spooky360's starred repositories

Language:PythonStargazers:7Issues:0Issues:0

EnableWindowsLogSettings

Documentation and scripts to properly enable Windows event logs.

Language:BatchfileLicense:GPL-3.0Stargazers:505Issues:0Issues:0

shflags

shFlags is a port of the Google gflags library for Unix shell.

Language:ShellLicense:Apache-2.0Stargazers:279Issues:0Issues:0

client-side-prototype-pollution

Prototype Pollution and useful Script Gadgets

Stargazers:1342Issues:0Issues:0

DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️

Language:PythonLicense:MITStargazers:5394Issues:0Issues:0

ditto

A tool for IDN homograph attacks and detection.

Language:GoLicense:NOASSERTIONStargazers:716Issues:0Issues:0
Language:SvelteLicense:Apache-2.0Stargazers:641Issues:0Issues:0

Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

Language:JavaScriptLicense:GPL-3.0Stargazers:16674Issues:0Issues:0

huntr

Public Roadmap | huntr.dev

Stargazers:265Issues:0Issues:0

StandardizedImageProcessingTest

A test suite built with Mocha/Chai to test for behavioral differences between image libraries for the web

Language:JavaScriptLicense:Apache-2.0Stargazers:68Issues:0Issues:0

dfir-orc

Forensics artefact collection tool for systems running Microsoft Windows

Language:C++License:LGPL-2.1Stargazers:360Issues:0Issues:0

Commodity-Injection-Signatures

Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT

Language:HTMLLicense:GPL-3.0Stargazers:383Issues:0Issues:0

Wordlist

Wordlists for Bug Bounty

Stargazers:23Issues:0Issues:0

gitGraber

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

Language:PythonLicense:GPL-3.0Stargazers:1958Issues:0Issues:0

Responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

Language:PythonLicense:GPL-3.0Stargazers:4398Issues:0Issues:0

can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Language:PythonLicense:CC-BY-4.0Stargazers:4572Issues:0Issues:0

bruteforce-http-auth

Bruteforce HTTP Authentication

Language:PythonStargazers:135Issues:0Issues:0

jexboss

JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

Language:PythonLicense:NOASSERTIONStargazers:2384Issues:0Issues:0

aquatone

A Tool for Domain Flyovers

Language:GoLicense:MITStargazers:5540Issues:0Issues:0

XSSFuzzer

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Language:HTMLStargazers:1Issues:0Issues:0

Acamar

A Python3 based single-file subdomain enumerator

Language:PythonLicense:MITStargazers:92Issues:0Issues:0

pocorgtfo

a "Proof of Concept or GTFO" mirror with an extensive index with also whole issues or individual articles as clean PDFs.

Language:TeXStargazers:1246Issues:0Issues:0
Language:C#Stargazers:59Issues:0Issues:0

detectionString

list of sql-injection and XSS strings

Stargazers:114Issues:0Issues:0

PenTestScripts

Scripts that are useful for me on pen tests

Language:PythonLicense:GPL-3.0Stargazers:522Issues:0Issues:0

b374k

PHP Webshell with handy features

Language:CSSLicense:MITStargazers:2348Issues:0Issues:0

hackthebox-writeups

Writeups for HacktheBox 'boot2root' machines

License:GPL-3.0Stargazers:1852Issues:0Issues:0
Language:CLicense:AGPL-3.0Stargazers:9258Issues:0Issues:0

XSS-Gif-Payload

A XSS Payload in a gif file

Stargazers:41Issues:0Issues:0