0xBrAinsTorM's Stars
bluscreenofjeff/Red-Team-Infrastructure-Wiki
Wiki to collect Red Team infrastructure hardening resources
epinna/tplmap
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
jonaslejon/malicious-pdf
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
netwrix/pingcastle
PingCastle - Get Active Directory Security at 80% in 20% of the time
kost/dvcs-ripper
Rip web accessible (distributed) version control systems: SVN/GIT/HG...
Dec0ne/KrbRelayUp
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
irsdl/IIS-ShortName-Scanner
latest version of scanners for IIS short filename (8.3) disclosure vulnerability
tokyoneon/Chimera
Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
iagox86/hash_extender
blacklanternsecurity/TREVORspray
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
Greenwolf/ntlm_theft
A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)
MysticRyuujin/guac-install
Script for installing Guacamole on Ubuntu
leechristensen/SpoolSample
PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
cfalta/MicrosoftWontFixList
A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))
tomnomnom/qsreplace
Accept URLs on stdin, replace all query string values with a user-supplied value
nyxgeek/o365recon
retrieve information via O365 and AzureAD with a valid cred
3v4Si0N/HTTP-revshell
Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware
luisfontes19/xxexploiter
Tool to help exploit XXE vulnerabilities
modzero/mod0BurpUploadScanner
HTTP file upload scanner for Burp Proxy
mgeeky/tomcatWarDeployer
Apache Tomcat auto WAR deployment & pwning penetration testing tool.
SafeBreach-Labs/SirepRAT
Remote Command Execution as SYSTEM on Windows IoT Core (releases available for Python2.7 & Python3)
synacktiv/eos
Enemies Of Symfony - Debug mode Symfony looter
cnotin/SplunkWhisperer2
Local privilege escalation, or remote code execution, through Splunk Universal Forwarder (UF) misconfigurations
vivami/OutlookParasite
Outlook persistence using VSTO add-ins
ptswarm/impacket
Impacket Fork for Contributing and Sharing Our Knowledge about Windows
snovvcrash/peas
Modified version of PEAS client for offensive operations
qtc-de/wconv
wconv - Converting Windows native formats into human readable form
jackrichardzon/s4p0
Loumaris/hetzner_vagrant
Connecting a vagrant machine to an additional IP or subnet
JnTournier/domi-owned
IBM/Lotus Domino exploitation