Dan Borges

Elite
@ahhh

Reverse_DNS_Shell. A python reverse shell that uses DNS as the c2 channel

505

Cybersecurity-Tradecraft. A repo to support the book

112

gscripts. A repo full of example gscripts

101

PSSE. PowerShell Scripting Expert repository, contains template code for security and administrative scripting, largely derived through taking the SecurityTube PowerShell for Pentesters course

87

Reverse_SSH_Shell. A reverse ssh shell written in python, intended for penetration testers to use as a covert channel on windows

87

Reverse_HTTPS_Bot. A python based https remote access trojan for penetration testing

84

phish_composer. Automatically spin up infra for phishing

63

NTP_Trojan. Reverse NTP remote access trojan in python, for penetration testers

62

GoRedLoot. A tool to collect secrets (keys and passwords) and stage (compress and encrypt) them for exfiltration.

61

Stego_Dropper. A python based dropper, that uses steganography and an image over http to transfer a file

59

SPSE. Collection of scripts created while taking the SecurityTube Python Scripting Expert course

56

XMPP_Shell_Bot. A shell / chat bot for XMPP and cloud services

49

Wifi_Trojans. A collection of wireless based bind and reverse connect shells for penetration testers to use in demonstrating persistence to a network via rouge access points.

42

macOS_profiles. a collection of profiles for macOS designed for penetration testing or red teaming

37

GoRedShell. A cross platform tool for verifying credentials and executing single commands

32

HoneyTags. An opensource project similar to HoneyDocs

26

jammer. This is a fuzzer for automated web application scanners and vulnerability scanners. The idea is to send an unexpectedly large response to attack strings, and crash the scanner.

24

YARA. a collection of yara rules for binary analysis

24

GLSE. GoLang Scripting Expert, a repo for template scripts regarding basic golang functions, many with a security focus

22

GoRedSpy. post exploitation user monitoring tool

20

presentations. various slides and presentations I've worked on

19

GoRedDeath. Experimenting with destructive file attacks in Go

18

AppleScripts. experimenting w/ apple script for various macOS functionality

14

Ducky_Maker. A fun script to teach automation and create ducky scripts, from existing scripts or ASCII art files

7

nmap-to-netscan. A helper utility for turning nmap xml files into target lists for go-netscan

7

Go_Shells. a collection of shells written with the go programming language, golang

6

Jamf-Attack-Toolkit. Suite of tools to facilitate attacks against the Jamf macOS management platform.

6

go-powershell. a clone of the old gorillalabs go-powershell

4

godns. a simple client lib for doing dns over http

4

pocorgtfo. mirror to the Poc||GTFO zine

4

gloot. gloot is GoRedLoot adapted for gscript

4

Shr3dKit. Red Team Tool Kit

4

GoRedPrompt. POC cross platform prompts for creds

3

lavalink-musicbot. Music bot that uses Lavalink for its audio player.

3

replicant. social media bots

3

CloneWars. Test repo for cloning code signing certs on Windows

3

malware_sources. Pascal

3

DEFCON22-BADGE. My custom code for the DEFCON22 Badge, all in good fun.

3

CVE-2016-3714. ImaegMagick Code Execution (CVE-2016-3714)

2

gopkgs. a fork of github.com/uudashr/gopkgs

2

Awesome-Red-Teaming. List of Awesome Red Teaming Resources

2

awesome-incident-response. A curated list of tools for incident response

2

go-mimikatz. A wrapper around a pre-compiled version of the Mimikatz executable for the purpose of anti-virus evasion.

2

polaroid. Self contained phish endpoint generator and web server.

1

GoFileHash. fun project to mess around with hashing files

1

ad-ldap-enum. An LDAP based Active Directory user and group enumeration tool

1

CVE-2018-15473-Exploit. Exploit written in Python for CVE-2018-15473 with threading and export formats

1

bintriage. additional debug information about executable files

1

PrepCreds. small utility for preparing credential files for hydra or go-netscan

1

Invoke-Obfuscation. PowerShell Obfuscator

1

CVE-2014-4113. PowerShell CVE-2014-4113

1
51
Apply