
metta
An information security preparedness tool to do adversarial simulation.

An information security preparedness tool to do adversarial simulation.

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

📦 Make security testing of K8s, Docker, and Containerd easier.

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

A personal RAG system for offensive security knowledge

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated file read in Check Point Security Gateways; scans single or multiple IP targets and…

In-depth technical analysis of Cisco ISE RCE vulnerabilities, including exploitation techniques, evasion methods, and remediation strategies for…

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

Go toolkit for authorized Azure security assessments: enumerates subscriptions and resources, audits misconfigurations, and attacks public Blob…

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…