olympiador's Stars
raesene/bWAPP
urbanadventurer/WhatWeb
Next generation web scanner
epinna/weevely3
Weaponized web shell
paranoidninja/CarbonCopy
A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux
owtf/owtf
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
Ekultek/WhatWaf
Detect and bypass web application firewalls and protection systems
dionach/CMSmap
CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
rapid7/hackazon
A modern vulnerable web app
Audi-1/sqli-labs
SQLI labs to test error based, Blind boolean based, Time based.
sqlmapproject/sqlmap
Automatic SQL injection and database takeover tool
MHaggis/hunt-detect-prevent
Lists of sources and utilities utilized to hunt, detect and prevent evildoers.
pluralsight/PS-AutoLab-Env
A PowerShell module for creating lab configurations using Lability and Desired State Configuration. Look at README.md for more information.
nccgroup/ScoutSuite
Multi-Cloud Security Auditing Tool
mitre-attack/attack-navigator
Web app that provides basic navigation and annotation of ATT&CK matrices
mattifestation/PSSysmonTools
Sysmon Tools for PowerShell
Invoke-IR/PowerForensics
PowerForensics provides an all in one platform for live disk forensic analysis
dirkjanm/PrivExchange
Exchange your privileges for Domain Admin privs by abusing Exchange
mitre/brawl-public-game-001
Data from a BRAWL Automated Adversary Emulation Exercise
marco-lancini/goscan
Interactive Network Scanner
Cyb3rWard0g/HELK
The Hunting ELK
VirusTotal/yara
The pattern matching swiss knife
denandz/KeeFarce
Extracts passwords from a KeePass 2.x database, directly from memory.
NextronSystems/APTSimulator
A toolset to make a system look as if it was the victim of an APT attack
SadProcessor/SomeStuff
Some PowerShell Stuff
codingo/Reconnoitre
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
HumanEquivalentUnit/pingm
securitytxt/security-txt
A proposed standard that allows websites to define security policies.
kurobeats/wordhound
It builds dictionaries off of generic websites, plain text (for example emails), Twitter, PDF's and Reddit.
evilsocket/xray
XRay is a tool for recon, mapping and OSINT gathering from public networks.