Cybersecurity Specialist. Offensive Operator. Adversary Hunter. Crafting creative solutions for not-yet-existing problems. Hobby flag collector.
Awesome-Cybersecurity-Handbooks. A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
3.9kOSCP. OSCP Cheat Sheet
3.8kRed-Team-Playbooks. This repository contains cutting-edge open-source security notes and tools that will help you during your Red Team assessments.
437vx-underground-wordlist. Wordlist to crack .zip-file password
202CTF-Notes. From Zero To Hero
40Cybersecurity-Glossary. A summary of the most abbreviations I encountered so far
30Cybersecurity-Book-Recommendations. This repository is about books I recommend in terms of cybersecurity.
15Red-Team-Field-Guide. Field guide to gather low-hanging fruits
14OSCP-Note-Vault. Obsidian Vault for note taking during the OSCP exam.
10InfoScraper. Python implementation of two famous JavaScript payloads for Bug Bounty.
80xsyr0.
7Log4Shell. This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.
6atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
5Obsidian-Snippets. Obsidian snippets for generating engagements reports
5Bobber. Bounces when a fish bites - Evilginx database monitoring with exfiltration automation
4syshell. Protected web shell for offensive security purposes.
4sliver. Adversary Emulation Framework
3nuclei-templates. A collection of useful nuclei templates
30xsyr0.github.io. A minimal, responsive, and powerful Jekyll theme for presenting professional writing.
3Havoc. The Havoc Framework
2phishing-templates. Over 50 of The Most Deceptive Phishing Templates, Pages & Links for GoPhish!
2RustRedOps. 🦀 | RustRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on the Rust programming language. (In Construction)
2thc-tips-tricks-hacks-cheat-sheet. Various tips & tricks
2OffensiveNim. My experiments in weaponizing Nim (https://nim-lang.org/)
2bindshell. bindshell project for understanding purposes
2Red-Teaming-Toolkit. This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
2pytroj. This repository contains files for the Python programming series of Alh4zr3d on YouTube.
2PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework
2Empire. Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
2GadgetToJScript. A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
2peeko. peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.
1Mythic_NimSyscallPacker_Wrapper. Mythic C2 wrapper for NimSyscallPacker
1ZigStrike. ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.
1PackMyPayload. A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats. Supports: ZIP, 7zip, PDF, ISO, IMG, CAB, VHD, VHDX
1FindMeAccess. Python
1dittobytes. Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
1PowerShellRunner. PowerShell runner for executing malicious payloads in order to bypass Windows Defender.
1Black-Hat-Zig. This project provides some code examples of Zig for malwares, hacking, and red teaming.
1sliver-cheatsheet. Sliver CheatSheet for OSEP
1merlin-agent-dll. Go
1Nimcrypt2. .NET, PE, & Raw Shellcode Packer/Loader Written in Nim
1PowerSharpPack. PowerShell
1nishang. Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
1OffensivePipeline. OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.
1Ransomware. Python
1evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
1