Carlos's starred repositories

PoshC2

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Language:PowerShellLicense:BSD-3-ClauseStargazers:1730Issues:0Issues:0

adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Language:CLicense:Apache-2.0Stargazers:1610Issues:0Issues:0

spy-pixel

A spy pixel which can be emedded into web pages or emails.

Language:PythonStargazers:59Issues:0Issues:0

Data-Acquisition-OSINT

You can find links to data acquisition websites.

Stargazers:181Issues:0Issues:0

awesome-web-hacking

A list of web application security

License:MITStargazers:5609Issues:0Issues:0

skyhook

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Language:JavaScriptLicense:MITStargazers:248Issues:0Issues:0

Voidgate

A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfvenom) by performing on-the-fly decryption of individual encrypted assembly instructions, thus rendering memory scanners useless for that specific memory page.

Language:C++License:BSD-3-ClauseStargazers:397Issues:0Issues:0

XnlReveal

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements.

Language:JavaScriptLicense:MITStargazers:290Issues:0Issues:0

toutatis

Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails, phone numbers and more

Language:PythonLicense:GPL-3.0Stargazers:1767Issues:0Issues:0

Security-101

8 Lessons, Kick-start Your Cybersecurity Learning.

License:CC0-1.0Stargazers:3786Issues:0Issues:0

Havoc-C2-SSRF-poc

Havoc C2 0.7 Teamserver SSRF exploit

Language:PythonStargazers:23Issues:0Issues:0

IHxExec

Process injection alternative

Language:C++Stargazers:182Issues:0Issues:0

ADSpider

Monitor changes in Active Directory with replication metadata

Language:PowerShellStargazers:49Issues:0Issues:0

bifrost

Objective-C library and console to interact with Heimdal APIs for macOS Kerberos

Language:Objective-CLicense:BSD-3-ClauseStargazers:133Issues:0Issues:0

RemoteSessionEnum

Remotely Enumerate sessions using undocumented Windows Station APIs

Language:C++License:GPL-3.0Stargazers:25Issues:0Issues:0

incidental

An opensource incident management platform integrating with Slack.

Language:PythonLicense:MITStargazers:416Issues:0Issues:0

collateral-damage

Kernel exploit for Xbox SystemOS using CVE-2024-30088

Language:CLicense:MITStargazers:198Issues:0Issues:0

lemma

Remote CLI tools at your fingertips

Language:PythonLicense:Apache-2.0Stargazers:204Issues:0Issues:0

JScripter

JScripter is a Python script designed to scrape and save unique JavaScript files from a list of URLs or a single URL.

Language:PythonLicense:MITStargazers:14Issues:0Issues:0

theHarvester

E-mails, subdomains and names Harvester - OSINT

Language:PythonStargazers:10756Issues:0Issues:0
Language:YARAStargazers:1185Issues:0Issues:0

ssdeep

Fuzzy hashing API and fuzzy hashing tool

Language:CLicense:GPL-2.0Stargazers:646Issues:0Issues:0

dfir-toolkit

CLI tools for forensic investigation of Windows artifacts

Language:RustLicense:GPL-3.0Stargazers:268Issues:0Issues:0

CVE-2024-4879

CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow

Stargazers:14Issues:0Issues:0

Parth

Heuristic Vulnerable Parameter Scanner

Language:PythonLicense:GPL-3.0Stargazers:540Issues:0Issues:0
Language:PythonLicense:MITStargazers:47Issues:0Issues:0

Red-Team-Infrastructure-Wiki

Wiki to collect Red Team infrastructure hardening resources

License:BSD-3-ClauseStargazers:4020Issues:0Issues:0

blackbox-fuzzing

Fuzzing IoT Devices Using the Router TL-WR902AC as Example

Language:CStargazers:64Issues:0Issues:0
Language:PythonStargazers:1305Issues:0Issues:0