Highlights
- Pro
Stars
Uma aplicação web propositalmente vulnerΓ‘vel para vocΓͺ ownar
Script for encrypting a GNU/Linux filesystem and then destroying the keys
All knowledge I gained from CTFs, real life penetration testing and learning by myself.
This repository contains cheatsheets and payloads compiled from completing the labs at PortSwigger Academy.
Top disclosed reports from HackerOne
This repository contains list of web security related resources that you can use to gain new skills and extend knowledge
Inject RDPThief into memory with PowerShell.
Simple Python script that will set up a PHP server for stealing cookies - and provided the payload needed.
π Amazon Web Services β a practical guide
PowerShell Constrained Language Mode Bypass
Powershell tool to automate Active Directory enumeration.
A PowerShell tool that takes strong inspiration from CrackMapExec / NetExec
A source generator to add a user-defined set of Win32 P/Invoke methods and supporting types to a C# project.
A slightly more fun way to disable windows defender + firewall. (through the WSC api)
Introductory guide on the configuration and subsequent exploitation of Active Directory Certificate Services with Certipy. Based on the white paper Certified Pre-Owned.
Obsidian Templates for OSCP, CPTS, and Training labs
A repository for additional files related to the book Windows Security Internals with PowerShell from No Starch Press.
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
AWSGoat : A Damn Vulnerable AWS Infrastructure
π΅οΈββοΈ All-in-one OSINT tool for analysing any website
BacenSimulator is a docker image to simulate bacen, a official brazilian payment infrastructure
A companion tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.