yrkan's Stars
evilsocket/xray
XRay is a tool for recon, mapping and OSINT gathering from public networks.
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
random-robbie/My-Shodan-Scripts
Collection of Scripts for shodan searching stuff.
orangetw/My-CTF-Web-Challenges
Collection of CTF Web challenges I made
1N3/BruteX
Automatically brute force all services running on a target.
1N3/BlackWidow
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
1N3/ReverseAPK
Quickly analyze and reverse engineer Android packages
1N3/Findsploit
Find exploits in local and online databases instantly
apsdehal/awesome-ctf
A curated list of CTF frameworks, libraries, resources and softwares
peass-ng/PEASS-ng
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
lxc/distrobuilder
System container image builder for LXC and Incus
Crypto-Cat/CTF
CTF chall write-ups, files, scripts etc (trying to be more organised LOL)
veracode-research/rogue-jndi
A malicious LDAP server for JNDI injection attacks
puzzlepeaches/Log4jUnifi
Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.
abhivaikar/howtheytest
A collection of public resources about how software companies test their software
BlackArch/webshells
Various webshells. We accept pull requests for additions to this collection.
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
Bo0oM/fuzz.txt
Potentially dangerous files
S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
shabarkin/pointer
Pointer was developed for massive hunting and mapping Cobalt Strike servers exposed on the internet.
int0x33/nc.exe
Netcat for windows 32/64 bit
enaqx/awesome-pentest
A collection of awesome penetration testing resources, tools and other shiny things
calebstewart/pwncat
Fancy reverse and bind shell handler
imp/dnsmasq
Mirror of the upstream dnsmasq repository
gentilkiwi/mimikatz
A little tool to play with Windows security
m3n0sd0n4ld/GooFuzz
GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).
carlospolop/Auto_Wordlists
OJ/gobuster
Directory/File, DNS and VHost busting tool written in Go
lgandx/Responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.