Gotham Security's repositories
Getting-into-InfoSec-and-Cybersecurity
A shorter, less intimidating list of infosec resources helpful for anyone trying to learn.
main-security-testing-tools
A curated list of network penetration testing tools.
pyExploitDb
An optimized Python3 library to fetch the most recent exploit-database, create searchable indexes for CVE->EDBID and EDBID -> CVE, and provide methods to perform searches.
Log4jShell_Scanner
Python script to tamper with pages to test for Log4J Shell vulnerability.
pentest-scripts
List of pentest related scripts edited or created by GoVanguard
pyHaveIBeenPwned
Python library to query HaveIBeenPwned.com with handling for CloudFlare anti-bot.
IP-Blacklist-CSV-Generator
Short multiprocessed Python 3 script that generates CSV files containing blacklisted IP addresses, pulling from firehol/blocklist-ipsets repo
SecretScanner
Shell script for performing secret scanning on a directory of files
AzureSnake
A suite of PowerShell scripts to automate portions of Azure Risk Assessments and Penetration Tests
SecretSearcher
Python re-implementation of the classic SecretScanner shell script
GothamSuperTemplate
A Microsoft Threat modeling template containing stencils, threat types and assessment rules for AWS and Azure
linux-build
Rock64 Linux build scripts, tools and instructions
Log4jShell_Vulnerable_Site
Test site that is intentionally vulnerable to log4jshell
Parrot-Armbian
Armbian build tools /w ParrotSec OS support
veracodeIntegration
Veracode integrations
wazuh-helm
Wazuh-helm is a helm template for deploying Wazuh
wordpress-azure-multisite
wordpress for azure marketplace
AstraGlide
Python3 port of the abandoned API fuzzing tool Astra
Gotham-Security-Aggregate-Repo
Aggregate repo of tools commonly used by Gotham Security which are not readily accessible via Pypi or Kali mirrors
linkedin2username
OSINT Tool: Generate username lists for companies on LinkedIn
log4jshell-pdf
The purpose of this project is to demonstrate the Log4Shell exploit with Log4J vulnerabilities using PDF as delivery channel
Microsoft-Win32-Content-Prep-Tool
A tool to wrap Win32 App and then it can be uploaded to Intune
Payloads_N_Lists
Testing Arsenal
Responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
SecretScannerTurbo
A C implementation of SecretScanner