Fernando's starred repositories

amass

In-depth attack surface mapping and asset discovery

Language:GoLicense:NOASSERTIONStargazers:11616Issues:210Issues:643

prowler

Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more

Language:PythonLicense:Apache-2.0Stargazers:10366Issues:124Issues:872

wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Language:DockerfileLicense:CC-BY-SA-4.0Stargazers:6976Issues:327Issues:342

ScoutSuite

Multi-Cloud Security Auditing Tool

Language:PythonLicense:GPL-2.0Stargazers:6376Issues:130Issues:862

awesome-shodan-queries

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

lscript

The LAZY script will make your life easier, and of course faster.

Language:ShellLicense:GPL-3.0Stargazers:3994Issues:287Issues:303

pentest-wiki

PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.

Language:PythonLicense:MITStargazers:3387Issues:223Issues:19

phpggc

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

Language:PHPLicense:Apache-2.0Stargazers:3137Issues:63Issues:59

awesome-api-security

A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.

License:GPL-3.0Stargazers:2870Issues:65Issues:0

OSINT

Collections of tools and methods created to aid in OSINT collection

Checklists

Red Teaming & Pentesting checklists for various engagements

Active-Directory-Exploitation-Cheat-Sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Language:PowerShellLicense:MITStargazers:2403Issues:74Issues:2

WebShell

Webshell && Backdoor Collection

Language:PHPLicense:GPL-2.0Stargazers:1773Issues:60Issues:6

Lockdoor-Framework

🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources

Language:PythonLicense:AGPL-3.0Stargazers:1331Issues:62Issues:18

Bug-Bounty-Wordlists

A repository that includes all the important wordlists used while bug hunting.

leaky-paths

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

assessment-mindset

Security Mindmap that could be useful for the infosec community when doing pentest, bug bounty or red-team assessments.

Linux-Privilege-Escalation

This cheatsheet is aimed at the OSCP aspirants to help them understand the various methods of Escalating Privilege on Linux based Machines and CTFs with examples.

CVE-2019-11708

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

Language:JavaScriptLicense:MITStargazers:618Issues:19Issues:1

MARA_Framework

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse engineering and analysis tools to assist in testing mobile applications against the OWASP mobile security threats.

Language:PythonLicense:LGPL-3.0Stargazers:615Issues:46Issues:20

overlord

Overlord - Red Teaming Infrastructure Automation

Language:PythonLicense:MITStargazers:607Issues:24Issues:7

keepnote

Quick and Dirty Penetration Testing Notes

information-security-relatory

Reports from various areas of information security

Books

Free Online Books

Stargazers:140Issues:0Issues:0

securefoundation

Secure components enabling application authentication, secure file storage, app level file-based keychain, and shredding for files on disk

Language:Objective-CLicense:NOASSERTIONStargazers:59Issues:19Issues:12

o365creeper-ng

Python script that performs email address validation against Office 365 without submitting login attempts.

Language:PythonLicense:BSD-2-ClauseStargazers:10Issues:1Issues:0