Stars
A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework.
The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.
Admin to Kernel code execution using the KSecDD driver
A proof-of-concept Remote Desktop (RDP) session hijack utility
Partial python implementation of SharpGPOAbuse
This repository provides penetration testers and red teams with an extensive collection of dynamic phishing templates designed specifically for use with Evilginx3. May be updated periodically.
Fully featured and community-driven hacking environment
A swiss army knife for pentesting networks
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. [email protected]
WebGoat is a deliberately insecure application
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
An intentionally vulnerable NGINX setup
Generate graphs and charts based on password cracking result
Dump NTDS with golden certificates and UnPAC the hash
A python tool to automate KeePass discovery and secret extraction.
Six Degrees of Domain Admin
A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.