mdr1337 Goto Github PK
Type: User
Type: User
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time.
A Python based ingestor for BloodHound
CORS Misconfiguration Scanner
A swiss army knife for pentesting networks
Here record some tips about pwn. Something is obsoleted and won't be updated. Sorry about that.
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
Empire is a PowerShell and Python 3.x post-exploitation framework.
Use case-driven examples for using Puppeteer and headless chrome
Collection of python3 exploits written by me to practice exploit development. Also is good preparation for OSED-301 course released by offensive security.
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
Impacket is a collection of Python classes for working with network protocols.
.NET IPv4/IPv6 machine-in-the-middle tool for penetration testers
A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens
A tool to perform Kerberos pre-auth bruteforcing
Tool to audit and attack LAPS environments
OSINT Tool: Generate username lists for companies on LinkedIn
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
Interview questions to screen offensive (red team/pentest) candidates
Rockyou for web fuzzing
bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
PowerSploit - A PowerShell Post-Exploitation Framework
Red Teaming Tactics and Techniques
Responder Windows Version Beta
Trying to tame the three-headed dog.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.