Pinned Repositories
actions2aws
Assume AWS IAM roles from GitHub Actions workflows with no stored secrets
angular-demo
Created with StackBlitz ⚡️
cvelist
Pilot program for CVE submission through GitHub
image-upload-exploits
This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests and bug bounty.
LinEnum
Scripted Local Linux Enumeration & Privilege Escalation Checks
python-fitbit
Fitbit API Python Client Implementation
TeamDojo
UI für verschiedene Reifegrad-Dimensionen
terraform-aws-cross-account-persistence
Offensive Terraform module which creates an IAM role with trust relationship with attacker's AWS account and attaches managed IAM Policy to an IAM role.
WebGoat
WebGoat 8.0
winscppasswd
WinSCP Password Extractor/Decrypter/Revealer written in go language
codethatrocks's Repositories
codethatrocks/actions2aws
Assume AWS IAM roles from GitHub Actions workflows with no stored secrets
codethatrocks/angular-demo
Created with StackBlitz ⚡️
codethatrocks/cvelist
Pilot program for CVE submission through GitHub
codethatrocks/image-upload-exploits
This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests and bug bounty.
codethatrocks/LinEnum
Scripted Local Linux Enumeration & Privilege Escalation Checks
codethatrocks/python-fitbit
Fitbit API Python Client Implementation
codethatrocks/TeamDojo
UI für verschiedene Reifegrad-Dimensionen
codethatrocks/terraform-aws-cross-account-persistence
Offensive Terraform module which creates an IAM role with trust relationship with attacker's AWS account and attaches managed IAM Policy to an IAM role.
codethatrocks/WebGoat
WebGoat 8.0
codethatrocks/winscppasswd
WinSCP Password Extractor/Decrypter/Revealer written in go language
codethatrocks/ASVS
Application Security Verification Standard
codethatrocks/azure
Repo for Azure-related stuff
codethatrocks/deeper-sast-demo
codethatrocks/Defending-DevOps
Lab Material for the Two-Day Defending Modern DevOps Environments Course
codethatrocks/demo-vulnerable-springboot-app
codethatrocks/DevSecOps-MaturityModel
codethatrocks/HolisticInfoSec-For-WebDevelopers-Fascicle1
:books: VPS :lock: Network :lock: Cloud :lock: Web Applications :books:
codethatrocks/linuxprivchecker
linuxprivchecker.py -- a Linux Privilege Escalation Check Script
codethatrocks/owasp-masvs
The Mobile Application Security Verification Standard (MASVS) is a standard for mobile app security.
codethatrocks/owasp-mstg
The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing and reverse engineering.
codethatrocks/Privesc
Privilege escalation tools on Mainframe
codethatrocks/px
An HTTP proxy server to automatically authenticate through an NTLM proxy
codethatrocks/racf-passticket-generator
A prototype implementation of the RACF PassTicket algorithm in Java.
codethatrocks/Scan-Spring-GO
针对SpringBoot的渗透工具,Spring漏洞利用工具
codethatrocks/scripts
Scripts I use during pentest engagements.
codethatrocks/threatspec
ThreatSpec - Continuous threat modelling through code - https://threatspec.org