This is your work, valued

Portugal

Filipi Pires

Elite
@filipi86

Head of Technical Advocacy & Global Threat Researcher and Field CTO, Instructor, Speaker and Writer about Malware Hunting

MalwareAnalysis-in-PDF. Malicious PDF files recently considered one of the most dangerous threats to the system security. The flexible code-bearing vector of the PDF format enables to attacker to carry out malicious code on the computer system for user exploitation.

236

CVE-2024-6387-Vulnerability-Checker. This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.

102

httpdoom. HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly gaining an overview of HTTP-based attack surface.

23

Threat-Hunting. The purpose of these documents, it was to execute several efficiency and detection tests in some endpoint solutions, this document brings the result of the defensive security analysis with an offensive mindset performed in the execution many different Malwares in our lab environment.

21

ConnectBoxDOCSIS-3.0. The Connect Box is the worldwide most compact EuroDOCSIS 3.0 Voice Gateway which provides the ideal all-in-one wired and wireless solution, designed for your home, home office, or small business/enterprise. It can be used in households with one or more computers capable of wireless connectivity for remote access to the wireless gateway.

10

CrowdStrike. The purpose of this document, it was to execute several efficiency and detection tests in our lab environment protected with an endpoint solution, provided by CrowdStrike, this document brings the result of the defensive security analysis with an offensive mindset using reverse shell techniques to gain the access inside the victim's machine and after that performing a Malware in VBS to infected the victim machine through use some scripts in PowerShell to call this malware, in our environment.

8

Awesome-Hacking. A collection of various awesome lists for hackers, pentesters and security researchers

8

filipi86.github.io. First Version of my website, Welcome aboard!

6

theZoo. A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

5

Red-Teaming-Toolkit. A collection of open source and commercial tools that aid in red team operations.

4

Cybereason. Articles

4

Awesome-Red-Teaming. List of Awesome Red Teaming Resources

4

Awesome-Red-Team-Operations.

4

horusec-demo. Some examples to perform Horusec demonstration

4

awesome-k8s-security. A curated list for Awesome Kubernetes Security resources

3

DevSecOpsGuideline. The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

3

OSCE-Complete-Guide. OSWE, OSEP, OSED

3

awesome-appsec. A curated list of resources for learning about application security

3

awesome-command-control. A collection of awesome Command & Control (C2) frameworks, tools and resources for post-exploitation and red teaming assessments.

3

awesome-malware-analysis. Defund the Police.

3

filipi86.

3

awesome-python. A curated list of awesome Python frameworks, libraries, software and resources

3

awesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources

3

apidetector. APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.

2

awesome-soc. A collection of sources of documentation, as well as field best practices, to build/run a SOC

2

websploit. This is a virtual machine (VM) created by Omar Santos for different Cybersecurity Ethical Hacking (Web Penetration Testing) training sessions .The purpose of this VM is to have a single VM lab environment with several vulnerable applications running in Docker containers; the tools that come in Kali Linux; a few additional tools; intentionally vulnerable applications running in Docker containers, and a mobile device emulator. https://websploit.h4cker.org

2

h4cker. This repository is primarily maintained by Omar Santos and includes thousands of resources related to ethical hacking / penetration testing, digital forensics and incident response (DFIR), vulnerability research, exploit development, reverse engineering, and more.

2

aws-incident-response-playbooks.

2

horusec-platform. Horusec Platform is a set of web services that integrate with the Horusec CLI to facilitate the visualization and management of found vulnerabilities.

2

awesome-honeypots. an awesome list of honeypot resources

2

horusec. Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

2

AwesomeXSS. Awesome XSS stuff

2

Awesome-Hacking-Resources. A collection of hacking / penetration testing resources to make you better!

2

Studies-Python-Bases. Repository based on my Pythons studies.

2

OSCP. Repository to put my notes related to OSCP certification

2

awesome-go. A curated list of awesome Go frameworks, libraries and software

2

awesome-security. A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

2

awesome-hacking-1. A curated list of awesome Hacking tutorials, tools and resources

2

guiadecybersecurity. Esse guia contém todas as informações necessárias para se introduzir na área de segurança da informação, dessa maneira, você encontrará, cursos, indicações de livros, roadmaps, playlists, certificações e demais outras coisas.

2

awesome-virtualization. Collection of resources about Virtualization

2

k8spacket. k8spacket - packets traffic visualization for kubernetes

1

awesome-devsecops. An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

1

awesome-web-hacking. A list of web application security

1

Cloud-Security_Content. Splunk Security Content

1

Awesome-aws-security. Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security

1

PracticalMalwareAnalysis-Labs. Binaries for the book Practical Malware Analysis

1

Cloud-Detection-Security. Generic Signature Format for SIEM Systems

1

awesome-devops. A curated list of awesome DevOps tools, platforms and resources

1

purple-team-exercise-framework. Purple Team Exercise Framework

1

Awesome-Azure-Pentest. A collection of resources, tools and more for penetration testing and securing Microsofts cloud platform Azure.

1

EnterprisePurpleTeaming. Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study. Doctor of Science Cybersecurity at Marymount University Dissertation by Xena Olsen.

1

DevSecOps. Ultimate DevSecOps library

1

awesome-cicd-attacks. Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

1