Payloads All The Things
A subdomain enumeration tool for penetration testers and security researchers.
Offensive security testing uncovers vulnerabilities through simulated attacks.
A subdomain enumeration tool for penetration testers and security researchers.
A credit card/magstripe spoofer that can emulate any magnetic stripe or credit card wirelessly.
CLI tool for offensive and defensive security assessments on the Joi validator library with a wide range of attacks.
A blog post discussing the often overlooked dangers of CSV injection in applications.
A tool that visits suspected phishing pages, takes screenshots, and extracts interesting files.
A C/C++ tool for remote process injection, supporting x64 and x86 operations, with system call macros generated by SysWhispers script.
Phrack Magazine is a digital magazine that focuses on computer security and hacking, featuring articles, interviews, and tutorials on various topics related to computer security.
Inceptor is a template-driven framework for evading Anti-Virus and Endpoint Detection and Response solutions, allowing users to create custom evasion techniques and test their security controls.
A tool for interacting with the MSBuild API, enabling malicious activities and evading detection.
Open-source project for building instrumented environments to simulate attacks and test detections.
Weaponize Word documents with PowerShell Empire using the Microsoft DDE exploit.
Boofuzz is a network protocol fuzzing tool that aims to fuzz everything
Emulates Docker HTTP API with event logging and AWS deployment script.
FOCA is a tool used to find metadata and hidden information in scanned documents, with capabilities to analyze various file types and extract EXIF information.
MiniCPS is a framework for Cyber-Physical Systems real-time simulation with support for physical process and control devices simulation, and network emulation.
FOCA is a tool used to find metadata and hidden information in scanned documents, with capabilities to analyze various file types and extract EXIF information.
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang for efficient and secure communication.
Collection of penetration testing scripts for AWS with a focus on reconnaissance.
Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.
Charlotte is an undetected C++ shellcode launcher for executing shellcode with stealth.
A scripting engine for interacting with GraphQL endpoints for pentesting purposes.