
recon-skills
Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

Cloud pentesting framework deploying vulnerable-by-demand AWS resources with quest-based scenarios to teach practical penetration testing and…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

A collection of awesome penetration testing resources and tools

Directory/File, DNS and VHost busting tool written in Go

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

A fast enumeration tool for publicly exposed Azure Storage blobs.

A list of awesome penetration testing tools and resources.

Modular penetration testing framework with a Metasploit-like interactive shell, pre-built CVE exploit modules, and cloud/network reconnaissance…

Read-only AWS service enumerator with 600+ API calls for cloud reconnaissance, info dumping, and result analysis during penetration testing.

A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.

Gorsair gives root access on remote docker containers that expose their APIs

A fork of the great TokenTactics with support for CAE and token endpoint v2

A tool that can help detect and takeover subdomains with dead DNS records

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.