Skip to content

All

    Repositories list

    • OCInferno

      Public
      A pentesting tool for enumeration/download/graphical analysis of OCI content. Includes an OpenGraph generator for Bloodhound-style analysis.
      Python
      BSD 3-Clause "New" or "Revised" License
      22212Updated Sep 3, 2026Sep 3, 2026
    • OCISigner

      Public
      A Burp Suite extension to sign OCI HTTP requests using all supported OCI authentication mechanisms including API keys, session tokens, instance principals, & re…
      Java
      BSD 3-Clause "New" or "Revised" License
      0601Updated Sep 1, 2026Sep 1, 2026
    • The Java Burp Extension version of @intrudir's BypassFuzzer tool
      Java
      MIT License
      4100Updated Aug 28, 2026Aug 28, 2026
    • gcpwn

      Public
      Pentesting framework for GCP & Google Workspace that enumerates/downloads data that feeds into a BloodHound Opengraph model. Includes credential management, wor…
      Python
      BSD 3-Clause "New" or "Revised" License
      2930903Updated Aug 28, 2026Aug 28, 2026
    • BOFscale

      Public
      A collection of BOF-PE's that allow running tailscale from memory
      Go
      BSD 3-Clause "New" or "Revised" License
      1813211Updated Aug 27, 2026Aug 27, 2026
    • A utility to convert OCI IAM Policy Statements and Dynamic Group Matching Rules to serialized JSON output.
      Python
      BSD 3-Clause "New" or "Revised" License
      0300Updated Aug 12, 2026Aug 12, 2026
    • Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
      Python
      BSD 3-Clause "New" or "Revised" License
      2019910Updated Aug 9, 2026Aug 9, 2026
    • Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and f…
      Python
      BSD 3-Clause "New" or "Revised" License
      34801Updated Jul 30, 2026Jul 30, 2026
    • A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a process as possible
      Shell
      44000Updated Jul 23, 2026Jul 23, 2026
    • confused

      Public
      Tool to check for dependency confusion vulnerabilities in multiple package management systems
      Go
      MIT License
      109100Updated Jul 8, 2026Jul 8, 2026
    • A collection of scripts for assessing Microsoft Azure security
      PowerShell
      BSD 3-Clause "New" or "Revised" License
      3402.4k32Updated Jun 29, 2026Jun 29, 2026
    • This is a wiki for Azure pentesting techniques. Powered by Zensical and GitHub Pages
      HTML
      BSD 3-Clause "New" or "Revised" License
      0200Updated Jun 23, 2026Jun 23, 2026
    • Used for testing NetSPI Platform MCP. Can be deleted after July 2026.
      TypeScript
      MIT License
      19k004Updated Jun 21, 2026Jun 21, 2026
    • Automatically run and save ffuf scans for multiple IPs
      Python
      Other
      268200Updated Jun 5, 2026Jun 5, 2026
    • Demonstrating UEFI emulation techniques for identifying security vulnerabilities in extracted firmware binaries.
      Python
      0000Updated May 20, 2026May 20, 2026
    • efiSeek

      Public
      Ghidra analyzer for UEFI firmware.
      Java
      Apache License 2.0
      40000Updated Apr 27, 2026Apr 27, 2026
    • Go
      0000Updated Apr 3, 2026Apr 3, 2026
    • A wiki focusing on aggregating and documenting various SQL injection methods
      HTML
      14880023Updated Apr 1, 2026Apr 1, 2026
    • NetSPI PowerShell Scripts
      PowerShell
      10734401Updated Feb 10, 2026Feb 10, 2026
    • BOF-PE

      Public
      An example reference design for a proposed BOF PE
      C++
      BSD 3-Clause "New" or "Revised" License
      3424502Updated Jan 23, 2026Jan 23, 2026
    • bambdas

      Public
      Bambdas collection for Burp Suite Professional and Community.
      Java
      GNU Lesser General Public License v3.0
      86001Updated Dec 12, 2025Dec 12, 2025
    • NetSIP

      Public
      NetSIP is a Python-powered SIP repeater that lets you craft, replay, and inspect SIP traffic.
      Python
      GNU General Public License v3.0
      0200Updated Nov 6, 2025Nov 6, 2025
    • FuncoPop

      Public
      Tools for attacking Azure Function Apps
      PowerShell
      Other
      118911Updated Oct 28, 2025Oct 28, 2025
    • PXEThief

      Public
      PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager
      Python
      GNU General Public License v3.0
      71000Updated Oct 28, 2025Oct 28, 2025
    • PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
      PowerShell
      Other
      1181.1k130Updated Oct 15, 2025Oct 15, 2025
    • A Burp extension for generic extraction and reuse of data within HTTP requests and responses.
      Java
      3410083Updated Oct 7, 2025Oct 7, 2025
    • Whois parser for domain whois information parsing in Go(Golang).
      Go
      Apache License 2.0
      105000Updated Sep 25, 2025Sep 25, 2025
    • ATEAM

      Public
      Python
      BSD 3-Clause "New" or "Revised" License
      1514921Updated Sep 9, 2025Sep 9, 2025
    • Snaffler

      Public
      a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
      C#
      GNU General Public License v3.0
      285100Updated Sep 8, 2025Sep 8, 2025
    • Allows testing all egress ports, an updated version of egressbuster
      0000Updated Sep 4, 2025Sep 4, 2025
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.