Gitworm's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
GTFOBins/GTFOBins.github.io
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
1N3/Sn1per
Attack Surface Management Platform
lgandx/Responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
s0md3v/Arjun
HTTP parameter discovery suite.
Hackplayers/evil-winrm
The ultimate WinRM shell for hacking/pentesting
TheWover/donut
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
almandin/fuxploider
File upload vulnerability scanner and exploitation tool.
skelsec/pypykatz
Mimikatz implementation in pure Python
An0nUD4Y/blackeye
The ultimate phishing tool with 38 websites available!
neex/phuip-fpizdam
Exploit for CVE-2019-11043
p3nt4/Invoke-SocksProxy
Socks proxy, and reverse socks server using powershell.
infodox/python-pty-shells
Python PTY backdoors - full PTY or nothing!
StrangerealIntel/CyberThreatIntel
Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups
lclevy/firepwd
firepwd.py, an open source tool to decrypt Mozilla protected passwords
Raikia/UhOh365
A script that can see if an email address is valid in Office365 (user/email enumeration). This does not perform any login attempts, is unthrottled, and is incredibly useful for social engineering assessments to find which emails exist and which don't.
mandatoryprogrammer/sonar.js
A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and external resource fingerprinting.
creaktive/tsh
Tiny SHell - An open-source UNIX backdoor (I'm not the author!)
sensepost/DNS-Shell
DNS-Shell is an interactive Shell over DNS channel
threatland/TL-TROJAN
A collection of source code for various RATs, Stealers, and other Trojans.
p3nt4/Nuages
A modular C2 framework
outflanknl/Excel4-DCOM
PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)
dorkerdevil/CVE-2019-11932
double-free bug in WhatsApp exploit poc
misterch0c/what_is_this_c2
For all these times you're asking yourself "what is this panel again?"
matterpreter/Shhmon
Neutering Sysmon via driver unload
NuID/nebulousAD
NebulousAD automated credential auditing tool.
threatland/TL-FRAUD
A collection of fraud related tools for research.
zodiacon/ApiSetView
API Set Viewer
skelsec/pypykatz_wasm
pypykats in your browser
x1tan/CVE-2019-13025
Connect Box CH7465LG (CVE-2019-13025)