This is your work, valued
juicy-potato. A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
★ 2.8ksocks-my-vpn. OpenVPN-client + SOCKS server in a Docker container
★ 28telugu. A game for Apple devices
★ 6Misc-PowerShell. Misc. PowerShell scripts
★ 2xray. XRay is a tool for recon, mapping and OSINT gathering from public networks.
★ 2KDU. Kernel Driver Utility
★ 1mkhtaccess_red. Auto-generate an HTaccess for payload delivery -- automatically pulls ips/nets/etc from known sandbox companies/sources that have been seen before, and redirects them to a benign payload.
★ 1bettercap. The Swiss Army knife for 802.11, BLE and Ethernet networks reconnaissance and MITM attacks.
★ 1markdown-tricks.
★ 1newtowner. Abuse trust-boundaries to bypass firewalls and network controls
★ 424CrossCheck. A tool to test cross-device authentication protocol security
★ 28sunlight. A Certificate Transparency log implementation and monitoring API designed for scalability, ease of operation, and reduced cost.
★ 299justatemp. 📮 The free temporary email service powered by Cloudflare
★ 226legba. The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷
★ 1.9kSMShell. PoC for a SMS-based shell. Send commands and receive responses over SMS from mobile broadband capable computers
★ 372RunasCs. RunasCs - Csharp and open version of windows builtin runas.exe
★ 1.4kneferpitool. A tool that combines DNS and WHOIS to automatically monitor domain name changes.
★ 18Dirty-Vanity. A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass-28417
★ 677CS-Remote-OPs-BOF. Remote operations commands implemented using Beacon Object Files
★ 1.2kWSuspicious. WSuspicious - A tool to abuse insecure WSUS connections for privilege escalations
★ 378DetectionLab. Automate the creation of a lab environment complete with security tooling and logging best practices
★ 5kdaedalOS. Desktop environment in the browser
★ 13knpk. A mostly-serverless distributed hash cracking platform
★ 661captcha-killer-modified. captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite
★ 1.9kproxmark3. Iceman Fork - Proxmark3
★ 5.9kEVTX-ETW-Resources. Event Tracing For Windows (ETW) Resources
★ 433security_guides. Collected and authored guides for personal and operational security.
★ 68Max. Maximizing BloodHound. Max is a good boy.
★ 534bluehatil22. Slides from out talk at BH IL 2022
★ 28gsocket. Connect like there is no firewall. Securely.
★ 1.9kfakelogonscreen. Fake Windows logon screen to steal passwords
★ 1.4kstratus-red-team. :cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
★ 2.4kAmsiHooker. Hookers are cooler than patches.
★ 171ldd2bh. Convert ldapdomaindump to Bloodhound
★ 81yubikey-agent. yubikey-agent is a seamless ssh-agent for YubiKeys.
★ 2.9kSimuLand. Understand adversary tradecraft and improve detection strategies
★ 714SSHPry2.0. SSHPry v2 - Spy & Control os SSH Connected client's TTY
★ 401RemotePotato0. Windows Privilege Escalation from User to Domain Admin.
★ 1.5kCobaltStrikeScan. Scan files or process memory for CobaltStrike beacons and parse their configuration
★ 918SharPyShell. SharPyShell - tiny and obfuscated ASP.NET webshell for C# web applications
★ 1.1kpuppeteer-cluster. Puppeteer Pool, run a cluster of instances in parallel
★ 5juicy_2. juicypotato for win10 > 1803 & win server 2019
★ 98muraena. Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
★ 1.1kDendrobate. Managed code hooking template.
★ 134juicy-potato. A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
★ 2.8kuroboros. A GNU/Linux monitoring and profiling tool focused on single processes.
★ 671geacon. Practice Go programming and implement CobaltStrike's Beacon in Go
★ 1.3knecrobrowser. necromantic session control
★ 186macOS-Simple-KVM. Tools to set up a quick macOS VM in QEMU, accelerated by KVM.
★ 14kuntrusted-types. Svelte
★ 700StreamDivert. Redirecting (specific) TCP, UDP and ICMP traffic to another destination.
★ 438nccfsas. Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.
★ 609AMSI.fail. C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.
★ 455Awesome-CobaltStrike. List of Awesome CobaltStrike Resources
★ 4.4kPiano-LED-Visualizer. Piano LED Visualizer: Connect an LED strip to your Raspberry Pi and create an immersive visual experience for your piano playing
★ 753KDU. Kernel Driver Utility
★ 2.7kchromium-all-old-stable-versions. Collections of Chromium all old/history stable versions, releases. Support me via Bitcoin: bc1qqgkmph9cvygzxfpupv4jr4n0nfx3qumwg39j5w
★ 120browser-detection. JavaScript library for detecting browsers and platforms using features.
★ 9exploits. A handy collection of my public exploits, all in one place.
★ 676bitleaker. This tool can decrypt a BitLocker-locked partition with the TPM vulnerability
★ 228pwnagotchi. (⌐■_■) - Deep Reinforcement Learning instrumenting bettercap for WiFi pwning.
★ 9.2kzerodrop. A stealth URL toolkit optimized for bypassing censorship filters and/or dropping malware
★ 112gitrob. Reconnaissance tool for GitHub organizations
★ 6.2kzOS. z/OS - all things security
★ 88vulhub. Pre-Built Vulnerable Environments Based on Docker-Compose
★ 21kThe-Hackers-Hardware-Toolkit. The best hacker's gadgets for Red Team pentesters and security researchers.
★ 2.2kwebsite. bettercap official documentation and website contents
★ 39mkcert. A simple zero-config tool to make locally trusted development certificates with any names you'd like.
★ 59ktermshark. A terminal UI for tshark, inspired by Wireshark
★ 10kchromedp. A faster, simpler way to drive browsers supporting the Chrome DevTools Protocol.
★ 13kheadless-cat-n-mouse. Is headless chrome currently detectable? Let's pit the detections and detection evasions against eachother.
★ 661chefbot. ChefBot is a social bot for Slack that helps you to rate dishes from http://lunch.team .
★ 4dockerfiles. Various Dockerfiles I use on the desktop and on servers.
★ 14kislazy. A Go library containing a set of opinionated packages, objects, helpers and functions implemented with the KISS principle in mind.
★ 163fetch-some-proxies. Simple Python script for fetching "some" (usable) proxies
★ 578shellz. shellz is a small utility to manage your ssh, telnet, kubernetes, winrm, web or any custom shell in a single place.
★ 617puppeteer. JavaScript API for Chrome and Firefox
★ 95kGoRAT. GoRAT is a (WiP/PoC) RAT in go that uses Google Drive/Sheet APIs
★ 14whatstrapp. The fastest tool for analyzing and dumping WhatsApp accounts (in ~15s).
★ 97gitignore. A collection of useful .gitignore templates
★ 175kExchangeRelayX. An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.
★ 305mitmproxy. An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
★ 45kCatMyPhish. Search for categorized domain
★ 462typofinder. A finder of domain typos showing country of IP address
★ 166caplets. caplets and proxy modules.
★ 521pi-hole. A black hole for Internet advertisements
★ 60katomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
★ 12ktoken-priv. Token Privilege Research
★ 886Red-Baron. Automate creating resilient, disposable, secure and agile infrastructure for Red Teams.
★ 924DomainFrontingLists. A list of Domain Frontable Domains by CDN
★ 577bettercap. The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
★ 20karc. A manager for your secrets.
★ 967awesome-go. A curated list of awesome Go frameworks, libraries and software
★ 180kMisc-PowerShell. Misc. PowerShell scripts
★ 120JStillery. Advanced JavaScript Deobfuscation via Partial Evaluation
★ 897PowerMemory. Exploit the credentials present in files and memory
★ 846gandi-api. Go library for the gandi.net API
★ 26fresh. Build and (re)start go web apps after saving/creating/deleting source files.
★ 3.9kPowerDNS. PowerDNS: Powershell DNS Delivery
★ 218demiguise. HTA encryption tool for RedTeams
★ 1.4kds_store_exp. A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.
★ 1.7kwtfjs. 🤪 A list of funny and tricky JavaScript examples
★ 38kHTTPLeaks. HTTPLeaks - All possible ways, a website can leak HTTP requests
★ 2.1kWMImplant. This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.
★ 862poodle-PoC. :poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle:
★ 265Red-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources
★ 4.5kawesome-industrial-control-system-security. A curated list of resources related to Industrial Control System (ICS) security.
★ 2kCrackMapExec. A swiss army knife for pentesting networks
★ 9.2krtfm. A database of common, interesting or useful commands, in one handy referable form
★ 750xray. XRay is a tool for recon, mapping and OSINT gathering from public networks.
★ 2.3kNetRipper. NetRipper - Smart traffic sniffing for penetration testers
★ 1.4kmastg. The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
★ 13kResponder. Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
★ 6.5kfilterbypass. Browser's XSS Filter Bypass Cheat Sheet
★ 1.2ktamperchrome. Tamper Dev is an extension that allows you to intercept and edit HTTP/HTTPS requests and responses as they happen without the need of a proxy. Works across all operating systems (including Chrome OS).
★ 4.2kresearch.
★ 2.2ktplmap. Server-Side Template Injection and Code Injection Detection and Exploitation Tool
★ 4.2kkeymaker-alpha. C++
★ 3js-vuln-db. A collection of JavaScript engine CVEs with PoCs
★ 2.3kopenvpn-install. OpenVPN road warrior installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and Fedora
★ 21kohmyzsh. 🙃 A delightful community-driven (with 2,500+ contributors) framework for managing your zsh configuration. Includes 300+ optional plugins (rails, git, macOS, hub, docker, homebrew, node, php, python, etc), 140+ themes to spice up your morning, and an auto-update tool that makes it easy to keep up with the latest updates from the community.
★ 189kwebshell. This is a webshell open source project
★ 11kPentest-Bookmarks. Database of websites for penetration testing
★ 184ssh-audit. SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)
★ 3kandroid-security-awesome. A collection of android security related resources
★ 9.6kbettercap. DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap
★ 2.5kMobileApp-Pentest-Cheatsheet. The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
★ 5.2kYubiKey-Guide. Community guide to using YubiKey for GnuPG and SSH - protect secrets with hardware crypto.
★ 12kmacOS-Security-and-Privacy-Guide. Community guide to securing and improving privacy on macOS.
★ 22kwrite-ups-2016. Wiki-like CTF write-ups repository, maintained by the community. 2016
★ 1.6klinpostexp. Linux post exploitation enumeration and exploit checking tools
★ 180public-pentesting-reports. A list of public penetration test reports published by several consulting firms and academic security groups.
★ 9.7kmaltrail. Malicious traffic detection system
★ 8.6kSecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
★ 73kxvwa. XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
★ 1.8kburp-hash. Java
★ 33write-ups-2015. Wiki-like CTF write-ups repository, maintained by the community. 2015
★ 2kXSSChallengeWiki. Welcome to the XSS Challenge Wiki!
★ 1.6kbeef. The Browser Exploitation Framework Project
★ 11krips. RIPS - A static source code analyser for vulnerabilities in PHP scripts
★ 364You-Dont-Know-JS. A book series (2 published editions) on the JS language.
★ 185kawesome. 😎 Awesome lists about all kinds of interesting topics
★ 491kCryptoTerminology.
★ 56data_hacking. Data Hacking Project
★ 783H5SC. HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
★ 2.9kwafw00f. WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
★ 6.5kphp-ref. A better alternative to print_r / var_dump
★ 342DOMPurify. DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
★ 17kWhatWeb. Next generation web scanner
★ 6.8ksqlmap. Automatic SQL injection and database takeover tool
★ 38kwpspider. Wordpress.org svn repositories spider
★ 13sqli-labs. SQLI labs to test error based, Blind boolean based, Time based.
★ 5.8kSQLol. A configurable SQL injection test-bed
★ 122