0xEval's Stars
ethereumbook/ethereumbook
Mastering Ethereum, by Andreas M. Antonopoulos, Gavin Wood
gitleaks/gitleaks
Find secrets with Gitleaks 🔑
projectdiscovery/katana
A next-generation crawling and spidering framework.
Orange-Cyberdefense/GOAD
game of active directory
SunWeb3Sec/DeFiHackLabs
Reproduce DeFi hacked incidents using Foundry.
RhinoSecurityLabs/pacu
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
christophetd/CloudFlair
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
dafthack/CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
NetSPI/MicroBurst
A collection of scripts for assessing Microsoft Azure security
Hacking-the-Cloud/hackingthe.cloud
An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
ine-labs/AWSGoat
AWSGoat : A Damn Vulnerable AWS Infrastructure
SunWeb3Sec/DeFiVulnLabs
To learn common smart contract vulnerabilities using Foundry!
metlo-labs/metlo
Metlo is an open-source API security platform.
PentestPad/subzy
Subdomain takeover vulnerability checker
nascentxyz/simple-security-toolkit
A collection of practical security-focused guides and checklists for smart contract development
BishopFox/eyeballer
Convolutional neural network for analyzing pentest screenshots
nccgroup/singularity
A DNS rebinding attack framework.
0xacb/recollapse
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
muraenateam/muraena
Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
dafthack/MSOLSpray
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.
crytic/ethersplay
EVM dissassembler
ine-labs/AzureGoat
AzureGoat : A Damn Vulnerable Azure Infrastructure
NUL0x4C/AtomPePacker
A Highly capable Pe Packer
trailofbits/eth-security-toolbox
A Docker container preconfigured with all of the Trail of Bits Ethereum security tools.
iknowjason/PurpleCloud
A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4
spearbit/portfolio
PatrickAlphaC/hardhat-security-fcc
MarkoH17/Spray365
Spray365 makes spraying Microsoft accounts (Office 365 / Azure AD) easy through its customizable two-step password spraying approach. The built-in execution plan features options that attempt to bypass Azure Smart Lockout and insecure conditional access policies.
oldrho/ip2provider
Resolves an IP address to the cloud provider it is hosted on