Skip to content
Change the repository type filter

All

    Repositories list

    • efiSeek

      Public
      Ghidra analyzer for UEFI firmware.
      Java
      Apache License 2.0
      36000Updated Apr 27, 2026Apr 27, 2026
    • OCInferno

      Public
      A pentesting tool for enumeration/download/graphical analysis of OCI content. Includes an OpenGraph generator for Bloodhound-style analysis.
      Python
      BSD 3-Clause "New" or "Revised" License
      21400Updated Apr 24, 2026Apr 24, 2026
    • OCISigner

      Public
      A Burp Suite extension to sign OCI HTTP requests using all supported OCI authentication mechanisms including API keys, session tokens, instance principals, & re…
      Java
      BSD 3-Clause "New" or "Revised" License
      0300Updated Apr 24, 2026Apr 24, 2026
    • A utility to convert OCI IAM Policy Statements and Dynamic Group Matching Rules to serialized JSON output.
      Python
      BSD 3-Clause "New" or "Revised" License
      0300Updated Apr 19, 2026Apr 19, 2026
    • Automatically run and save ffuf scans for multiple IPs
      Python
      Other
      268200Updated Apr 9, 2026Apr 9, 2026
    • Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and f…
      Python
      BSD 3-Clause "New" or "Revised" License
      33900Updated Apr 7, 2026Apr 7, 2026
    • Go
      0000Updated Apr 3, 2026Apr 3, 2026
    • A wiki focusing on aggregating and documenting various SQL injection methods
      HTML
      14879423Updated Apr 1, 2026Apr 1, 2026
    • A collection of scripts for assessing Microsoft Azure security
      PowerShell
      BSD 3-Clause "New" or "Revised" License
      3362.4k41Updated Mar 15, 2026Mar 15, 2026
    • Fuzz 401/403/404 pages for bypasses
      Python
      52400Updated Feb 27, 2026Feb 27, 2026
    • NetSPI PowerShell Scripts
      PowerShell
      11034501Updated Feb 10, 2026Feb 10, 2026
    • BOF-PE

      Public
      An example reference design for a proposed BOF PE
      C++
      BSD 3-Clause "New" or "Revised" License
      3120602Updated Jan 23, 2026Jan 23, 2026
    • bambdas

      Public
      Bambdas collection for Burp Suite Professional and Community.
      Java
      GNU Lesser General Public License v3.0
      87001Updated Dec 12, 2025Dec 12, 2025
    • NetSIP

      Public
      NetSIP is a Python-powered SIP repeater that lets you craft, replay, and inspect SIP traffic.
      Python
      GNU General Public License v3.0
      0200Updated Nov 6, 2025Nov 6, 2025
    • FuncoPop

      Public
      Tools for attacking Azure Function Apps
      PowerShell
      Other
      118811Updated Oct 28, 2025Oct 28, 2025
    • PXEThief

      Public
      PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager
      Python
      GNU General Public License v3.0
      69000Updated Oct 28, 2025Oct 28, 2025
    • PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
      PowerShell
      Other
      1091k110Updated Oct 15, 2025Oct 15, 2025
    • A Burp extension for generic extraction and reuse of data within HTTP requests and responses.
      Java
      349883Updated Oct 7, 2025Oct 7, 2025
    • Whois parser for domain whois information parsing in Go(Golang).
      Go
      Apache License 2.0
      102000Updated Sep 25, 2025Sep 25, 2025
    • ATEAM

      Public
      Python
      BSD 3-Clause "New" or "Revised" License
      1514320Updated Sep 9, 2025Sep 9, 2025
    • Snaffler

      Public
      a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
      C#
      GNU General Public License v3.0
      275100Updated Sep 8, 2025Sep 8, 2025
    • Allows testing all egress ports, an updated version of egressbuster
      0000Updated Sep 4, 2025Sep 4, 2025
    • PowerShell collector for adding MSSQL attack paths to BloodHound with OpenGraph
      PowerShell
      GNU General Public License v3.0
      20100Updated Jul 30, 2025Jul 30, 2025
    • PoC for CVE-2025-4660 demonstrating exploitation of the Forescout SecureConnector on Windows
      Python
      BSD 3-Clause "New" or "Revised" License
      41600Updated Jul 16, 2025Jul 16, 2025
    • set_sail

      Public
      SailPoint IQService - RCE via Default Encryption Key
      Python
      Other
      3100Updated Jul 8, 2025Jul 8, 2025
    • 0000Updated Jun 18, 2025Jun 18, 2025
    • gcpwn

      Public
      Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @WebbinRoot
      Python
      BSD 3-Clause "New" or "Revised" License
      2729210Updated May 16, 2025May 16, 2025
    • wopper

      Public
      Automatically upload, execute, and delete a PHP file using Wordpress administrator credentials.
      Shell
      BSD 3-Clause "New" or "Revised" License
      0300Updated Apr 23, 2025Apr 23, 2025
    • 0000Updated Apr 22, 2025Apr 22, 2025
    • NetSPi fork of the official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc) us…
      Python
      19000Updated Mar 11, 2025Mar 11, 2025
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.