mgv's Stars
puresec/sas-top-10
Serverless Architectures Security Top 10 Guide
nccgroup/ScoutSuite
Multi-Cloud Security Auditing Tool
pr0cf5/kernel-exploit-practice
repository for kernel exploit practice
physics-sec/DetectCrossOriginMessaging
This Burp extension helps you to find usages of postMessage and recvMessage
pomerium/awesome-security-audits
A collection of public security audits.
xairy/vmware-exploitation
A collection of links related to VMware escape exploits
ticarpi/jwt_tool
:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens
urbanadventurer/WhatWeb
Next generation web scanner
tomnomnom/unfurl
Pull out bits of URLs provided on stdin
orangetw/Tiny-URL-Fuzzer
A tiny and cute URL fuzzer
byt3bl33d3r/WitnessMe
Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.
mirfansulaiman/Command-Mobile-Penetration-Testing-Cheatsheet
Mobile penetration testing android & iOS command cheatsheet
tyranid/WindowsRpcClients
This respository is a collection of C# class libraries which implement RPC clients for various versions of the Windows Operating System from 7 to Windows 10.
ripienaar/free-for-dev
A list of SaaS, PaaS and IaaS offerings that have free tiers of interest to devops and infradev
fuzzitdev/pythonfuzz
coverage guided fuzz testing for python
HoLyVieR/prototype-pollution-nsec18
Content released at NorthSec 2018 for my talk on prototype pollution
Consensys/smart-contract-best-practices
A guide to smart contract security best practices
WithSecureLabs/C3
Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.
andresriancho/vpc-vpn-pivot
Pivot into private VPC networks using a VPN connection
nccgroup/tracy
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.
gquere/pwn_jenkins
Notes about attacking Jenkins servers
vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose
phpstan/phpstan
PHP Static Analysis Tool - discover bugs in your code without running it!
trailofbits/algo
Set up a personal VPN in the cloud
allanlw/svg-cheatsheet
A cheatsheet for exploiting server-side SVG processors.
daeken/httprebind
Automatic tool for DNS rebinding-based SSRF attacks
doyensec/electronegativity
Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.
fnk0c/cangibrina
A fast and powerfull dashboard (admin) finder
clirimemini/Keye
Keye is a reconnaissance tool that was written in Python with SQLite3 integrated. After adding a single URL, or a list of URLs, it will make a request to these URLs and try to detect changes based on their response's body length.
tldr-pages/tldr
📚 Collaborative cheatsheets for console commands