Reverse_DNS_Shell. A python reverse shell that uses DNS as the c2 channel
505Cybersecurity-Tradecraft. A repo to support the book
112gscripts. A repo full of example gscripts
101PSSE. PowerShell Scripting Expert repository, contains template code for security and administrative scripting, largely derived through taking the SecurityTube PowerShell for Pentesters course
87Reverse_SSH_Shell. A reverse ssh shell written in python, intended for penetration testers to use as a covert channel on windows
87Reverse_HTTPS_Bot. A python based https remote access trojan for penetration testing
84phish_composer. Automatically spin up infra for phishing
63NTP_Trojan. Reverse NTP remote access trojan in python, for penetration testers
62GoRedLoot. A tool to collect secrets (keys and passwords) and stage (compress and encrypt) them for exfiltration.
61Stego_Dropper. A python based dropper, that uses steganography and an image over http to transfer a file
59SPSE. Collection of scripts created while taking the SecurityTube Python Scripting Expert course
56XMPP_Shell_Bot. A shell / chat bot for XMPP and cloud services
49Wifi_Trojans. A collection of wireless based bind and reverse connect shells for penetration testers to use in demonstrating persistence to a network via rouge access points.
42macOS_profiles. a collection of profiles for macOS designed for penetration testing or red teaming
37GoRedShell. A cross platform tool for verifying credentials and executing single commands
32HoneyTags. An opensource project similar to HoneyDocs
26jammer. This is a fuzzer for automated web application scanners and vulnerability scanners. The idea is to send an unexpectedly large response to attack strings, and crash the scanner.
24YARA. a collection of yara rules for binary analysis
24GLSE. GoLang Scripting Expert, a repo for template scripts regarding basic golang functions, many with a security focus
22GoRedSpy. post exploitation user monitoring tool
20presentations. various slides and presentations I've worked on
19GoRedDeath. Experimenting with destructive file attacks in Go
18AppleScripts. experimenting w/ apple script for various macOS functionality
14Ducky_Maker. A fun script to teach automation and create ducky scripts, from existing scripts or ASCII art files
7nmap-to-netscan. A helper utility for turning nmap xml files into target lists for go-netscan
7Go_Shells. a collection of shells written with the go programming language, golang
6Jamf-Attack-Toolkit. Suite of tools to facilitate attacks against the Jamf macOS management platform.
6go-powershell. a clone of the old gorillalabs go-powershell
4godns. a simple client lib for doing dns over http
4pocorgtfo. mirror to the Poc||GTFO zine
4gloot. gloot is GoRedLoot adapted for gscript
4Shr3dKit. Red Team Tool Kit
4GoRedPrompt. POC cross platform prompts for creds
3lavalink-musicbot. Music bot that uses Lavalink for its audio player.
3replicant. social media bots
3CloneWars. Test repo for cloning code signing certs on Windows
3malware_sources. Pascal
3DEFCON22-BADGE. My custom code for the DEFCON22 Badge, all in good fun.
3CVE-2016-3714. ImaegMagick Code Execution (CVE-2016-3714)
2gopkgs. a fork of github.com/uudashr/gopkgs
2Awesome-Red-Teaming. List of Awesome Red Teaming Resources
2awesome-incident-response. A curated list of tools for incident response
2go-mimikatz. A wrapper around a pre-compiled version of the Mimikatz executable for the purpose of anti-virus evasion.
2polaroid. Self contained phish endpoint generator and web server.
1GoFileHash. fun project to mess around with hashing files
1ad-ldap-enum. An LDAP based Active Directory user and group enumeration tool
1CVE-2018-15473-Exploit. Exploit written in Python for CVE-2018-15473 with threading and export formats
1bintriage. additional debug information about executable files
1PrepCreds. small utility for preparing credential files for hydra or go-netscan
1Invoke-Obfuscation. PowerShell Obfuscator
1CVE-2014-4113. PowerShell CVE-2014-4113
1