Starred repositories
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Real-time face swap for PC streaming or video calls
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Exploitation Framework for Embedded Devices
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
An open-source post-exploitation framework for students, researchers and developers.
A swiss army knife for pentesting networks
🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens
Automated All-in-One OS Command Injection Exploitation Tool.
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
IntelOwl: manage your Threat Intelligence at scale
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
A python script that finds endpoints in JavaScript files
A DNS meta-query spider that enumerates DNS records, and subdomains.
Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database.
Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, Th…
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
Privilege Escalation Project - Windows / Linux / Mac
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
SSRF (Server Side Request Forgery) testing resources
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor
Tools & Interesting Things for RedTeam Ops
A collection of Azure AD/Entra tools for offensive and defensive security purposes
The Offensive Manual Web Application Penetration Testing Framework.
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
Burpsuite Extension to bypass 403 restricted directory