Stars
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, i…
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
rvrsh3ll / cors-anywhere
Forked from Rob--W/cors-anywhereCORS Anywhere is a NodeJS reverse proxy which adds CORS headers to the proxied request.
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
A fork of the great TokenTactics with support for CAE and token endpoint v2
A collection of Azure AD/Entra tools for offensive and defensive security purposes
TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation".
Custom Query list for the Bloodhound GUI based off my cheatsheet
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
Slides, documentation, and files from my presentation at Red Team Village for HackerOne's hacktivitycon.
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
A fast, simple, recursive content discovery tool written in Rust.
latest version of scanners for IIS short filename (8.3) disclosure vulnerability
🔱 Powerfull XSS Scanning and Parameter analysis tool&gem
.NET IPv4/IPv6 machine-in-the-middle tool for penetration testers
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities
Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit