
hashcat
World's fastest and most advanced password recovery utility

World's fastest and most advanced password recovery utility

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

bash CLI trainer — 30 levels from ls to privilege escalation

A WiFi security auditing software mainly based on aircrack-ng tools suite

The famous WPA precomputed cracker, Migrated from Google.

CredsHunter - Credential Hunting scripts for Windows and Linux OS

A small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper.

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

Free hands-on digital forensics labs for students and faculty

Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales,…

Minimal terminal-based password manager

Awesome Privacy - A curated list of services and alternatives that respect your privacy because PRIVACY MATTERS.

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

Correlates NTLM hashes, BloodHound data, and cracked passwords for Active Directory penetration testing. Imports NTDS.dit, syncs to Neo4j, analyzes…

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

Sources of Synacktiv's challenge for leHack 2026

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…