RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation scenario.
Source Code Security Audit (源代码安全审计)
DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap
A Blazing fast Security Auditing tool for Kubernetes
Google Cloud Platform Security Tool
Identify hardcoded secrets and dangerous behaviours
Open Cloud Security Posture Management Engine
Sbt Dependency Check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈
Biu-framework🚀 Security Scan Framework For Enterprise Intranet Based Services(企业内网基础服务安全扫描框架)
Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
YAWAST ...where a pentest starts. Security Toolkit for Web-based Applications
nnposter's alternate fingerprint dataset for Nmap script http-default-accounts
Anteater - CI/CD Gate Check Framework
Recsech is a tool for doing Footprinting and Reconnaissance on the target web. Recsech collects information such as DNS Information, Sub Domains, HoneySpot Detected, Subdomain takeovers, Reconnaissance On Github and much more you can see in Features in tools .
A simple tool for interacting with OWASP ZAP from the commandline.
Advanced vulnerability scanning with Nmap NSE
proxy poc implementation of STARTTLS stripping attacks
A Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
Harden the world is a community driven project to develop hardening guidelines and checklists for common software and devices.
NebulousAD automated credential auditing tool.
A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public
Custom memory allocator that helps discover reads from uninitialized memory
🕵️♀️ MixAudit provides a mix deps.audit task to scan a project Mix dependencies for known Elixir security vulnerabilities
A tool for auditing security properties of GCP projects.
This code is vulnerable to SQL Injection and having SQLite database. For SQLite database, SQL Injection payloads are different so it is for fun. Just enjoy it \m/
Edr Testing Script
Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter/Invoke-DOSfuscation payloads
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
Automated NoSQL database enumeration and web application exploitation tool.
Find Sec Bugs
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
Powerful Visual Subdomain Enumeration at the Click of a Mouse
Set of tools to audit SIP based VoIP Systems
Send encrypted PGP messages with one click
Audit Windows Security with best Practice
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Kubernetes Common Configuration Scoring System
Cat-Nip Automated Basic Pentest Tool - Designed For Kali Linux
Gda Android Reversing Tool
GDA is a new fast and powerful decompiler in C++(working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, dat…
A static-code-analysis tool for performing security-focused code reviews. It enables an auditor to swiftly map the attack-surface of a large application, with an emphasis on identifying development anti-patterns and footguns.
VOIP Security Audit Framework
Aws Securitygroup Grapher
This ansible role gets information from an AWS VPC and generate a graphical representation of security groups
Unit testing framework for test driven security of AWS, GCP, Heroku and more.
Collection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)
Passively scan for Bluetooth Low Energy devices and attempt to fingerprint them
Rails Security Checklist
🔑 Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)