Stars
Microsoft signed ActiveDirectory PowerShell module
A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration
Veil Evasion is no longer supported, use Veil 3.0!
A list of cyber-chef recipes and curated links
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
nddmars / dvta
Forked from secvulture/dvtaDamn Vulnerable Thick Client App
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
Search for Directory Traversal Vulnerabilities
A curated list of CTF frameworks, libraries, resources and softwares
Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penet…
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
NodeJS module and commandline utility for re-signing iOS applications (IPA files).
iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, …
Checklist of the most important security countermeasures when designing, testing, and releasing your API
A completely free, open source and online course about Reverse Engineering iOS Applications.
A simple Python Exploit to Write Data to Insecure/vulnerable firebase databases! Commonly found inside Mobile Apps. If the owner of the app have set the security rules as true for both "read" & "wr…
Hackish way to intercept and modify non-HTTP protocols through Burp & others.
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Git All the Payloads! A collection of web attack payloads.
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…
A laboratory for learning secure web and mobile development in a practical manner.
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
Awesome Golang Security resources 🕶🔐
Demonstrate how usage of the Java Security Manager can prevent Remote Code Execution (RCE) exploits.