Stars
Offensive tools as Dockerfiles. Lightweight & Ready to go
A tool for checking if MFA is enabled on multiple Microsoft Services
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. #nsacyber
Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities
A cloud-backed password cracking and assessment tool - Sponsored by Open Security
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
PingCastle - Get Active Directory Security at 80% in 20% of the time
APT & CyberCriminal Campaign Collection
Fast passive subdomain enumeration tool.
File upload vulnerability scanner and exploitation tool.
John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs, GPUs, and even some FPGAs
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Automate the creation of a lab environment complete with security tooling and logging best practices
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, a…
PEDA - Python Exploit Development Assistance for GDB
World's fastest and most advanced password recovery utility
A collaborative, multi-platform, red teaming framework
GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.
Small and highly portable detection tests based on MITRE's ATT&CK.
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.