R.'s starred repositories

How-To-Secure-A-Linux-Server

An evolving how-to guide for securing a Linux server.

semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Language:OCamlLicense:LGPL-2.1Stargazers:10109Issues:103Issues:2916

httpx

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

Language:PythonLicense:MITStargazers:3933Issues:369Issues:32

axiom

The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!

Language:ShellLicense:MITStargazers:3929Issues:89Issues:422

gau

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Language:GoLicense:MITStargazers:3749Issues:48Issues:98

dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

BruteShark

Network Analysis Tool

Language:C#License:GPL-3.0Stargazers:2959Issues:97Issues:67

RE-iOS-Apps

A completely free, open source and online course about Reverse Engineering iOS Applications.

Stowaway

👻Stowaway -- Multi-hop Proxy Tool for pentesters

Language:GoLicense:MITStargazers:2513Issues:38Issues:54

DefenderCheck

Identifies the bytes that Microsoft Defender flags on.

Language:C#License:BSD-3-ClauseStargazers:2214Issues:43Issues:18
Language:PythonLicense:Apache-2.0Stargazers:2122Issues:150Issues:38

dnsx

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

shad0w

A post exploitation framework designed to operate covertly on heavily monitored environments

Awesome-Asset-Discovery

List of Awesome Asset Discovery Resources

C3

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.

Language:C++License:NOASSERTIONStargazers:1483Issues:50Issues:23

pwndb

Search for leaked credentials

Language:PythonLicense:MITStargazers:1266Issues:64Issues:39

red-team-scripts

A collection of Red Team focused tools, scripts, and notes

Language:PowerShellLicense:BSD-3-ClauseStargazers:1104Issues:53Issues:1

TREVORspray

TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

Language:PythonLicense:GPL-3.0Stargazers:993Issues:17Issues:28

Damn_Vulnerable_C_Program

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Belati

The Traditional Swiss Army Knife for OSINT

Language:PythonLicense:GPL-2.0Stargazers:524Issues:39Issues:29

commonspeak2-wordlists

Wordlists that have been compiled using Commonspeak2. This repo is updated every time new wordlists are generated.

License:Apache-2.0Stargazers:509Issues:24Issues:0

LiveTargetsFinder

Generates lists of live hosts and URLs for targeting, automating the usage of MassDNS, Masscan and nmap to filter out unreachable hosts and gather service information

DNSCewl

A DNS Bruteforcing Wordlist Generator

Language:C++License:GPL-3.0Stargazers:343Issues:10Issues:8

APT06202001

Applied Purple Teaming - (ITOCI4hr) - Infrastructure, Threat Optics, and Continuous Improvement - June 6, 2020

o365creeper

Python script that performs email address validation against Office 365 without submitting login attempts.

Language:PythonLicense:BSD-2-ClauseStargazers:313Issues:6Issues:1

pasties

A collection of random bits of information common to many individual penetration tests, red teams, and other assessments

Language:ShellStargazers:107Issues:9Issues:0
Language:PythonStargazers:32Issues:2Issues:0

rengine

reNgine is an automated reconnaissance framework meant for gathering information during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information.

Language:JavaScriptLicense:GPL-3.0Stargazers:17Issues:3Issues:0