phaz0n's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
owasp-amass/amass
In-depth attack surface mapping and asset discovery
fuzzdb-project/fuzzdb
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
projectdiscovery/httpx
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
michenriksen/aquatone
A Tool for Domain Flyovers
lgandx/Responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
trustedsec/ptf
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
RedSiege/EyeWitness
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
joeyism/linkedin_scraper
A library that scrapes Linkedin for user data
haccer/subjack
Subdomain Takeover tool written in Go
DataDog/stratus-red-team
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
threatexpress/malleable-c2
Cobalt Strike Malleable C2 Design and Reference Guide
threatexpress/domainhunter
Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
SecurityRiskAdvisors/VECTR
VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
austinsonger/Incident-Playbook
GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
assetnote/wordlists
Automated & Manual Wordlists provided by Assetnote
roottusk/vapi
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
OWASP/crAPI
completely ridiculous API (crAPI)
erev0s/VAmPI
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing
maldevel/EmailHarvester
Email addresses harvester
hausec/Bloodhound-Custom-Queries
Custom Query list for the Bloodhound GUI based off my cheatsheet
Cgboal/SonarSearch
A rapid API for the Project Sonar dataset
Mr-Un1k0d3r/CatMyPhish
Search for categorized domain
3CORESec/MAL-CL
MAL-CL (Malicious Command-Line)
mantvydasb/Red-Team-Infrastructure-Automation
Disposable and resilient red team infrastructure with Terraform
jhaddix/KingOfBugBountyTips
BankSecurity/Threat_Hunting
Some Threat Hunting queries useful for blue teamers
xpn/DemoLab
A very simple lab to demo some Terraform, DSC, Inspec and Gitlab CI
Internon/GitDorker
A Python program to scrape secrets from GitHub through usage of a large repository of dorks.