dzflack's Stars
ant-design/ant-design
An enterprise-class UI design language and React UI library
juliocesarfort/public-pentesting-reports
A list of public penetration test reports published by several consulting firms and academic security groups.
majd/ipatool
Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store
ropnop/kerbrute
A tool to perform Kerberos pre-auth bruteforcing
dafthack/CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
dirkjanm/ROADtools
A collection of Azure AD/Entra tools for offensive and defensive security purposes
saljam/webwormhole
Peer authenticated WebRTC.
mandatoryprogrammer/xsshunter-express
An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!
Azure/Stormspotter
Azure Red Team tool for graphing Azure and Azure Active Directory objects
m8sec/CrossLinked
LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping
mgeeky/RedWarden
Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation
xuanxuan0/DripLoader
Evasive shellcode loader for bypassing event-based injection detection (PoC)
CCob/BOF.NET
A .NET Runtime for Cobalt Strike's Beacon Object Files
cfalta/adsec
An introduction to Active Directory security
threatexpress/cs2modrewrite
Convert Cobalt Strike profiles to modrewrite scripts
ajpc500/BOFs
Collection of Beacon Object Files
vysecurity/DomainFrontingLists
A list of Domain Frontable Domains by CDN
cvilsmeier/sqinn-go
Golang SQLite without cgo
xforcered/InvisibilityCloak
Proof-of-concept obfuscation toolkit for C# post-exploitation tools
GoSecure/pywsus
Standalone implementation of a part of the WSUS spec. Built for offensive security purposes.
byt3bl33d3r/pyMalleableC2
Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.
ramen0x3f/AggressorScripts
outflanknl/FindObjects-BOF
A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.
EncodeGroup/UAC-SilentClean
New UAC bypass for Silent Cleanup for CobaltStrike
NetSPI/DAFT
DAFT: Database Audit Framework & Toolkit
G0ldenGunSec/SharpTransactedLoad
Load .net assemblies from memory while having them appear to be loaded from an on-disk location.
mdsecactivebreach/SharpPack
An Insider Threat Toolkit
MartinIngesen/MSOLSpray
A Python implementation of dafthack's MSOLSpray. A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.
RiccardoAncarani/bloodhound-playbook
Reproducible and extensible BloodHound playbooks
fly-apps/smokescreen
An example of deploying Smokescreen on Fly.io