Highlights
Stars
Python and Powershell internal penetration testing framework
Shellphish's automated exploitation engine, originally created for the Cyber Grand Challenge.
fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps.
MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a normal SSH connection. The way it works is by injec…
A fully featured Windows backdoor that uses Gmail as a C&C server
Cloak can backdoor any python script with some tricks.
SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.
A collection of scripts which may come in handy during your freedom fighting activities.
Egressbuster is a method to check egress filtering and identify if ports are allowed. If they are, you can automatically spawn a shell.
WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and exploit mitigation software.
Fast SNMP brute force, enumeration, CISCO config downloader and password cracking script.
python-masscan is a python library which helps in using masscan port scanner.
Finds public elite anonymity proxies and concurrently tests them
Leverage certificate transparency live feed to monitor for newly issued subdomain certificates (last 90 days, configurable), for domains participating in bug bounty programs.
port of mimipenguin.sh in python with some additional protection features
Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity
outis is a custom Remote Administration Tool (RAT) or something like that. It was build to support various transport methods (like DNS) and platforms (like Powershell).
A webshell connection tool with customized WAF bypass payloads
Ragpicker is a Plugin based malware crawler with pre-analysis and reporting functionalities. Use this tool if you are testing antivirus products, collecting malware for another analyzer/zoo.