sherlock-project/sherlock
Hunt down social media accounts by username across social networks
2,162 repositories
Hunt down social media accounts by username across social networks
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
🕵️♂️ Collect a dossier on a person by username from 6K websites
The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
E-mails, subdomains and names Harvester - OSINT
Web path scanner
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
Tools and Techniques for Red Team / Penetration Testing
chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
List of Awesome Red Teaming Resources
Cyber Security ALL-IN-ONE Platform
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
The all-in-one browser extension for offensive security professionals 🛠
autonomous red teaming platform; multi-agent offensive-security meta-harness
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Adversary simulation and Red teaming platform with AI
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Red Teaming Tactics and Techniques
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
List of Awesome CobaltStrike Resources
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
面向网络安全从业者的知识文库🍃 (停止更新)
Snoop — инструмент разведки на основе открытых данных (OSINT world)
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
Automation for internal Windows Penetrationtest / AD-Security