Njsscan : A Semantic Aware SAST Tool That Can Find Insecure Code Patterns In Node.js Applications

4 years ago

Njsscan is a static application testing (SAST) tool that can find insecure code patterns in your node.js applications using simple pattern…

Snaffler : A Tool For Pentesters To Help Find Delicious Candy

4 years ago

Snaffler is a tool for pentesters to help find delicious candy needles (creds mostly, but it's flexible) in a bunch of horrible…

Macrome : Excel Macro Document Reader/Writer For Red Teamers And Analysts

4 years ago

Macrome an Excel Macro Document Reader/Writer for Red Teamers & Analysts. Blog posts describing what this tool actually does can…

FakeLogonScreen : Fake Windows Logon Screen To Steal Passwords

4 years ago

FakeLogonScreen is a utility to fake the Windows logon screen in order to obtain the user's password. The password entered…

Shellcodetester : An Application To Test Windows And Linux Shellcodes

4 years ago

Shellcodetester is a tool that tests generated ShellCodes. Usage Example ShellCode Tester Linux Installation git clone https://github.com/helviojunior/shellcodetester.git cd shellcodetester/Linux make…

Flare-Qdb : Command-line And Python Debugger For Instrumenting And Modifying Native Software

4 years ago

Flare-qdb is a command-line and scriptable Python-based tool for evaluating and manipulating native program state. It uses Vivisect to set a breakpoint…

Autotimeliner : Automagically Extract Forensic Timeline From Volatile Memory Dump

4 years ago

Autotimeliner tool will automagically extract forensic timeline from volatile memory dumps. Requirements Python 3Volatilitymactime (from SleuthKit) (Developed and tested on…

Droopescan : A Plugin-Based Scanner That Aids Security Researchers

4 years ago

Droopescan is a plugin-based scanner that aids security researchers in identifying issues with several CMS. Usage of droopescan for attacking…

Exrop : Automatic ROP Chain Generation

4 years ago

Exrop is automatic ROP chains generator tool which can build gadget chain automatically from given binary and constraints Requirements : Triton, ROPGadget…

truffleHog : Searches Through Git Repositories For High Entropy Strings And Secrets

4 years ago

truffleHog previously functioned by running entropy checks on git diffs. This functionality still exists, but high signal regex checks have…