sec-js
- Dallas texas
Highlights
- Pro
Pentest
Small and highly portable detection tests based on MITRE's ATT&CK.
Collection of commands, tips and tricks and references I found useful during preparation for OSCP exam.
Experimental tool for Windows. PentestBro combines subdomain scans, whois, port scanning, banner grabbing and web enumeration into one tool. Uses subdomain list of SecLists. Uses nmap service probe...
Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation
Red Teaming Tactics and Techniques
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments...
C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.
Covenant is a collaborative .NET C2 framework for red teamers.
Scripts featured in the book How to Hack Like a Legend
Tools and Techniques for Red Team / Penetration Testing
OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team exercises.
A collection of awesome one-liner scripts especially for bug bounty tips.
LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping
Nimbo-C2 is yet another (simple and lightweight) C2 framework
HTML smuggling is not an evil, it can be useful
Use HTTP Smuggling Lab to learn HTTP Smuggling.
A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! π»
Awesome information for WebSockets security research
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
Attack Surface Analyzer can help you analyze your operating system's security configuration for changes during software installation.
Automated penetration testing & attack surface management platform. Recon, scan, exploit, report β 600+ exploits, 90+ integrations, 10K+ detections.
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters