sanreee's Stars
dmaasland/dmaasland.github.io
chenjj/CORScanner
🎯 Fast CORS misconfiguration vulnerabilities scanner
balgan/binaryedge-cheatsheet
A list of queries and actions that I repeat over and over again
m4ll0k/SecretFinder
SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files
ION28/BLUESPAWN
An Active Defense and EDR software to empower Blue Teams
m4ll0k/BBTz
BBT - Bug Bounty Tools (examples💡)
Integration-IT/Active-Directory-Exploitation-Cheat-Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
ncsc-fi/minion-rules
Minion rules for DFIR work.
Elemental-attack/Elemental
Elemental - An ATT&CK Threat Library
maldevel/intelspy
Perform automated network reconnaissance scans
TheBinitGhimire/Web-Shells
Some of the best web shells that you might need!
jhaddix/tbhm
The Bug Hunters Methodology
mitre/cti
Cyber Threat Intelligence Repository expressed in STIX 2.0
microsoft/Microsoft-365-Defender-Hunting-Queries
Sample queries for Advanced hunting in Microsoft 365 Defender
iGotRootSRC/Dorkers
Dorks for Google, Shodan and BinaryEdge
1N3/Goohak
Automatically Launch Google Hacking Queries Against A Target Domain
pinnace/burp-jwt-fuzzhelper-extension
JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.
minimaxir/big-list-of-naughty-strings
The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
hakluke/hakrawler
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
GerbenJavado/LinkFinder
A python script that finds endpoints in JavaScript files
elkokc/reflector
Burp plugin able to find reflected XSS on page in real-time while browsing on site
lc/gau
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
itm4n/FullPowers
Recover the default privilege set of a LOCAL/NETWORK SERVICE account
P4T12ICK/Sigma2SplunkAlert
Converts Sigma detection rules to a Splunk alert configuration.
ropnop/windapsearch
Python script to enumerate users, groups and computers from a Windows domain through LDAP queries
Tib3rius/AutoRecon
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
ropnop/kerbrute
A tool to perform Kerberos pre-auth bruteforcing
BishopFox/GadgetProbe
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
aarju/Kibana_ForensicDashboards
Dashboards for conducting forensic investigation using windows events in Kibana
OTRF/ThreatHunter-Playbook
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.