Lists (3)
Sort Name ascending (A-Z)
Stars
The SpecterOps project management and reporting engine
GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.
Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.
Arabhunters / Monitorizer
Forked from BitTheByte/Monitorizerالنسخة المعدلة من Monitorizer
Script to root AVDs running with QEMU Emulator from Android Studio
The Startup CTO's Handbook, a book covering leadership, management and technical topics for leaders of software engineering teams
Different types of data structures and their implementations in C++
Compilation of Resources from TCM's Practical Ethical Hacking Udemy Course
This repository contains 0 click exploits to some HackTheBox machines, I used it to study for OSWE
Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
SQLI labs to test error based, Blind boolean based, Time based.
Automate creating resilient, disposable, secure and agile infrastructure for Red Teams.
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Tips on how to write exploit scripts (faster!)
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations
Automation for internal Windows Penetrationtest / AD-Security
Impacket is a collection of Python classes for working with network protocols.
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world.…
Interview questions to screen offensive (red team/pentest) candidates
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Monitor linux processes without root permissions