Stars
A simple script just made for self use for bypassing 403
SeImpersonate privilege escalation tool for Windows 8 - 11 and Windows Server 2012 - 2022 with extensive PowerShell and .NET reflection support.
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Username tools for penetration testing
Collection of username lists for enumerating kerberos domain users
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
A little tool to play with Windows security
A tool to perform Kerberos pre-auth bruteforcing
A python tool to automate KeePass discovery and secret extraction.
Script to retrieve the master password of a keepass database <= 2.53.1
John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs, GPUs, and even some FPGAs
Firefox Decrypt is a tool to extract passwords from Mozilla (Firefox™, Waterfox™, Thunderbird®, SeaMonkey®) profiles
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
A tool to dump a git repository from a website
A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.
OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to …
WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Directory/File, DNS and VHost busting tool written in Go