threlfall's starred repositories

GitGot

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Language:PythonLicense:LGPL-3.0Stargazers:1416Issues:0Issues:0

o365-attack-toolkit

A toolkit to attack Office365

Language:GoStargazers:1022Issues:0Issues:0

magic-wormhole

get things from one computer to another, safely

Language:PythonLicense:MITStargazers:18553Issues:0Issues:0

dtd-finder

List DTDs and generate XXE payloads using those local DTDs.

Language:KotlinStargazers:599Issues:0Issues:0

honeybits

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward your honeypots

Language:GoLicense:GPL-3.0Stargazers:272Issues:0Issues:0

render

easily manage HTTP request / response payloads of Go HTTP services

Language:GoLicense:MITStargazers:286Issues:0Issues:0
Language:JavaStargazers:71Issues:0Issues:0

the-art-of-subdomain-enumeration

This repository contains all the supplement material for the book "The art of sub-domain enumeration"

Language:PythonStargazers:633Issues:0Issues:0

femida

Automated blind-xss search for Burp Suite

Language:PythonLicense:MITStargazers:275Issues:0Issues:0

DeTTECT

Detect Tactics, Techniques & Combat Threats

Language:SCSSLicense:GPL-3.0Stargazers:2028Issues:0Issues:0

CollabOzark

CollabOzark is a simple tool which helps the researchers track SSRF, RCE, Blind XSS, XXE, External Resource Access payloads triggers.

Language:PHPStargazers:136Issues:0Issues:0

chw00t

chw00t - Unices chroot breaking tool

Language:CStargazers:550Issues:0Issues:0

barq

barq: The AWS Cloud Post Exploitation framework!

Language:PythonLicense:MITStargazers:384Issues:0Issues:0

Jenkins-Pillage

A tool for automatically gathering sensitive information from exposed Jenkins servers

Language:PythonLicense:MITStargazers:103Issues:0Issues:0

blackboxprotobuf

Blackbox Protobuf is a set of tools for working with encoded Protocol Buffers (protobuf) without the matching protobuf definition.

Language:PythonLicense:MITStargazers:497Issues:0Issues:0

SAP_GW_RCE_exploit

SAP Gateway RCE exploits

Language:PythonLicense:GPL-2.0Stargazers:150Issues:0Issues:0

WeblogicScan

Weblogic一键漏洞检测工具,V1.5,更新时间:20200730

Language:PythonLicense:MITStargazers:2150Issues:0Issues:0

CVE-2019-2618

Weblogic Unrestricted File Upload

Stargazers:52Issues:0Issues:0

hacks

A collection of hacks and one-off scripts

Language:GoStargazers:2111Issues:0Issues:0

ActiveScanPlusPlus

ActiveScan++ Burp Suite Plugin

Language:PythonLicense:Apache-2.0Stargazers:580Issues:0Issues:0

J2EEScan

J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.

Language:JavaLicense:GPL-2.0Stargazers:640Issues:0Issues:0

SSRF-Testing

SSRF (Server Side Request Forgery) testing resources

Language:PythonStargazers:2327Issues:0Issues:0

CRLF-Injection-Payloads

Payloads for CRLF Injection

Stargazers:207Issues:0Issues:0

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Language:PHPLicense:MITStargazers:136Issues:0Issues:0

GCPBucketBrute

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

Language:PythonLicense:BSD-3-ClauseStargazers:473Issues:0Issues:0

Awesome-WAF

🔥 Web-application firewalls (WAFs) from security standpoint.

Language:PythonLicense:Apache-2.0Stargazers:6129Issues:0Issues:0

Paper

Web Security Technology & Vulnerability Analysis Whitepapers

Stargazers:534Issues:0Issues:0

IntruderPayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

Language:BlitzBasicStargazers:3607Issues:0Issues:0

oxml_xxe

A tool for embedding XXE/XML exploits into different filetypes

Language:RubyStargazers:1025Issues:0Issues:0

DNSlivery

Easy files and payloads delivery over DNS

Language:PythonLicense:MITStargazers:409Issues:0Issues:0