This is your work, valued

France

Soufiane Tahiri

Elite
@soufianetahiri

Breaking things since 1999

Anxun-isoon. I-SOON/Anxun leak related stuff

342

Mirai-Botnet. Mirai Botnet Client, Echo Loader and CNC source code (for the sake of knowledge)

101

TeamsNTLMLeak. Leak NTLM via Website tab in teams via MS Office

80

CitrixSecureAccessAuthCookieDump. Dump Citrix Secure Access auth cookie from the process memory

76

Vault-8-Hive. Hive solves a critical problem for the malware operators at the CIA.

66

RansomwareMonitor. A ransomware group monitoring bot written in C#.

57

Leaked-Password. A database containing 22409485 clear and equivalent sha256 hash passwords

39

dnspy-mcp. MCP server for .NET reverse engineering workflows (dnSpy/ILSpy ecosystem), built in C#.

39

RansomwareSimulator.public. Ransomware simulator written in C#

38

AD-Pentest-Cheatsheet. AD Pentest Cheatsheet by BlackWasp

26

ransomware_Incident_Response_FR. petit "playbook" qui pourrait servir de base à une réponse à incident lors d'une attaque de type ransomware

21

ContiLeaks.

19

deepdarkCTI. Collection of Cyber Threat Intelligence sources from the deep and dark web

16

Digital-Forensics-Incident-Response. This post is inspired by all the hard working DFIR, and more broadly security professionals, who have put in the hard yards over the years to discuss in depth digital forensics and incident response. (by Jai Minton)

14

MagentoScanner. Magento Security Scanner

13

LLMExploiter. A comprehensive security testing framework for Large Language Models based on OWASP Top 10 for LLMs, and NIST AI 600 frameworks. Features advanced false positive reduction, parallel testing, and comprehensive reporting.

9

Valkyrie. Another OSINT tool

7

HttpRquestPlayer. This small utility could help you to find authorization bugs.

7

sqlmap-cheat-sheet. sqlmap cheat sheet

7

X-Twitter-Mass-Delete-Script. A JavaScript-based tool to bulk delete your X/Twitter posts. This script allows you to delete tweets from specific time periods using X's advanced search features.

6

ESXi_ransomware_bitcoinWallets. ESXi semi-automated ransomware attacks bitcoin wallets

5

CitrixSecureAccessSAML. Citrix Secure Access SAML abuse

4

os-security-assessment. An automated security assessment tool for analyzing operating system vulnerabilities, patch statuses, and end-of-life risks.

4

ICMP. Send file over ICMP (reverse shell)

3

ai_llm_risk.

2

DoubleAgent. Zero-Day Code Injection and Persistence Technique

2

SecLists. SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.

2

Awesome-WAF. 🔥 Everything awesome about web-application firewalls (WAF).

2

AutoSploit. Automated Mass Exploiter

2

Ysoserial. Compiled jar version ysoserial (java payloads)

2

bug-bounty-reference. Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature

2

randomLists. Random wordlists (dirs,files,xss...)

2

RedTeaming_CheatSheet. Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.

2

oss-fuzz. OSS-Fuzz - continuous fuzzing of open source software

2

Cyberwatch. Building a consolidated RSS feed for articles about cyberattacks

2

Resources-for-Beginner-Bug-Bounty-Hunters. A list of resources for those interested in getting started in bug bounties

2

Bloodhound-Custom-Queries. Custom Query list for the Bloodhound GUI based off my cheatsheet

1

CVE-2021-34527. PowerShell

1

RandomCreditCardNumberGenerator. This is a port of the port of of the Javascript credit card number generator now in C# by Kev Hunter https://kevhunter.wordpress.com

1

One-Liners. A collection of awesome one-liners for bug bounty hunting.

1

Amass. In-depth Attack Surface Mapping and Asset Discovery

1

GraphQLmap. GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.

1

public-pentesting-reports. Curated list of public penetration test reports released by several consulting firms and academic security groups

1

awesome-osint. :scream: A curated list of amazingly awesome OSINT

1

Red-Team-Management. HTML

1

Active-Directory-Exploitation-Cheat-Sheet. A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

1

CVE-2021-26868. C

1

sql-injection-payload-list. 🎯 SQL Injection Payload List

1

HackerArt. A collection of art inspired by the world of cybersecurity and hacking culture.

1

fuzzdb. Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

1

RemoteAssemblyLoader. C#

1

bruteforce-lists. Some files for bruteforcing certain things.

1

xss-cheat-sheet. Ultimate Cross Site Scripting Attack Cheat Sheet

1

Probable-Wordlists. Wordlists sorted by probability originally created for password generation and testing

1