lc8992's Stars
ghostty-org/ghostty
👻 Ghostty is a fast, feature-rich, and cross-platform terminal emulator that uses platform-native UI and GPU acceleration.
JumpsecLabs/TokenSmith
TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of the box with many popular Azure post exploitation tools.
CyberSecurityUP/GCP-Pentest-Checklist
RhinoSecurityLabs/GCP-IAM-Privilege-Escalation
A collection of GCP IAM privilege escalation methods documented by the Rhino Security Labs team.
S3cur3Th1sSh1t/PowerSharpPack
garrettfoster13/pre2k
dafthack/MSOLSpray
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.
dafthack/CloudPentestCheatsheets
This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
rvrsh3ll/cors-anywhere
CORS Anywhere is a NodeJS reverse proxy which adds CORS headers to the proxied request.
SpecterOps/AzureHound
Azure Data Exporter for BloodHound
dafthack/GraphRunner
A Post-exploitation Toolset for Interacting with the Microsoft Graph API
f-bader/TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2
dirkjanm/ROADtools
A collection of Azure AD/Entra tools for offensive and defensive security purposes
Flangvik/TeamFiltration
TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
rvrsh3ll/TokenTactics
Azure JWT Token Manipulation Toolset
ExAndroidDev/fakemeeting
Creates and sends fake meeting invite
lanjelot/patator
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
RUB-NDS/Terrapin-Scanner
This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation".
hausec/Bloodhound-Custom-Queries
Custom Query list for the Bloodhound GUI based off my cheatsheet
knavesec/CredMaster
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
cwolff411/RedTeamVillage-SSHTunnels
Slides, documentation, and files from my presentation at Red Team Village for HackerOne's hacktivitycon.
emtunc/SlackPirate
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
epi052/feroxbuster
A fast, simple, recursive content discovery tool written in Rust.
Pennyw0rth/NetExec
The Network Execution Tool
pentestmonkey/php-reverse-shell
chipik/SAP_GW_RCE_exploit
SAP Gateway RCE exploits
irsdl/IIS-ShortName-Scanner
latest version of scanners for IIS short filename (8.3) disclosure vulnerability
davidtavarez/pwndb
Search for leaked credentials
hahwul/XSpear
🔱 Powerfull XSS Scanning and Parameter analysis tool&gem
Kevin-Robertson/Inveigh
.NET IPv4/IPv6 machine-in-the-middle tool for penetration testers