Pinned Repositories
awesome-pentest
A collection of awesome penetration testing resources, tools and other shiny things
CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
DomainPasswordSpray
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
dotfiles
.files, including ~/.osx — sensible hacker defaults for OS X
faraday
Collaborative Penetration Test and Vulnerability Management Platform
GraphRunner
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
MailSniper
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
MFASweep
A tool for checking if MFA is enabled on multiple Microsoft Services
MSOLSpray
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.
Test
Tester
justinmurphy's Repositories
justinmurphy/dotfiles
.files, including ~/.osx — sensible hacker defaults for OS X
justinmurphy/Test
Tester
justinmurphy/awesome-pentest
A collection of awesome penetration testing resources, tools and other shiny things
justinmurphy/CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
justinmurphy/DomainPasswordSpray
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
justinmurphy/faraday
Collaborative Penetration Test and Vulnerability Management Platform
justinmurphy/GraphRunner
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
justinmurphy/MailSniper
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
justinmurphy/MFASweep
A tool for checking if MFA is enabled on multiple Microsoft Services
justinmurphy/MSOLSpray
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.
justinmurphy/PowerMeta
PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing searches. It then allows for the download of those files from the target domain. After retrieving the files, the metadata associated with them can be analyzed by PowerMeta.
justinmurphy/tfc-workshop