Kwetsbaarhedenbeheer
231 projecten in Beveiliging & identiteit
Toont top 200 van 231 op Atlas Score; verfijn met de filters hierboven.
Osintgram
@DataluxOsintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
openvas-scanner
@greenboneThis repository contains the scanner component for Greenbone Community Edition.
emba
@e-m-b-aEMBA - The firmware security analyzer
osv.dev
@googleOpen source vulnerability DB and triage service.
AllHackingTools
@mishakorzikAll-in-One Hacking Tools For Hackers! And more hacking tools! For termux.
PhoneSploit-Pro
@AzeemIdrisiAn all-in-one hacking tool to remotely take over Android devices.
Copa
@project-copacetic🧵 CLI tool for directly patching container images!
thc-hydra
@vanhauser-thchydra
Awesome-Cybersecurity-Handbooks
@0xsyr0A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
AngryOxide
@Ragnt802.11 Attack Tool
cve
@trickestGather and update all available and newest CVEs with their PoC.
cameradar
@UllaakutCameradar hacks its way into RTSP videosurveillance cameras
Pentest-Swarm-AI
@Armur-AiAutonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.
SSTImap
@vladko312Automatic SSTI detection tool with interactive interface
reconftw
@six2dezreconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Nettacker
@OWASPAutomated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
mutillidae
@webpwnizedOWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.
AutoCVE
@larlaruaAgent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.
Penetration_Testing_POC
@Mr-xn渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
knockpy
@guelfowebKnock Subdomain Scan
brutespray
@x90skysn3kFast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
medusa
@Ch0pinMobile Edge-Dynamic Unified Security Analysis
ssh-mitm
@ssh-mitmSSH-MITM - ssh audits made simple
DedSec
@dedsec1121fkOfficial repository of the DedSec Project.
malicious-pdf
@jonaslejon💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
redamon
@samugit83An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
pwneye
@HackerestYour ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥
linWinPwn
@lefayjeylinWinPwn is a bash script that streamlines the use of a number of Active Directory tools
APKHunt
@Cyber-BuddyAPKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
wordlists
@trickestReal-world infosec wordlists, updated regularly
Hunting-Queries-Detection-Rules
@Bert-JanPKQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
pentest-ai
@0xStephOpen-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
guac
@guacsecGUAC aggregates software security metadata into a high fidelity graph database.
afrog
@zan8inA Security Tool for Bug Bounty, Pentest and Red Teaming.
cloud_enum
@initstringMulti-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
L0p4Map
@HaxL0p4Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites.
DSInternals
@MichaelGrafnetterDirectory Services Internals (DSInternals) PowerShell Module and Framework
scilla
@edoardotttInformation Gathering tool - DNS / Subdomains / Ports / Directories enumeration
pentest
@ZishanAdThandarPentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.
Awesome-Hacking-Resources
@vitalysimA collection of hacking / penetration testing resources to make you better!
codex-redteam-mode
@chAng-L19针对于红队攻击思维做出的red team模式(破限项目,封号概不负责)##可自行适配其他Agent。项目问题请提issue
rengine
@yogeshojhareNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
xalgorix
@xalgorixAutonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
GooFuzz
@m3n0sd0n4ldGooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).
Exegol
@ThePorgsFully featured and community-driven hacking environment
Ghostwriter
@GhostManagerThe SpecterOps project management and reporting engine
tugarecon
@skynet0x01TugaRecon is an advanced subdomain reconnaissance and intelligence framework built for security researchers, penetration testers and OSINT professionals. It combines OSINT enumeration, semantic analysis, temporal intelligence and automated reactions to continuously improve asset discovery and prioritization.
linkedin2username
@initstringOSINT Tool: Generate username lists for companies on LinkedIn
nmap
@UllaakutIdiomatic nmap library for go developers
sysreptor
@SysliftersA customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
inql
@doyensecInQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
vuln-bank
@Commando-XA deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn pentesting and secure coding practices.
tactical-exploitation
@0xdeaModern tactical exploitation toolkit.
clairvoyance
@nikitastupinObtain GraphQL API schema even if the introspection is disabled
Sitadel
@shenrilWeb Application Security Scanner
WhatWeb
@urbanadventurerNext generation web scanner
pacu
@RhinoSecurityLabsThe AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
DDoSlayer
@blackhatethicalhackingAn Advanced Layer 7 DDoS tool, Able to bypass CF and offers various DoS Techniques
PlumHound
@PlumHoundBloodhound Reporting for Blue and Purple Teams
Cybermes
@ZyrexnnAutonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
Payloader
@3516634930渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
gvmd
@greenboneGreenbone Vulnerability Manager - The database backend for the Greenbone Community Edition
opencve
@opencveVulnerability Intelligence Platform
ARL-Next
@owl234现代化资产测绘与漏洞监控平台 (ARL-Next)。经典 ARL 架构重构,聚焦企业资产关联、异步解耦并发调度与原生 MCP 协议集成,容器化开箱部署。
arsenal-ng
@halilkirazkayaThe classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.
NoSQLMap
@codingoAutomated NoSQL database enumeration and web application exploitation tool.
penetration-testing-cheat-sheet
@ivan-sincekWork in progress...
php-reverse-shell
@ivan-sincekPHP shells that work on Linux OS, macOS, and Windows OS.
TraceSurface
@pis10发现藏在前端代码里的 API,验证未授权访问风险 · 动态浏览器追踪 × JavaScript 静态分析
commando-vm
@mandiantComplete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
titus
@praetorian-incHigh-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
missing-cve-nuclei-templates
@edoardotttWeekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.
pwnagotchi
@jayofelony(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.
dirsearch
@maurosoriaWeb path scanner
evillimiter
@bitbruteTool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access
Red-Team-Playbooks
@0xsyr0This repository contains cutting-edge open-source security notes and tools that will help you during your Red Team assessments.
cra-agent
@kulkarnirohit123Autonomous agentic AI for CRA (Cyber Resilience Act) compliance: scans repos, triages findings, opens Jira tickets, and auto-fixes vulnerabilities via PR.
OffSec-Reporting
@SysliftersOffensive Security OSCP+, OSEP, OSWP, OSWA, OSWE, OSED, OSMR, OSEE, OSDA, OSIR, OSTH Exam and Lab Reporting / Note-Taking Tool
hackingthe.cloud
@Hacking-the-CloudAn encyclopedia for offensive and defensive security knowledge in cloud native technologies.
xurlfind3r
@hueristiqA command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.
BCHackTool
@ByCh4nAll-in-one launcher and installer for popular penetration-testing and OSINT tools on Kali Linux and Termux.
Zen-Ai-Pentest
@SHAdd0WTAka🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️
VulnerableApp
@SasanLabsOWASP VulnerableApp Project: Break it. Scan it. Reproduce it. Benchmark against it. Improve it.
command
@safe6Sec红队常用命令速查
AppSec-Payloads
@sh377c0d3AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters
CVE_Prioritizer
@TURROKSStreamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time threat information, gain a competitive advantage, and stay informed about the latest trends.
graphql-cop
@dolevfSecurity Auditor Utility for GraphQL APIs
android-penetration-testing-cheat-sheet
@ivan-sincekWork in progress...
ezXSS
@sslezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Buildware-Tools
@v4lkyr0Buildware-Tools is an all-in-one multitool for security research and automation.
scant3r
@MindPatchScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
thc-ipv6
@vanhauser-thcIPv6 attack toolkit
huntkit
@mcnameeDocker - Ubuntu with a bunch of PenTesting tools and wordlists
crlfuzz
@dwisiswant0A fast tool to scan CRLF vulnerability written in Go
Web-Cache-Vulnerability-Scanner
@HackmanitWeb Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
Bug-Bounty-Methodology
@tuhin1729These are my checklists which I use during my hunting.
graphw00f
@dolevfgraphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.
EtherGhost
@Marven11新一代Webshell管理器,兼容蚁剑与冰蝎的PHP webshell
AutoPWN-Suite
@GamehunterKaanAutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.
pyhtools
@dmdhrumilmistryA Python Hacking Library consisting of network scanner, arp spoofer and detector, dns spoofer, code injector, packet sniffer, network jammer, email sender, downloader, wireless password harvester credential harvester, keylogger, download&execute, ransomware, data harvestors, etc.
ios-penetration-testing-cheat-sheet
@ivan-sincekWork in progress...
wstg
@OWASPThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Infosec_Reference
@rmusser01An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
Web-Fuzzing-Box
@gh0stkeyWeb Fuzzing Box - Web 模糊测试字典与一些Payloads
PentestTools
@arch3rProAwesome Pentest Tools Collection
adscan
@ADScanProFree Active Directory pentesting tool for Linux, macOS and Windows. Automates AD and LDAP enumeration, Kerberoasting, ASREPRoast, password spraying, ADCS/ESC1, DCSync, RBCD, gMSA, shadow credentials, NTLM relay and credential dumping across 104 techniques, mapping BloodHound-compatible attack paths to Domain Admin. NIS2 / ISO 27001 reports.
MBPTL
@bayufedraBest hands-on lab for learning the fundamentals of cybersecurity and penetration testing workflows also packaged as Docker containers for fast, safe setup.
EasY_HaCk
@sabri-zakiHack the World using Termux
MCP-Kali-Server
@Wh0am123MCP configuration to connect AI agent to a Linux machine.
Garud
@R0X4RAn automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
PingRAT
@umutcamliyurtPingRAT secretly passes C2 traffic through firewalls using ICMP payloads.
changeme
@ztgraceA default credential scanner.
dianxing
@tianchong-zerotempDianXing - AI-Driven End-to-End Code Security Auditing
agartha
@volkandindarA Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.
Sn1per
@1N3Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
Interlace
@codingoEasily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
JustTryHarder
@sinfulzJustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
masvs
@OWASPThe OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
SQLiDetector
@eslam3klSimple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
hoaxshell
@t3l3machusA Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.
Damn-Vulnerable-GraphQL-Application
@dolevfDamn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
VHostScan
@codingoA virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
leaky-paths
@ayoubfathiA collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
hackingtoolkit
@CodingRanjithALL IN ONE Hacking Tool For Hackers, Penetration Tester and Cybersecurity. New Version Beginner to Advanced Tool. This Tool is made for educational purpose only ! Author will not be responsible for any misuse of this toolkit !
TryHackMe
@migueltc13Master cybersecurity skills with this free-only TryHackMe learning path, complete with a progress-tracking template and a collection of my write-ups and solutions.
psudohash
@t3l3machusGenerates millions of keyword-based password mutations in seconds.
RedTeam_toolkit
@signorrayanRed Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.
HackTheBox-Reporting
@SysliftersHack The Box CPTS, CWES, CDSA, CWEE, CAPE, CJCA Exam and Lab Reporting / Note-Taking Tool
lpe-toolkit
@portbuster1337Multi-architecture Linux privilege escalation toolkit with 29 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched exploits, tries each until root.
QuillAudit_smart_contract_audit_Reports
@QuillhashQuillAudits — Smart Contract Audits for DeFi, RWA, DEXs, Tokens, DeAI & DApps
pentest-guide
@VoorivexPenetration tests guide based on OWASP including test cases, resources and examples.
gitjacker
@liamg🔪 :octocat: Leak git repositories from misconfigured websites
SILENTCHAIN
@silentchainaiAI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
A-Red-Teamer-diaries
@ihebskiRedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
passphrase-wordlist
@initstringPassphrase wordlist and hashcat rules for offline cracking of long, complex passwords
Lockdoor-Framework
@SofianeHamlaoui🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
Penetration-Testing-Tools
@mgeekyA collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
gmailc2
@machine1337A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions
vulscan
@scipagAdvanced vulnerability scanning with Nmap NSE
reversingBits
@mohitmishra786A comprehensive collection of cheatsheets for reverse engineering, binary analysis, and assembly programming tools. This repository serves as a one-stop reference for security researchers, reverse engineers, and low-level programmers.
badKarma
@r3vnnetwork reconnaissance toolkit
toxssin
@t3l3machusAn XSS exploitation command-line interface and payload generator.
habu
@fportantierHacking Toolkit
IPRotate_Burp_Extension
@RhinoSecurityLabsExtension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.
ADB-Toolkit
@ASHWIN990ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!
Reconnoitre
@codingoA security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
rapidscan
@skavngr:new: The Multi-Tool Web Vulnerability Scanner.
buster
@sham00nAn advanced tool for email reconnaissance
Brutal
@screetsecPayload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is a toolkit to quickly create various payload,powershell attack , virus attack and launch listener for a Human Interface Device ( Payload Teensy )
Bug-bounty-Writeups
@insecrezRepository of Bug-Bounty Writeups
pwncat
@cytopiapwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)
vulnerable-AD
@safebufferCreate a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
DigiSpark-Scripts
@CedArcticUSB Rubber Ducky type scripts written for the DigiSpark.
Bug-Bounty
@AnLoMinusBug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More
broxy
@rhaidizAn HTTP/HTTPS intercept proxy written in Go.
subscraper
@m8secSubdomain and target enumeration tool built for offensive security testing
Passhunt
@ViralmaniarPasshunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.
slowloris
@gkbrkLow bandwidth DoS tool. Slowloris rewrite in Python.
AWSBucketDump
@jordanpottiSecurity Tool to Look For Interesting Files in S3 Buckets
ThunderSearch
@xzajyjsmacOS上的小而美【Fofa、Shodan、Hunter、Zoomeye、Quake网络空间搜索引擎】闪电搜索器;GUI图形化(Mac/Windows)渗透测试信息搜集工具;资产搜集引擎;hw红队工具hvv
hacktronian
@thehackingsageTools for Pentesting
hackerpro
@jaykaliAll in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog
HostHunter
@SpiderLabsHostHunter a recon tool for discovering hostnames using OSINT techniques.
dotdotpwn
@wireghoulDotDotPwn - The Directory Traversal Fuzzer
htshells
@wireghoulSelf contained htaccess shells and attacks
phishing-frenzy
@pentestgeekRuby on Rails Phishing Framework
Villain
@t3l3machusVillain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
watchdog
@flipkart-incubatorWatchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
SwiftnessX
@ehrishirajsharmaA cross-platform note-taking & target-tracking app for penetration testers.
metagoofil
@opsdiskSearch Google and download specific file types
Gsec
@gotr00t0dayWeb Security Scanner
fuxi
@jeffzh3ngPenetration Testing Platform
HACK-CAMERA
@hackerxphantomHack Victim android Camera Using Link with Termux/Kali-linux
sublert
@yassineaboukirSublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
netcat
@diegocrNetCat for Windows
lazyaircrack
@3xploitGuyAutomated tool for WiFi hacking.
Application-Security
@Anof-cyberResources for Application Security including Web, API, Android, iOS and Thick Client
Pentest-Everything
@The-Viper-OneA collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.
link
@postrequestlink is a command and control framework written in rust
THC-Archive
@hackerschoiceAll releases of the security research group (a.k.a. hackers) The Hacker's Choice
Flask-Unsign
@ParadoxisCommand line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
Pentest-Notes
@SofianeHamlaouiCollection of Pentest Notes and Cheatsheets
BabySploit
@M4cs:baby: BabySploit Beginner Pentesting Toolkit/Framework Written in Python :snake:
breaking-and-pwning-apps-and-servers-aws-azure-training
@appseccoCourse content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
wifi-penetration-testing-cheat-sheet
@ivan-sincekWork in progress...
seccubus
@seccubusEasy automated vulnerability scanning, reporting and analysis
Slackor
@Coalfire-ResearchA Golang implant that uses Slack as a command and control server
kaboom
@Leviathan36A tool to automate penetration tests
nishang
@samratashokNishang - Offensive PowerShell for red team, penetration testing and offensive security.
GodGenesis
@SaumyajeetDasA Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.
Vanquish
@frizbVanquish is Kali Linux based Enumeration Orchestrator. Vanquish leverages the opensource enumeration tools on Kali to perform multiple active information gathering phases.
AllAboutBugBounty
@daffainfoAll about bug bounty (bypasses, payloads, and etc)
whonow
@brannondorseyA "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)
vulscan
@vulscanteamvulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...
DarkAngel
@BywalksDarkAngel 是一款全自动白帽漏洞扫描器,从hackerone、bugcrowd资产监听到漏洞报告生成、漏洞URL截屏、消息通知。
Redeye
@redeye-frameworkRedeye is a tool intended to help you manage your data during a pentest operation
GScan
@grayddq本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。
SonarSearch
@CgboalA rapid API for the Project Sonar dataset
the_cyber_plumbers_handbook
@opsdiskFree copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.
urlcrazy
@urbanadventurerGenerate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.