Pinecone : A WLAN Red Team Framework
Pinecone is a WLAN networks auditing tool, suitable for red team usage. It is extensible via modules, and it is designed to be run...
Koh : The Token Stealer
Koh is a C# and Beacon Object File (BOF) toolset that allows for the capture of user credential material via purposeful token/logon session leakage.
Some...
Zenbuster : Multi-threaded URL Enumeration/Brute-Forcing Tool
ZenBuster is a multi-threaded, multi-platform URL enumeration tool written in Python by Zach Griffin (@0xTas).
I wrote this tool as a way to deepen my familiarity...
Kubeaudit : Tool To Audit Your Kubernetes Clusters Against Common Security Controls
Kubeaudit no longer supports APIs deprecated as of Kubernetes v.1.16 release. So, it is now a requirement for clusters to run Kubernetes >=1.16
kubeaudit is a command...
Dumpscan : Tool To Extract And Dump Secrets From Kernel And Windows Minidump Formats
Dumpscan is a command-line tool designed to extract and dump secrets from kernel and Windows Minidump formats. Kernel-dump parsing is provided by volatility3.
Features
x509 Public and Private...
Trufflehog : Find Credentials All Over The Place
TruffleHog v3 is a complete rewrite in Go with many new powerful features.
We've added over 700 credential detectors that support active verification against their respective...
Bypass-Url-Parser : Tool That Tests Many URL Bypasses To Reach A 40X Protected Page
Bypass-Url-Parser is a Tool that tests MANY url bypasses to reach a 40X protected page.
If you wonder why this code is nothing but a dirty curl wrapper, here's...
WebView2-Cookie-Stealer : Attacking With WebView2 Applications
WebView2-Cookie-Stealer, According to Microsoft, “Microsoft Edge WebView2 control allows you to embed web technologies (HTML, CSS, and JavaScript) in your native apps”. Essentially, WebView2...
Tofu : Windows Offline Filesystem Hacking Tool For Linux
Tofu is a modular tool for hacking offline Windows filesystems and bypassing login screens. Can do hashdumps, OSK-Backdoors, user enumeration and more.
How It Works...
Frostbyte : FrostByte Is A POC Project That Combines Different Defense Evasion Techniques
FrostByte Is A POC Project That Combines Different Defense Evasion Techniques. In the past few days I've been experimenting with the AppDomain manager injection technique had...