Highlights
Starred repositories
Clean-room, closed-loop simulation of an ATM software stack — CEN/XFS device layer, ISO 8583 switch & issuer, HSM crypto, EMV chip flow, and XFS4IoT - in native C++ with a C# GUI. For learning and …
A Modern, High-Performance, Context-Driven Reconnaissance Framework for Bug Bounty Hunters
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
API Security Vulnerability Scanner designed to help you secure your APIs.
OWASP Web Application Security Testing Checklist
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
This repository houses some of the small scripts I had used to quickly document throughout my OSCP course. This was referenced on YouTube, and should be made available to others!
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Python2 based Bufferoverflow scripts i developed while doing the Vulnhub box Netsart by Foxlox
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Web recon script. No need to fear, sumrecon is here!
Find domains and subdomains related to a given domain
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
Compilation of Resources from TCM's Practical Ethical Hacking Udemy Course
A little tool to play with Windows security
Six Degrees of Domain Admin
Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.
Impacket is a collection of Python classes for working with network protocols.
JADX-gui scripting plugin for dynamic decompiler manipulation
CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done
Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab