InfoSec
Free copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.
List of Awesome Red Teaming Resources
Issues to consider when planning a red team exercise.
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Pester is the ubiquitous test and mock framework for PowerShell.
Wiki to collect Red Team infrastructure hardening resources
🐧 Abuse of Google Colab for cracking hashes.
Password spraying and bruteforcing tool for Active Directory Domain Services
Zero Infrastructure Password Cracking
A powerful browser extension to create, edit and delete cookies
Python script to enumerate users, groups and computers from a Windows domain through LDAP queries
Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens
(⌐■_■) - Deep Reinforcement Learning instrumenting bettercap for WiFi pwning.
Nmap - the Network Mapper. Github mirror of official SVN repository.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Confidant: your secret keeper. https://lyft.github.io/confidant
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber
A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileg…
A Collection of Scripts Which Disable / Remove Windows 10 Features and Apps
🕵️♂️ Collect a dossier on a person by username from thousands of sites
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
iptablesbuild is effectively a configuration manager for iptables. It is intended to manage iptables configurations in a centralized location for multiple systems.
Various tips & tricks
A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.