Burp-LFI-tests View Burp-LFI-tests
A unified repository for different Metasploit Framework payloads.
Offensive security testing uncovers vulnerabilities through simulated attacks.
A unified repository for different Metasploit Framework payloads.
A guide on using Apache mod_rewrite to strengthen phishing attacks and bypass mobile device restrictions
Emulates Docker HTTP API with event logging and AWS deployment script.
A black-box obfuscation tool for Android apps with Android App Bundle support.
APT Simulator is a tool for simulating a compromised system on Windows.
Utilizing Alternate Data Streams (ADS) to bypass AppLocker default policies by loading DLL/CPL binaries.
A PowerShell toolkit for attacking Azure environments
Skyhook facilitates obfuscated HTTP file transfers to bypass IDS detections, enhancing secure data exchange.
A document that helps inform red team planning by contrasting against the very specific red team style described in Red Teams.
A blog post discussing the often overlooked dangers of CSV injection in applications.
A framework for testing and exploiting race conditions in software
A toolkit to attack Office365, including tools for password spraying, password cracking, token manipulation, and exploiting vulnerabilities in Office365 APIs and services.
Caldera is a cybersecurity framework by MITRE for automated security assessments and adversary emulation.
A tool that visits suspected phishing pages, takes screenshots, and extracts interesting files.
Tool for randomizing Cobalt Strike Malleable C2 profiles to evade static, signature-based detection controls.
A collection of resources for practicing penetration testing
A set of commands for exploit developers and reverse-engineers to enhance GDB functionality.
A managed code hooking template for .NET assemblies, enabling API hooking, code injection, and runtime manipulation.
A list of useful payloads and bypasses for Web Application Security.
Data exfiltration & infiltration tool using text-based steganography to evade security controls.
A full-featured reconnaissance framework for web-based reconnaissance with a modular design.
Check if a domain is in the Alexa or Cisco top one million domain list.