Stars
The following include a list of pentest tools available across the web. Many are free and even open source, others are premium tools and require a monthly or yearly subscription. We’ll note when pe…
A curated list of amazingly awesome Burp Extensions
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …
Community curated list of templates for the nuclei engine to find security vulnerabilities.
Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.
A next-generation crawling and spidering framework.
An evolving how-to guide for securing a Linux server.
KubeStalk discovers Kubernetes and related infrastructure based attack surface from a black-box perspective.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
This cheatsheet was created to assist Red Teamers and Penetration Testers in hunting down vulnerabilities using "Nmap."
「🔑」A tool used to hunt down API key leaks in JS files and pages
KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes, BloodHound, NTDS and DCSync).
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
GraphQL automated security testing toolkit
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
Abusing impersonation privileges through the "Printer Bug"
Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities
The ultimate WinRM shell for hacking/pentesting
SharpSploit is a .NET post-exploitation library written in C#
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.
A python script to scan for Apache Tomcat server vulnerabilities.