Stars
- All languages
- Assembly
- Batchfile
- BlitzBasic
- Boo
- C
- C#
- C++
- CMake
- CSS
- Dart
- Dockerfile
- Go
- HCL
- HTML
- Java
- JavaScript
- Julia
- Jupyter Notebook
- Lua
- Max
- Meson
- Nim
- Objective-C
- Objective-C++
- OpenSCAD
- PHP
- Perl
- PowerShell
- Processing
- Python
- Roff
- Ruby
- Rust
- SCSS
- Scala
- Shell
- SourcePawn
- Swift
- SystemVerilog
- TeX
- TypeScript
- VBA
- Visual Basic
- Vue
- XSLT
- YARA
OSINT Tool for Finding Passwords of Compromised Email Addresses
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
A collection of Azure AD/Entra tools for offensive and defensive security purposes
An evil RAT (Remote Administration Tool) for macOS / OS X.
Stealing Signatures and Making One Invalid Signature at a Time
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments…
A Python based ingestor for BloodHound
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
Tool to scan for secret files on HTTP servers
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.
Veil Evasion is no longer supported, use Veil 3.0!
A tool for automating cracking methodologies through Hashcat from the TrustedSec team.
[Node, Python, Java] Repository of sample Custom Rules for AWS Config.
The SpecterOps project management and reporting engine
Passive hostname, domain and IP lookup tool for non-robots
Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
Uses Empire's (https://github.com/BC-SECURITY/Empire) RESTful API to automate gaining Domain and/or Enterprise Admin rights in Active Directory environments using some of the most common offensive …
Run PowerShell command without invoking powershell.exe
Lists of .NET Obfuscator (Free, Freemium, Paid and Open Source )
LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping
Security Tool to Look For Interesting Files in S3 Buckets