Modlishka. Modlishka. Reverse Proxy.
5.4kPortspoof. Portspoof
2.4kHeaderScan. "HeaderScan" Burp Plugin
16Shr3dKit. Red Team Tool Kit
16Red_Team. Some scripts useful for red team activities
13bypass_waf. waf自动爆破(绕过)工具
10WebViewApps. Swift
9evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
7xploits.
6muraena. Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
5password_cracking_rules. One rule to crack all passwords. or atleast we hope so.
5AndroidProjectCreator. Convert an APK to an Android Studio Project using multiple open-source decompilers
5SirepRAT. Remote Command Execution as SYSTEM on Windows IoT Core
5beautiful-jekyll. :sparkles: Build a beautiful and simple website in literally minutes. Demo at http://deanattali.com/beautiful-jekyll
4xss-payload-list. 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
4cve-2019-1003000-jenkins-rce-poc. Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
4sploits. C++
4rescope. Parse scope definitions to Burp Suite / ZAP compatible formats for import
4Exploits. Windows Exploits
4domained. Multi Tool Subdomain Enumeration
4juicy-potato. A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
4stuffz. Basically a script thrift shop
4muddyc3. Leaked Muddyc3 C2 source.
3frida-scripts. A collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile Apps.
3blog.github.io. Build a Jekyll blog in minutes, without touching the command line.
3exploit-database. The official Exploit Database repository
3fuzzdb. Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
3pocs. C
3sqlmap. Automatic SQL injection and database takeover tool
3Face-Depixelizer. Face Depixelizer based on "PULSE: Self-Supervised Photo Upsampling via Latent Space Exploration of Generative Models" repository.
3exploit_generator. Automated Exploit generation with WinDBG
3assets.
3dlinject. Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace
2webshellz. Various Web Shells
2JNI-Frida-Hook. Script to quickly hook natives call to JNI in Android
2portspoof.github.io. HTML
2fpmvuln. bash poc scripts to exploit open fpm ports
2DetectFrida. Detect Frida for Android
2Noah. Lightweight node/service registry inspired by Apache Zookeeper
2ewus. eWUS - PHP library implementing eWUS functionality
2WP-Vulnerabilities-Exploits. Huge Collection of Wordpress Exploits and CVES
2Vectors. reboot spear phishing
2delete-self-poc. A way to delete a locked, or current running executable, on disk.
2cloudformation-templates. AWS CloudFormation templates for common tasks.
2rev-regexp-lib. Reverse regular expression C++ library
2CVE-2021-26855. Go
2strong-frida. make frida strong, bypass frida detection.
1Lagrange. A minimalist Jekyll theme for running a personal blog
1Blind-XSS-SVG. Blind XSS SVG
1SkCodecFuzzer. Fuzzing harness for testing proprietary image codecs supported by Skia on Android
1duszynski.github.io.
1kpn-security-policy. KPN Security Policy
1osx. Unofficial GitHub-import of OS X source packages from http://opensource.apple.com/
1struts-scan. Python2编写的struts2漏洞全版本检测和利用工具
1