Lists (1)
Sort Name ascending (A-Z)
Stars
Complementary files and scripts for the "Owner or Pwned?" whitepaper.
WifiForge is a tool developed by Black Hills InfoSec to help train Pentesters on different Wi-Fi attack vectors and Wireless capabilities.
Shodan Eye This tool collects all the information about all devices directly connected to the internet using the specified keywords that you enter. Author: Jolanda de Koff
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
This repo contains some Amsi Bypass methods i found on different Blog Posts.
Scripts for rapid Windows endpoint "tactical triage" and investigations with Velociraptor and KAPE
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
Greenshot for Windows - for more information look here:
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
Fake sshd that logs ip addresses, usernames, and passwords.
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
Find, verify, and analyze leaked credentials
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, i…
onedrive user enumeration - pentest tool to enumerate valid o365 users
AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
A collection of scripts for assessing Microsoft Azure security
🔭 Powerful tool for testing WebHooks and more
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
(CVE-2018-9995) Get DVR Credentials
A list of public penetration test reports published by several consulting firms and academic security groups.
Exchange Server support tools and scripts
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azur…