Mystikal. macOS Initial Access Payload Generator
326PersistentJXA. Collection of macOS persistence methods and miscellaneous tools in JXA
290Go4aRun. Shellcode runner in GO that incorporates shellcode encryption, remote process injection, block dlls, and spoofed parent process
227security. Notes and Commands for CTFs
26Dylib-Hijack-Scanner. JavaScript for Automation (JXA) version of Patrick Wardle's tool that searches applications for dylib hijacking opportunities
22InSync. Finder Plugin Persistence
10InjectCheck. Swift
9Custom_URL_Scheme. Tool to create a template to abuse Custom URL Schemes
9LaunchAgentPersistence. Persistence using Launch Agents for OSX in JXA
7VBA-SystemInfo. VBA Macro to gather system networking info
3ctf. Script for CTF events
3windows-privesc-check. Automatically exported from code.google.com/p/windows-privesc-check
2CVE-2019-8656. CVE-2019-8656 GateKeeper Bypass
2docker-elk. The Elastic stack (ELK) powered by Docker and Compose.
2HELK. The Hunting ELK
1macos-loginitems. A library to parse macOS LoginItems
1apfell. JavaScript for Automation (JXA) macOS agent
1Mythic. A collaborative, multi-platform, red teaming framework
1hermes. Swift 5 macOS agent
1Mount. Default VMware mount script
1MacOSX-SDKs. A collection of SDK folders
1thanatos. Mythic C2 agent targeting Linux and Windows hosts written in Rust
1Misc-Powershell-Scripts. Random Tools
1Reconnoitre. A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing. Included virtual host scanner.
1struts-pwn. An exploit for Apache Struts CVE-2017-5638
1simplefirefoxloop. This bash script takes a a list of IPs and opens them in firefox for you to save time copy and pasting
1