ScantronA distributed nmap / masscan scanning framework complete with an API client for automation workflows
WhonowA "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)
Commando VmComplete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution.
[email protected] HackerproAll in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog
Thc ArchiveAll releases of the security research group (a.k.a. hackers) The Hacker's Choice
ChimeraChimera is a (shiny and very hack-ish) PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
PentestkitUseful tools and scripts during Penetration Testing engagements
JusttryharderJustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
VanquishVanquish is Kali Linux based Enumeration Orchestrator. Vanquish leverages the opensource enumeration tools on Kali to perform multiple active information gathering phases.
Dradis CeDradis Framework: Colllaboration and reporting for IT Security teams
HosthunterHostHunter a recon tool for discovering hostnames using OSINT techniques.
Cloud enumMulti-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
PwndocPentest Report Generator
PoweropsPowerShell Runspace Portable Post Exploitation Tool aimed at making Penetration Testing with PowerShell "easier"
SifterSifter aims to be a fully loaded Op Centre for Pentesters
ArchstrikeAn Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.
StegcrackerSteganography brute-force utility to uncover hidden data inside files
GhostwriterThe SpecterOps project management and reporting engine
Slackor A Golang implant that uses Slack as a command and control server
NmapIdiomatic nmap library for go developers
Cerberus一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
BusterAn advanced tool for email reconnaissance
A Red Teamer DiariesRedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
Infosec referenceAn Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
Vulnhub Ctf WriteupsThis cheasheet is aimed at the CTF Players and Beginners to help them sort Vulnhub Labs. This list contains all the writeups available on hackingarticles.
Vulnerable AdCreate a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
SitadelWeb Application Security Scanner
Hunter(l)user hunter using WinAPI calls only
Awesome InfosecA curated list of awesome infosec courses and training resources.
KaboomA tool to automate penetration tests
OsintgramOsintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
ConptyshellConPtyShell - Fully Interactive Reverse Shell for Windows
HackdroidAndroid Apps, Roms and Platforms for Pentesting
WebkillerTool Information Gathering Write By Python.
SonarsearchA MongoDB importer and API for Project Sonars DNS datasets
Teamviewer permissions hook v1A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.
Dnscat2 PowershellA Powershell client for dnscat2, an encrypted DNS command and control tool.
Cheatsheet GodPenetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
OsmedeusFully automated offensive security framework for reconnaissance and vulnerability scanning
NovahotA webshell framework for penetration testers.
EastExploits and Security Tools Framework 2.0.1
SitebrokerA cross-platform python based utility for information gathering and penetration testing automation!
FaradayFaraday introduces a new concept - IPE (Integrated Penetration-Test Environment) a multiuser Penetration test IDE. Designed for distributing, indexing, and analyzing the data generated during a security audit.
Penetration testing poc渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss penetration-testing-poc csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
ArachniWeb Application Security Scanner Framework