
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.

Small and highly portable detection tests based on MITRE's ATT&CK.

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Penetration tests guide based on OWASP including test cases, resources and examples.

Tips and Tutorials for Bug Bounty and also Penetration Tests.

Automating situational awareness for cloud penetration tests.

Exploits Windows IPv6 default configuration to spoof DNS via DHCPv6, redirecting victim traffic for credential relaying and man-in-the-middle attacks…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support protocols that are not currently supported by…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Tests your WAF with +160 payloads

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and…

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

A tool to automate penetration tests

A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Azure mindmap for penetration tests