curiousseclady's starred repositories

Photon

Incredibly fast crawler designed for OSINT.

Language:PythonLicense:GPL-3.0Stargazers:10943Issues:323Issues:105

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Mindmap

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them

wafw00f

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Language:PythonLicense:BSD-3-ClauseStargazers:5194Issues:140Issues:98

apkleaks

Scanning APK file for URIs, endpoints & secrets.

Language:PythonLicense:Apache-2.0Stargazers:4874Issues:79Issues:58

afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.

CloudPentestCheatsheets

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

CVE-2024-1086

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.

awesome-exploit-development

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

TeamsPhisher

Send phishing messages and attachments to Microsoft Teams users

InternalAllTheThings

Active Directory and Internal Pentest Cheatsheets

Language:HTMLStargazers:897Issues:10Issues:0

AWS-IAM-Privilege-Escalation

A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.

GraphRunner

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

Language:PowerShellLicense:MITStargazers:859Issues:18Issues:11

nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

secator

secator - the pentester's swiss knife

Language:PythonLicense:NOASSERTIONStargazers:811Issues:11Issues:267

BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition

graphw00f

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

Language:PythonLicense:BSD-3-ClauseStargazers:550Issues:7Issues:16
Language:PythonLicense:MITStargazers:476Issues:9Issues:0

horus

An OSINT / digital forensics tool built in Python

Language:PythonLicense:GPL-3.0Stargazers:318Issues:8Issues:9

terraform-iam-policy-validator

A command line tool that validates AWS IAM Policies in a Terraform template against AWS IAM best practices

Language:PythonLicense:MIT-0Stargazers:296Issues:5Issues:11

RedTeam

This repo offers notes and resources on ethical hacking, covering information gathering, scanning, web hacking, exploitation, and Windows/Linux hacking.

free-API-security-test-action

APIsec|SCAN - Free API security testing using Github actions

Language:PythonStargazers:91Issues:0Issues:3

Practical-Hardware-Pentesting

Practical Hardware Pentesting, published by Packt

Language:CLicense:MITStargazers:64Issues:7Issues:2

pass-station

CLI & library to search for default credentials among thousands of Products / Vendors

Language:RubyLicense:MITStargazers:62Issues:4Issues:5

github-dorks

The repository contains useful GitHub dorks for finding open-source vulnerabilities.

License:MITStargazers:55Issues:3Issues:0

OffensiveCon24-uefi-task-of-the-translator

OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"

Language:AssemblyStargazers:43Issues:2Issues:0

aws-security-checks

AWS Security Checks

security_incidents_from_caching

Collection of incidents resulting from caching issues