Stars
Collection of CTF Web challenges I made
Awesome secure by default libraries to help you eliminate bug classes!
E-mails, subdomains and names Harvester - OSINT
bazel (starlark) rules to test and monitor targets for vulnerabilities in external open source dependencies
Automating situational awareness for cloud penetration tests.
🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens
Back7.co 3D Files for the Raspberry Pi Recovery Kit
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations
CLI tool and python library that converts the output of popular command-line tools, file-types, and common strings to JSON, YAML, or Dictionaries. This allows piping of output to tools like jq and …
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
get things from one computer to another, safely
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
A collection of browser-based side channel attack vectors.
ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
Scripts and tools used in our Black Hat USA 2021 talk, "Come to The Dark Side, We Have Apples: Turning macOS Management Evil".
A Python implementation that facilitates finding timeless timing attack vulnerabilities.
OSINT tool for finding profiles by username
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Fast subdomains enumeration tool for penetration testers
GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
A collection of modern/faster/saner alternatives to common unix commands.