Skip to content
Change the repository type filter

All

    Repositories list

    • PowerShell collector for adding MSSQL attack paths to BloodHound with OpenGraph
      PowerShell
      10000Updated Jul 30, 2025Jul 30, 2025
    • A collection of scripts for assessing Microsoft Azure security
      PowerShell
      3262.2k41Updated Jul 23, 2025Jul 23, 2025
    • PoC for CVE-2025-4660 demonstrating exploitation of the Forescout SecureConnector on Windows
      Python
      41200Updated Jul 16, 2025Jul 16, 2025
    • set_sail

      Public
      SailPoint IQService - RCE via Default Encryption Key
      Python
      3100Updated Jul 8, 2025Jul 8, 2025
    • 0000Updated Jun 18, 2025Jun 18, 2025
    • gcpwn

      Public
      Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @WebbinRoot
      Python
      2525810Updated May 16, 2025May 16, 2025
    • wopper

      Public
      Automatically upload, execute, and delete a PHP file using Wordpress administrator credentials.
      Shell
      0300Updated Apr 23, 2025Apr 23, 2025
    • 0000Updated Apr 22, 2025Apr 22, 2025
    • BOF-PE

      Public
      An example reference design for a proposed BOF PE
      C++
      1818001Updated Apr 17, 2025Apr 17, 2025
    • PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
      PowerShell
      95853100Updated Apr 5, 2025Apr 5, 2025
    • NetSPi fork of the official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc) using TruffleHog.
      Python
      16000Updated Mar 11, 2025Mar 11, 2025
    • 1000Updated Mar 7, 2025Mar 7, 2025
    • NetSPI PowerShell Scripts
      PowerShell
      10933401Updated Jan 24, 2025Jan 24, 2025
    • AWSSigner

      Public
      Burp Extension for AWS Signing
      Java
      408972Updated Jan 10, 2025Jan 10, 2025
    • bambdas

      Public
      Bambdas collection for Burp Suite Professional and Community.
      Java
      57000Updated Dec 30, 2024Dec 30, 2024
    • HTML
      31500Updated Dec 16, 2024Dec 16, 2024
    • Fuzz 401/403/404 pages for bypasses
      Python
      42400Updated Dec 14, 2024Dec 14, 2024
    • PowerHunt

      Public
      PowerHunt is a modular threat hunting framework written in PowerShell that leverages PowerShell Remoting for data collection on scale.
      PowerShell
      137130Updated Dec 12, 2024Dec 12, 2024
    • PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server
      PowerShell
      4812.6k214Updated Dec 12, 2024Dec 12, 2024
    • FuncoPop

      Public
      Tools for attacking Azure Function Apps
      PowerShell
      118301Updated Oct 29, 2024Oct 29, 2024
    • ZAP Add-ons
      HTML
      733000Updated Oct 22, 2024Oct 22, 2024
    • A collection of ZAP scripts and tips provided by the community - pull requests very welcome!
      JavaScript
      248000Updated Oct 18, 2024Oct 18, 2024
    • zaproxy

      Public
      The ZAP by Checkmarx Core project
      Java
      2.4k000Updated Oct 3, 2024Oct 3, 2024
    • TypeScript
      14000Updated Sep 21, 2024Sep 21, 2024
    • ZAP Python API
      Python
      90000Updated Sep 16, 2024Sep 16, 2024
    • PowerShell module to check if a Windows binary (EXE/DLL) has been compiled with ASLR, DEP, SafeSEH, StrongNaming, and Authenticode.
      PowerShell
      15064961Updated Jul 31, 2024Jul 31, 2024
    • Native Binary for Creating a Scheduled Task
      C++
      2301Updated Jul 25, 2024Jul 25, 2024
    • Wiki theme for various NetSPI wikis
      HTML
      4100Updated May 20, 2024May 20, 2024
    • A wiki focusing on aggregating and documenting various SQL injection methods
      HTML
      14878022Updated May 8, 2024May 8, 2024
    • Automatically run and save ffuf scans for multiple IPs
      Python
      267900Updated Mar 19, 2024Mar 19, 2024