This is your work, valued
ultimate-nmap-parser. parse nmap files
★ 162wordlist-tools. A set of tools for making life easier with wordlists
★ 8sysinfo-win. better windows sysinfo for the hacker ;)
★ 3pentest_db. just my Pentest commands database
★ 2vulnsearch. searches for vulns on the web
★ 1my_wordlists. A collection of my wordlists if put together. most are a mish mash of others
★ 1screenshotter. a macro to take screenshots of bits you need for a windows build review
★ 1nessus-helper. a simple script to help get nessus auth scanning on windows working
★ 1wireless. script to help with wireless pentesting
★ 1host-disc. Host Discovery Toolkit
★ 1old-win-pentest-tools. Repo hosting hard to get old skool windows tools that are useful for pentesting
★ 1CertCheck. SSL/TLS Certificate Checker - A Python script to validate SSL/TLS certificates for common misconfigurations and output the results in JSON format.
★ 20search-plugins. Search plugins for qBittorrent search feature
★ 6.5ktrading-skills. 17 triggers × 44 algorithms × 3 AI experts — live crypto trading signals for Claude Code, Codex, Cursor & 30+ agents. Free during beta.
★ 99NetExec. The Network Execution Tool
★ 1gopacket. A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free binary.
★ 701Firefox-Security-Toolkit. A tool that transforms Firefox browsers into a penetration testing suite
★ 513vmware-cis-vsphere8-audit. VMware vSphere 8 CIS benchmark auditing and compliance validation tools
★ 15WindowsSecurityAudit. A comprehensive Windows security auditing and threat detection toolkit. Features 58 production-ready PowerShell functions organized into 14 modules for enterprise-grade security assessment, compliance validation, and incident response.
★ 87audit_scripts. Scripts to gather system configuration information for offline/remote auditing
★ 84Wordlist-Hub. Welcome to the Bug Hunter's Wordlists repository! 🐛🔍 This repository serves as a comprehensive collection of essential wordlists utilized by bug hunters, penetration testers, and security enthusiasts during their reconnaissance and vulnerability assessment processes.
★ 155AD_Miner. AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses
★ 1.5ktmuxai. AI-Powered, Non-Intrusive Terminal Assistant
★ 1.9kAi-Terminal-X. 🔥AI-Terminal-X is an AI-powered Linux terminal assistant🔥 that converts natural language commands into executable terminal commands using Google’s Gemini AI. It enhances productivity with safe execution checks, command suggestions, and real-time feedback.
★ 38sysinfo-win. better windows sysinfo for the hacker ;)
★ 3hacktricks-cloud. CSS
★ 768unstract. LLM-Driven Extraction of Unstructured Data — Built for API Deployments & ETL Pipeline Workflows
★ 7.1kGf-Patterns. GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
★ 1.4ktextgen-extensions.
★ 676knowsmore. KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes, BloodHound, NTDS and DCSync).
★ 269autobloody. Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound
★ 705bloodyAD. BloodyAD is an Active Directory Privilege Escalation Framework
★ 2.3kJustEvadeBro. JustEvadeBro, a cheat sheet which will aid you through AMSI/AV evasion & bypasses.
★ 317Adalanche. Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?
★ 2.2kpingcastle. PingCastle - Get Active Directory Security at 80% in 20% of the time
★ 2.9kBlueTuxedo. A tiny tool built to find and fix common misconfigurations in Active Directory-integrated DNS
★ 154HardeningKitty. HardeningKitty - Checks and hardens your Windows configuration
★ 1.8kLocksmith. A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.
★ 1.6kpywhisker. Python version of the C# tool for "Shadow Credentials" attacks
★ 918juice-shop. OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
★ 14kAwesome-GPT-Agents. A curated list of GPT agents for cybersecurity
★ 6.6kSharpDPAPI. SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
★ 1.4kRubeus-GUI. GUI alternative to the Rubeus command line tool, for all your Kerberos exploit requirements
★ 186SharpSCCM. A C# utility for interacting with SCCM
★ 702PS2. A port scanner written purely in PowerShell.
★ 82wappybird. Wappalyzer CLI tool to find Web Technologies
★ 60Whisker. Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.
★ 951PortBender. TCP Port Redirection Utility
★ 788CredGuess. Generate password spraying lists based on the pwdLastSet-attribute of users.
★ 56LinikatzV2. linikatz is a tool to attack AD on UNIX
★ 156RedTeaming_CheatSheet. Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.
★ 1.6kPsMapExec. Dominate Active Directory with PowerShell.
★ 1.2kwinssh. Rust
★ 66PowerShellArmoury. A PowerShell armoury for security guys and girls
★ 469ThreatCheck. Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.
★ 1.6kSUDO_KILLER. A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
★ 2.5kspiderfoot. SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
★ 20kRedTeam-Tools. Tools and Techniques for Red Team / Penetration Testing
★ 9.5kbbot. The recursive internet scanner for hackers. 🧡
★ 10kSpoofy. Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
★ 770NetExec. The Network Execution Tool
★ 5.7k3rdpartypooper. Python
★ 5DCToolbox. Tools for Microsoft cloud fans
★ 378Practice-AD-CS-Domain-Escalation. Introductory guide on the configuration and subsequent exploitation of Active Directory Certificate Services with Certipy. Based on the white paper Certified Pre-Owned.
★ 144awesome-privilege-escalation. A curated list of awesome privilege escalation
★ 1.6kBChecks. BChecks collection for Burp Suite Professional and Burp Suite DAST
★ 785VhostFinder. Identify virtual hosts by similarity comparison
★ 141virtual-host-discovery. A script to enumerate virtual hosts on a server.
★ 695rlwrap. A readline wrapper
★ 3.1kC-Reverse-Shell. a simple c++ reverse shell for windows
★ 116ldapnomnom. Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)
★ 1.1kVillain. Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
★ 4.4kWINAudit. Windows security configuration audit.
★ 5cypherhound. Your template-based BloodHound terminal companion tool
★ 454Farmer. C#
★ 427RedTeamOps-Havoc-101. Materials for the workshop "Red Team Ops: Havoc 101"
★ 399nextgenmap. Nmap GUI with SearchSploit and vulnerability script integrations, schedules, and reports
★ 12nlist. An nmap script to produce target lists for use with various tools.
★ 33CVEScannerV2. Nmap script that scans for probable vulnerabilities based on services discovered in open ports.
★ 227nmap-log4shell. Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)
★ 78Penetration-List. Penetration-List: A comprehensive resource for testers, covering all types of vulnerabilities and materials used in Penetration Testing. Includes payloads, dorks, fuzzing materials, and offers in-depth theory sections. Visit our Medium profile for more information.
★ 905unix_collector. unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
★ 43SlinkyCat. Slinky Cat attempts to give users an easy-to-navigate menu offering predefined Active Directory Service Interfaces (ADSI) and .NET queries which can be used to enumerate a Windows domain.
★ 80Hardening-Audit-Tool-AuditTAP. FBPro Audit Test Automation Package allows you to create compliance reports for your systems. The resulting HTML-reports provide a transparent overview of your devices' security configuration compared to international security standards and hardening guides.
★ 170windows_hardening. HardeningKitty and Windows Hardening Settings
★ 2.6kContainerKitty. Invoke-ContainerKitty - Automates container scans with Docker Engine
★ 72ms. Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git
★ 155powerview.py. Powerview on steroids
★ 981Pentest-Tools-Collection. PowerShell
★ 906resocks. mTLS-Encrypted Back-Connect SOCKS5 Proxy
★ 483pentestmindmap. a mindmap on pentest #pentestmindmap #oscp #lpt #ecsa #ceh #bugbounty
★ 348Mindmap. This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them
★ 9.2kPowermad. PowerShell MachineAccountQuota and DNS exploit tools
★ 1.5kASREPRoast. Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled.
★ 209FullPowers. Recover the default privilege set of a LOCAL/NETWORK SERVICE account
★ 700PrintSpoofer. Abusing impersonation privileges through the "Printer Bug"
★ 2.3kLovely-Potato. Automating juicy potato local privilege escalation exploit for penetration testers
★ 149BloodHoundQueries. Python
★ 776targetedKerberoast. Kerberoast with ACL abuse capabilities
★ 675ldeep. In-depth ldap enumeration utility
★ 598BloodHound-Owned. A collection of files for adding and leveraging custom properties in BloodHound.
★ 185krbrelayx. Kerberos relaying and unconstrained delegation abuse toolkit
★ 1.6k3snake. Tool for extracting information from newly spawned processes
★ 783ADACLScanner. Repo for ADACLScan.ps1 - Your number one script for ACL's in Active Directory
★ 1.2kADCSPwn. A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.
★ 878GeoWordlists. GeoWordlists is a tool to generate wordlists of passwords containing cities at a defined distance around the client city.
★ 165Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes. A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.
★ 1.8kldapdomaindump. Active Directory information dumper via LDAP
★ 1.4kysoserial.net. Deserialization payload generator for a variety of .NET formatters
★ 3.8kExegol-resources. Hacking resources for the Exegol project
★ 47PENTESTING-BIBLE. articles
★ 14kmitm6. pwning IPv4 via IPv6
★ 1.9kCypherDog. PoSh BloodHound Dog Whisperer
★ 193Bloodhound-Custom-Queries. Custom Query list for the Bloodhound GUI based off my cheatsheet
★ 856DonPAPI. Dumping DPAPI credz remotely
★ 1.4kosep-tools. PowerShell
★ 43BloodHound.py. A Python based ingestor for BloodHound
★ 2.4kadidnsdump. Active Directory Integrated DNS dumping by any authenticated user
★ 1.2kcorkscrew. Corkscrew is a tool for tunneling SSH through HTTP proxies.
★ 193Lfi-Space. Lfi Scan Tool
★ 112webmatcher. A tool to find valid subdomains for a given domain which resolve to the provided, in-scope IP addresses. Useful on externals when you are only given public IP ranges, find loads of web services, but cannot access them as you have no knowledge of the subdomains needed for the URL.
★ 2awesome-gpt-security. A curated list of awesome security tools, experimental case or other interesting things with LLM or GPT.
★ 663CrucibleC2. A C# Command & Control framework
★ 1kPrivilege-Escalation. This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.
★ 3.6kNope-Proxy. TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
★ 1.7kThick-Client-Pentest-Checklist. A OWASP Based Checklist With 80+ Test Cases
★ 202git-scanner. A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public
★ 383SQLiWeb. Lab Website For Practicing Different Types of SQL Injection Vulnerabilities
★ 21GitTools. A repository with 3 tools for pwn'ing websites with .git repositories available
★ 4.2kfingerprintx. Standalone utility for service discovery on open ports!
★ 758ad-ldap-enum. An LDAP based Active Directory user and group enumeration tool
★ 313NfSpy. ID-spoofing NFS client
★ 298static-binaries-i386. static binaries linux i386
★ 118waf-bypass. Check your WAF before an attacker does
★ 1.5kgtfo. Search gtfobins and lolbas files from your terminal
★ 464NFStash. NFS client CLI toolkit
★ 79pwdsearch. Tool searching for different default passwords.
★ 17mssql-cli. A command-line client for SQL Server with auto-completion and syntax highlighting
★ 1.4kSniffAir. A framework for wireless pentesting.
★ 1.2kDatabase-Security-Audit. Training course materials, scripts and notes related to database security audit and penetration testing
★ 77nmap-query-xml. A simple program to query nmap xml files in the terminal.
★ 27mapcidr. Utility program to perform multiple operations for a given subnet/CIDR ranges.
★ 1.2kCheat-Sheet---Active-Directory. This cheat sheet outlines common enumeration and attack methods for Windows Active Directory using PowerShell.
★ 642nmap-formatter. A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot), sqlite, excel and d2-lang. Simply put it's nmap converter.
★ 733pdtm. ProjectDiscovery's Open Source Tool Manager
★ 1.1kawesome-bugbounty-tools. A curated list of various bug bounty tools
★ 6.1kffufsee. Ffuf output browser
★ 38offsec-tools. Compiled tools for internal assessments
★ 389certsync. Dump NTDS with golden certificates and UnPAC the hash
★ 648api_wordlist. A wordlist of API names for web application assessments
★ 922C99Shell-PHP7. PHP 7 and safe-build Update of the popular C99 variant of PHP Shell.
★ 151kiterunner. Contextual Content Discovery Tool
★ 3.2kGHunt. 🕵️♂️ Offensive Google framework.
★ 19kpwndbg. Exploit Development and Reverse Engineering with GDB & LLDB Made Easy
★ 11kAwesome-AI.
★ 49adduser-dll. Simple DLL that add a user to the local Administrators group
★ 77SmartContracts-audit-checklist. A checklist of things to look for when auditing Solidity smart contracts.
★ 798OneRuleToRuleThemStill. A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule
★ 650Exegol. Fully featured and community-driven hacking environment
★ 3kDFSCoerce. Python
★ 845wordlists. Real-world infosec wordlists, updated regularly
★ 1.8kLoop. UNIX's missing `loop` command
★ 697haiti. :key: Hash type identifier (CLI & lib)
★ 994SilentHound. Quietly enumerate an Active Directory Domain via LDAP parsing users, admins, groups, etc.
★ 504WindowsElevation. Windows Elevation(持续更新)
★ 669gateway-finder-imp. Tool to identify routers on the local LAN and paths to the Internet
★ 69CyberChef. The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
★ 35korpheus. Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types
★ 421Certipy. Tool for Active Directory Certificate Services enumeration and abuse
★ 3.6keml_analyzer. A cli script to analyze an E-Mail in the EML format for viewing the header, extracting attachments, etc.
★ 120shells. Script for generating revshells
★ 487WeaponizeKali.sh. Collection of extra pentest tools for Kali Linux
★ 126wwwtree. A utility for quickly and easily locating, web hosting and transferring resources (e.g., exploits/enumeration scripts) from your filesystem to a victim machine during privilege escalation.
★ 182mips-binaries. Various binaries for the mips architecture.
★ 350static-tools. Static compiled binaries + scripts ready to use on systems
★ 152TheFatRat. Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software protection .
★ 11kotseca. Open source security auditing tool to search and dump system configuration. It allows you to generate reports in HTML or RAW-HTML formats.
★ 520awesome-security-hardening. A collection of awesome security hardening guides, tools and other resources
★ 6.5kpuredns. Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
★ 2.2kparsenmap. Simple Nmap XML parsing script. Doesn't do anything fancy
★ 22enumy. Linux post exploitation privilege escalation enumeration
★ 256revshellgen. Reverse shell generator written in Python 3.
★ 566OffensiveReverseShellCheatSheet. Collection of reverse shells for red team operations.
★ 540NFSClient. NFSClient is an application for Microsoft Windows. It's an client for NFS server supporting protocols NFS 2, NFS 3 and NFS 4.1
★ 91ocd-mindmaps. Orange Cyberdefense mindmaps
★ 1.6kApacheTomcatScanner. A python script to scan for Apache Tomcat server vulnerabilities.
★ 891Apache-Tomcat-Pentesting. Apache Tomcat exploit and Pentesting guide for penetration tester
★ 66tomcatWarDeployer. Apache Tomcat auto WAR deployment & pwning penetration testing tool.
★ 446osint_stuff_tool_collection. A collection of several hundred online tools for OSINT
★ 8.6kFlipper_Zero_Badusb_hack5_payloads. hack5 badusb payloads moded for be played with flipper zero
★ 1.3knmap-static-binaries. Static binaries, removing any required dependencies from the operating system. Gziped files availabe to download via curl onto your targeted system.
★ 86static-binaries. Various *nix tools built as statically-linked binaries
★ 3.7khacktricks. Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
★ 12kdorks_hunter. Simple Google Dorks search tool
★ 344DumpsterDiver. Tool to search secrets in various filetypes.
★ 1kazucar. Security auditing tool for Azure environments
★ 585BruteShark. Network Analysis Tool
★ 3.4kbrutespray. Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
★ 2.5ksteampipe-mod-microsoft365-compliance. Run individual controls or full compliance benchmarks for CIS across all of your Microsoft 365 and Office 365 tenants using Powerpipe and Steampipe.
★ 27iodine. Official git repo for iodine dns tunnel
★ 7.9kKage. Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler
★ 1.2kSQLInjectionWiki. A wiki focusing on aggregating and documenting various SQL injection methods
★ 795sprayhound. Password spraying tool and Bloodhound integration
★ 260awesome-kubernetes-security. A curated list of awesome Kubernetes security resources
★ 965kubernetes-security-checklist. Kubernetes Security Checklist and Requirements - All in One (authentication, authorization, logging, secrets, configuration, network, workloads, dockerfile)
★ 486dive. A tool for exploring each layer in a docker image
★ 54kicmpdoor. ICMP Reverse Shell written in Python 3 and with Scapy (backdoor/rev shell)
★ 423Posh-SSH. PowerShell Module for automating tasks on remote systems using SSH
★ 1.1kNeo-reGeorg. Neo-reGeorg is a project that seeks to aggressively refactor reGeorg
★ 3.4kgowitness. 🔍 gowitness - a golang, web screenshot utility using Chrome Headless
★ 13RedEye. RedEye is a visual analytic tool supporting Red & Blue Team operations
★ 2.8k