mimikittenz. A post-exploitation powershell tool for extracting juicy info from memory.
1.9kasnrecon. ASN reconnaissance script
136spinningcat. JavaScript
92polyrange. JavaScript
19hardmail. Hardened, shell-free native email tools for the Hermes agent (Gmail/IMAP/SMTP/Resend). Reads open; sends are operator-approved and fail-closed.
8x-reaper. Dig up old/protected tweets
4codec. One-shot @persona routing on the Hermes gateway (@snake/@otacon/...). Reads agent.personalities; not sticky.
3youshallnotpass. Per-tool, per-platform pre_tool_call policy gate for the Hermes agent. Turns a prompt-injection into a vetoable approval, or blocks it.
2shiftleft-js-demo. JavaScript
1juice-shop. OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
1hosts. Consolidating and extending hosts files from several well-curated sources. You can optionally pick extensions to block pornography, social media, and other categories.
1sast-scan. Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.
1mutillidae. OWASP Mutillidae II is a free, open source, deliberately vulnerable web-application providing a target for web-security enthusiast. Mutillidae can be installed on Linux and Windows using LAMP, WAMP, and XAMMP. It is pre-installed on SamuraiWTF and OWASP BWA. The existing version can be updated on these platforms. With dozens of vulnerabilities and hints to help the user; this is an easy-to-use web hacking environment designed for labs, security enthusiast, classrooms, CTF, and vulnerability assessment tool targets. Mutillidae has been used in graduate security courses, corporate web sec training courses, and as an "assess the assessor" target for vulnerability assessment software.
1pam-poc. Ghetto forensics repo. Maybe useful in reversing the Optus API issue.
1vault. A tool for secrets management, encryption as a service, and privileged access management
1Cloud-Testing-Guide.
1owasp.github.io. OWASP Foundation main site repository
1snyk. CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies
1wstg. The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.
1nuclei-action. Vulnerability Scan with Nuclei
1chieffancypants. HTML
1markdown-badges. Badges for your Profile and Projects.
1can-i-take-over-xyz. "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
1shuffledns. shuffleDNS is a wrapper around massdns written in go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output support.
1