alic4fer's starred repositories

nativefier

Make any web page a desktop application

Language:TypeScriptLicense:MITStargazers:34926Issues:442Issues:1238

public-pentesting-reports

A list of public penetration test reports published by several consulting firms and academic security groups.

traitor

:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

linux-smart-enumeration

Linux enumeration tool for pentesting and CTFs with verbosity levels

Language:ShellLicense:GPL-3.0Stargazers:3436Issues:57Issues:47

Privilege-Escalation

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

SSRFmap

Automatic SSRF fuzzer and exploitation tool

Language:PythonLicense:MITStargazers:2987Issues:56Issues:24

MailSniper

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.

Language:PowerShellLicense:MITStargazers:2925Issues:98Issues:53

CloudPentestCheatsheets

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

BurpSuite-For-Pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and completely with "BurpSuite".

lazyrecon

This script is intended to automate your reconnaissance process in an organized fashion

Name-That-Hash

🔗 Don't know what type of hash it is? Name That Hash will name that hash type! 🤖 Identify MD5, SHA256 and 300+ other hashes ☄ Comes with a neat web app 🔥

Language:PythonLicense:GPL-3.0Stargazers:1475Issues:16Issues:37

pentest_compilation

Compilation of commands, tips and scripts that helped me throughout Vulnhub, Hackthebox, OSCP and real scenarios

JustTryHarder

JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)

Language:PythonStargazers:792Issues:33Issues:0

Linux-Privilege-Escalation

This cheatsheet is aimed at the OSCP aspirants to help them understand the various methods of Escalating Privilege on Linux based Machines and CTFs with examples.

CVE-2022-29072

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area.

Language:HTMLLicense:GPL-3.0Stargazers:685Issues:26Issues:12

hackthebox

Notes Taken for HTB Machines & InfoSec Community.

Language:PythonLicense:MITStargazers:353Issues:16Issues:0

tryhackme-ctf

TryHackMe CTFs writeups, notes, drafts, scrabbles, files and solutions.

Language:ShellLicense:GPL-3.0Stargazers:217Issues:9Issues:0

Awesome-PenTest-Practice

Hackthebox, Vulnhub, TryHackMe and Real World PenTest

TryHackMe-Write-Up

The entire walkthrough of all my resolved TryHackMe rooms

Language:ShellLicense:GPL-3.0Stargazers:68Issues:4Issues:1
Language:PythonLicense:GPL-3.0Stargazers:44Issues:1Issues:0

Reverse-Shell-Bash-Alias

Generate common Reverse Shells for Pentesting

CTF-Write-Ups-And-Items

A collection of various capture the flag event write-ups and anomalies

Trendr_App

Twitter Trends history explorer app. Trending topics can be explored by date and location. Backend served with Lambda Function (NodeJS) from AWS. Frontend made with VueJS. Twitter API queried with a Python script from Google Colab. MongoDB database.

CTF-ToolsRus

Practise using tools such as dirbuster, hydra, nmap, nikto and metasploit

infosecBasics

Basics required for anyone to enter into the world of InfoSec

pwntools_usage

Description and example of using pwntools

quicklookups

A cheetsheet for things that you might need often

sudo-enumeration-shellcode

This developed shellcode checks whether the sudo running on the operating system has the current public vulnerability.

Language:CLicense:GPL-3.0Stargazers:3Issues:2Issues:0