- All languages
- ASP
- ActionScript
- Arduino
- Assembly
- Astro
- Batchfile
- C
- C#
- C++
- CSS
- Dockerfile
- Go
- HTML
- Hack
- Haskell
- Java
- JavaScript
- Jinja
- Jupyter Notebook
- Kotlin
- Logos
- Lua
- Makefile
- Meson
- Nix
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Python
- QML
- Raku
- Ruby
- Rust
- SCSS
- Shell
- Swift
- Tcl
- TeX
- TypeScript
- VBA
- Visual Basic
- XSLT
Starred repositories
Malleable C2 Profiles. A collection of profiles used in different projects using Cobalt Strike & Empire.
🧊 Indulge in nostalgia with useless 3D effects.
As a bug hunter, are your bug bounty reports getting rejected because you don't use a "malicious" Proof of Concept (PoC) app to exploit the vulnerabilities? I've got you covered!
Tool for Active Directory Certificate Services enumeration and abuse
BC-SECURITY / Empire
Forked from EmpireProject/EmpireEmpire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
Extracts URLs from OSINT Archives for Security Insights
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!
An open source threat modeling tool from OWASP
ripgrep recursively searches directories for a regex pattern while respecting your gitignore
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
PabloDraw is an Ansi/Ascii text and RIPscrip vector graphic art editor/viewer with multi-user capabilities.
Simple HS256, HS384 & HS512 JWT token brute force cracker.
Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Generates millions of keyword-based password mutations in seconds.
"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.
A light-weight first-stage C2 implant written in Nim (and Rust).
❄️ ChatGPT Desktop Application (Mac, Windows and Linux)
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.
Find interesting Amazon S3 Buckets by watching certificate transparency logs.
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools