Skip to content
View threatyodeling's full-sized avatar

Block or report threatyodeling

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

Python 1,327 182 Updated Nov 26, 2024

TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

Python 1,100 150 Updated Nov 13, 2024

This challenge is Inon Shkedy's 31 days API Security Tips.

2,109 332 Updated Apr 20, 2022

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

2,610 519 Updated Sep 17, 2024

Penetration tests guide based on OWASP including test cases, resources and examples.

2,518 551 Updated Mar 23, 2022

Automatic SSRF fuzzer and exploitation tool

Python 3,056 530 Updated Jun 10, 2024

SSRF (Server Side Request Forgery) testing resources

Python 2,376 481 Updated Oct 12, 2024

Awesome Node.js Security resources

2,767 244 Updated Dec 22, 2024

A collection of custom security tools for quick needs.

Python 3,165 792 Updated May 1, 2023

Attack and defend active directory using modern post exploitation adversary tradecraft activity

4,462 1,040 Updated Nov 7, 2024

FCL (Fileless Command Lines) - Known command lines of fileless malicious executions

462 78 Updated Apr 8, 2021

A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and re…

C 2,498 731 Updated Jun 22, 2020

Miscellaneous pentesting scripts for OSCP

Shell 57 10 Updated Dec 3, 2018

2018年初整理的一些内网渗透TIPS,后面更新的慢,所以整理出来希望跟小伙伴们一起更新维护~

4,530 1,093 Updated Feb 24, 2023

This tool is used to map out the network data flow to help penetration testers identify potentially valuable targets.

Ruby 244 34 Updated Oct 22, 2021

Compilation of commands, tips and scripts that helped me throughout Vulnhub, Hackthebox, OSCP and real scenarios

XSLT 1,332 408 Updated Dec 22, 2022

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

C# 2,218 224 Updated Nov 2, 2024

XSS payloads designed to turn alert(1) into P1

JavaScript 1,350 218 Updated Sep 12, 2023

This cheasheet is aimed at the CTF Players and Beginners to help them sort the CTF Challenges on the basis of Difficulties.

762 190 Updated Oct 23, 2022

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

3,342 624 Updated Feb 11, 2023

A laboratory for learning secure web and mobile development in a practical manner.

PHP 916 446 Updated Sep 25, 2024

vulnerable single sign on

Java 147 28 Updated Aug 1, 2024

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

PHP 685 176 Updated Aug 21, 2023

Shell script for testing DNS zone transfer (AXFR query) on domains and subdomains recursively.

Shell 49 14 Updated Dec 6, 2020

A simple tool which could be useful to identify the exploits afflicting a Windows OS

Python 125 27 Updated Jun 10, 2023

Linux Local Privesc Helper and Agent

Python 165 13 Updated Dec 2, 2019

Extract credentials from lsass remotely

Python 2,081 250 Updated Dec 31, 2024

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Go 4,575 507 Updated Dec 21, 2024
Next