Pinned Repositories
ADAPE-Script
Active Directory Assessment and Privilege Escalation Script
adfs2
Multi Vagrant environment with Active Directory
apt2
automated penetration toolkit
APTSimulator
A toolset to make a system look as if it was the victim of an APT attack
Arjun
Arjun is a python script for finding hidden GET & POST parameters.
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
s1shed's Repositories
s1shed/Privesc
Windows batch script that finds misconfiguration issues which can lead to privilege escalation.
s1shed/DockerAttack
Various Tools and Docker Images
s1shed/H5SC
HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
s1shed/LinkedInt
LinkedIn Recon Tool
s1shed/Invoke-WMILM
s1shed/RedTips
Red Team Tips as posted by @vysecurity on Twitter
s1shed/lpeworkshop
Windows / Linux Local Privilege Escalation Workshop
s1shed/adfs2
Multi Vagrant environment with Active Directory
s1shed/redshellguide
python script allow red teaming , hackthebox Pwners , OSCP lovers to shorten their time by these useful shells
s1shed/Arjun
Arjun is a python script for finding hidden GET & POST parameters.
s1shed/cuttlefish
dynamic parallelized host enumeration in golang
s1shed/bug-bounty-reference
Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
s1shed/pixiewps
An offline Wi-Fi Protected Setup brute-force utility
s1shed/burp-suite-http-proxy-history-converter
Python script that converts Burp Suite HTTP proxy history files to CSV or HTML
s1shed/Exchange-AD-Privesc
Exchange privilege escalations to Active Directory
s1shed/dostoevsky-pentest-notes
Notes for taking the OSCP in 2097. Read in book form on GitBook
s1shed/Invoke-Obfuscation
PowerShell Obfuscator
s1shed/DPAT
Domain Password Audit Tool for Pentesters
s1shed/FiercePhish
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.
s1shed/RandomPS-Scripts
PowerShell Scripts focused on Post-Exploitation Capabilities
s1shed/autoDANE
Auto Domain Admin and Network Exploitation.
s1shed/lois_lane
Lois Lane is a tool to create reports out of JSON data and Jinja templates.
s1shed/mimikittenz
A post-exploitation powershell tool for extracting juicy info from memory.
s1shed/borg
Deduplicating archiver with compression and authenticated encryption.
s1shed/borgmatic
A simple wrapper script for the Borg backup software that creates and prunes backups
s1shed/HostRecon
This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase. It gathers information about the local system, users, and domain information. It does not use any 'net', 'ipconfig', 'whoami', 'netstat', or other system commands to help avoid detection.
s1shed/dnuos
s1shed/searchscan
Search Nmap and Metasploit scanning scripts.
s1shed/PathToMastery
s1shed/redteam-plan
Issues to consider when planning a red team exercise.