Red Team Operator | Purple Team | OSCP | CRTP | CRTO | GPEN | GCIH | CREST CPSA-CRT | CISSP | ISO27001 LA | Next...
SUDO_KILLER. A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
2.5kEDR-Test. Automating EDR Testing with reference to MITRE ATTACK via Cobalt Strike [Purple Team].
158SCREEN_KILLER. This script was developed to track progress for reporting (capture screenshot, commands and outputs) during pentest engagement and OSCP.
74OFFPORT_KILLER. This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services running locally. The tool is useful when nmap or any scanning tool is not available and in the situation during which you did a manual port scanning and then want to identify the services running behind the identified ports.
51genAvatar. This script was developped to assist in SpearPhishing campaign during Red Team operations. It can be used to generate random name based on country of origin, sex and how common the combination of surname and firstname can be.
13CONFIG_KILLER. Script written in bash to identify and dump services config files
5SecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
5keepnote-rip. Keepnote is no more maintain on kali. Being used to keepnote, I tried to find a way to continue to use it as before on my fully upgraded kali. In this repo, I will explain how to do that.
5linux-kernel-exploits. linux-kernel-exploits Linux平台提权漏洞集合
3Ciphey. Automatically decode encryptions without a key, decode encodings, and crack hashes
2ffuf. Fast web fuzzer written in Go
2OSCPRepo. A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' Keepnote. Reconscan in scripts folder.
2MobaXterm-Decryptor. MobaXterm Decryptor
2RTProgress. A Red Team Activity Hub
2powershell-scripts-ms. Office 365 Reporting PowerShell Scripts
1SOC-Ressources. Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
1DeadPotato. DeadPotato is a windows privilege escalation utility from the Potato family of exploits, leveraging the SeImpersonate right to obtain SYSTEM privileges. This script has been customized from the original GodPotato source code by BeichenDream.
1BlueTeam-Tools. Tools and Techniques for Blue Team / Incident Response
1TTP-vectr. Test case indexes
1hacktricks. Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
1microsoft-architecture-pptx-icons. Microsoft Architecture Icons compiled in PowerPoint
1MFASweep. A tool for checking if MFA is enabled on multiple Microsoft Services
1OST-C2-Spec. Open Source C&C Specification
1Internal-Monologue. Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
1CMS-Hunter. CMS漏洞测试用例集合
1LaZagne. Credentials recovery project
1sshuttle. Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS tunneling.
1suspicious. Suspicious is a powerful web application designed to help users submit and analyze emails, files, IP addresses, and URLs
1windows-kernel-exploits. windows-kernel-exploits Windows平台提权漏洞集合
1jok3r. Jok3r - Network and Web Pentest Framework
1CTF. Shell
1