A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Aug 11, 2021 - Python
{{ message }}
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The Swiss Army knife for 802.11, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks.
Learn ethical hacking.Learn about reconnaissance,windows/linux hacking,attacking web technologies,and pen testing wireless networks.Resources for learning malware analysis and reverse engineering.
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
List of Awesome Red Teaming Resources
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Red Teaming Tactics and Techniques
个人维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Automation for internal Windows Penetrationtest / AD-Security
cobaltstrike的相关资源汇总 / List of Awesome CobaltStrike Resources
Collection of quality safety articles. Awesome articles.
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Current implementation of proclist plugin uses win32_ps_list_procs() php function on Windows host.
Therefore, linux implementation is a simple system("ps -a"), which is OPSEC unsafe, an would probably trigger EDR alerts.
A better implementation should avoid relying on system command execution.
Venom - A Multi-hop Proxy for Penetration Testers
Viper (炫彩蛇) 开源图形化内网渗透工具
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
Snoop — инструмент разведки на основе открытых данных (OSINT world)
CyberSecurityRSS: 优秀的网络安全知识来源 / A collection of cybersecurity rss to make you better!
记录自己编写、修改的部分工具
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
Utilities for MITRE™ ATT&CK
Add a description, image, and links to the redteam topic page so that developers can more easily learn about it.
To associate your repository with the redteam topic, visit your repo's landing page and select "manage topics."
Some of the dorks are not that helpful and coul be replaced with more useful stuff.