Stars
a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
Red Team Tips as posted by @vysecurity on Twitter
Fork of SafetyKatz that dynamically fetches the latest pre-compiled release of Mimikatz directly from gentilkiwi GitHub repo, runtime patches signatures and uses SharpSploit DInvoke to PE-Load into…
Microsoft » Windows 10 : Security Vulnerabilities
GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.
A curated list of Awesome Threat Intelligence resources
Search for potential frontable domains
CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!
A collection of Ansible Playbooks that configure Kali to use Fish & install a number of tools
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A curated list of amazingly awesome Burp Extensions
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Build a basic Command & Control botnet in C
Misc dictionaries for directory/file enumeration, username enumeration, password dictionary/bruteforce attacks
PowerSploit - A PowerShell Post-Exploitation Framework
In-depth attack surface mapping and asset discovery
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.
A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.