cloudflare Workers to establish persistence and exfiltrate sensitive data at the edge.
15fun-with-vpc-endpoints. HCL
14telegram-downbot. A Telegram bot to monitor websites
5polybot. CoffeeScript
4unix-commands. Some useful UNIX commands
4my-arsenal-of-aws-security-tools. List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
3vulnerable-java-application. This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).
3PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework
2known_aws_accounts. List of known AWS accounts
2powercoders-docker. Repository for Powercoders Docker presentation and workshop
2falias. Shell
2aws-security-cert-service-notes. Security aspects of AWS products for the Security Specialist certification
2container-security-site. HTML
1fun-with-aws-load-balancers. HCL
1BloodHound. Six Degrees of Domain Admin
1opennem. Energy market data access platform
1manifesto. The OpenTF Manifesto expresses concern over HashiCorp's switch of the Terraform license from open-source to the Business Source License (BSL) and calls for the tool's return to a truly open-source license.
1filezilla-passwords-revealer. JavaScript
1fos2015.github.io. Website for the Foundations of Software course at EPFL in the Fall 2015 semester
1