1-day current streak·12-day longest streak
👋 Hi, I'm Chandrapal Badshah 👀 I'm a Cloud and Cloud Native Security Researcher 🔒 I'm building Hardenly.co - Secure your NextJS & Vercel projects 💼 I'm building SecRoles.com -…
- 👋 Hi, I'm Chandrapal Badshah
- 👀 I'm a Cloud and Cloud Native Security Researcher
- 🔒 I'm building Hardenly.co - Secure your NextJS & Vercel projects
- 💼 I'm building SecRoles.com - Find your next cybersecurity role in one place
- 💞️ I maintain Hack-with-GitHub
- 📫 Learn more about my work at badshah.io
README.md (this file) appears on your GitHub profile.
You can click the Preview link to take a look at your changes.
--->-
Awesome-MitM
Curated List of MitM frameworks on GitHub
★ 257 8y agoExplain → -
WinHotspot ▣
A free open source python program to start WiFi hotspot in Windows without any external software
Python ★ 27 10y agoExplain → -
aws-mfa-enforce ▣
Serverless function to automate enforcement of Multi-Factor Authentication (MFA) to all AWS IAM users with access to AWS Management Console.
JavaScript ★ 13 7y agoExplain → -
Dependabot-Dashboard ▣
No description.
Python ★ 4 3y agoExplain → -
hacks ▣
No description.
Go ★ 4 4y agoExplain → -
owasp-mstg ⑂
The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security development, testing and reverse engineering.
HTML ★ 4 6y agoExplain → -
changeme ⑂
A default credential scanner.
Python ★ 4 7y agoExplain → -
0xbadshah
No description.
★ 3 1mo agoExplain → -
strix ⑂
Open-source AI agents for penetration testing
Python ★ 3 6mo agoExplain → -
aws-summarize-account-activity ⑂
Analyzes CloudTrail data of a given AWS account and generates a summary of recently active IAM principals, API calls they made, as well as regions, IP addresses and user agents they used.
★ 3 1y agoExplain → -
wireguard-tunnel
Full-tunnel WireGuard client for cloud VMs. Routes all traffic through your WireGuard server, survives system updates, keeps SSH working.
Shell ★ 2 4mo agoExplain → -
Awesome-Black-Friday-Cyber-Monday ⑂
Awesome deals on Black Friday: Apps, SaaS, Books, Courses, etc.
★ 2 1y agoExplain → -
Awesome-Asset-Discovery ⑂
List of Awesome Asset Discovery Resources
★ 2 7y agoExplain → -
GCP-pentest-lab ⑂
A vulnerable environment for exploring common GCP misconfigurations and vulnerabilities
★ 2 1y agoExplain → -
ansible-lemp-wp-certbot-playbook ⑂
Ansible playbook to deploy a static html, php, php+mysql or wordpress website with Let's Encrypt SSL/TLS certificate
PHP ★ 2 7y agoExplain → -
vulnerable-api ⑂
Enhanced with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops
★ 2 5y agoExplain → -
android-security-awesome ⑂
A collection of android security related resources
★ 2 8y agoExplain → -
get_schemas ⑂
Print out URL schemas from an Android app
Python ★ 2 7y agoExplain → -
blackhat-arsenal-tools ⑂
Official Black Hat Arsenal Security Tools Repository
★ 2 8y agoExplain → -
puppeteer-lambda-starter-kit ⑂
Starter Kit for running Headless-Chrome by Puppeteer on AWS Lambda.
JavaScript ★ 2 7y agoExplain → -
local-sheriff ⑂
Think of Local sheriff as a recon tool in your browser (WebExtension). While you normally browse the internet, Local Sheriff works in the background to empower you in identifying what data points (PII) are being shared / leaked to which all third-parties.
JavaScript ★ 2 7y agoExplain → -
shhgit ⑂
Find GitHub secrets in real time
★ 2 6y agoExplain → -
Proxy-List
Python program to check accessible proxy sites
Python ★ 2 9y agoExplain → -
WIZwiki-W7500
No description.
★ 2 9y agoExplain → -
vuls ⑂
Agent-less vulnerability scanner for Linux/FreeBSD/WordPress/Programming language libraries/Network devices
Go ★ 2 7y agoExplain → -
go-pillage-registries ⑂
Pentester-focused Docker registry tool to enumerate and pull images
★ 2 6y agoExplain → -
OSINTforPenTests ⑂
Slides from my ShellCon Talk, OSINT for Pen Tests, given 10/19.
★ 2 8y agoExplain → -
awesome-web-security ⑂
🐶 A curated list of Web Security materials and resources.
★ 2 8y agoExplain → -
spiderfoot ⑂
SpiderFoot, the open source footprinting and intelligence-gathering tool.
Python ★ 2 8y agoExplain → -
003Recon ⑂
Some tools to automate recon - 003random
Shell ★ 2 8y agoExplain → -
bXSS ⑂
bXSS is a simple Blind XSS application adapted from https://cure53.de/m
JavaScript ★ 2 7y agoExplain → -
steampipe-plugin-cloudflare ⑂
Use SQL to instantly query accounts, zones and more from Cloudflare. Open source CLI. No DB required.
★ 1 1mo agoExplain → -
InfoSec-Black-Friday ⑂
All the deals for InfoSec related software/tools this Black Friday
★ 1 1y agoExplain → -
prowler ⑂
Prowler is an Open Cloud Security tool for AWS, Azure, GCP and Kubernetes. It helps for continuos monitoring, security assessments and audits, incident response, compliance, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more.
Python ★ 1 4mo agoExplain → -
testing-devcontainer
No description.
Python ★ 1 1y agoExplain → -
Kotlin ▣
Sample Android apps I made to learn Kotlin
Kotlin ★ 1 8y agoExplain → -
k8s-security-dashboard ⑂
A security monitoring solution for Kubernetes
Python ★ 1 7y agoExplain → -
CVE-2018-13379 ⑂
CVE-2018-13379
Python ★ 1 6y agoExplain → -
codeql-javascript-unsafe-jquery-plugin ▣
No description.
CodeQL ★ 1 4y agoExplain → -
my-arsenal-of-aws-security-tools ⑂
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Shell ★ 1 7y agoExplain → -
seltzer ⑂
A Burp Suite extension for headless, unattended scanning.
★ 1 6y agoExplain → -
serverless_toolkit ⑂
A collection of useful Serverless functions I use when pentesting
JavaScript ★ 1 7y agoExplain → -
Misc-Scripts
Random scripts which helped me to improve my programming skills
Python ★ 1 9y agoExplain → -
megplus ⑂
Automated reconnaissance wrapper — TomNomNom's meg on steroids.
Shell ★ 1 8y agoExplain → -
Gorsair ⑂
Gorsair hacks its way into remote docker containers that expose their APIs.
Go ★ 1 7y agoExplain → -
heroku-static-site ⑂
A basic Ruby/Rack app for publishing a static HTML/CSS/javascript website on Heroku (for free)
CSS ★ 1 7y agoExplain → -
turbo-intruder ⑂
Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.
Kotlin ★ 1 6y agoExplain → -
keyhacks ⑂
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
★ 1 6y agoExplain → -
mobsf-ci ⑂
All that is required to run MobSF in the ci
Shell ★ 1 6y agoExplain → -
proctor-helm-charts ⑂
No description.
★ 1 6y agoExplain → -
protobuf-decoder ⑂
A simple Google Protobuf Decoder for Burp
★ 1 6y agoExplain → -
K-Map
A Java implementation of resolving K-Maps
Java ★ 1 9y agoExplain → -
aifs
Implements general patterns related to machine learning and information classification.
PHP ★ 1 9y agoExplain → -
LinkedInt ⑂
LinkedInt: A LinkedIn scraper for reconnaissance during adversary simulation
Python ★ 1 8y agoExplain → -
FridaWorkshop ⑂
Break Apps with Frida workshop material
HTML ★ 1 8y agoExplain → -
Belati ⑂
The Traditional Swiss Army Knife for OSINT
Python ★ 1 8y agoExplain → -
awesome-pentest-cheat-sheets ⑂
Collection of the cheat sheets useful for pentesting
★ 1 8y agoExplain → -
datasploit ⑂
A tool to perform various OSINT techniques, aggregate all the raw data, visualise it on a dashboard, and facilitate alerting and monitoring on the data.
Python ★ 1 8y agoExplain → -
PlaystoreDownloader ⑂
A command line tool to download Android applications directly from the Google Play Store
Python ★ 1 8y agoExplain → -
gplaycli ⑂
Google Play Downloader via Command line
Python ★ 1 8y agoExplain → -
ctfhub ⑂
Some Docker for CTF environments
PHP ★ 1 8y agoExplain → -
Vagrantfiles
Collection of useful Vagrantfiles
Ruby ★ 1 8y agoExplain → -
documenso ⑂
The Open Source DocuSign Alternative.
★ 0 2mo agoExplain → -
nuxt-studio ⑂
Edit your Markdown website, in production.
★ 0 2mo agoExplain → -
testiiiing
No description.
★ 0 2mo agoExplain → -
kubernetes-goat ⑂
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
★ 0 6mo agoExplain → -
ShipFree ⑂
Open Source Next.js Saas Boilerplate Alternative to ShipFast
★ 0 1y agoExplain → -
ai-sdk-demo
No description.
TypeScript ★ 0 6mo agoExplain → -
BoxPwnr ⑂
An experimental project exploring the use of Large Language Models (LLMs) to solve HackTheBox machines autonomously.
★ 0 6mo agoExplain → -
bug-collection ⑂
Vulnerable React/Next application
★ 0 9mo agoExplain → -
security-vulnerability-examples-next-js-postgres ⑂
No description.
★ 0 9mo agoExplain → -
cve-genie ⑂
CVE-Genie
★ 0 9mo agoExplain → -
cve-genie-prompts ⑂
This repository shows the prompts we used for each agent in CVE-Genie
★ 0 1y agoExplain → -
yara-python ⑂
The Python interface for YARA
C ★ 0 6y agoExplain → -
magnovite-2017 ▣
No description.
Python ★ 0 9y agoExplain → -
dvws-node ⑂
Damn Vulnerable Web Service is a vulnerable web service/API/application that can be used to learn webservices/API vulnerabilities.
★ 0 5y agoExplain → -
comments
Repo to hold all comments made on my website - https://badshah.io
★ 0 6y agoExplain → -
LoveIt ⑂
❤️A clean, elegant but advanced blog theme for Hugo 一个简洁、优雅且高效的 Hugo 主题
★ 0 6y agoExplain → -
swachalit ⑂
Swachalit - The null Automation Platform that hosts null.co.in. This repository contains code that is periodically synced from development repository. We plan to eventually move to completely open source development.
Ruby ★ 0 6y agoExplain → -
RCEScanner ⑂
Simple python script to extract unsafe functions from php projects
★ 0 8y agoExplain → -
indigo ⑂
:ramen: Minimalist Jekyll Template
HTML ★ 0 6y agoExplain → -
PyNamecheap ⑂
Namecheap API client in Python.
★ 0 8y agoExplain → -
DevSecOps-Studio ⑂
Virtual environment for learning DevSecOps
Shell ★ 0 7y agoExplain → -
pathbrute ⑂
Pathbrute
Go ★ 0 8y agoExplain → -
reconvillage ⑂
Repo for reconvillage.org website.
CSS ★ 0 7y agoExplain → -
fuzzing_ftw ⑂
DEF CON 26 WorkShop - Fuzzing FTW
Python ★ 0 7y agoExplain → -
Astra ⑂
Automated Security Testing For REST API's
Python ★ 0 7y agoExplain → -
inception ⑂
A highly configurable tool to check for whatever you like against any number of hosts.
HTML ★ 0 7y agoExplain → -
DVSA ⑂
a Damn Vulnerable Serverless Application
★ 0 7y agoExplain → -
cloud-custodian ⑂
Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
Python ★ 0 7y agoExplain → -
c7n-policies ⑂
Cloud Custodian Policies for Automated Amazon Resource Management
Python ★ 0 7y agoExplain → -
azure-functions-docker-python-sample ⑂
A sample of using docker to deploy a Python based app
Python ★ 0 7y agoExplain → -
Serverless-Top-10-Project ⑂
No description.
★ 0 7y agoExplain → -
examples ⑂
Serverless Examples – A collection of boilerplates and examples of serverless architectures built with the Serverless Framework and AWS Lambda
JavaScript ★ 0 7y agoExplain → -
serverless ⑂
Serverless Framework – Build web, mobile and IoT applications with serverless architectures using AWS Lambda, Azure Functions, Google CloudFunctions & more! –
JavaScript ★ 0 7y agoExplain → -
alldaysecops ⑂
No description.
★ 0 7y agoExplain → -
BReview
Reviews and notes of technical books I read
★ 0 7y agoExplain → -
IoTSecurity101 ⑂
From IoT Pentesting to IoT Security
★ 0 7y agoExplain → -
re-scripts ⑂
IDA, Radare2 and Bninja scripts
Python ★ 0 7y agoExplain → -
magisk-module-template ⑂
template
Shell ★ 0 7y agoExplain → -
MagiskFrida ⑂
Runs frida-server on boot as root with magisk.
Shell ★ 0 8y agoExplain → -
personal_script ⑂
No description.
Java ★ 0 8y agoExplain → -
frida-snippets ⑂
TIL for Frida
JavaScript ★ 0 7y agoExplain → -
dnsutil ⑂
dns dig for golang
Go ★ 0 7y agoExplain → -
bugbounty-cheatsheet ⑂
A list of interesting payloads, tips and tricks for bug bounty hunters.
★ 0 8y agoExplain → -
can-i-take-over-xyz ⑂
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
★ 0 8y agoExplain → -
house ⑂
A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python.
Python ★ 0 8y agoExplain → -
awesome-frida ⑂
Awesome Frida - A curated list of Frida resources http://www.frida.re/ (https://github.com/frida/frida)
★ 0 8y agoExplain → -
badges ⑂
ToolsWatch and Black Hat Arsenal selection of badges
★ 0 8y agoExplain → -
Some-Kernel-Fuzzing-Paper ⑂
Some kernel fuzzing paper about windows and linux
★ 0 8y agoExplain → -
VagrantBuild ⑂
Vagrant + ansible scripts used to create the AndroidTamer distribution
Shell ★ 0 8y agoExplain → -
tinfoleak ⑂
The most complete open-source tool for Twitter intelligence analysis
Python ★ 0 8y agoExplain → -
iBoot ⑂
Source code for a core component of the iPhone's operating system
C ★ 0 8y agoExplain → -
coffeeMiner ⑂
collaborative (mitm) cryptocurrency mining pool in wifi networks
Python ★ 0 8y agoExplain → -
Awesome-Red-Teaming ⑂
List of Awesome Red Teaming Resources
★ 0 8y agoExplain → -
College
Random College stuff
Java ★ 0 9y agoExplain →
No repos match these filters.