Skip to content
Change the repository type filter

All

    Repositories list

    • OCInferno

      Public
      A pentesting tool for enumeration/download/graphical analysis of OCI content. Includes an OpenGraph generator for Bloodhound-style analysis.
      Python
      BSD 3-Clause "New" or "Revised" License
      21400Updated Apr 24, 2026Apr 24, 2026
    • OCISigner

      Public
      A Burp Suite extension to sign OCI HTTP requests using all supported OCI authentication mechanisms including API keys, session tokens, instance principals, & re…
      Java
      BSD 3-Clause "New" or "Revised" License
      0300Updated Apr 24, 2026Apr 24, 2026
    • A utility to convert OCI IAM Policy Statements and Dynamic Group Matching Rules to serialized JSON output.
      Python
      BSD 3-Clause "New" or "Revised" License
      0300Updated Apr 19, 2026Apr 19, 2026
    • Automatically run and save ffuf scans for multiple IPs
      Python
      Other
      268200Updated Apr 9, 2026Apr 9, 2026
    • Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and f…
      Python
      BSD 3-Clause "New" or "Revised" License
      33900Updated Apr 7, 2026Apr 7, 2026
    • Go
      0000Updated Apr 3, 2026Apr 3, 2026
    • A wiki focusing on aggregating and documenting various SQL injection methods
      HTML
      14879423Updated Apr 1, 2026Apr 1, 2026
    • A collection of scripts for assessing Microsoft Azure security
      PowerShell
      BSD 3-Clause "New" or "Revised" License
      3372.4k41Updated Mar 15, 2026Mar 15, 2026
    • Fuzz 401/403/404 pages for bypasses
      Python
      52400Updated Feb 27, 2026Feb 27, 2026
    • NetSPI PowerShell Scripts
      PowerShell
      11034501Updated Feb 10, 2026Feb 10, 2026
    • BOF-PE

      Public
      An example reference design for a proposed BOF PE
      C++
      BSD 3-Clause "New" or "Revised" License
      3120602Updated Jan 23, 2026Jan 23, 2026
    • bambdas

      Public
      Bambdas collection for Burp Suite Professional and Community.
      Java
      GNU Lesser General Public License v3.0
      87001Updated Dec 12, 2025Dec 12, 2025
    • NetSIP

      Public
      NetSIP is a Python-powered SIP repeater that lets you craft, replay, and inspect SIP traffic.
      Python
      GNU General Public License v3.0
      0200Updated Nov 6, 2025Nov 6, 2025
    • FuncoPop

      Public
      Tools for attacking Azure Function Apps
      PowerShell
      Other
      118811Updated Oct 28, 2025Oct 28, 2025
    • PXEThief

      Public
      PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager
      Python
      GNU General Public License v3.0
      69000Updated Oct 28, 2025Oct 28, 2025
    • PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
      PowerShell
      Other
      1091k110Updated Oct 15, 2025Oct 15, 2025
    • A Burp extension for generic extraction and reuse of data within HTTP requests and responses.
      Java
      349883Updated Oct 7, 2025Oct 7, 2025
    • Whois parser for domain whois information parsing in Go(Golang).
      Go
      Apache License 2.0
      102000Updated Sep 25, 2025Sep 25, 2025
    • ATEAM

      Public
      Python
      BSD 3-Clause "New" or "Revised" License
      1514220Updated Sep 9, 2025Sep 9, 2025
    • Snaffler

      Public
      a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
      C#
      GNU General Public License v3.0
      275100Updated Sep 8, 2025Sep 8, 2025
    • Allows testing all egress ports, an updated version of egressbuster
      0000Updated Sep 4, 2025Sep 4, 2025
    • PowerShell collector for adding MSSQL attack paths to BloodHound with OpenGraph
      PowerShell
      GNU General Public License v3.0
      19100Updated Jul 30, 2025Jul 30, 2025
    • PoC for CVE-2025-4660 demonstrating exploitation of the Forescout SecureConnector on Windows
      Python
      BSD 3-Clause "New" or "Revised" License
      41600Updated Jul 16, 2025Jul 16, 2025
    • set_sail

      Public
      SailPoint IQService - RCE via Default Encryption Key
      Python
      Other
      3100Updated Jul 8, 2025Jul 8, 2025
    • 0000Updated Jun 18, 2025Jun 18, 2025
    • gcpwn

      Public
      Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @WebbinRoot
      Python
      BSD 3-Clause "New" or "Revised" License
      2729210Updated May 16, 2025May 16, 2025
    • wopper

      Public
      Automatically upload, execute, and delete a PHP file using Wordpress administrator credentials.
      Shell
      BSD 3-Clause "New" or "Revised" License
      0300Updated Apr 23, 2025Apr 23, 2025
    • 0000Updated Apr 22, 2025Apr 22, 2025
    • NetSPi fork of the official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc) us…
      Python
      19000Updated Mar 11, 2025Mar 11, 2025
    • 1000Updated Mar 7, 2025Mar 7, 2025
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.