- Stockholm
- bertho.eu
- @bertho.eu
Stars
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
D2 is a modern diagram scripting language that turns text to diagrams.
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.
Visualization of all roads within any city
A collection of several hundred online tools for OSINT
πΈ Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! π§ββοΈ
Everything about Web Application Firewalls (WAFs) from Security Standpoint! π₯
Collection of Cyber Threat Intelligence sources from the deep and dark web
Open Source Intelligence gathering tool aimed at reducing the time spent harvesting information from open sources.
Privilege Escalation Enumeration Script for Windows
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
A Python program to scrape secrets from GitHub through usage of a large repository of dorks.
Protect yourself from being tracked π by AirTags π· and Find My accessories π
Sample queries for Advanced hunting in Microsoft 365 Defender
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. π‘οΈβοΈπ§
Authentication, authorization, traceability and auditability for SSH accesses.
Use Log4Shell vulnerability to vaccinate a victim server against Log4Shell
π Don't know what type of hash it is? Name That Hash will name that hash type! π€ Identify MD5, SHA256 and 300+ other hashes β Comes with a neat web app π₯
Simple checklist to help you deploying the most important areas of the GNU/Linux production systems - work in progress.
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.