Stars
collect for learning cases
Complete list of LPE exploits for Windows (starting from 2023)
Find, verify, and analyze leaked credentials
A tool to perform Kerberos pre-auth bruteforcing
Native rewrite of Aerochat, a WLM 09 themed Discord client
Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...
Store my 'Useful Commands' for HTB/OSCP and additional notes from my Obisidan. Merge into Obsidian for direct formatting. Also check out my build/scripts - https://github.com/islanddog/kali-clean-p…
Tutorials for getting started with Pwntools
Red Teaming Tactics and Techniques
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The best hacker's gadgets for Red Team pentesters and security researchers.
Active Directory and Internal Pentest Cheatsheets
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
API Security Project aims to present unique attack & defense methods in API Security field
A nessus editor/parser/querior for the exasperated pentester.
Diaphora, the most advanced Free and Open Source program diffing tool.
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Live Feed of C2 servers, tools, and botnets
⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
CHOMTE.SH is a powerful shell script designed to automate reconnaissance tasks during penetration testing. It utilizes various Go-based tools to gather information and identify the attack surface, …
Svendsen Tech's PowerShell nmap-like port scanner accepting IPv4 CIDR notation