Stars
Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.
A set of programs for analyzing common vulnerabilities in COM
Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.
The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.
Cmd.exe Command Obfuscation Generator & Detection Test Harness
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
Static binaries, removing any required dependencies from the operating system. Gziped files availabe to download via curl onto your targeted system.
Standalone binaries for Linux/Windows of Impacket's examples
A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository…
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique present…
Template-Driven AV/EDR Evasion Framework
A pentest reporting tool written in Python. Free yourself from Microsoft Word.
A collection of all the data i could extract from 1 billion leaked credentials from internet.
GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint List and exfiltrate files using Google Drive or…
Collection of PoC and offensive techniques used by the BlackArrow Red Team
collect for learning cases
This map lists the essential techniques to bypass anti-virus and EDR
Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)
🔗 Don't know what type of hash it is? Name That Hash will name that hash type! 🤖 Identify MD5, SHA256 and 300+ other hashes ☄ Comes with a neat web app 🔥