jtomkiel's Stars
certbot/certbot
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
trustedsec/social-engineer-toolkit
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
byt3bl33d3r/CrackMapExec
A swiss army knife for pentesting networks
n1nj4sec/pupy
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
1N3/Sn1per
Attack Surface Management Platform
pwndbg/pwndbg
Exploit Development and Reverse Engineering with GDB Made Easy
nelhage/reptyr
Reparent a running program to a new terminal
RedSiege/EyeWitness
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
commixproject/commix
Automated All-in-One OS Command Injection Exploitation Tool.
lanjelot/patator
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
DanMcInerney/net-creds
Sniffs sensitive data from interface or pcap
s4n7h0/xvwa
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
citronneur/rdpy
Remote Desktop Protocol in Twisted Python
pentestgeek/phishing-frenzy
Ruby on Rails Phishing Framework
earwig/git-repo-updater
A console script that allows you to easily update multiple git repositories at once
g0tmi1k/os-scripts
Personal Collection of Operating Systems Scripts
kurobeats/fimap
fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps.
tatanus/SPF
SpeedPhishing Framework
xsscx/Commodity-Injection-Signatures
Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT
DanMcInerney/pentest-machine
Automates some pentest jobs via nmap xml file
trustedsec/spraywmi
SprayWMI is an easy way to get mass shells on systems that support WMI. Much more effective than PSEXEC as it does not leave remnants on a system.
portcullislabs/xssshell-xsstunnel
XSS Tunnel is a standard HTTP proxy which sits on an attacker’s system. XSS Shell is a powerful XSS backdoor, in XSS Shell one can interactively send requests and get responses from victim and it allows you to keep the control of session.
nccgroup/WebFEET
Web Filter External Enumeration Tool (WebFEET)