Stars
The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
Data exfiltration over DNS request covert channel
Deployment scripts & config for Sock Shop
Certified Kubernetes Administrator - CKA Course
Vulnerable Kustomize Kubernetes templates for training and education
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
Check Point CloudGuard Network Security repository containing solution templates, Terraform templates, tools and scripts for deploying and configuring CloudGuard Network Security products.
Check Point Useful Management API Tools contain scripts and tools that were used as solutions for customers.
Check Point ExportImportPolicyPackage tool enables you to export a policy package from a Management database to a .tar.gz file, which can then be imported into any other Management database. The to…
Basic Anomaly IDS capabilities with Python and Bro
iperf3: A TCP, UDP, and SCTP network bandwidth measurement tool
Various public documents, whitepapers and articles about APT campaigns
A collection of various awesome lists for hackers, pentesters and security researchers
A curated list of Awesome Threat Intelligence resources
WAFNinja is a tool which contains two functions to attack Web Application Firewalls.
Find exploits in local and online databases instantly
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Penetration Testing tools - one repo to clone them all... containing latest pen testing tools
Methods for attacking KeePass 2.X databases, including extracting of encryption key material from memory.
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
A list of public penetration test reports published by several consulting firms and academic security groups.
This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.
Six Degrees of Domain Admin
LogViewer for viewing and searching large text files...