Stars
Labtainers: A Docker-based cyber lab framework
A collection of red team and adversary emulation resources developed and released by MITRE.
Automated Attack Simulation in the Cloud, complete with detection use cases.
DevSecOps, ASPM, Vulnerability Management. All on one platform.
ThreatBox is a standard and controlled Linux based attack platform. I've used a version of this for years. It started as a collection of scripts, lived as a rolling virtual machine, existed as code…
Various tips & tricks
A collective list of public APIs for use in security. Contributions welcome
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
Tool for extracting comments or subtitles from youtube video's
Great List of Resources to Build an Enterprise Grade Home Lab
Another API-less Instagram pictures and videos downloader.
Collections of tools and methods created to aid in OSINT collection
Awesome Burp Suite Resources. 400+ open source Burp plugins, 400+ posts and videos.
A step-by-step walkthrough of CloudGoat 2.0 scenarios.
This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into product…
Bloodhound Reporting for Blue and Purple Teams
An open source, online threat modelling tool from OWASP
A collection of various scripts in perl/python/bash which i use while administering my own servers.
Empire is a PowerShell and Python post-exploitation agent.
Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail f…
Wordpress security functions for paranoid folks. (themes functions.php and .htaccess). Take what you want, leave what you think should be added to it.
Helps with finding and registering categorized domains
CPH:SEC - Copenhagen Ethical Hacking and Penetration Testing Society
Impacket is a collection of Python classes for working with network protocols.
ATT&CK Remote Threat Hunting Incident Response