Mongoaudit🔥 A powerful MongoDB auditing and pentesting tool 🔥
OscpOur OSCP repo: from popping shells to mental health.
Netmap.jsFast browser-based network discovery module
PentestingazureappsScript samples from the book Pentesting Azure Applications (2018, No Starch Press)
Red Team Curation ListA list to discover work of red team tooling and methodology for penetration testing and security assessment
GtfonowAutomatic privilege escalation for misconfigured capabilities, sudo and suid binaries
ReconcatA small Php application to fetch archive url snapshots from archive.org. using it you can fetch complete list of snapshot urls of any year or complete list of all years possible. Made Specially for penetration testing purpose.
CloakifyCloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection
Attack Surface Detector BurpThe Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
NeedleThe iOS Security Testing Framework
ResourcesA Storehouse of resources related to Bug Bounty Hunting collected from different sources. Latest guides, tools, methodology, platforms tips, and tricks curated by us.
RedsnarfRedSnarf is a pen-testing / red-teaming tool for Windows environments
VulmapVulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞利用功能
Kill RouterFerramenta para quebrar senhas administrativas de roteadores Wireless, routers, switches e outras plataformas de gestão de serviços de rede autenticados.
DeltaPROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK
Burpsuite CollectionsBurpSuite收集:包括不限于 Burp 文章、破解版、插件(非BApp Store)、汉化等相关教程,欢迎添砖加瓦---burpsuite-pro burpsuite-extender burpsuite cracked-version hackbar hacktools fuzzing fuzz-testing burp-plugin burp-extensions bapp-store brute-force-attacks brute-force-passwords waf sqlmap jar
SpellbookMicro-framework for rapid development of reusable security tools
Pentest⛔️ offsec batteries included
Pentesting BibleLearn ethical hacking.Learn about reconnaissance,windows/linux hacking,attacking web technologies,and pen testing wireless networks.Resources for learning malware analysis and reverse engineering.
SsrfmapSimple Server Side Request Forgery services enumeration tool.
MilkyA .NET Standard library for pentesting web apps against credential stuffing attacks.
PrivesccheckPrivilege Escalation Enumeration Script for Windows
SleightEmpire HTTP(S) C2 redirector setup script
Log Requests To SqliteBURP extension to record every HTTP request send via BURP and create an audit trail log of an assessment.
KeyloggerA simple keylogger for Windows, Linux and Mac
DnsbruteDNS Sub-domain brute forcer, in Python + gevent
Eyes👀 🖥️ Golang rewrite of eyes.sh. Let's you perform domain/IP address information gathering. Wasn't it esr who said "With enough eyeballs, all your IP info are belong to us?" 🔍 🕵️
DirhuntFind web directories without bruteforce
Social AnalyzerAPI, CLI & Web App for analyzing & finding a person's profile across +1000 social media \ websites (Detections are updated regularly by automated systems)
Babysploit👶 BabySploit Beginner Pentesting Toolkit/Framework Written in Python 🐍
Kubernetes GoatKubernetes Goat is "Vulnerable by Design" Kubernetes Cluster. Designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security.
SudomySudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
V3n0m ScannerPopular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns
CommoncrawlparserSimple multi threaded tool to extract domain related data from commoncrawl.org
Pwncatpwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)
SecuritySome of my security stuff and vulnerabilities. Nothing advanced. More to come.
HashtopolisA Hashcat wrapper for distributed hashcracking
SessiongopherSessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.
Ciphey⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
Sn0intSemi-automatic OSINT framework and package manager
SprayingtoolkitScripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient
GoscanInteractive Network Scanner
PrivescA collection of Windows, Linux and MySQL privilege escalation scripts and exploits.
PupyPupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python
Dumpsterfire"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
PerunPerun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架
EvillimiterTool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access.
SpoilerwallSpoilerwall introduces a brand new concept in the field of network hardening. Avoid being scanned by spoiling movies on all your ports!