Howdy, I'm Christopher Maddalena! 👋 _Director of Internal and Community Projects_ at SpecterOps | Author of Printing Props | BlackHat Trainer 📖 Author & Speaker Printing Props: A Beginner's Guide…
Howdy, I'm Christopher Maddalena! 👋
_Director of Internal and Community Projects_ at SpecterOps | Author of Printing Props | BlackHat Trainer
  https://www.linkedin.com/in/cmaddalena/" rel="noopener nofollow" target="_blank">
python
class Christopher():
pronouns = ["he", "him"]
contact = "[email protected]"
languages = ["Python", "C#", "JavaScript", "HTML/CSS"]
tools = ["Docker", "AWS", "Django", "GraphQL"]
current_focus = {
"role": "Director @ SpecterOps",
"projects": ["Ghostwriter", "Community Tools"],
"passion": "Building open source security tools"
}
📖 Author & Speaker
Printing Props: A Beginner's Guide to 3D Printing for Cosplay and Replicas — A comprehensive guide to 3D printing for makers and cosplayers.
Speaking & Training: BlackHat USA (Trainer), DerbyCon, CircleCityCon, CodeMash, BSides Detroit
🔐 Security Community Work
At SpecterOps, I lead internal tooling and community-focused open source projects supporting offensive security operations and the broader security community.
Current Projects
Ghostwriter — *Creator @ GhostManager Org*
Ghostwriter is an open-source platform that enhances offensive security operations by streamlining reporting, asset tracking, and assessment management. Its powerful reporting engine includes collaborative writing features and customizable templates, enabling teams to produce polished deliverables with minimal manual effort.
Ghostwriter CLI — *Creator @ GhostManager Org*
Ghostwriter CLI abstracts Docker Compose commands to simplify installation, management, and maintenance of Ghostwriter instances.
BloodHound CLI — *Contributor @ SpecterOps*
BloodHound CLI abstracts Docker Compose commands to simplify installation, management, and maintenance of BloodHound Community Edition instances.
Past Projects
ODIN — *Creator*
Automated intelligence gathering and reconnaissance framework for OSINT operations.
Cooper — *Creator*
Cooper was a toolkit for cloning websites and emails to create templates for red team assessment phishing campaigns.
Goreport — *Creator*
Goreport was an early supporting tool for the Gophish project that created bespoke reports from Gophish campaign results, generating Word documents with events and stats from one or more campaigns.
-
ODIN
Automated network asset, email, and social media profile discovery and cataloguing.
Python ★ 666 4y agoExplain → -
Goreport
A Python script to collect campaign data from Gophish and generate a report
Python ★ 200 3y agoExplain → -
SharpCloud
Simple C# for checking for the existence of credential files related to AWS, Microsoft Azure, and Google Compute.
C# ★ 177 7y agoExplain → -
Fox
A companion tool for BloodHound offering Active Directory statistics and number crunching
Python ★ 64 8y agoExplain → -
Cooper
A Python tool for ingesting HTML and producing HTML source suitable for phishing campaigns.
Python ★ 60 2d agoExplain → -
RedTeamMemory
A repo for holding cheat sheets for myself that cover various penetration testing tools and commands.
★ 40 8y agoExplain → -
UsefulScripts
A collection of useful scripts
Python ★ 24 7y agoExplain → -
ShellHerder
An MSF plugin to send notifications to Slack when shells are created or killed
Ruby ★ 14 9y agoExplain → -
DocPatch
A simple script that edits the XML of a macro-enabled Word document (.docm or Word 97 document) to add a reference to a remote stylesheet.
Python ★ 11 3y agoExplain → -
Postfix-Server-Setup ⑂
No description.
Shell ★ 8 8y agoExplain → -
ExploitDev
Practice exploit development and misc things
Python ★ 6 8y agoExplain → -
subTee-gits-backups ⑂
subTee gists code backups
C# ★ 4 8y agoExplain → -
Grouper ⑂
A PowerShell script for helping to find vulnerable settings in AD Group Policy.
PowerShell ★ 3 8y agoExplain → -
OSCARf-public ⑂
Python tool to aid in the collection of OSINT data
Python ★ 3 10y agoExplain → -
LAPSToolkit ⑂
Tool to audit and attack LAPS environments
PowerShell ★ 2 8y agoExplain → -
Ghostwriter ⑂
The SpecterOps project management and reporting engine
Python ★ 2 4y agoExplain → -
StatusBoard
Arduino-controlled work from home status board based on the Adafruit Huzzah
C ★ 2 5y agoExplain → -
DomainSnooper
Tool for checking a list of domains for the purpose of gathering emails and social media handles and checking for potential issues
Python ★ 2 10y agoExplain → -
discover ⑂
For use with Kali Linux - custom bash scripts used to automate various portions of a pentest.
Shell ★ 2 11y agoExplain → -
ANGRYPUPPY ⑂
Bloodhound Attack Path Automation in CobaltStrike
PowerShell ★ 1 9y agoExplain → -
AutomatedLabScripts
My personal scripts for generating labs using AutomatedLab
★ 1 8y agoExplain → -
phpbash ⑂
A semi-interactive PHP shell compressed into a single file.
PHP ★ 1 8y agoExplain → -
domainhunter ⑂
Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
Python ★ 1 7y agoExplain → -
fireprox ⑂
AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
Python ★ 1 7y agoExplain → -
DuckyScripts
Some fun Rubber Ducky scripts
★ 1 9y agoExplain → -
SenseSational
Python script for managing and recording data with a Raspberry PI Sense HAT
Python ★ 1 9y agoExplain → -
meeting-reminder ⑂
cute banner that reminds you that a meeting is upcoming.
Swift ★ 0 19d agoExplain → -
capabilities ⑂
Public source of the Dreadnode capabilities in app.dreadnode.io — agents, tools, skills, MCP servers, and workers.
★ 0 1mo agoExplain → -
grimmory ⑂
Grimmory is the successor of booklore.
★ 0 2mo agoExplain → -
chrismaddalena
No description.
★ 0 7mo agoExplain → -
skills-publish-packages
My clone repository
HTML ★ 0 6mo agoExplain → -
BloodHound ⑂
Six Degrees of Domain Admin
Go ★ 0 1y agoExplain → -
mintlify-docs
No description.
MDX ★ 0 1y agoExplain → -
docs
No description.
MDX ★ 0 1y agoExplain → -
BloodHoundLegacy ⑂
Six Degrees of Domain Admin
PowerShell ★ 0 7y agoExplain → -
PrintingPropsModels
3D design files to accompany the Printing Props book
★ 0 1y agoExplain → -
y-crdt ⑂
Rust port of Yjs
★ 0 1y agoExplain → -
cs2modrewrite ⑂
Convert Cobalt Strike profiles to modrewrite scripts
Python ★ 0 3y agoExplain → -
whitep4nth3r ⑂
No description.
★ 0 4y agoExplain → -
Mythic_CLI ⑂
Golang CLI binaries to replace the bash scripts controlling Mythic
★ 0 4y agoExplain → -
djangorestframework-api-key ⑂
🔐 API key permissions for Django REST Framework
Python ★ 0 4y agoExplain → -
chrismaddalena.github.io ⑂
:sparkles: Build a beautiful and simple website in literally minutes. Demo at http://deanattali.com/beautiful-jekyll
HTML ★ 0 7mo agoExplain → -
commando-vm ⑂
Complete Mandiant Offensive VM (Commando VM), the first full Windows-based penetration testing virtual machine distribution. The security community recognizes Kali Linux as the go-to penetration testing platform for those that prefer Linux. Commando VM is for penetration testers that prefer Windows. We know that building a Windows penetration testing environment can be tedious - we aim to streamline and simplify this process. Commando VM includes over 140 tools.
PowerShell ★ 0 7y agoExplain → -
github-actions-tutorial ⑂
A guided introduction to Github Actions
Go ★ 0 4y agoExplain → -
go-mimikatz ⑂
A wrapper around a pre-compiled version of the Mimikatz executable for the purpose of anti-virus evasion.
Go ★ 0 10y agoExplain → -
presentations-1 ⑂
SpecterOps Presentations
★ 0 5y agoExplain → -
scope_creep ⑂
Mass target enumeration
★ 0 6y agoExplain → -
snapback ⑂
HTTP(s) Screenshots for Pen Testers Who Value Their Time
★ 0 6y agoExplain → -
pyRevDNS
python reverse dns script
Python ★ 0 10y agoExplain → -
Seatbelt ⑂
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
C# ★ 0 7y agoExplain → -
S3Scanner ⑂
Scan for open S3 buckets and dump
Python ★ 0 8y agoExplain → -
AWSBucketDump ⑂
Security Tool to Look For Interesting Files in S3 Buckets
Python ★ 0 8y agoExplain → -
RottenPotatoNG ⑂
New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.
C++ ★ 0 8y agoExplain → -
bettercap ⑂
The state of the art network attack and monitoring framework.
Go ★ 0 8y agoExplain → -
DomainFrontingLists ⑂
A list of Domain Frontable Domains by CDN
★ 0 8y agoExplain → -
Canvas ⑂
No description.
Python ★ 0 8y agoExplain → -
AllTheThings ⑂
Copy of Subtee's Repository That's Taken Down
JavaScript ★ 0 8y agoExplain → -
FindFrontableDomains ⑂
Search for potential frontable domains
Python ★ 0 8y agoExplain → -
Responder ⑂
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Python ★ 0 8y agoExplain → -
CobaltStrike-ToolKit ⑂
Some useful scripts for CobaltStrike
Shell ★ 0 8y agoExplain → -
windows-operating-system-archaeology ⑂
windows-operating-system-archaeology @Enigma0x3 @subTee
PowerShell ★ 0 9y agoExplain → -
koadic ⑂
Koadic C3 COM Command & Control - JScript RAT
Python ★ 0 8y agoExplain → -
bashbunny-payloads ⑂
Payloads for the Hak5 Bash Bunny
Python ★ 0 9y agoExplain → -
Presentations
No description.
★ 0 8y agoExplain → -
check ⑂
Check.py - An extended ip / domain lookup tool
Python ★ 0 9y agoExplain → -
MeterpreterHelper
No description.
Ruby ★ 0 9y agoExplain → -
metasploit-framework ⑂
Metasploit Framework
Ruby ★ 0 9y agoExplain → -
ssh-audit ⑂
SSH server auditing (banner, key exchange, encryption, mac, compression, compatbility, etc)
Python ★ 0 10y agoExplain → -
BurpSmartBuster ⑂
A Burp Suite content discovery plugin that add the smart into the Buster!
Python ★ 0 10y agoExplain → -
Small_Tasks ⑂
Small scripts for doing repeatable tasks
Python ★ 0 10y agoExplain → -
dtc2 ⑂
Duct Tape Command and Control!
Shell ★ 0 10y agoExplain → -
theHarvester ⑂
E-mail, subdomain and people names harvester
Python ★ 0 10y agoExplain → -
social-engineer-toolkit ⑂
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
Python ★ 0 10y agoExplain → -
CodeMash2016
CodeMash 2016 Presentation - "What to Expect from a Penetration Test"
★ 0 10y agoExplain →
No repos match these filters.