Drew's starred repositories

chisel

A fast TCP/UDP tunnel over HTTP

git-blame-someone-else

Blame someone else for your bad code.

Language:ShellLicense:MITStargazers:10686Issues:78Issues:0

evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Language:GoLicense:BSD-3-ClauseStargazers:10243Issues:290Issues:853

LaZagne

Credentials recovery project

Language:PythonLicense:LGPL-3.0Stargazers:9275Issues:413Issues:467

windows-kernel-exploits

windows-kernel-exploits Windows平台提权漏洞集合

traitor

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

ScoutSuite

Multi-Cloud Security Auditing Tool

Language:PythonLicense:GPL-2.0Stargazers:6318Issues:129Issues:853

UACME

Defeating Windows User Account Control

Language:CLicense:BSD-2-ClauseStargazers:6067Issues:277Issues:116

wfuzz

Web application fuzzer

Language:PythonLicense:GPL-2.0Stargazers:5748Issues:168Issues:197

maestro

Unix-like kernel written in Rust

Language:RustLicense:AGPL-3.0Stargazers:2832Issues:22Issues:16

PrivescCheck

Privilege Escalation Enumeration Script for Windows

Language:PowerShellLicense:BSD-3-ClauseStargazers:2755Issues:77Issues:48

pwndrop

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Language:JavaScriptLicense:GPL-3.0Stargazers:1929Issues:43Issues:44

Leaked-GPTs

Leaked GPTs Prompts Bypass the 25 message limit or to try out GPTs without a Plus subscription.

cvemap

Navigate the CVE jungle with ease.

Language:GoLicense:MITStargazers:1527Issues:23Issues:41

nginxpwner

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

Language:PythonLicense:Apache-2.0Stargazers:1399Issues:11Issues:6

shopify_python_api

ShopifyAPI library allows Python developers to programmatically access the admin section of stores

Language:PythonLicense:MITStargazers:1204Issues:525Issues:397

SharpGPOAbuse

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.

ntlm_theft

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

Language:PythonLicense:GPL-3.0Stargazers:909Issues:28Issues:3

DSEFix

Windows x64 Driver Signature Enforcement Overrider

Language:CLicense:BSD-2-ClauseStargazers:697Issues:44Issues:13

forensictools

Collection of forensic tools

Language:Inno SetupLicense:Apache-2.0Stargazers:479Issues:4Issues:12

binjection

Injects additional machine instructions into various binary formats.

Language:GoLicense:GPL-3.0Stargazers:265Issues:11Issues:2

nac_bypass

Script collection to bypass Network Access Control (NAC, 802.1x)

Language:ShellLicense:MITStargazers:258Issues:10Issues:3

debian-from-scratch

An instruction manual for teaching Linux From Scratch users how to make a fully-fledged Debian system based on LFS.

proxyhub

An advanced [Finder | Checker | Server] tool for proxy servers, supporting both HTTP(S) and SOCKS protocols. 🎭

Language:PythonLicense:Apache-2.0Stargazers:181Issues:6Issues:2

disposable-email-domain-list

A list of disposable email domains, cleaned and validated by scanning MX records.

Language:PythonLicense:MITStargazers:86Issues:6Issues:6

bully

Bully WPS Attack Tool

Language:CLicense:GPL-3.0Stargazers:51Issues:6Issues:5

CVE-2023-38646-PoC

Metabase Pre-auth RCE

Language:PythonLicense:GPL-3.0Stargazers:12Issues:1Issues:0

GSheet-MultiSelect

Script to add Google Sheets MultiSelect fields

smtp2go-python

Python library for interacting with the smtp2go API

Language:PythonLicense:MITStargazers:3Issues:4Issues:5