A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Oct 20, 2020 - Python
{{ message }}
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The Swiss Army knife for 802.11, BLE and Ethernet networks reconnaissance and MITM attacks.
Learn ethical hacking.Learn about reconnaissance,windows/linux hacking,attacking web technologies,and pen testing wireless networks.Resources for learning malware analysis and reverse engineering.
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
Curated list of Unix binaries that can be exploited to bypass system security restrictions
List of Awesome Red Teaming Resources
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Collection of quality safety articles
Red Teaming Tactics and Techniques
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Current implementation of proclist plugin uses win32_ps_list_procs() php function on Windows host.
Therefore, linux implementation is a simple system("ps -a"), which is OPSEC unsafe, an would probably trigger EDR alerts.
A better implementation should avoid relying on system command execution.
Venom - A Multi-hop Proxy for Penetration Testers
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
Automation for internal Windows Penetrationtest / AD-Security
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
Utilities for MITRE™ ATT&CK
This is the list of all rootkits found so far on github and other sites.
Snoop — инструмент разведки на основе открытых данных (OSINT world)
Perun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架
Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
mXtract - Memory Extractor & Analyzer
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
Add a description, image, and links to the redteam topic page so that developers can more easily learn about it.
To associate your repository with the redteam topic, visit your repo's landing page and select "manage topics."
Some of the dorks are not that helpful and coul be replaced with more useful stuff.