Pinned Repositories
ABC
Script to check a list of passwords against haveibeenpwned.com/Passwords without sharing the real password.
herohunter
Searches urlscan.io submissions for webpages that contain common phishing files such as common credential login splash pages.
HTTP-Info
Homemade urlscan.io in a docker container
knockknock
How to test if FireEye is inline
OVERFLOW
Microsoft Flow Attack Framework
rumpshaker
Zoom Vulnerability URL path that allows an unauthenticated attacker to guess a meeting room id. Successful exploit may lead to sensitive information disclosure as well as access to a valid meeting id.
St2-057
St2-057 Poc Example
vulhub
Docker-Compose files for vulnerability environments
surbo's Repositories
surbo/OVERFLOW
Microsoft Flow Attack Framework
surbo/ABC
Script to check a list of passwords against haveibeenpwned.com/Passwords without sharing the real password.
surbo/herohunter
Searches urlscan.io submissions for webpages that contain common phishing files such as common credential login splash pages.
surbo/HTTP-Info
Homemade urlscan.io in a docker container
surbo/knockknock
How to test if FireEye is inline
surbo/rumpshaker
Zoom Vulnerability URL path that allows an unauthenticated attacker to guess a meeting room id. Successful exploit may lead to sensitive information disclosure as well as access to a valid meeting id.
surbo/St2-057
St2-057 Poc Example
surbo/vulhub
Docker-Compose files for vulnerability environments
surbo/April
surbo/artillery
The Artillery Project is an open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.
surbo/BloodHound
Six Degrees of Domain Admin
surbo/cortex_urlscan_analyzer
Cortex analyzer for urlscan.io.
surbo/CyberChef-VBS
The start of vbs tool for cyberchef
surbo/elevate
surbo/ESPCanary
surbo/Golang_Reverse_HTTPS_Meterpreter
A reverse https meterpreter payload written in Go
surbo/hhupd.exe
surbo/Invoke-LoginPrompt
Invokes a Windows Security Login Prompt and outputs the clear text password.
surbo/log4jscanwin
Log4j Vulnerability Scanner for Windows
surbo/MISC
surbo/misp-modules
Modules for expansion services, import and export in MISP
surbo/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
surbo/reverse_ssh
By far one of the stupidest things I've been thinking of for a while. Have an ssh client connect to a server, and then provide the server the ability to control the client
surbo/Sparrow
Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.
surbo/WARP-ZONE
Download tool-kits and other payloads by blending in with Microsoft Azure Infrastructure. Bypass web proxy restrictions when downloading files.
surbo/workbench
surbo/xmlrpc-scan
Scan a list of domain names looking for XMLRPC.php