Awesome Lists

awesome-csirt

by Spacial

awesome listCpushed about 2 years ago

Awesome CSIRT is an curated list of links and resources in security and CSIRT daily activities.

AI summary

CSIRT resource hub

A curated list of links and resources for security professionals to stay informed on CSIRT daily activities and security best practices.

stars
482
forks
87
watching
36
entries
3,177

What's in the list

3,177 links in 262 sections, with live GitHub stats.activeno commit in 2y

Books

CVEs

  • here

    Some CVEs stuff and links and in

  • MikroTik

    search on shodan

  • TROMMEL

    : Sift Through Directories of Files to Identify Indicators That May Contain Vulnerabilities

  • cve_manager

    : A python script that a) parses NIST NVD CVEs, b) prcoesses and exports them to CSV files, c) creates a postgres database and imports all the data in it, d) provides query capabilities for this CVEs database

  • dorkbot

    : Command-line tool to scan Google search results for vulnerabilities

  • NotQuite0DayFriday

    : This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly

  • Exploit Prediction Scoring System (EPSS)

    : The Exploit Prediction Scoring System (EPSS) is an open, data-driven effort for predicting when software vulnerabilities will be exploited. Our goal is to assist network defenders to better prioritize vulnerability remediation efforts

  • CVE PoC

    : Almost every publicly available CVE PoC

Malware Analysis

Malware Analysis / Malware Development:

Malware Analysis

Malware Analysis / Web Malwares

Malware Analysis / Malware Samples

Malware Analysis / Repos

  • malware.one

    is a binary substring searchable malware catalog containing terabytes of malicious code

  • MalwareWorld

    : Check for Suspicious Domains and IPs. Repo: : System based on +500 blacklists and 5 external intelligences to detect internet potencially malicious hosts

  • C2Matrix

    : The goal of this site is to point you to the best C2 framework for your needs based on your adversary emulation plan and the target environment

  • LOLBITS

    : C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for EDR user-mode hooking evasion

  • MalwareBazaar

    : is a project from abuse.ch with the goal of sharing malware samples with the infosec community, AV vendors and threat intelligence providers

  • What is MWDB Core?

    : Malware repository component for samples & static configuration with REST API interface

  • Malpedia

    : The primary goal of Malpedia is to provide a resource for rapid identification and actionable context when investigating malware. Openness to curated contributions shall ensure an accountable level of quality in order to foster meaningful and reproducible research

Malware Analysis / Ransomwares

Malware Analysis / Virus/Anti-Virus

Malware Analysis / Trojans/Loggers

Malware Analysis / Malware Articles and Sources

Reverse Engineering

Reverse Engineering / IDA Pro:

Reverse Engineering / GDB:

Reverse Engineering / Frida:

Reverse Engineering / Immunity:

  • mona

    site. : is a python script that can be used to automate and speed up specific searches while developing exploits (typically for the Windows platform). It runs on Immunity Debugger and WinDBG, and requires python 2.7. Although it runs in WinDBG x64, the majority of its features were written specifically for 32bit processes

Reverse Engineering

  • LIEF

    : Library to Instrument Executable Formats ( )

  • DEBIN

    : Predicting Debug Information in Stripped Binaries

  • Manticore

    : Symbolic Execution Tool For Analysis Of Binaries And Smart Contracts. : Symbolic execution tool

  • Beam me up, CFG.

    : Earlier in 2018 while revisiting the Delay Import Table, I used dumpbin to check the Load Configuration data of a file and noticed new fields in it. And at the time of writing this, more fields were added! The first CFGuard caught my attention and I learned about Control Flow Guard, it is a new security feature. To put it simple, it protects the execution flow from redirection - for example, from exploits that overwrite an address in the stack. Maybe they should call it the Security Directory instead

  • PBA - Analysis Tools

    : My own versions from the programs of the book "Practical Binary Analysis"

  • functrace

    : is a tool that helps to analyze a binary file with dynamic instrumentation using DynamoRIO

  • Signature-Base

    : signature-base is the signature database for my scanners LOKI and SPARK Core

Reverse Engineering / Signature-Base

  • Generic Anomalies

    : Detects an embedded executable in a non-executable file

Reverse Engineering

Reverse Engineering / ELF

Reverse Engineering

Reverse Engineering / Obfuscation/Deobfuscation:

Reverse Engineering

Reverse Engineering / VX Underground

  • MalwareSourceCode

    : Collection of malware source code for a variety of platforms in an array of different programming languages

  • VXUG-Papers

    : Research code & from members of vx-underground

Reverse Engineering

Reverse Engineering / Decompilers

Reverse Engineering / Yara

Reverse Engineering / Yara / Rules DB:

  • xored_pefile_mini

    : detects files with a PE header at uint32(0x3c), xored with a key of 1, 2 or 4 bytes. by

Reverse Engineering / Ghidra

Frameworks

Patching

  • They Did

    Did Microsoft Just Manually Patch Their Equation Editor Executable? Why Yes, Yes . (CVE-2017-11882)

Hardening

Hardening / RHEL Like systems:

  • RHEL7-CIS

    : Ansible RHEL 7 - CIS Benchmark Hardening Script

  • cisecurity

    : Configures Linux systems to Center for Internet Security Linux hardening standard

Hardening

Hardening / Kubernetes:

Hardening

Hardening / WebServers / A lot of good posts by geek flare:

Hardening / WebServers / CaCerts

Hardening / WebServers / Apache:

Hardening / WebServers / Nginx:

Hardening / WebServers / PHP:

  • Cheatsheet for finding vulnerable PHP code using grep

    : This will assist you in the finding of potentially vulnerable PHP code. Each type of grep command is categorized in the type of vulnerabilities you generally find with that function

  • It's All About Time

    . - A tool for performing feasibility analyses of timing attacks. : A tool for performing network timing attacks on plaintext and hashed password authentication

  • snuffleupagus

    : Security module for php7 - Killing bugclasses and virtual-patching the rest!

  • FOPO-PHP-Deobfuscator

    : A simple script to deobfuscate PHP file obfuscated with FOPO Obfuscator

  • Decode.Tools

    : Decode PHP Obfuscator by FOPO

Hardening / WebServers / Ruby:

  • TSS - Threshold Secret Sharing

    : A Ruby implementation of Threshold Secret Sharing (Shamir) as defined in IETF Internet-Draft draft-mcgrew-tss-03.txt

Hardening / WebServers

Credentials

  • WhiteIntel

    : WhiteIntel assists companies in identifying compromised credentials through malware campaigns

  • Cr3dOv3r

    Search if your credentials where leaked:

  • pw-pwnage-cfworker

    : Deploy a Cloudflare Worker to sanely score users' new passwords with zxcvbn AND check for matches against haveibeenpwned's 5.1+ billion breached accounts

  • login_duress

    : A BSD authentication module for duress passwords

  • XSStrike

    : Most advanced XSS detection suite

  • Was my password leaked?

    : Search for creadentials leaked on pwndb

  • bitwarden_rs

    : Unofficial Bitwarden compatible server written in Rust

  • pcfg_cracker

    : Probabilistic Context Free Grammar (PCFG) password guess generator

  • Depix

    : Recovers passwords from pixelized screenshots

  • pwndb

    : Search for leaked credentials

  • Password Lists

    : Password lists with top passwords to optimize bruteforce attacks

  • awsome

    KeePass :Curated list of KeePass-related projects

Credentials / awsome

Credentials / Tokens

Secure Programming

Secure Programming / SSL/TLS for dummies:

  • part 1

    : Ciphersuite, Hashing, Encryption;

  • part 2

    : Understanding key exchange algorithm;

  • part 3

    : Understanding Certificate Authority

Secure Programming

  • heaphopper

    : HeapHopper is a bounded model checking framework for Heap-implementations

  • Ristretto

    is a technique for constructing prime order elliptic curve groups with non-malleable encodings

  • SEI CERT C Coding Standard

    : The C rules and recommendations in this wiki are a work in progress and reflect the current thinking of the secure coding community. Because this is a development website, many pages are incomplete or contain errors. As rules and recommendations mature, they are published in report or book form as official releases. These releases are issued as dictated by the needs and interests of the secure software development community

Secure Programming / SEI CERT C Coding Standard

Secure Programming

Secure Programming / Web Training

Secure Programming / SAST

Secure Programming / Secure Web dev / OWASP:

Secure Programming / Secure Web dev / OWASP: / CheatSheets:

Secure Programming / Secure Web dev / OWASP:

Secure Programming / Secure Web dev

Secure Programming / Formal Analysis

Secure Programming / Fuzzing

Secure Programming / API

Secure Programming / API / API Security Testing

Secure Programming / API

CTFs / CTFd:

CTFs

CTFs / CTFs tools

  • nc-chat-ctf

    : Chat Server for CTF Players wrapped in SSL

  • Ciphr

    : CLI crypto swiss-army knife for performing and composing encoding, decoding, encryption, decryption, hashing, and other various cryptographic operations on streams of data from the command line; mostly intended for ad hoc, infosec-related uses

  • sec-tools

    : A set of security related tools

  • Real World CTF 2023

    : Solving a Java CTF challenge by writing static analysis passes!

Phreak

Archs

Archs / Hardware

Archs / Hardware / Blutetooth:

Archs / Hardware / Wireless / Wifi:

Archs / Hardware / Drone:

  • SkyJack

    is a drone engineered to autonomously seek out, hack, and wirelessly take over other drones within wifi distance, creating an army of zombie drones under your control

  • eaphammer

    : Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks

  • whereami

    : Uses WiFi signals and machine learning to predict where you are

Archs / Hardware / Car Hacking:

Archs / Hardware / Internet of Things (IoT):

Archs / Hardware

Archs / ARM / Arm Heap Exploitation, by Azeria:

Archs / ARM

Archs / ARM / ARM64 Reversing and Exploitation

Pentesting

  • Awesome Penetration Testing

    : A collection of awesome penetration testing resources, tools and other shiny things

  • Seclists

    is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place

  • osquery

    Search operating systems on the network:

  • fleet

    : The premier osquery

  • Intrusion Detection

    Penetration Testing Cheat Sheet For Windows Machine –

Pentesting / Zero Day Zen Garden:

  • Part 0

    Windows Exploit Development -

  • Part 1

    Windows Exploit Development -

  • Part 2

    Windows Exploit Development -

  • Part 3

    Windows Exploit Development -

  • Part 4

    Windows Exploit Development -

Pentesting

  • Pown.js

    : is the security testing an exploitation framework built on top of Node.js and NPM

  • Sandmap

    is a tool supporting network and system reconnaissance using the massive Nmap engine

  • trackerjacker

    : Like nmap for mapping wifi networks you're not connected to, plus device tracking

  • TIDoS-Framework

    : The offensive web application penetration testing framework

  • GitMiner

    : Tool for advanced mining for content on Github

  • DHCPwn

    : All your IPs are belong to us

  • badKarma

    : advanced network reconnaissance toolkit

  • Danger-zone

    : Correlate data between domains, IPs and email addresses, present it as a graph and store everything into Elasticsearch and JSON files

  • go-tomcat-mgmt-scanner

    : A simple scanner to find and brute force tomcat manager logins

  • IoTSecurity101

    : From IoT Pentesting to IoT Security

  • IoT Pentesting

    and : A Virtual environment for Pentesting IoT Devices

  • SharpSploitConsole

    : SharpSploit Console is just a quick proof of concept binary to help penetration testers or red teams with less C# experience play with some of the awesomeness that is SharpSploit

  • CrackMapExec

    : A swiss army knife for pentesting networks

  • DarkSpiritz

    : A penetration testing framework for Linux, MacOS, and Windows systems

  • proxycannon-ng

    : A private botnet using multiple cloud environments for pentesters and red teamers. - Built by the community during a hackathon at the WWHF 2018 security conference

  • PentestHardware

    : Kinda useful notes collated together publicly

  • MarkBaggett’s gists

    : This is a collection of code snippets used in my Pen Test Hackfest 2018 Presentation

  • pentest_scripts

    : scrapes linkedin and generates emails list

  • Penetration Testing Tools Cheat Sheet ∞

    : Penetration testing tools cheat sheet, a quick reference high level overview for typical penetration testing engagements. Designed as a quick reference cheat sheet providing a high level overview of the typical commands you would run when performing a penetration test

  • IVRE

    : Network recon framework ( )

  • DomainInformation

    (pt-br) : Tool para a identificação de arquivos, pastas, servidores DNS, E-mail. Tenta fazer transferência de zona, Busca por subdomínios e por ultimo, procura por portas abertas em cada ip dos subdomínios.. Desfrutem =)

  • Spawning a TTY Shell

    : Often during pen tests you may obtain a shell without having tty, yet wish to interact further with the system

  • LeakLooker

    : Find Open Databases in Seconds

  • pown-recon

    : A powerful target reconnaissance framework powered by graph theory

  • Micro8

    : The Micro8 series is suitable for junior and intermediate security practitioners, Party B security testing, Party A security self-test, network security enthusiasts, etc., enterprise security protection and improvement, the series complies with: Free, free, shared, open source

  • Payloads All The Things

    : A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques!

  • Penetration Test Guide based on the OWASP + Extra

    : This guid is for the penetration testers seeking for the appropriate test cases required during a penetration test project. I rearranged the OWASP Testing Guide v4 from my point of view including 9 Test Classes and each class has several Test Cases to conduct against the target. Each Test Case covers several OWASP tests which also is useful for the report document. I've also added 15 extra Tests Cases marked by the EXTRA-TEST. I hope it will be useful in both penetration test projects and bug-bounty

Pentesting / Penetration Test Guide based on the OWASP + Extra

Pentesting

Pentesting / Better API Penetration Testing with Postman:

Pentesting

  • SiteBroker

    : A cross-platform python based utility for information gathering and penetration testing automation!

  • PENTESTING-BIBLE

    : This repository was created and developed by Ammar Amer @cry__pto Only. Updates to this repository will continue to arrive until the number of links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources

  • Nikto

    : web server scanner

  • physical-docs

    : This is a collection of legal wording and documentation used for physical security assessments. The goal is to hopefully allow this as a template for other companies to use and to protect themselves when conducting physical security assessments

  • pentest-tools

    : Custom pentesting tools

  • HACKING WITH ENVIRONMENT VARIABLES

    : Interesting environment variables to supply to scripting language interpreters

  • rootend

    : A *nix Enumerator & Auto Privilege Escalation tool

  • DroneSploit

    : Drone pentesting framework console

  • HAck Tricks

    ( ): Here you will find the typical flow that you should follow when pentesting one or more machines

  • Huawei_Thief

    : Huawei DG8045 & HG633 Devices Exploitation Tool

  • urldozer

    : Perform operations on URLs like extracting paths, parameter names and/or values, domain name, host name (without HTTP[s])

  • Snaffler

    : a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

Pentesting / Several ways to download and execute malicious codes (LOLBAS)

Pentesting

Pentesting / Reconnaissance

  • Automated Reconnaissance Pipeline

    : An automated target reconnaissance pipeline

  • subfinder

    is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing

  • urlhunter

    : a recon tool that allows searching on URLs that are exposed via shortener services

  • URLBrute

    : Directory/Subdomain scanner developed in GoLang

  • degoogle

    : search Google and extract results directly. skip all the click-through links and other sketchiness

  • Investigator

    : An online handy-recon tool

Pentesting / Enumeration

  • linux-smart-enumeration

    : Linux enumeration tool for pentesting and CTFs with verbosity levels

  • Sublist3r

    : Fast subdomains enumeration tool for penetration testers

  • subscraper

    : External pentest tool that performs subdomain enumeration through various techniques. In addition, SubScraper will provide information such as HTTP & DNS lookups to aid in potential next steps

  • massh-enum

    : OpenSSH 7.x Mass Username Enumeration

  • LinEnum

    : Scripted Local Linux Enumeration & Privilege Escalation Checks

  • linpostexp

    : Linux post exploitation enumeration and exploit checking tools

  • Social Mapper

    A Social Media Enumeration & Correlation Tool

  • The art of subdomain enumeration

    : This repository contains all the supplement material for the book "The art of sub-domain enumeration"

  • social_mapper

    : A Social Media Enumeration & Correlation Tool by Jacob Wilkin(Greenwolf)

  • LEGION

    Automatic Enumeration Tool

  • discover

    Custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit

  • Z/OS System Enumeration Scripts

    : PoC REXX Script to Help with z/OS System enumeration via OMVS/TSO/JCL

  • WPExploitation

    : simples scripts to help windows enumeration

  • CTFR

    does not use neither dictionary attack nor brute-force, it just abuses of Certificate Transparency logs

  • feroxbuster

    : A fast, simple, recursive content discovery tool written in Rust

  • grinder

    : Python framework to automatically discover and enumerate hosts from different back-end systems (Shodan, Censys)

  • Admin-Scanner

    : This tool is to design to find admin panel of websites

  • Virtual host scanner

    : A script to enumerate virtual hosts on a server

  • vhost-brute

    : A PHP tool to brute force vhost configured on a server

  • grab_beacon_config

    : nmap strip to get beacon info

  • assetfinder

    : Find domains and subdomains related to a given domain

Pentesting / Enumeration / Wordlists:

Pentesting / Enumeration

  • Ghost Eye

    Informationgathering Footprinting Scanner and Recon Tool Release. Ghost Eye is an Information Gathering Tool I made in python 3. To run Ghost Eye, it only needs a domain or ip. Ghost Eye can work with any Linux distros if they support Python 3. Author: Jolanda de Koff

  • SuperEnum

    : This script does the basic enumeration of any open port along with screenshots

  • Domain Dossier

    : The Domain Dossier tool generates reports from public records about domain names and IP addresses to help solve problems, investigate cybercrime, or just better understand how things are set up

  • X41 BeanStack

    : Java Fingerprinting using Stack Traces

  • Skanuvaty

    : Dangerously fast DNS/network/port scanner

  • TireFire

    : Automate the scanning and enumeration of machines externally while maintaining complete control over scans shot to the target. Comfortable GUI-ish platform. Great for OSCP/HTB type Machines as well as penetration testing

Pentesting / WebShells

Pentesting / ShellCodes

Pentesting / ShellCodes / Windows:

  • Unicorn

    is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory

  • pe_to_shellcode

    : Converts PE into a shellcode

  • stager.dll

    : Code from this

  • ThreadBoat

    : Program uses Thread Execution Hijacking to Inject Native Shellcode into a Standard Win32 Application

  • Excel4-DCOM

    : PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)

  • MaliciousMacroMSBuild

    : Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass

  • SnapLoader

    : Injecting shellcode into 'ntdll.dll' address space in target process, and hijacking its thread without calling GetThreadContext, evading memory scanners, and more

Pentesting / ShellCodes / Linux:

Pentesting / ShellCodes

Pentesting / ShellCodes / Reverse Shell:

Pentesting / ShellCodes

Pentesting / ShellCodes / Gadgets:

Pentesting / ShellCodes

Pentesting / Reporting

Pentesting / OSINT - Open Source INTelligence

Pentesting / OSINT - Open Source INTelligence / WhatsMyName

Pentesting / OSINT - Open Source INTelligence

  • shadowbanned

    : Shadowban Tester for Twitter

  • sherlock

    : Hunt down social media accounts by username across social networks

  • usufy

    is a GPLv3+ piece of software that checks the existence of a profile for a given user in a bunch of different platforms. It uses the error messages displayed by most platforms when a user profile has not been found as the evidence of the existence or not of a given profile

  • osrf

    : OSRFramework, the Open Sources Research Framework is a AGPLv3+ project by i3visio focused on providing API and tools to perform more accurate online researches

  • IntelMQ

    : A tool-suite solution for IT security teams (CERTs & CSIRTs, SOCs abuse departments, etc.) for collecting and processing security feeds using a message queuing protocol. Its main goal is to give to incident responders an easy way to collect & process threat intelligence thus improving the incident handling processes of CERTs

  • OSINT SAN Framework.

    (ru) : OSINT-SAN Framework makes it possible to quickly find information and de-anonymize Internet users. The software is a framework that contains 30 functions for searching information or de-anonymizing users. With the help of my software, you can collect information about users on the Internet, anonymously and without special skills

  • Scrummage

    : The Ultimate OSINT and Threat Hunting Framework

  • viper

    : Intranet pentesting tool with webui 开源图形化内网渗透工具

  • ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾

    is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

  • 3WiFi

    : Free Wireless Database

  • ExportData

    Twitter data export tool. Allows downloading historical tweets since 2006, exporting followers & followings and collects historical trends in 467 locations

  • DetectDee

    : Hunt down social media accounts by username, email or phone across social networks

  • OSINT framework

    focused on gathering information from free tools or resources

  • h8mail

    : Password Breach Hunting & Email OSINT tool, locally or using premium services. Supports chasing down related email

  • PwnBin

    : Python Pastebin Webcrawler that returns list of public pastebins containing keywords

  • ODBParser

    : OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories

  • pastego

    : Scrape/Parse Pastebin using GO and expression grammar (PEG)

  • Instagram Scraper

    : Scrapes an instagram user's photos and videos

  • galer

    : A fast tool to fetch URLs from HTML attributes by crawl-in

  • SpyScrap

    : CLI and GUI for OSINT. Are you very exhibited on the Internet? Check it! Twitter, Tinder, Facebook, Google, Yandex, BOE. It uses facial recognition to provide more accurate results.F

  • pwnedOrNot

    OSINT Tool for Finding Passwords of Compromised Email Addresses

  • dorking

    (how to find anything on the Internet)

  • DorkGenius

    : Generate custom dorks for Google, Bing, DuckDuckGo, & more!

  • chatter

    : internet monitoring osint telegram bot for windows

  • Slackhound

    : Slackhound allows red and blue teams to perform fast reconnaissance on Slack workspaces/organizations to quickly search user profiles, locations, files, and other objects

  • ail-feeder-telegram

    : External telegram feeder for AIL framework

  • signald

    : unofficial daemon for interacting with Signal

  • Telegram messenger CLI

    : for Telegram IM

  • TelegramScraper

    : Telegram scraping tool for researching mis-/disinformation and investigating shade goings on

  • OSINT-Discord-resources

    : Some OSINT Discord resources

Pentesting / Vulnerability

Pentesting / WAFs

Pentesting / WAFs / How to find real IP of a site behind cloudflare

Pentesting / WAFs

Pentesting / Exploits

Pentesting / Exploits / Glibc Heap Exploitation Basics:

Pentesting / Exploits

Pentesting / Exploits / Patchless AMSI bypass using SharpBlock

Pentesting / Exploits

Pentesting / Payloads

Pentesting / Payloads / Payloads Collection

Pentesting / Payloads / MSFVenom:

Pentesting / Payloads

Pentesting / Payloads / SQL Injection:

Pentesting / Payloads / CSRF:

Pentesting / Payloads / HTTP Request Smuggling:

Pentesting / Payloads / XSS:

Pentesting / Payloads

Pentesting / Payloads / RPC:

Pentesting / Payloads

Pentesting / Payloads / REST Assured: Penetration Testing REST APIs Using Burp Suite:

Pentesting / Payloads

Pentesting / Red Team

Pentesting / Purple Team

  • Purple Cloud

    : An Infrastructure as Code (IaC) deployment of a small Active Directory pentest lab in the cloud. The deployment simulates a semi-realistic corporate enterprise Active Directory with a DC and endpoints. Purple team goals include blue team detection capabilities and R&D for detection engineering new approaches. On

DNS

  • dref

    : DNS Rebinding Exploitation Framework

  • dns-rebind-toolkit

    : A front-end JavaScript toolkit for creating DNS rebinding attacks

  • Bypass firewalls by abusing DNS history

    : Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters

  • dnstwist

    : Domain name permutation engine for detecting typo squatting, phishing and corporate espionage

  • Can I take over XYZ?

    : a list of services and how to claim (sub)domains with dangling DNS records

  • SubR3con

    : is a script written in python. It uses Sublist3r to enumerate all subdomains of specific target and then it checks for stauts code for possible subdomain takeover vulnerability. This works great with Subover.go

  • TakeOver-v1

    : script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability

  • subzy

    : Subdomain takeover vulnerability checker

  • subdomain-takeover

    : SubDomain TakeOver Scanner by 0x94

  • DNSCrypt

    is a protocol that authenticates communications between a DNS client and a DNS resolver. It prevents DNS spoofing. It uses cryptographic signatures to verify that responses originate from the chosen DNS resolver and haven’t been tampered with. , and

  • pdns-qof

    : Passive DNS Common Output Format

  • dnsdbq

    : DNSDB API Client, C Version

DNS / DNS Logging:

DNS

Exfiltration

Exfiltration / LOLBIN/LOLBAS:

Exfiltration

Exfiltration / Steganography

Phishing

Forensics

  • O-Saft

    : OWASP SSL advanced forensic tool

  • PcapXray

    A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction

  • swap_digger

    is a tool used to automate Linux swap analysis during post-exploitation or forensics

  • The Sleuth Kit® (TSK)

    is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data

  • CDQR

    : The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted drives and extracted artifacts from Windows, Linux and MacOS devices

  • mac_apt

    : macOS Artifact Parsing Tool

  • MacForensics

    : Repository of scripts for processing various artifacts from macOS (formerly OSX)

  • imago-forensics

    : Imago is a python tool that extract digital evidences from images

  • remedi-infrastructure

    : setup and deployment code for setting up a REMEDI machine translation cluster

  • Tsurugi Linux

    is a new DFIR open source project that is and will be totally free, independent without involving any commercial brand

  • libelfmaster

    : Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools

  • usbrip

    (derived from "USB Ripper", not "USB R.I.P." 😲) is an open source forensics tool with CLI interface that lets you keep track of USB device artifacts (aka USB event history, "Connected" and "Disconnected" events) on Linux machines

  • Digital Forensics and Incident Response

    : This post is inspired by all the hard working DFIR, and more broadly security professionals, who have put in the hard yards over the years to discuss in depth digital forensics and incident response

  • KAPE

    Kroll Artifact Parser And Extractor: Find, collect and process forensically useful artifacts in minutes. . and

  • AVML

    (Acquire Volatile Memory for Linux)

  • turbinia

    : Automation and Scaling of Digital Forensics Tools

  • MacQuisition

    : A powerful, 4-in-1 forensic imaging software solution for Macs for triage, live data acquisition, targeted data collection, and forensic imaging

  • Kuiper

    : Digital Forensics Investigation Platform

  • PowerForensics

    : PowerForensics provides an all in one platform for live disk forensic analysis

  • OfficeForensicTools

    : A set of tools for collecting forensic information

  • CHIRP

    : A forensic collection tool written in Python

  • L0phtCrack

    is a password auditing and recovery application originally produced by Mudge from L0pht Heavy Industries. It is used to test password strength and sometimes to recover lost Microsoft Windows passwords, by using dictionary, brute-force, hybrid attacks, and rainbow tables

  • Foremost

    : is a console program to recover files based on their headers, footers, and internal data structures. This process is commonly referred to as data carving. Foremost can work on image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive. The headers and footers can be specified by a configuration file or you

  • TrID

    : is an utility designed to identify file types from their binary signatures. While there are similar utilities with hard coded logic, TrID has no fixed rules. Instead, it's extensible and can be trained to recognize new formats in a fast and automatic way

  • image-unshredding

    : Image unshredding using a TSP solver

  • FastIR Artifacts

    : Live forensic artifacts collector

  • MVT

    (Mobile Verification Toolkit) helps conducting forensics of mobile devices in order to find signs of a potential compromise

  • Forensic Investigation

    Cisco Stealthwatch at work

  • Andriller CE (Community Edition)

    : is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive acquisition from Android devices

  • Dshell

    is a network forensic analysis framework

  • exif-gps-tracer

    : A python script which allows you to parse GeoLocation data from your Image files stored in a dataset.It also produces output in CSV file and also in HTML Google Maps

Forensics / Anti-Forensics:

  • ShredOS x86_64 - Disk Eraser

    : for all Intel 64 bit processors as well as processors from AMD and other vendors which make compatible 64 bit chips. ShredOS - Secure disk erasure/wipe

Forensics

  • dfir_ntfs

    : An NTFS/FAT parser for digital forensics & incident response

  • MemProcFS

    : is an easy and convenient way of viewing physical memory as files in a virtual file system

  • LeechCore

    : Physical Memory Acquisition Library & The LeechAgent Remote Memory Acquisition Agent

  • PCILeech

    : Direct Memory Access (DMA) Attack Software

Forensics / PDF

Forensics / Email Headers

Forensics / Distros

Forensics / Volatility

Blue Team / MITRE ATT&CK:

Blue Team

Blue Team / Sysmon:

Blue Team

Blue Team / Threat Hunting

Blue Team / Threat Hunting / Mordor PCAPs 📡:

Blue Team / Threat Hunting

  • securityonion

    : Security Onion 2.0 (Pre-release) - Linux distro for threat hunting, enterprise security monitoring, and log management

  • TheHive

    : a Scalable, Open Source and Free Security Incident Response Platform

  • TheHive4py

    : Python API Client for TheHive

  • TheHiveIRPlaybook

    is a collection of TheHive case templates used for Incident Response

  • Cortex-Analyzers

    : Cortex Analyzers Repository

  • Nimbus Network

    Traffic Analyzer Augmented with our world-class threat intelligence

  • ja3

    is a standard for creating SSL client fingerprints in an easy to produce and shareable way

  • API-To-Event

    Some repos from hunters-forge: , ,

  • Watcher

    : Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS

Blue Team / Threat Hunting / Network Analysys:

Blue Team / Threat Hunting

Blue Team / Threat Hunting / Tutorials:

Blue Team / Threat Hunting

Blue Team / IoCs

Blue Team / SIEM

  • Sigma

    : Generic Signature Format for SIEM Systems

Blue Team / SIEM / Sigma

  • Suspicious Use of Procdump

    : Detects suspicious uses of the SysInternals Procdump utility by using a special command line parameter in combination with the lsass.exe process. This way we're also able to catch cases in which the attacker has renamed the procdump executable

Blue Team / SIEM

Browsers

Browsers / Browsers Addons

Operating Systems

  • bochspwn-reloaded

    : A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3

  • drltrace

    : Drltrace is a library calls tracer for Windows and Linux applications

  • shellz

    : is a small utility to track and control your ssh, telnet, web and custom shells

  • CLIP OS

    : Open Source secured operating system by Agence nationale de la sécurité des systèmes d'information

  • routeros

    : RouterOS Bug Hunt Materials Presented at Derbycon 2018

  • Awesome-Study-Resources-for-Kernel-Hacking

    : Kernel Hacking study materials collection

  • Skadi

    : Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

  • taintgrind

    :A taint-tracking plugin for the Valgrind memory checking tool

  • UPX

    is a free, portable, extendable, high-performance executable packer for several executable formats

Operating Systems / Mainframe:

  • MF Sniffer

    : Mainframe TN3270 unencrypted TSO session user ID and password sniffer

Operating Systems

  • magic-trace

    : collects and displays high-resolution traces of what a process is doing

Operating Systems / UEFI

Operating Systems / Windows

Operating Systems / Windows / pdf

Operating Systems / Windows

Operating Systems / Windows

Operating Systems / Windows / Privilege Escalation:

Operating Systems / Windows

Operating Systems / Windows / The Internals of AppLocker:

Operating Systems / Windows

Operating Systems / Windows / Five PE Analysis Tools Worth Looking At

  • pestudio

    : The goal of pestudio is to spot suspicious artifacts within executable files in order to ease and accelerate Malware Initial Assessment and is used by Computer Emergency Response Teams and Labs worldwide

  • NTCore

    Explorer Suite

Operating Systems / Windows

Operating Systems / Windows / Here are a few tool resources for using WinRM w/o PowerShell

Operating Systems / Windows

Operating Systems / Windows / BloodHound:

Operating Systems / Windows

Operating Systems / Windows / Kerberos basics & (ab)use of Certificates within Active Directory (i.e. AD CS and PKINIT)

Operating Systems / Windows / Kerberos:

Operating Systems / Windows

Operating Systems / macOS/iOS

Operating Systems / macOS/iOS / Objective-See:

Operating Systems / macOS/iOS

Mobile

Mobile / Android

Mobile / Linux/ *Nix

Mobile / Linux/ *Nix / Ground Zero: Reverse Engineering

Mobile / Linux/ *Nix / Ground Zero: Reverse Engineering / Active Directory Dojo:

Mobile / Linux/ *Nix

Mobile / Cloud

Mobile / GCP/Google

Mobile / Azure

Mobile / AWS

  • git-secrets

    : Prevents you from committing secrets and credentials into git repositories

  • CloudMapper

    : CloudMapper helps you analyze your Amazon Web Services (AWS) environments

  • Security Monkey

    : Security Monkey monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time

  • my-arsenal-of-aws-security-tools

    : List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc

  • RKMS

    : RKMS is a highly available key management service, built on top of AWS's KMS

  • FireProx

    : AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

  • Sadcloud

    : A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

  • Endgame

    : Creating

  • Bucky

    : An automatic S3 bucket discovery tool

  • Prowler

    : Prowler is a security tool to perform AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness

  • barq

    : The AWS Cloud Post Exploitation framework!

  • Text → AWS IAM Policy

    : Describe your ideal AWS IAM Policy in plain text and will use GPT-3 from Open AI to generate an AWS IAM policy

Risk Assessment and Vulnerability Management

Risk Assessment and Vulnerability Management / Nuclei

Risk Assessment and Vulnerability Management

Risk Assessment and Vulnerability Management / Guidelines

ICS (SCADA)

ICS (SCADA) / Synchrophasor

ICS (SCADA)

Radio

Radio / Spectrum Analyzers, Linux

Radio

  • The LibreCellular project

    aims to make it easier to create 4G cellular networks with open source software and low cost software-defined radio (SDR) hardware

  • RFSec-ToolKit

    is a collection of Radio Frequency Communication Protocol Hacktools

Radio / Satellite

Radio / Satellite / How Do I Crack Satellite and Cable Pay TV? (33c3)

Social Engineering

Social Engineering / The Basics of Social Engineering

Social Engineering

Tools

Tools / commando-vm

Tools

Tools / Note-taking

  • SwiftnessX

    : A cross-platform note-taking & target-tracking app for penetration testers

  • cherrytree

    : A hierarchical note taking application, featuring rich text and syntax highlighting, storing data in a single xml or sqlite file

  • cherrytree

    : A hierarchical note taking application, featuring rich text and syntax highlighting, storing data in a single xml or sqlite file

  • SwiftnessX

    : A cross-platform note-taking & target-tracking app for penetration testers

  • https://github.com/zadam/trilium

    [trilium] ): Build your personal knowledge base with Trilium Notes

  • obsidian

    : is a powerful knowledge base that works on top of a local folder of plain text Markdown files

  • marktext

    : A simple and elegant markdown editor, available for Linux, macOS and Windows

  • helix

    : A post-modern modal text editor

Tools / Kali

  • hurl

    : hexadecimal & URL encoder + decoder. : hURL is a small utility that can encode and decode between multiple formats

Tools / IP Reputation

Tools / Shell tools

  • Python-Scripts

    : some scripts for penetration testing

  • SubEnum

    : bash script for Subdomain Enumeration

  • password-store

    : Simple password manager using gpg and ordinary unix directories

Tools / Search Engines

Tools / Search Engines / Search engines for Hackers

Tools / Search Engines / Search engines for Hackers / shodan.io

  • TriOp

    : Tool for quickly gathering statistical information from Shodan.io

Tools / Search Engines / Search engines for Hackers

Tools / Search Engines

  • Insecam

    : Network live IP video cameras directory

Tools / VPN

  • jigsaw project

    by Alphabet/Google. : VPN Server

  • SSHuttle

    : Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS tunneling

  • WireGuard

    : is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography. It aims to be faster, simpler, leaner, and more useful than IPSec, while avoiding the massive headache

  • Crockford’s base 32 encoding

    : Crockford’s base 32 encoding is a compromise between efficiency and human legibility

  • Sputnik

    -An Open Source Intelligence Browser Extension

  • PCredz

    : This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface

  • uncaptcha2

    : defeating the latest version of ReCaptcha with 91% accuracy

  • Nefarious LinkedIn

    : A look at how LinkedIn spies on its users

  • ProtonVPN-CLI

    : Linux command-line client for ProtonVPN. Written in Python

  • Nebula

    : A scalable overlay networking tool with a focus on performance, simplicity and security

  • AirVPN

    A VPN based on OpenVPN and operated by activists and hacktivists in defence of net neutrality, privacy and against censorship

Tools / Secure Sharing

  • CryFS

    : Keep your data safe in the cloud

  • Cryptomator

    : Multi-platform transparent client-side encryption of your files in the cloud

  • VeraCrypt

    : is a free open source disk encryption software for Windows, Mac OSX and Linux

  • CipherShed

    : is a program that can be used to create encrypted files or encrypt entire drives (including USB flash drives and external HDDs)

  • Boxcryptor

    : Security for your Cloud

  • Nextcloud E2E

    : End-to-end encryption RFC. Some old news

  • DiskCryptor

    is an open encryption solution that offers encryption of all disk partitions, including the system partition

  • ProjectSend

    is a free, open source software that lets you share files with your clients, focused on ease of use and privacy. It supports clients groups, system users roles, statistics, multiple languages, detailed logs... and much more!

  • send

    Mozilla : Simple, private file sharing from the makers of Firefox (archived). Revival:

Privacy

General

General / Configs

Resources

  • pwn.college

    is a first-stage education platform for students (and other interested parties) to learn about, and practice, core cybersecurity concepts in a hands-on fashion. It is designed to take a “white belt” in cybersecurity to becoming a “blue belt”, able to approach (simple) CTFs and wargames. The philosophy of pwn.college is “practice makes perfect”

  • 'pwnable.kr'

    is a non-commercial wargame site which provides various pwn challenges regarding system exploitation. the main purpose of pwnable.kr is 'fun'

  • Pwnable.tw

    is a wargame site for hackers to test and expand their binary exploiting skills

  • Security Zines

    : graphical way of learning concepts of Application & Web Security

Resources / Training and Certifications

Resources / Conferences and Slides

  • H2HC

    Hackers To Hackers Conference:

Resources / Conferences and Slides / H2HC

  • H2HC 2017

    : H2HC 2017 Slides/Materials/Presentations

  • H2HC 2018

    : Slides/Materials/Presentations

  • JavaDeserH2HC

    : Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC)

Resources / Conferences and Slides / CCC:

Resources / Conferences and Slides / BlackHat:

Resources / Conferences and Slides / BlackHat: / 2021:

Resources / Conferences and Slides / DEFCON:

Resources / Conferences and Slides / DEFCON: / 2021:

Resources / Conferences and Slides

  • SBSeg 2018

    : Simpósio Brasileiro em Segurança da Informação e de Sistemas Computacionais (SBSeg)

Resources / Conferences and Slides / Objective by the Sea (2018):

Resources / Conferences and Slides

Resources / Conferences and Slides / r2con2020

Resources / Conferences and Slides

Resources / Sans / Quiz:

Resources / Sans

psyops

Sources

Sources / hasherezade's 1001 nights

Sources

Sources / Github repos:

Sources / Damn Vulnerable Web Application:

Sources

Fun

Articles

Other Repos

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.