bravo2day's Stars
UnaPibaGeek/ctfr
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
Viralmaniar/Passhunt
Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.
DanMcInerney/icebreaker
Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment
eladshamir/Internal-Monologue
Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
redcanaryco/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
1N3/BlackWidow
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
ellerbrock/docker-security-images
:closed_lock_with_key: Docker Container for Penetration Testing & Security
GoFetchAD/GoFetch
GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.
SadProcessor/Cheats
Various Cheat Sheets
SadProcessor/SomeStuff
Some PowerShell Stuff
clr2of8/DPAT
Domain Password Audit Tool for Pentesters
SpecterOps/BloodHound-Legacy
Six Degrees of Domain Admin
api0cradle/UltimateAppLockerByPassList
The goal of this repository is to document the most common techniques to bypass AppLocker.
threatexpress/red-team-scripts
A collection of Red Team focused tools, scripts, and notes
BloodHoundAD/SharpHound2
The Old BloodHound C# Ingestor (Deprecated)