cxosmo's starred repositories

Language:PythonStargazers:3Issues:0Issues:0

wafw00f

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Language:PythonLicense:BSD-3-ClauseStargazers:5048Issues:0Issues:0

CrackQL

CrackQL is a GraphQL password brute-force and fuzzing utility.

Language:PythonLicense:BSD-3-ClauseStargazers:305Issues:0Issues:0

EnterprisePurpleTeaming

Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.

License:MITStargazers:630Issues:0Issues:0

PurpleSharp

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments

Language:C#License:BSD-3-ClauseStargazers:754Issues:0Issues:0

owasp-asvs-checklist

OWASP ASVS checklist for audits

License:MITStargazers:181Issues:0Issues:0

altip

Convert an IP into Alternative / Obfuscated versions of itself

Language:GoLicense:MITStargazers:14Issues:0Issues:0

CS-Situational-Awareness-BOF

Situational Awareness commands implemented using Beacon Object Files

Language:CLicense:GPL-2.0Stargazers:1186Issues:0Issues:0

testssl.sh

Testing TLS/SSL encryption anywhere on any port

Language:ShellLicense:GPL-2.0Stargazers:7777Issues:0Issues:0

rlwrap

A readline wrapper

Language:CLicense:GPL-2.0Stargazers:2465Issues:0Issues:0

Ghostwriter

The SpecterOps project management and reporting engine

Language:PythonLicense:BSD-3-ClauseStargazers:1242Issues:0Issues:0

SSRF-Testing

SSRF (Server Side Request Forgery) testing resources

Language:PythonStargazers:2314Issues:0Issues:0

Search-That-Hash

🔎Searches Hash APIs to crack your hash quickly🔎 If hash is not found, automatically pipes into HashCat⚡

Language:PythonLicense:GPL-3.0Stargazers:1231Issues:0Issues:0

SSTImap

Automatic SSTI detection tool with interactive interface

Language:PythonLicense:GPL-3.0Stargazers:715Issues:0Issues:0

oauth-scan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Language:JavaLicense:GPL-3.0Stargazers:183Issues:0Issues:0
License:MITStargazers:652Issues:0Issues:0

semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Language:OCamlLicense:LGPL-2.1Stargazers:10108Issues:0Issues:0

sslip.io

Golang-based DNS server which maps DNS records with embedded IP addresses to those addresses.

Language:GoLicense:Apache-2.0Stargazers:579Issues:0Issues:0

CrackMapExec

A swiss army knife for pentesting networks

Language:PythonLicense:BSD-2-ClauseStargazers:8265Issues:0Issues:0

clairvoyance

Obtain GraphQL API schema even if the introspection is disabled

Language:PythonLicense:Apache-2.0Stargazers:965Issues:0Issues:0

fuzzuli

fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.

Language:GoLicense:MITStargazers:613Issues:0Issues:0

codeql

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Language:CodeQLLicense:MITStargazers:7360Issues:0Issues:0

flare-floss

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

Language:PythonLicense:Apache-2.0Stargazers:3118Issues:0Issues:0

smuggler

Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3

Language:PythonLicense:MITStargazers:1741Issues:0Issues:0

svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

Stargazers:665Issues:0Issues:0

CeWL

CeWL is a Custom Word List Generator

Language:RubyStargazers:1845Issues:0Issues:0

homoglyph

A big list of homoglyphs and some code to detect them

Language:JavaScriptLicense:MITStargazers:514Issues:0Issues:0

redirect-fuzzer

Fuzzing script for redirect URL validator

Language:PythonStargazers:49Issues:0Issues:0

code-server

VS Code in the browser

Language:TypeScriptLicense:MITStargazers:66691Issues:0Issues:0