Peter Kim

Elite
@cheetz

sslScrape. SSLScrape | A scanning tool for scaping hostnames from SSL certificates.

341

thp2. thp2 setup

267

THP3_Updates.

206

Easy-P. PowerShell Helper Tool

150

brutescrape. A web scraper for generating password files based on plain text found

130

PowerTools. Veil's PowerTools are a collection of PowerShell projects with a focus on offensive operations.

99

THP-ChatSupportSystem. The Hacker Playbook 3 - Web Commands

85

hidemyps. Python

42

icmpshock. A scanning tool for the ShellShock bash vulnerability

34

PowerShell_Popup. PowerShell_Popup

33

PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework

30

generateJenkinsExploit. Python

29

thpDropper. Custom THP Dropper

26

ceylogger. Basic c-keylogger

26

adobe_password_checker. Python

21

reddit_xss. Reddit XSS Gather Tool

20

c2. Covert Channels for C2 Server

17

spearphishing. HTML

15

pi_phone_home. Raspberry Pi 2 C2

15

Password_Plus_One. initial push

14

THP1-2_Updates.

14

nishang. Nishang - PowerShell for penetration testing and offensive security.

14

atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.

9

Probable-Wordlists. Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!

8

meterssh. MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a normal SSH connection. The way it works is by injecting shellcode into memory, then wrapping a port spawned (meterpeter in this case) by the shellcode over SSH back to the attackers machine. Then connecting with meterpreter's listener to localhost will communicate through the SSH proxy, to the victim through the SSH tunnel. All communications are relayed through the SSH tunnel and not through the network.

7

jenkins-decrypt. Credentials dumper for Jenkins

6

Responder. Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

5

NoSQL_Test. Test lab from https://github.com/tcstool/NoSQLMap

5

LinEnum. Scripted Local Linux Enumeration & Privilege Escalation Checks

5

Web_Password_Gen. Python

4

dirtycow.

4

stayroot. C

3

metasploit-payloads. Unified repository for different Metasploit Framework payloads

3

dnscat2. C++

2

Internal-Monologue. Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

1
35
Apply