
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
This repository contains cutting-edge open-source security tools (OST) that will help you during adversary simulation and as information intended for threat hunter can make detection and prevention control easier. The list of tools below that could be potentially misused by threat actors such as APT and Human-Operated Ransomware (HumOR). If you want to contribute to this list send me a pull request.
| Name | Description | URL |
|---|---|---|
| RustScan | The Modern Port Scanner. Find ports quickly (3 seconds at its fastest). Run scripts through our scripting engine (Python, Lua, Shell supported). | https://github.com/RustScan/RustScan |
| Amass | In-depth Attack Surface Mapping and Asset Discovery | https://github.com/OWASP/Amass |
| gitleaks | Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos. | https://github.com/zricethezav/gitleaks |
| S3Scanner | Scan for open S3 buckets and dump the contents | https://github.com/sa7mon/S3Scanner |
| cloud_enum | Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud. | https://github.com/initstring/cloud_enum |
| Recon-ng | Open Source Intelligence gathering tool aimed at reducing the time spent harvesting information from open sources. | https://github.com/lanmaster53/recon-ng |
| buster | An advanced tool for email reconnaissance | https://github.com/sham00n/buster |
| linkedin2username | OSINT Tool: Generate username lists for companies on LinkedIn | https://github.com/initstring/linkedin2username |
| WitnessMe | Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier. | https://github.com/byt3bl33d3r/WitnessMe |
| pagodo | pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching | https://github.com/opsdisk/pagodo |
| AttackSurfaceMapper | AttackSurfaceMapper is a tool that aims to automate the reconnaissance process. | https://github.com/superhedgy/AttackSurfaceMapper |
| SpiderFoot | SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate. | https://github.com/smicallef/spiderfoot |
| dnscan | dnscan is a python wordlist-based DNS subdomain scanner. | https://github.com/rbsec/dnscan |
| spoofcheck | A program that checks if a domain can be spoofed from. The program checks SPF and DMARC records for weak configurations that allow spoofing. | https://github.com/BishopFox/spoofcheck |
| LinkedInt | LinkedIn Recon Tool | https://github.com/vysecurity/LinkedInt |
| BBOT | Recursive internet scanner inspired by Spiderfoot, but designed to be faster, more reliable, and friendlier to pentesters, bug bounty hunters, and developers. | https://github.com/blacklanternsecurity/bbot |
| Gato (Github Attack TOolkit) | Gato, or GitHub Attack Toolkit, is an enumeration and attack tool that allows both blue teamers and offensive security practitioners to identify and exploit pipeline vulnerabilities within a GitHub organization's public and private repositories. | https://github.com/praetorian-inc/gato |
| Name | Description | URL |
|---|---|---|
| SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient | https://github.com/byt3bl33d3r/SprayingToolkit |
| o365recon | Retrieve information via O365 with a valid cred | https://github.com/nyxgeek/o365recon |
| CredMaster | Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling | https://github.com/knavesec/CredMaster |