
Ghostwriter
The SpecterOps project management and reporting engine

The SpecterOps project management and reporting engine

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

A DNS rebinding attack framework.

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Efficient and advanced man in the middle framework

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Find interesting Amazon S3 Buckets by watching certificate transparency logs.

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Collection of Offensive C# Tooling

A Python based ingestor for BloodHound

Powershell tool to automate Active Directory enumeration.

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

SharpSploit is a .NET post-exploitation library written in C#

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Centralized data enrichment platform for offensive security assessments that ingests, enriches, and enables collaborative analysis of collected files…