This is your work, valued
OSWE. OSWE Preparation
★ 686OSEE. OSEE Preparation
★ 197OSEP. PEN-300/OSEP Public resources for PEN-300 Training
★ 134exploit. Just some exploits :P
★ 47splunk. Splunk Stuffs!
★ 14OSCP. C
★ 4SLAE. SecurityTube Linux Assembly Expert
★ 2OSED.
★ 2threatintel. Python
★ 1paloalto_networks. Palo Alto Networks Firewall Customized Syslog Filter for Splunk
★ 1pownie. The agent harness for offsec. It's a plugin for Claude Code packed with skills, hooks, memory system that works best for using Claude Code to achieve autonomous pentest/ctf
★ 24auto-southwest-check-in. A Python script that automatically checks in to your Southwest flight 24 hours beforehand.
★ 592deep-threat-model. Deep-TreatModel uses multi-agents to craft comprehensive and reliable threat models.
★ 13Insider-Threat. Creating a resource to help build and manage an Insider Threat program.
★ 104beanshooter. JMX enumeration and attacking tool.
★ 509RsyncOSX_archived. A macOS GUI for rsync.
★ 1.3kopencti. Open Cyber Threat Intelligence Platform
★ 9.8kterraform-provider-esxi. Terraform-provider-esxi plugin
★ 568awesome-api-security-essentials. Awesome API Security: A Curated Collection of Resources for Bulletproof API Protection!
★ 63Mythic. A collaborative, multi-platform, red teaming framework
★ 4.7kMemLabs. Educational, CTF-styled labs for individuals interested in Memory Forensics
★ 1.9ksliver. Adversary Emulation Framework
★ 12kMachOView. MachOView fork
★ 2.9kposeidon. Poseidon is a Golang agent targeting Linux and macOS
★ 220hayabusa. Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
★ 3.3kSysmonForLinux. Sysmon for Linux
★ 2.1kSuperMem. A python script developed to process Windows memory images based on triage type.
★ 267BOPFunctionRecognition. This python/jython script is used as plugin to BinNavi tool to analyze a x86 binanry file to find buffer overflow prone functions. Such functions are important for vulnerability analysis.
★ 292021. Files and Folders for BSides Splunk 2021
★ 23EDRs. C
★ 2.2kScareCrow. ScareCrow - Payload creation framework designed around EDR bypass.
★ 2.9kSpoolSample. PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
★ 1.1kkube-forensics. Go
★ 234DotNetToJScript. A tool to create a JScript file which loads a .NET v2 assembly from memory.
★ 1.3kdiffy. :no_entry: (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.
★ 629All_NTLM_leak.
★ 94IOXIDResolver. IOXIDResolver.py from AirBus Security
★ 282ExploitRemotingService. A tool to exploit .NET Remoting Services
★ 538jwt_tool. :snake: A toolkit for testing, tweaking and cracking JSON Web Tokens
★ 6.7kPEASS-ng. PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
★ 20kCRT. Contact: CRT@crowdstrike.com
★ 756at-ps. Adversary Tactics - PowerShell Training
★ 1.6kred_team_tool_countermeasures. YARA
★ 2.7kplaso. Super timeline all the things
★ 2.1kKapeFiles. This repository serves as a place for community created Targets and Modules for use with KAPE.
★ 863pcodedmp. A VBA p-code disassembler
★ 488leonidas. Automated Attack Simulation in the Cloud, complete with detection use cases.
★ 617ingest_eval_examples. Jupyter Notebook
★ 33report_examples. Example reports from prior years of the Collegiate Penetration Testing Competition
★ 167Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
★ 3.2kmarshalsec. Java
★ 3.7kABD. Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories
★ 1.2kk8s-ctf-rocks. Kubernetes Easter CTF
★ 59krane. Kubernetes RBAC static analysis & visualisation tool
★ 744kubeaudit. kubeaudit helps you audit your Kubernetes clusters against common security controls
★ 1.9kdive. A tool for exploring each layer in a docker image
★ 54kwww-project-kubernetes-security-testing-guide. OWASP Kubernetes Security Testing Guide
★ 44ida-plugins. A collection of my IDA plugins
★ 137kubernetes-goat. Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
★ 5.7kgo-audit. go-audit is an alternative to the auditd daemon that ships with many distros
★ 1.7ksplunk-operator. Splunk Operator for Kubernetes
★ 259attack_range. A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
★ 2.5kSANS2019-HolidayHackChallenge. SANS 2019 Holiday Hack Challenge - KringleCon 2.0 - Turtle Doves Writeup
★ 3k-rail. Kubernetes security tool for policy enforcement
★ 440handouts. materials we hand out
★ 146DVIA-v2. Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment. This project is developed and maintained by @prateekg147. The vulnerabilities and solutions covered in this app are tested up to iOS 11. The current version is writen in Swift and has the following vulnerabilities.
★ 1.1ksplunk-connect-for-kubernetes. Helm charts associated with kubernetes plug-ins
★ 359nebula. A scalable overlay networking tool with a focus on performance, simplicity and security
★ 18kalerting-detection-strategy-framework. A framework for developing alerting and detection strategies for incident response.
★ 891My-CTF-Web-Challenges. Collection of CTF Web challenges I made
★ 2.9kThreatHunter-Playbook. A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
★ 4.6ksysmon-config. Sysmon configuration file template with default high-quality event tracing
★ 5.6kCVE-2019-8978. Banner Web Tailor and Banner Enterprise Identity Services Vulnerability Disclosure
★ 9Hands-On-AWS-Penetration-Testing-with-Kali-Linux. Hands-On AWS Penetration Testing with Kali Linux published by Packt
★ 136vulnerable-node. A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of security analyzers tools tools
★ 489pytm. A Pythonic framework for threat modeling
★ 1.1kGLSE. GoLang Scripting Expert, a repo for template scripts regarding basic golang functions, many with a security focus
★ 22ctf-2019-release. BSidesSF CTF 2019 release
★ 71cuckoo. Cuckoo Sandbox is an automated dynamic malware analysis system
★ 6kwinafl. A fork of AFL for fuzzing Windows binaries
★ 2.6khonggfuzz. Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)
★ 3.4ksanitizers. AddressSanitizer, ThreadSanitizer, MemorySanitizer
★ 12kdocker-py. A Python library for the Docker Engine API
★ 7.2ksplunk-ansible. Ansible playbooks for configuring and managing Splunk Enterprise and Universal Forwarder deployments
★ 402botsv2. Splunk Boss of the SOC version 2 dataset.
★ 439moby. The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems
★ 72kdocker-logging-plugin. Splunk Connect for Docker is a Docker logging plugin that allows docker containers to send their logs directly to Splunk Enterprise or a Splunk Cloud deployment.
★ 66exploits. Some of my exploits.
★ 602alloc8. Write-up for alloc8 untethered bootrom exploit for iPhone 3GS
★ 391canvas-data-sdk. Python SDK and command-line tool for working with the Canvas Data API
★ 24nudge-python. A tool to help users with pre-existing devices upgrade their OS version.
★ 210ysoserial. A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
★ 9kvim-splunk. Syntax highlighting for Splunk .conf files
★ 76router_badusb. BadUSB in Routers
★ 201ghidra. Ghidra is a software reverse engineering (SRE) framework
★ 72kgotraining. Go Training Class Material :
★ 12kScoutSuite. Multi-Cloud Security Auditing Tool
★ 7.8kkrbrelayx. Kerberos relaying and unconstrained delegation abuse toolkit
★ 1.6kmerlin. Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
★ 5.6kgscript. framework to rapidly implement custom droppers for all three major operating systems
★ 705laforge. Competition Infrastructure Management
★ 90CrackMapExec. A swiss army knife for pentesting networks
★ 9.2ksplunk-tableau-wdc. Splunk Tableau Web Data Connector (WDC) Example
★ 20scoringengine. Scoring Engine for Red/White/Blue Team Competitions
★ 137DarkSpiritz. :moon: Official Repository for DarkSpiritz Penetration Framework | Written in Python :snake:
★ 231config_explorer. Config viewer and file editor for Splunk. Based on VSCode.
★ 35DetectionLab. Automate the creation of a lab environment complete with security tooling and logging best practices
★ 5kwindows-event-forwarding. A repository for using windows event forwarding for incident detection and response
★ 1.3kpwndb. Search for leaked credentials
★ 1.4kOWASP_MobileMalwareSession.
★ 24presentations. various slides and presentations I've worked on
★ 19awesome-web-security. 🐶 A curated list of Web Security materials and resources.
★ 14kpocs. Proof of Concepts (PE, PDF...)
★ 1.6kkaggle_Microsoft_Malware. code for kaggle competition Microsoft malware classification
★ 252HEVD-Python-Solutions. Python solutions for the HackSysTeam Extreme Vulnerable Driver
★ 151HackSysExtremeVulnerableDriver. HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
★ 3kplaybooks. Phantom Community Playbooks
★ 546sandbox-attacksurface-analysis-tools. Set of tools to analyze Windows sandboxes for exposed attack surface.
★ 2.3kbotsv1.
★ 474ember. Elastic Malware Benchmark for Empowering Researchers
★ 1.2kLightGBM. A fast, distributed, high performance gradient boosting (GBT, GBDT, GBRT, GBM or MART) framework based on decision tree algorithms, used for ranking, classification and many other machine learning tasks.
★ 19k