Skip to content
Change the repository type filter

All

    Repositories list

    • SecLists

      Public
      SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
      PHP
      25k000Updated Jun 19, 2024Jun 19, 2024
    • Metasploit Framework
      Ruby
      15k000Updated Jun 11, 2024Jun 11, 2024
    • Multi-Cloud Security Auditing Tool
      Python
      1.2k000Updated Jun 11, 2024Jun 11, 2024
    • hayabusa

      Public
      Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
      Rust
      251000Updated Jun 11, 2024Jun 11, 2024
    • beef

      Public
      The Browser Exploitation Framework Project
      JavaScript
      2.3k000Updated Jun 10, 2024Jun 10, 2024
    • hashcat

      Public
      World's fastest and most advanced password recovery utility
      C
      3.3k000Updated Jun 10, 2024Jun 10, 2024
    • sqlmap

      Public
      Automatic SQL injection and database takeover tool
      Python
      6.1k000Updated Jun 10, 2024Jun 10, 2024
    • impacket

      Public
      Impacket is a collection of Python classes for working with network protocols.
      Python
      3.8k000Updated Jun 9, 2024Jun 9, 2024
    • pacu

      Public
      The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
      Python
      763000Updated Jun 8, 2024Jun 8, 2024
    • Find and verify secrets
      Go
      2.1k000Updated Jun 8, 2024Jun 8, 2024
    • masscan

      Public
      TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
      C
      3.2k000Updated Jun 7, 2024Jun 7, 2024
    • EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
      Python
      893000Updated Jun 7, 2024Jun 7, 2024
    • LOLBAS

      Public
      Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
      XSLT
      1.1k000Updated Jun 6, 2024Jun 6, 2024
    • sigma

      Public
      Main Sigma Rule Repository
      Python
      2.4k000Updated Jun 5, 2024Jun 5, 2024
    • A Linux version of the ProcDump Sysinternals tool
      C
      326000Updated May 31, 2024May 31, 2024
    • AADInternals PowerShell module for administering Azure AD and Office 365
      PowerShell
      241000Updated May 21, 2024May 21, 2024
    • CeWL

      Public
      CeWL is a Custom Word List Generator
      Ruby
      298000Updated May 16, 2024May 16, 2024
    • thc-hydra

      Public
      hydra
      C
      2.3k000Updated May 7, 2024May 7, 2024
    • tls-scan

      Public
      An Internet scale, blazing fast SSL/TLS scanner ( non-blocking, event-driven )
      C
      55000Updated Apr 17, 2024Apr 17, 2024
    • CloudMapper helps you analyze your Amazon Web Services (AWS) environments.
      JavaScript
      841000Updated Apr 3, 2024Apr 3, 2024
    • rita

      Public
      Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
      Go
      359000Updated Mar 21, 2024Mar 21, 2024
    • MSOLSpray

      Public
      A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.
      PowerShell
      175000Updated Mar 19, 2024Mar 19, 2024
    • AzViz

      Public
      ⚡ ☁ Azure Visualizer aka 'AzViz' : A #powershell module to automatically generate Azure resource topology diagrams by just typing a PowerShell cmdlet and passing the name of one or more Azure Resource groups
      PowerShell
      158000Updated Oct 24, 2023Oct 24, 2023
    • DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
      PowerShell
      402000Updated Sep 22, 2023Sep 22, 2023
    • This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
      548000Updated Sep 21, 2023Sep 21, 2023
    • Identifies the bytes that Microsoft Defender flags on.
      C#
      461000Updated Sep 14, 2023Sep 14, 2023
    • smbeagle

      Public
      SMBeagle - Fileshare auditing tool.
      C#
      82000Updated Jul 28, 2023Jul 28, 2023
    • A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.
      Python
      89000Updated May 26, 2023May 26, 2023
    • fireprox

      Public
      AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
      Python
      288000Updated Apr 3, 2023Apr 3, 2023
    • DPAT

      Public
      Domain Password Audit Tool for Pentesters
      Python
      161000Updated Jun 24, 2022Jun 24, 2022