-
-
InternalAllTheThings Public
Active Directory and Internal Pentest Cheatsheets
-
PayloadsAllTheThings Public
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
HardwareAllTheThings Public
Hardware/IOT Pentesting Wiki
-
SSRFmap Public
Automatic SSRF fuzzer and exploitation tool
-
swisskyrepo.github.io Public
Source of swisskyrepo.github.io - Public
-
Vulny-Code-Static-Analysis Public
Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex
-
WHID_Toolkit Public
Simple script for the WHID injector - a rubberducky wifi
-
GraphQLmap Public
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
-
jsleak Public
Forked from byt3hx/jsleakUpgrading jsleak with a CI/CD and new rules
-
Wordpresscan Public archive
WPScan rewritten in Python + some WPSeku ideas
-
SharpLAPS Public
Retrieve LAPS password from LDAP
-
Nephelees Public
Néphélées (Νεφήλαι, Nephḗlai) : cloud nymphs greek - also NTDS cracking tool on Google Cloud
-
DamnWebScanner Public
Another web vulnerabilities scanner, this extension works on Chrome and Opera