shad0w
A script to enumerate Google Storage buckets and determine access and privilege escalation
Offensive security testing uncovers vulnerabilities through simulated attacks.
A script to enumerate Google Storage buckets and determine access and privilege escalation
A standalone man-in-the-middle attack framework used for phishing login credentials and bypassing 2-factor authentication.
Pwndrop is a self-deployable file hosting service for red teamers, allowing easy upload and sharing of payloads over HTTP and WebDAV.
AzureC2Relay enhances security by validating and relaying Cobalt Strike beacon traffic through Azure Functions.
A tool that simplifies the installation of tools and configuration for Kali Linux
A tool for detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities
A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.
A comprehensive malware-analysis tool that utilizes external AV scanners to identify malicious elements in binary files.
A modern post-exploitation command and control framework with a client-server architecture and extensibility features.
A repository containing material for Android greybox fuzzing with AFL++ Frida mode
A guide on basic Linux privilege escalation techniques including enumeration, data analysis, exploit customization, and trial and error.
OWASP OWTF is a penetration testing framework focused on efficiency and alignment with security standards.
GNU/Linux Wireless distribution for security testing with XFCE desktop environment.
Metta is an information security preparedness tool for adversarial simulation.
A practical guide on NTLM relaying for Active Directory attacks.
Interactive online malware sandbox for real-time analysis and threat intelligence
Collection of vulnerable ARM binaries for beginner vulnerability researchers & exploit developers.
An exploration of a new method to abuse DCOM for remote payload execution and lateral movement.