Take it like a gift

shad0w
shad0w

A post exploitation framework designed to operate covertly on heavily monitored environments.

Grendel-Scan
Grendel-Scan

A tool for automated security scanning of web applications.

go-dork
go-dork

The fastest dork scanner written in Go.

gowitness
gowitness

A golang, web screenshot utility using Chrome Headless.

IVRE
IVRE

Network recon framework.

Hamburglar
Hamburglar

Collect useful information from urls, directories, and files.

Astra
Astra

Automated Security Testing For REST API's.

Athena OS
Athena OS

Arch Linux-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

Async DNS Brute
Async DNS Brute

DNS asynchronous brute force utility.

HTTPoxy Scanner
HTTPoxy Scanner

A Burp Suite extension that checks for the HTTPoxy vulnerability.

kube-bench
kube-bench

Checks whether Kubernetes is deployed according to security best practices.

Bugcrowd VRT
Bugcrowd VRT

Bugcrowd’s baseline priority ratings for common security vulnerabilities.

Arsenal
Arsenal

Just a quick inventory, reminder and launcher for pentest commands.

JNDI-Injection-Exploit
JNDI-Injection-Exploit

Generates JNDI links can start several servers to exploit JNDI Injection vulnerabilities.

AWS Sensitive Permissions
AWS Sensitive Permissions

This script enumerates the permissions of all the AWS principals of an account.