Brumstar's Stars
davidprowe/BadBlood
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time.
openai/spinningup
An educational resource to help anyone learn deep reinforcement learning.
openai/gym
A toolkit for developing and comparing reinforcement learning algorithms.
ffuf/ffuf
Fast web fuzzer written in Go
Wenzel/checksec.py
Checksec tool in Python, Rich output. Based on LIEF
tprynn/web-methodology
Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
google/tsunami-security-scanner
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
summitt/Nope-Proxy
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
microsoft/Detours
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
nidem/kerberoast
gentilkiwi/kekeo
A little toolbox to play with Microsoft Kerberos in C
GhostPack/Rubeus
Trying to tame the three-headed dog.
samratashok/nishang
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
besimorhino/powercat
netshell features all in version 2 powershell
hugsy/gef
GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
diego-treitos/linux-smart-enumeration
Linux enumeration tool for pentesting and CTFs with verbosity levels
frk1/hazedumper
up to date csgo offsets and hazedumper config
maxmind/GeoIP2-php
PHP API for GeoIP2 webservice client and database reader
PaperMtn/lil-pwny
Fast offline auditing of Active Directory passwords using Python.
SpecterOps/at-ps
Adversary Tactics - PowerShell Training
hackerschoice/thc-tips-tricks-hacks-cheat-sheet
Various tips & tricks
antonioCoco/Mapping-Injection
Just another Windows Process Injection
vaib25vicky/awesome-mobile-security
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
AlessandroZ/LaZagne
Credentials recovery project
0xsha/sweetie-data
This repo contains logstash of various honeypots
skysafe/reblog
SkySafe Miscellaneous Reverse Engineering Blog
nccgroup/singularity
A DNS rebinding attack framework.
cowrie/cowrie
Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io
GAM-team/GAM
command line management for Google Workspace
SadProcessor/Cheats
Various Cheat Sheets