A collaborative, multi-platform, red teaming framework
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
Patch Binaries via MITM: BackdoorFactory + mitmProxy.
Scripts I use during pentest engagements.
DotDotPwn - The Directory Traversal Fuzzer
Some setup scripts for security research tools.
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
An IRC based tool for testing the capabilities of a botnet.
A command line tool that recreates the famous data decryption effect seen in the 1992 movie Sneakers.
Faker is a Python package that generates fake data for you.
PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.
XRay is a tool for recon, mapping and OSINT gathering from public networks.
Uses Empire's ( RESTful API to automate gaining Domain and/or Enterprise Admin rights in Active Directory environments using some of the most common offensive …
DKMC - Dont kill my cat - Malicious payload evasion tool
Know the dangers of credential reuse attacks.
My personal hacklab, create your own.
Automate the creation of a lab environment complete with security tooling and logging best practices
The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
A collection of PHP exploit scripts, found when investigating hacked servers. These are stored for educational purposes and to test fuzzers and vulnerability scanners. Feel free to contribute.
CACTUSTORCH: Payload Generation for Adversary Simulations