Stars
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
A collaborative, multi-platform, red teaming framework
Covenant is a collaborative .NET C2 framework for red teamers.
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. [email protected]
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Red Team Tactics, Techniques, and Procedures
Veil 3.1.X (Check version info in Veil at runtime)
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
Linux Exploit Suggester; based on operating system release number
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.
A simple tool to dump users in popular forums and CMS :)
Check privileges, settings and other information on Linux systems and suggest exploits based on kernel versions
Patch Binaries via MITM: BackdoorFactory + mitmProxy.
Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities.
A utility for arming (creating) many bees (micro EC2 instances) to attack (load test) targets (web applications).
Qt Port for Linux, Mac OSX and Windows
Standalone Executable to Check for Simple Privilege Escalation Vectors on Windows Systems
Automatically exported from code.google.com/p/unix-privesc-check
Automatically exported from code.google.com/p/unix-security-file-parser
Scripts I use during pentest engagements.
Capture passwords of login attempts on non-existent and disabled accounts.
A unique automated LFi Exploiter with Bind/Reverse Shells