Boofuzz View Boofuzz
A front-end JavaScript toolkit for creating DNS rebinding attacks
Offensive security testing uncovers vulnerabilities through simulated attacks.
A front-end JavaScript toolkit for creating DNS rebinding attacks
A guide on using Apache mod_rewrite to strengthen phishing attacks and bypass mobile device restrictions
APT Simulator is a tool for simulating a compromised system on Windows.
A black-box obfuscation tool for Android apps with Android App Bundle support.
Emulates Docker HTTP API with event logging and AWS deployment script.
Utilizing Alternate Data Streams (ADS) to bypass AppLocker default policies by loading DLL/CPL binaries.
Skyhook facilitates obfuscated HTTP file transfers to bypass IDS detections, enhancing secure data exchange.
A PowerShell toolkit for attacking Azure environments
A blog post discussing the often overlooked dangers of CSV injection in applications.
A document that helps inform red team planning by contrasting against the very specific red team style described in Red Teams.
A tool that visits suspected phishing pages, takes screenshots, and extracts interesting files.
A toolkit to attack Office365, including tools for password spraying, password cracking, token manipulation, and exploiting vulnerabilities in Office365 APIs and services.
Tool for randomizing Cobalt Strike Malleable C2 profiles to evade static, signature-based detection controls.
A framework for testing and exploiting race conditions in software
Caldera is a cybersecurity framework by MITRE for automated security assessments and adversary emulation.
A full-featured reconnaissance framework for web-based reconnaissance with a modular design.
A collection of resources for practicing penetration testing
A set of commands for exploit developers and reverse-engineers to enhance GDB functionality.
Check if a domain is in the Alexa or Cisco top one million domain list.
Data exfiltration & infiltration tool using text-based steganography to evade security controls.
A managed code hooking template for .NET assemblies, enabling API hooking, code injection, and runtime manipulation.
A list of useful payloads and bypasses for Web Application Security.