Lists (1)
Sort Name ascending (A-Z)
Stars
Resources referenced by blog.compass-security.com
Vibe-coded backend for e-paper recipe display with telegram bot integration.
goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current privilege level (with MITRE ATT&CK mappings) and can scan l…
Resource to learn more about SSH (Secure Shell) attacks and best bractices with a hands-on lab environment.
The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers across function-level, repository-level, agentic, a…
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s…
Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
PCILeech module to exploit Windows 10 from UEFI when OS DMA protection is enabled
GitLabHound is a BloodHound OpenGraph collector for GitLab
Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens
Framework for tracking and building your own Google Find My Device / Find Hub trackers 🧭
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)
Convenience tool for hashcat
Reverse Engineering 101 training from our Vulnerability Researcher Development Program (VRDP)
PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft Graph, recursively downloads files, and logs every…
mTOTP is an experimental, manual variant of TOTP designed to be computed by a human without electronic devices. It explores the limits of time-based authentication under strict human constraints an…
Mobile Edge-Dynamic Unified Security Analysis
Universal Radio Hacker: Investigate Wireless Protocols Like A Boss
exploit to break out privileged containers with kernel 5.15
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
A collection of tips & tricks on how to escape a kiosk mode environment