rewardone's starred repositories

awesome-zsh-plugins

A collection of ZSH frameworks, plugins, themes and tutorials.

Language:ShellLicense:BSD-3-ClauseStargazers:14576Issues:180Issues:52

docker-bench-security

The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.

Language:ShellLicense:Apache-2.0Stargazers:8935Issues:237Issues:200

Red-Teaming-Toolkit

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

al-khaser

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

Language:C++License:GPL-2.0Stargazers:5560Issues:238Issues:100

weevely3

Weaponized web shell

Language:PythonLicense:GPL-3.0Stargazers:3083Issues:132Issues:134

updog

Updog is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use http basic auth.

Language:PythonLicense:MITStargazers:2839Issues:29Issues:46

onefuzz

A self-hosted Fuzzing-As-A-Service platform

PoshC2

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Language:PowerShellLicense:BSD-3-ClauseStargazers:1700Issues:63Issues:122

EggShell

iOS/macOS/Linux Remote Administration Tool

Language:Objective-CLicense:GPL-2.0Stargazers:1616Issues:113Issues:133

DKMC

DKMC - Dont kill my cat - Malicious payload evasion tool

Language:PythonLicense:NOASSERTIONStargazers:1355Issues:68Issues:36

intrigue-core

Discover Your Attack Surface!

Language:RubyLicense:NOASSERTIONStargazers:1329Issues:76Issues:112

Starkiller

Starkiller is a Frontend for PowerShell Empire.

Language:VueLicense:MITStargazers:1276Issues:36Issues:37

trevorc2

TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.

Language:CLicense:NOASSERTIONStargazers:1180Issues:59Issues:13

eyeballer

Convolutional neural network for analyzing pentest screenshots

Language:PythonLicense:GPL-3.0Stargazers:972Issues:29Issues:48

SharpRDP

Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

Language:C#License:BSD-3-ClauseStargazers:962Issues:33Issues:11

MaliciousMacroGenerator

Malicious Macro Generator

Language:Visual BasicLicense:NOASSERTIONStargazers:816Issues:43Issues:7

Fenrir

Simple Bash IOC Scanner

Language:ShellLicense:MITStargazers:663Issues:39Issues:0

MoveKit

Cobalt Strike kit for Lateral Movement

Language:C#License:GPL-3.0Stargazers:636Issues:18Issues:1

SharpHound2

The Old BloodHound C# Ingestor (Deprecated)

domdig

DOM XSS scanner for Single Page Applications

Language:JavaScriptLicense:GPL-3.0Stargazers:368Issues:11Issues:7
Language:PythonLicense:GPL-3.0Stargazers:332Issues:13Issues:8

SharpCompile

SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing using beacon's 'execute-assembly' in seconds.

Language:C#Stargazers:290Issues:22Issues:0

SharpGen

SharpGen is a .NET Core console application that utilizes the Rosyln C# compiler to quickly cross-compile .NET Framework console applications or libraries.

Language:C#License:BSD-3-ClauseStargazers:287Issues:18Issues:6

SharpShell

SharpShell is a proof-of-concept offensive C# scripting engine that utilizes the Rosyln C# compiler to quickly cross-compile .NET Framework console applications or libraries.

Language:C#License:BSD-3-ClauseStargazers:124Issues:8Issues:0

AMSI_Handler

Automate AV evasion by calling AMSI

Language:C#Stargazers:84Issues:8Issues:0

Detect-SSLmitm

This PowerShell script will determine if your connection to external servers over HTTPS is being decrypted by an intercepting proxy such as the internet proxies commonly found in corporate environments. It does this by comparing the SSL intermediate certificate being used for your connection to the true/known SSL certificate for the server.

Language:PowerShellStargazers:68Issues:8Issues:0

batten

Hardening and Auditing Tool For Docker Hosts & Containers

Language:GoLicense:MITStargazers:68Issues:8Issues:4

changeling

Change up a binary's embedded resources with this little creature.

Language:C#License:GPL-3.0Stargazers:32Issues:4Issues:0

Blowhole

Docker auditing and enumeration script.

Language:PythonStargazers:22Issues:3Issues:0