m14r41 / PentestingEverything

Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Table of Contents

No. DevSecOps Aspect No. Directory Name
1 Web Application Security 09 Active Directory Security
2 API Security 10 Infrastructure Security
3 Mobile Application Security 11 Threat Modeling
4 Thick Client Application Security 12 IoT Security
5 Source Code Review 13 OSINT (Open Source Intelligence)
6 Network Security 14 Blockchain Security
7 Wi-Fi Security 15 CI/CD Pipeline Security
8 Cloud Security 16 Docker Container Security
9 DevSecOps

No. DevSecOps Aspect Description
1 Web Application Security Assess and secure web applications for vulnerabilities.
2 API Security Test and enhance the security of APIs and microservices.
3 Mobile Application Security Evaluate the security of mobile apps and devices.
4 Thick Client Application Security Assess thick client applications for security issues.
5 Source Code Review Analyze source code to identify and rectify vulnerabilities.
6 Network Security Secure networks by identifying and addressing weaknesses.
7 Wi-Fi Network Security Evaluate the security of Wi-Fi networks and access points.
8 Cloud Security Assess the security of cloud-based systems and services.
9 Active Directory Security Evaluate the security of Active Directory environments.
10 Infrastructure Security Secure the underlying IT infrastructure and assets.
11 Threat Modeling Model and assess threats to enhance system security.
12 IoT Security Identify and mitigate vulnerabilities in IoT devices.
13 OSINT (Open Source Intelligence) Gather intelligence from open sources for security analysis.
14 Blockchain Security Assess blockchain systems for security and compliance.
15 CI/CD Pipeline Security Evaluate the security of continuous integration pipelines.
16 Docker Container Security Secure Docker containers and containerized applications.
17 DevSecOps Integrate security practices throughout the DevOps lifecycle.

πŸ›‘οΈ Pentesting & Tools πŸ›‘οΈ

Category Tools
Web App Pentesting Burp Suite Pro 🌐, OWASP ZAP 🌐, Nmap 🌐, Nikto 🌐, Acunetix, HCL-AppScan 🌐, Wfuzz 🌐, SQLMap 🌐, Amass 🌐, NetSparker 🌐, Fortify-WebInspect 🌐
Mobile App Pentesting Android::
MobSF πŸ“±, Frida πŸ“±, APKTool πŸ“±, JADX πŸ“±, AndroidStudio/Genymotion πŸ“±, Drozer πŸ“±, Magisk Root πŸ“±, APKX πŸ“±, mitmproxy πŸ“±, Objection πŸ“±, adb πŸ“±
iOS::
MobSF πŸ“±, Frida πŸ“±, Objection πŸ“±, Cycript πŸ“±, iOS Hook πŸ“±, Needle πŸ“±, Class-dump πŸ“±, Burp Suite Mobile Assistant πŸ“±, SSL Kill Switch 2 πŸ“±, iMazing πŸ“±
API Pentesting Postman πŸ“‘, Insomnia πŸ“‘, Burp Suite Pro πŸ“‘, OWASP Amass πŸ“‘, 42Crunch API Security πŸ“‘, Swagger Inspector πŸ“‘, Kite Runner πŸ“‘, SecApps Intercept πŸ“‘
Secure Code Review SonarQube πŸ”, Snyk πŸ“‘,Semgrep πŸ”, Checkmarx πŸ”, Veracode πŸ”, Fortify-WorkbencAudit πŸ”, CodeQL πŸ”, Bandit πŸ”, FindSecBugs πŸ”, Gitleaks πŸ”
Thick Client Pentesting Fiddler πŸ’», Burp Suite Pro πŸ’», dnSpy πŸ’», IDA Pro πŸ’», Ghidra πŸ’», Process Explorer πŸ’», CFF Explorer πŸ’», OllyDbg πŸ’», x64dbg πŸ’», Wireshark πŸ’»
Network Pentesting Nmap 🌐, Wireshark 🌐, Metasploit Framework 🌐, Nessus 🌐, OpenVAS 🌐, Responder 🌐, CrackMapExec 🌐, BloodHound 🌐, Netcat 🌐, Bettercap 🌐
Cloud Security Prowler ☁️, ScoutSuite ☁️, CloudSploit ☁️, Pacu ☁️, Steampipe ☁️, CloudMapper ☁️, NCC Group Scout ☁️, kube-bench ☁️
Container Security Trivy 🐳, Aqua Microscanner 🐳, Clair 🐳, Anchore 🐳, Docker Bench 🐳, kube-hunter 🐳, Falco 🐳, Sysdig 🐳, Snyk 🐳

πŸ‘¨β€πŸ’»πŸ‘©β€πŸ’» Contributors βœ¨πŸ‘¨β€πŸ’»πŸ‘©β€πŸ’»

I appreciate your interest in contributing! please read Contribution Guidelines.

A heartfelt thank you to these amazing individuals for their contributions to this project. You can view emoji key to see the various ways you can contribute!

Marko Živanović
Marko Živanović

πŸ”§
Madhurendra kumar
Madhurendra kumar

πŸ’»
0xanon
0xanon

πŸ’»
InfoBugs
InfoBugs

πŸ’»
Ratnesh kumar
Ratnesh kumar

πŸ’»
Chandrabhushan Kumar
Chandrabhushan Kumar

πŸ’»

Star History

Star History Chart


Support:

m14r41

About

Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...

License:MIT License


Languages

Language:JavaScript 100.0%