Anxun-isoon. I-SOON/Anxun leak related stuff
342Mirai-Botnet. Mirai Botnet Client, Echo Loader and CNC source code (for the sake of knowledge)
101TeamsNTLMLeak. Leak NTLM via Website tab in teams via MS Office
80CitrixSecureAccessAuthCookieDump. Dump Citrix Secure Access auth cookie from the process memory
76Vault-8-Hive. Hive solves a critical problem for the malware operators at the CIA.
66RansomwareMonitor. A ransomware group monitoring bot written in C#.
57Leaked-Password. A database containing 22409485 clear and equivalent sha256 hash passwords
39dnspy-mcp. MCP server for .NET reverse engineering workflows (dnSpy/ILSpy ecosystem), built in C#.
39RansomwareSimulator.public. Ransomware simulator written in C#
38AD-Pentest-Cheatsheet. AD Pentest Cheatsheet by BlackWasp
26ransomware_Incident_Response_FR. petit "playbook" qui pourrait servir de base à une réponse à incident lors d'une attaque de type ransomware
21ContiLeaks.
19deepdarkCTI. Collection of Cyber Threat Intelligence sources from the deep and dark web
16Digital-Forensics-Incident-Response. This post is inspired by all the hard working DFIR, and more broadly security professionals, who have put in the hard yards over the years to discuss in depth digital forensics and incident response. (by Jai Minton)
14MagentoScanner. Magento Security Scanner
13LLMExploiter. A comprehensive security testing framework for Large Language Models based on OWASP Top 10 for LLMs, and NIST AI 600 frameworks. Features advanced false positive reduction, parallel testing, and comprehensive reporting.
9Valkyrie. Another OSINT tool
7HttpRquestPlayer. This small utility could help you to find authorization bugs.
7sqlmap-cheat-sheet. sqlmap cheat sheet
7X-Twitter-Mass-Delete-Script. A JavaScript-based tool to bulk delete your X/Twitter posts. This script allows you to delete tweets from specific time periods using X's advanced search features.
6ESXi_ransomware_bitcoinWallets. ESXi semi-automated ransomware attacks bitcoin wallets
5CitrixSecureAccessSAML. Citrix Secure Access SAML abuse
4os-security-assessment. An automated security assessment tool for analyzing operating system vulnerabilities, patch statuses, and end-of-life risks.
4ICMP. Send file over ICMP (reverse shell)
3ai_llm_risk.
2DoubleAgent. Zero-Day Code Injection and Persistence Technique
2SecLists. SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
2Awesome-WAF. 🔥 Everything awesome about web-application firewalls (WAF).
2AutoSploit. Automated Mass Exploiter
2Ysoserial. Compiled jar version ysoserial (java payloads)
2bug-bounty-reference. Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
2randomLists. Random wordlists (dirs,files,xss...)
2RedTeaming_CheatSheet. Pentesting cheatsheet with all the commands I learned during my learning journey. Will try to to keep it up-to-date.
2oss-fuzz. OSS-Fuzz - continuous fuzzing of open source software
2Cyberwatch. Building a consolidated RSS feed for articles about cyberattacks
2Resources-for-Beginner-Bug-Bounty-Hunters. A list of resources for those interested in getting started in bug bounties
2Bloodhound-Custom-Queries. Custom Query list for the Bloodhound GUI based off my cheatsheet
1CVE-2021-34527. PowerShell
1RandomCreditCardNumberGenerator. This is a port of the port of of the Javascript credit card number generator now in C# by Kev Hunter https://kevhunter.wordpress.com
1One-Liners. A collection of awesome one-liners for bug bounty hunting.
1Amass. In-depth Attack Surface Mapping and Asset Discovery
1GraphQLmap. GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.
1public-pentesting-reports. Curated list of public penetration test reports released by several consulting firms and academic security groups
1awesome-osint. :scream: A curated list of amazingly awesome OSINT
1Red-Team-Management. HTML
1Active-Directory-Exploitation-Cheat-Sheet. A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
1CVE-2021-26868. C
1sql-injection-payload-list. 🎯 SQL Injection Payload List
1HackerArt. A collection of art inspired by the world of cybersecurity and hacking culture.
1fuzzdb. Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
1RemoteAssemblyLoader. C#
1bruteforce-lists. Some files for bruteforcing certain things.
1xss-cheat-sheet. Ultimate Cross Site Scripting Attack Cheat Sheet
1Probable-Wordlists. Wordlists sorted by probability originally created for password generation and testing
1