Stars
ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32
Exploring possibilities of ESP32 platform to attack on nearby Wi-Fi networks.
Headless Wireless Penetration Testing on ESP32
An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway and auth server with web UI supporting OpenClaw, MCP, OAuth, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, TOTP, MF…
A simple program to query nmap xml files in the terminal.
OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Quickly rewrite git repository history (filter-branch replacement)
The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.
Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. Sugar-Free and Secure: no any external dependencies except f…
Repository for my flipper zero badUSB payloads. Now almost entirely plug and play.
C4-PlantUML combines the benefits of PlantUML and the C4 model for providing a simple way of describing and communicate software architectures
An ESP32-S2 RubberDucky script parser, with Mouse/PenDrive support 🦆
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submissio…
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
Scanner For Nginx - Remote Integer Overflow Vulnerability
martinvw / pg_exec
Forked from dionach/pgexecScript and resources to execute shell commands using access to a PostgreSQL service
Password spraying using AWS Lambda for IP rotation
A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.