This is your work, valued
*nix and network security researcher, CTF player, and ridiculous toolsmith.
ssh-honeypot. Fake sshd that logs ip addresses, usernames, and passwords.
676rtfm. Cheat sheet and notes inspired by the book RTFM - Red Team Field Manual
188ELFcrypt. Simple ELF crypter. Uses RC4 encryption.
129icmp-backdoor. Backdoor that listens for specially crafted ICMP packets and spawns reverse shells.
75sshunt. SSH proxy with HASSH firewalling capabilities
30Awesome-anti-forensic. Tools and packages that are used for countering forensic activities, including encryption, steganography, and anything that modify attributes. This all includes tools to work with anything in general that makes changes to a system for the purposes of hiding information.
22ELFappend. PoC to append and extract data at the end of an ELF file
20pastebin-scrape. Utilize Pastebin's scraping API to find interesting pastes.
16greylost. DNS logging, detection, ...
15curl-portscan. Crappy shell script that port scans using curl
13thefuzz. Various fuzzers written in Python. Currently has a TCP server for fuzzing client software, and a CLI fuzzer to use against programs ran from the command line.
11harness. execute stuff in memory
10yararules. misc yara rules
9hammertime. PoC LKM to force run cleanup_module() on other LKMs
9break-web-scanners. Its like GORILLAS.BAS, just different. Creates a bunch of bogus files/directories to deceive web vulnerability scanners.
9gokiller. LKM to detect + kill golang bins
9exec-logger. LD_PRELOAD library to log all execve() calls to syslog
8pycompiler. Compile .py files as ELF using Cython
6rdpy-rdpfingerprint. OS Fingerprinting based on RDP login screen.
6ELFparasite. Simple parasite for ELF binaries using the concatenation method.
6noawareness. no awareness, swift as gold
5SLAE. SecurityTube Linux Assembly Expert exercises
5linux_amd64_static_tools. static linked bash, coreutils, and binutils for Linux/amd64
5papa-shango. ptrace injection
4sshady. SSH key monkeyshines.
4dotfiles. My dotfiles.
3usb-watch. Use Python's pyudev to monitor for USB events. Sends SMS texts using Twilio if a USB device is added or removed from your machines.
3syscallslol. Linux LKM that detects sys_call_table[] manipulation
3million_dollar_dream. EVERY MAN HAS A PRICE
3syslog_spoof. Sends spoofed syslog packets using scapy
3pinger. continuously ping hosts and make the data available via an HTTP API
3userlandexec. userland exec for Linux x86_64
2artillery. The Artillery Project is an open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.
2stroke. Updated "stroke" tool from Building Open Source Network Security Tools book by Mike Schiffman.
2natlas. Scaling Network Scanning
1scorebot. Scoring Engine for CTF competitions
1droberson. Too legit 2 quit.
1pattern. Recreation of Metasploit pattern_create.rb and pattern_offset.rb scripts.
1rehash. rehash
1meltdown-exploit. C
1notify. Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
1lilt. The littlest network watcher - libnids example
1merlin. Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
1pypacket. Parse packets
1gscript. Scriptable dynamic runtime execution of malware
1PcapPlusPlus. PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, WinPcap, DPDK and PF_RING.
1crappy_identd. SUPER AWESOME IDENT SERVER. RFC1413
1radare2. unix-like reverse engineering framework and commandline tools
1subrute. /bin/su brute forcer using pexpect.
1