Ismael Gonçalves's repositories

smbclient_cheatsheet

Useful commands/tricks using smbclient/nmap in a pentesting/auditing/redteaming

awesome-security-articles

This repository contains links to awesome security articles.

ms17-010

This contains a bundle with an executable to exploit ms17-010 remote or locally. It does not require Python.

Language:PythonStargazers:14Issues:0Issues:0

f5-waf-enforce-sig-Spring4Shell

This enforces F5 WAF signatures for Spring4Shell and Spring Cloud vulnerabilities across all policies on a BIG-IP ASM device

Language:PythonStargazers:8Issues:1Issues:0

f5-waf-enforce-sig-CVE-2021-44228

This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device

gcp_security

Google Cloud Platform Security

Language:ShellStargazers:7Issues:1Issues:0

jwtbf

Simple script to brute force JWT token signature

Language:PythonStargazers:7Issues:0Issues:0

slowdos_detector

slowdos_detector is Python tool to detect Slow HTTP DoS Attack (GET and POST) on pcap files.

Language:PythonStargazers:5Issues:0Issues:1

aws-signing-for-owasp-zap

A ZAP Help Add-On Script for signing requests to AWS

f5-waf-quick-patch-cve-2021-44228

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

Language:PythonStargazers:3Issues:1Issues:0

make-htdigest

This simple tool creates username/password combination for HTTP Digest Authentication. It can be used for password lookup during password auditing/assessment/pen-testing for WildFly / JBoss / Apache.

Language:PythonLicense:Apache-2.0Stargazers:3Issues:0Issues:0

Awesome-WAF

🔥 Everything awesome about web-application firewalls (WAF).

Language:PythonLicense:Apache-2.0Stargazers:2Issues:1Issues:0

barracuda-user-enum-exploit

Barracuda Platform (NGFW and ADC) brute force user enum using side channel

Language:PythonStargazers:1Issues:0Issues:0

bugbounty-scans

aquatone results for sites with bug bountys

Stargazers:1Issues:0Issues:0

community-scripts

A collection of ZAP scripts provided by the community - pull requests very welcome!

Language:JavaScriptStargazers:1Issues:0Issues:0

container-security-checklist

Checklist for container security - devsecops practices

License:Apache-2.0Stargazers:1Issues:0Issues:0

cryptonice

CryptoNice is both a command line tool and library which provides the ability to scan and report on the configuration of SSL/TLS for your internet or internal facing web services. Built using the sslyze API and ssl, http-client and dns libraries, cryptonice collects data on a given domain and performs a series of tests to check TLS configuration and supporting protocols such as HTTP2 and DNS.

Language:PythonLicense:GPL-3.0Stargazers:1Issues:0Issues:0

f5-distributed-cloud-labs-101

Introduction to Volterra lab environment

Language:HCLLicense:Apache-2.0Stargazers:1Issues:0Issues:0

f5-waf-quick-view

F5 Adv. WAF/ASM policies quick view.

Language:PythonLicense:Apache-2.0Stargazers:1Issues:1Issues:0

f5-waf-tester

Web Application Firewall Security Testing Tool

Language:PythonLicense:Apache-2.0Stargazers:1Issues:0Issues:0

f5_terraform

Terraform deployments for BIG-IP in public cloud environments (AWS, Azure, Google). F5 Automation Toolchain is used for easier device and app configuration.

Language:HCLStargazers:1Issues:0Issues:0

open-source-web-scanners

A list of open source web security scanners

License:Apache-2.0Stargazers:1Issues:0Issues:0

search

Search is a simple text search to look for various words within files on a give folder.

Language:PythonStargazers:1Issues:1Issues:0

tempo

Username Enumeration tool using Side-Channel (Timing) over HTTP

Language:PythonLicense:Apache-2.0Stargazers:1Issues:0Issues:0

terraform-gcp-bigip-module

Terraform module for Deploying BIG-IP in GCP

Language:HCLLicense:Apache-2.0Stargazers:1Issues:0Issues:0

wstg

The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.

Language:ShellLicense:CC-BY-SA-4.0Stargazers:1Issues:0Issues:0