drewsousa's Stars
docker/docker-bench-security
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
infosecn1nja/Red-Teaming-Toolkit
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
splunk/attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
Eilonh/s3crets_scanner
t3l3machus/eviltree
A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those that contain matches.
tenable/pyTenable
Python Library for interfacing into Tenable's platform APIs
markdown-templates/markdown-emojis
:fire: All the emojis :tada:
vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose
dafthack/PowerMeta
PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing searches. It then allows for the download of those files from the target domain. After retrieving the files, the metadata associated with them can be analyzed by PowerMeta. Some interesting things commonly found in metadata are usernames, domains, software titles, and computer names.
dafthack/CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
v4d1/Dome
Dome - Subdomain Enumeration Tool. Fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports.
openbullet/OpenBullet2
OpenBullet reinvented
Homebrew/brew
🍺 The missing package manager for macOS (or Linux)
BishopFox/bigip-scanner
Determine the running software version of a remote F5 BIG-IP management interface.
dafthack/HostRecon
This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase. It gathers information about the local system, users, and domain information. It does not use any 'net', 'ipconfig', 'whoami', 'netstat', or other system commands to help avoid detection.
thoughtbot/dotfiles
A set of vim, zsh, git, and tmux configuration files.
coreos/coreos-vagrant
Minimal Vagrantfile for Container Linux
freebsd/bugzilla
Bugzilla