Lists (4)
Sort Name ascending (A-Z)
Stars
Codes/Notebooks for AI Projects
OWASP Foundation web repository
Creates Kubernetes Golden Tickets through ServiceAccount token forging and user certificate forging.
Just another Powerview alternative but on steroids
Simple (relatively) things allowing you to dig a bit deeper than usual.
The Secure Coding Dojo is a platform for delivering secure coding knowledge.
Automation for internal Windows Penetrationtest / AD-Security
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
A curated list of awesome cloud security blogs, podcasts, standards, projects, and examples.
a security scanner for custom LLM applications
Research on the enumeration of IAM permissions without logging to CloudTrail
latest version of scanners for IIS short filename (8.3) disclosure vulnerability
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system computers. Here is a simple way to evade anti-virus …
Red Team Attack Lab for TTP testing & research
A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific situations are handled in bug bounties.
Threadless Process Injection using remote function hooking.
MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way …
A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.
Streamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time threat information, gain a competitive advantage, and stay infor…
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
GoPhish Templates that I have retired and/or templates I've recreated.