Skip to content

n3rada/n3rada

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

337 Commits
 
 
 
 
 
 

Repository files navigation

📦 Toolbox

A concise selection of interesting, if not essential, tools. Devised with a bit of ingenuity and a touch too much spare time.

Your RCE Companion

Try toboggan once and you will never want anything else for RCE during security assessments! It automatically adapts to diverse Linux environments (including AS/400) through intelligent binary detection (BusyBox, custom paths) and provides built-in actions for file transfers and post-exploitation tasks.

M365

  • msauth-browser: A Python 3 tool that uses the Playwright browser automation library to extract Microsoft OAuth tokens. Ideal when you need to authenticate as a user and retrieve their login tokens in order to send emails, for example.
  • msgraphx: Abusing the Microsoft Graph SDK to search and harvest SharePoint files, Outlook mail, Teams messages and lot of M365 things.

Microsoft SQL Server (MS SQL / MSSQL)

These two tools are designed to simplify complex T-SQL interactions for Microsoft SQL Server environments. You can impersonate any user along the way to the last linked server in your chain. Both tools prioritize modularity, extensibility, and operator experience, following robust OOP practices and addressing real-world red team requirements. Each tool serves a distinct purpose.

  • MSSQLand: A lightweight C# executable, designed for beacon assembly execution and restricted environments.
  • mssqlclient-ng: The Python3 twin built upon impacket's mssqlclient.py, ideal for external access.

Vendor Specific

Salesforce Experience Cloud

Salesforce portals are a class of target that existing tools barely scratch. Guest user enumeration, REST surface coverage, IDOR probing across sessions, and a deliverable-ready report all require stitching together multiple manual steps. sfmap does it in one command.

If you have ever worked with SAP during a penetration test, you know how cumbersome using SXPG_CALL_SYSTEM on a SAP server can be, sapsxpg is for you.

🃏 GitHub Badges

One of my commit sha starts with "a". I used only emojis in my commit message. My favorite word is "update". I am a polite coder. I collected 100 stars. I commit in the morning. I commit in the evening. I am a sleepy coder. Happy February 29th! I committed on a Leap Day! One of my commit sha starts with "ab". I pushed a commit with "cafe" once. I committed on Friday the 13th, One… By One… I've starred 4 my own repositories. I did 2 sequential fixes. Happy Programmers Day! I committed on a 256 Day of Year! I joined GitHub 5 years ago. When I delete code, I delete a lot. I made an epic commit with a message over 500 chars. I did 4 sequential fixes. I did 9 sequential fixes. I did 3 sequential fixes. I did 5 sequential fixes. I did 6 sequential fixes. I committed on the Halloween! Boo! I committed on the day Doctor Emmett Brown invented the flux capacitor! I did a little housekeeping! 🧹 I commit in the Winter solstice. May the 4th be with you! Happy March 14th! I committed on a Pi Day! I have participated in pull requests with 5 or more people I committed on St. Patrick's Day! I committed on the day when the crew of the USCSS Nostromo made their fateful landing and discovered the Xenomorph on LV-426! I commit at midnight. I pushed a commit with "dead" once. I made cosmetic commit. I have three public keys

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors