manuel-sommer's Stars
soimort/you-get
:arrow_double_down: Dumb downloader that scrapes the web
trustedsec/social-engineer-toolkit
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
Orange-Cyberdefense/GOAD
game of active directory
darkoperator/dnsrecon
DNS Enumeration Script
last-byte/PersistenceSniper
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
cisagov/ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines
D35m0nd142/LFISuite
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
jtesta/ssh-mitm
SSH man-in-the-middle tool
s0md3v/Corsy
CORS Misconfiguration Scanner
guacsec/guac
GUAC aggregates software security metadata into a high fidelity graph database.
SpecterOps/BloodHound
Six Degrees of Domain Admin
OWASP/crAPI
completely ridiculous API (crAPI)
yeswehack/PwnFox
PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.
xaitax/SploitScan
SploitScan is a sophisticated cybersecurity utility designed to provide detailed information on vulnerabilities and associated exploits.
mzfr/liffy
Local file inclusion exploitation tool
Err0r-ICA/Ransomware
Ransomwares Collection. Don't Run Them on Your Device.
ghsec/webHunt
Web App bug hunting
whitel1st/docem
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
0xDigimon/PenetrationTesting_Notes-
My Notes about Penetration Testing
AlteredSecurity/365-Stealer
365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.
twseptian/oneliner-bugbounty
oneliner commands for bug bounties
security-cheatsheet/metasploit-cheat-sheet
Metasploit Cheat Sheet 💣
undistro/zora
Zora is an open source solution that helps you achieve compliance with Kubernetes best practices recommended by industry-leading frameworks. By scanning your cluster with multiple plugins, Zora identifies potential issues, misconfigurations, and vulnerabilities.
SySS-Research/smbcrawler
smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares
apisec-university/free-API-security-test-action
APIsec|SCAN - Free API security testing using Github actions
Qazeer/FarsightAD
PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain compromise
DependencyTrack/hyades
Incubating project for decoupling responsibilities from Dependency-Track's monolithic API server into separate, scalable services.
latiotech/insecure-kubernetes-deployments
A full insecure kubernetes application for testing security tools
manuel-sommer/dependencytrack-pywrap
This is a python wrapper for the dependency track REST API.
manuel-sommer/Rusty-Hog-Wrapper
https://github.com/newrelic/rusty-hog