Stars
- All languages
- AGS Script
- Arduino
- Assembly
- Batchfile
- BlitzBasic
- Boo
- C
- C#
- C++
- CSS
- CodeQL
- Dockerfile
- FreeMarker
- Go
- HCL
- HTML
- Hack
- Java
- JavaScript
- Jinja
- Jupyter Notebook
- Kotlin
- Lua
- MDX
- Nim
- OCaml
- Open Policy Agent
- PHP
- Perl
- PowerShell
- Python
- Roff
- Ruby
- Rust
- Shell
- Smarty
- TypeScript
- TypeSpec
- VBA
- Verilog
- Vim Script
- Visual Basic
- Vue
- XSLT
- YARA
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
Automatic SQL injection and database takeover tool
The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the contr…
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
Incredibly fast crawler designed for OSINT.
OpenSnitch is a GNU/Linux interactive application firewall inspired by Little Snitch.
A swiss army knife for pentesting networks
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
🐚 Python-powered shell. Full-featured and cross-platform.
(⌐■_■) - Deep Reinforcement Learning instrumenting bettercap for WiFi pwning.
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
IntelOwl: manage your Threat Intelligence at scale
Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor
Striker is an offensive information and vulnerability scanner.
Stealing Signatures and Making One Invalid Signature at a Time
This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.
Know the dangers of credential reuse attacks.
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
Run PowerShell command without invoking powershell.exe
Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient