
pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.

Penetration tests guide based on OWASP including test cases, resources and examples.

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Small and highly portable detection tests based on MITRE's ATT&CK.

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Automation for internal Windows Penetrationtest / AD-Security

Automating situational awareness for cloud penetration tests.

Tips and Tutorials for Bug Bounty and also Penetration Tests.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Find web directories without bruteforce

Exploits Windows IPv6 default configuration to spoof DNS via DHCPv6, redirecting victim traffic for credential relaying and man-in-the-middle attacks…

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support protocols that are not currently supported by…

Pop shells like a master.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

MSDAT: Microsoft SQL Database Attacking Tool