A.'s starred repositories

sliver

Adversary Emulation Framework

Language:GoLicense:GPL-3.0Stargazers:9054Issues:150Issues:788

testssl.sh

Testing TLS/SSL encryption anywhere on any port

Language:ShellLicense:GPL-2.0Stargazers:8083Issues:180Issues:1154

HowToHunt

Collection of methodology and test case for various web vulnerabilities.

caldera

Automated Adversary Emulation Platform

Language:PythonLicense:Apache-2.0Stargazers:5944Issues:173Issues:810

RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Language:PythonLicense:BSD-3-ClauseStargazers:2433Issues:79Issues:142

vulnerable-AD

Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab

Language:PowerShellLicense:MITStargazers:2087Issues:44Issues:16

pi-pwnbox-rogueap

Homemade Pwnbox :rocket: / Rogue AP :satellite: based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap :bulb:

Language:ShellLicense:GPL-3.0Stargazers:1776Issues:71Issues:10

A-Red-Teamer-diaries

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

malleable-c2

Cobalt Strike Malleable C2 Design and Reference Guide

nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

breaking-and-pwning-apps-and-servers-aws-azure-training

Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!

Language:CSSLicense:MITStargazers:936Issues:48Issues:26

BypassAV

Cobalt Strike插件,用于快速生成免杀的可执行文件

JuicyPotatoNG

Another Windows Local Privilege Escalation from Service Account to System

Language:C++License:MITStargazers:835Issues:12Issues:6

blueteam_homelabs

Great List of Resources to Build an Enterprise Grade Home Lab

spoofcheck

Simple script that checks a domain for email protections

Language:PythonLicense:MITStargazers:784Issues:61Issues:5

Damn-Vulnerable-Bank

Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.

Language:JavaLicense:MITStargazers:679Issues:19Issues:10

Apollo

A .NET Framework 4.0 Windows Agent

Language:C#License:NOASSERTIONStargazers:466Issues:19Issues:38

Invoke-UserSimulator

Simulates common user behaviour on local and remote Windows hosts.

ATP-PowerShell-Scripts

Microsoft Signed PowerShell scripts

HellShell

transform your payload into ipv4/ipv6/mac arrays

Language:CLicense:MITStargazers:169Issues:5Issues:0

domain_audit

Audit tool for Active Directory. Automates a lot of checks from a pentester perspective.

Language:PowerShellLicense:GPL-3.0Stargazers:163Issues:5Issues:1

lazyweb

LazyWeb is a demonstration web application designed to showcase common server-side application vulnerabilities. Each vulnerability is categorized with its respective difficulty rating to provide a comprehensive learning experience for developers and security enthusiasts.

Language:PHPLicense:MITStargazers:117Issues:4Issues:0

ADImporter

Credit to Helge Klein - https://helgeklein.com/blog/2015/02/creating-realistic-test-user-accounts-active-directory/

Language:PowerShellLicense:MITStargazers:69Issues:4Issues:0

CobaltStrikeWindowsDefenderBypass

Windows Defender Bypass for Cobalt Strike v4.0 Powershell Payload

Language:PowerShellStargazers:10Issues:1Issues:0

Lazyxss

LazyXSS is a tool that can help you scan for reflected XSS, LFI without any effort.

Language:PythonLicense:LGPL-2.1Stargazers:8Issues:1Issues:0

sec642_wiki

Template for writing labs in Markdown with emphasis on print and electronic access, style

Language:CSSStargazers:2Issues:1Issues:0

wtf

The personal information dashboard for your terminal

Language:GoLicense:MPL-2.0Stargazers:1Issues:2Issues:0

Vulnerable-OAuth-2.0-Applications

vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.

Language:JavaScriptStargazers:1Issues:1Issues:0