Syzik's starred repositories

sherlock

Hunt down social media accounts by username across social networks

Language:PythonLicense:MITStargazers:52925Issues:1088Issues:941

phoneinfoga

Information gathering framework for phone numbers

Language:GoLicense:GPL-3.0Stargazers:12539Issues:668Issues:482

gophish

Open-Source Phishing Toolkit

Language:GoLicense:NOASSERTIONStargazers:11034Issues:350Issues:2791

evilginx2

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Language:GoLicense:BSD-3-ClauseStargazers:10374Issues:292Issues:858

maigret

🕵️‍♂️ Collect a dossier on a person by username from thousands of sites

Language:PythonLicense:MITStargazers:9940Issues:91Issues:1067

rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

Language:HTMLLicense:GPL-3.0Stargazers:7237Issues:143Issues:799

HELK

The Hunting ELK

Language:Jupyter NotebookLicense:GPL-3.0Stargazers:3735Issues:214Issues:452

IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

SSRFmap

Automatic SSRF fuzzer and exploitation tool

Language:PythonLicense:MITStargazers:2865Issues:57Issues:23

lsassy

Extract credentials from lsass remotely

Language:PythonLicense:MITStargazers:1984Issues:51Issues:36

cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Language:GoLicense:GPL-3.0Stargazers:1429Issues:13Issues:60

PrivExchange

Exchange your privileges for Domain Admin privs by abusing Exchange

Language:PythonLicense:MITStargazers:964Issues:31Issues:20

hashes

Magic hashes – PHP hash "collisions"

smbclient-ng

smbclient-ng, a fast and user friendly way to interact with SMB shares.

Language:PythonLicense:GPL-3.0Stargazers:671Issues:6Issues:44

ntlmv1-multi

NTLMv1 Multitool

Language:PythonLicense:MITStargazers:566Issues:17Issues:5

SMBetray

SMB MiTM tool with a focus on attacking clients through file content swapping, lnk swapping, as well as compromising any data passed over the wire in cleartext.

Language:PythonLicense:GPL-3.0Stargazers:385Issues:19Issues:6

gosecretsdump

Dump ntds.dit really fast

Language:GoLicense:GPL-3.0Stargazers:361Issues:9Issues:10

orpheus

Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types

Cloud-Security-Research

Cloud-related research releases from the Rhino Security Labs team.

Language:PythonLicense:BSD-3-ClauseStargazers:350Issues:22Issues:1

LDAPWordlistHarvester

A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.

alpaca

A local HTTP proxy for command-line tools. Supports PAC scripts and NTLM authentication.

Language:GoLicense:Apache-2.0Stargazers:185Issues:9Issues:54

bambdas

Bambdas collection for Burp Suite Professional and Community.

Language:JavaLicense:LGPL-3.0Stargazers:174Issues:7Issues:7
Language:PythonLicense:Apache-2.0Stargazers:168Issues:2Issues:0

modifyCertTemplate

ADCS cert template modification and ACL enumeration

osgint

OSINT tool to find informations about a github user (email2username, username2email, creation date ...)

pp-finder

PP-finder Help you find gadget for prototype pollution exploitation

ADcheck

Assess the security of your Active Directory with few or all privileges.

OUned

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Language:PythonStargazers:62Issues:3Issues:0

MailPermute

Generate email permutations from a name and verify if this email exist with different providers (gmail, duckduckgo, yahoo, yandex)

Language:PythonStargazers:33Issues:0Issues:0