14-day longest streak
-
Awareness ★ PINNED
Open-source security-awareness platform — build courses, run quizzes and phishing-style tests, track completion by department. No expensive SaaS or spreadsheets required.
Python ★ 14 5d agoExplain → -
OpenRecon ★ PINNED
Asynchronous recon toolkit — subdomain enumeration, port/TLS/WAF scanning, WHOIS profiling and full mail-security audit (SPF, DKIM, DMARC, MTA-STS, DNSSEC, security.txt).
Python ★ 25 1mo agoExplain → -
DockerHub-Scanner ★ PINNED
🐳 COMPANY DockerHub Scanner Automated scanner for DockerHub repositories. It pulls, extracts, scans Docker images for vulnerabilities, secrets, and sensitive data. Results are presented in the terminal and exported as CSV files.
Python ★ 12 1y agoExplain → -
PublicGuard ★ PINNED
Blocks IP ranges of public Threat Intelligence scanners (Shodan, Censys, ZoomEye, FOFA, BinaryEdge) via iptables/ipset - keeps test/dev infrastructure out of internet-wide scan databases.
Shell ★ 10 8mo agoExplain → -
l0phtcrack ★ PINNED
L0phtCrack 7 macOS fork — Apple Silicon port with hashcat engine (M1/M2/M3/M4)
C++ ★ 26 3mo agoExplain → -
cyberheap ★ PINNED
CyberHeap — fast Go CLI for pentest triage of Java HPROF heap dumps. Extracts credentials, keys, tokens via regex + class-aware spiders. Decrypts Jasypt / Shiro RememberMe / JWT locally.
Go ★ 11 2mo agoExplain → -
Wordlists
My wordlists
★ 6 2mo agoExplain → -
Forensics
Tools & script for Cyber Forensics
Python ★ 5 9mo agoExplain → -
bitrix-nuclei-templates
Complete collection of Nuclei templates for Bitrix CMS vulnerability testing
★ 5 11mo agoExplain → -
Villain ⑂
Villain is a Windows & Linux backdoor generator and multi-session handler that allows users to connect with sibling servers (other machines running Villain) and share their backdoor sessions, handy for working as a team.
★ 3 3y agoExplain → -
threat-feeds
A collection of threat sources for integration into SIEM, NGFW, etc.
Python ★ 2 1d agoExplain → -
aquatone ⑂
A Tool for Domain Flyovers
★ 2 4y agoExplain → -
FilelessPELoader ⑂
Loading Remote AES Encrypted PE in memory , Decrypted it and run it
★ 2 3y agoExplain → -
PrivescCheck ⑂
Privilege Escalation Enumeration Script for Windows
★ 2 2y agoExplain → -
DoubleAgent ⑂
No description.
★ 2 1y agoExplain → -
CVEs
All PoC
Python ★ 2 9mo agoExplain → -
n0kovo_subdomains ⑂
An extremely effective subdomain wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.
★ 1 3y agoExplain → -
hypobrychium ⑂
Duplicate not owned Token from Running Process
★ 1 3y agoExplain → -
Whisker ⑂
Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.
C# ★ 1 2y agoExplain → -
XSS_check
No description.
JavaScript ★ 1 8mo agoExplain →
No repos match these filters.