Skip to content
Change the repository type filter

All

    Repositories list

    • gcpwn

      Public
      Pentesting framework for GCP & Google Workspace that enumerates/downloads data that feeds into a BloodHound Opengraph model. Includes credential management, wor…
      Python
      BSD 3-Clause "New" or "Revised" License
      2830800Updated Aug 18, 2026Aug 18, 2026
    • OCISigner

      Public
      A Burp Suite extension to sign OCI HTTP requests using all supported OCI authentication mechanisms including API keys, session tokens, instance principals, & re…
      Java
      BSD 3-Clause "New" or "Revised" License
      0300Updated Aug 18, 2026Aug 18, 2026
    • OCInferno

      Public
      A pentesting tool for enumeration/download/graphical analysis of OCI content. Includes an OpenGraph generator for Bloodhound-style analysis.
      Python
      BSD 3-Clause "New" or "Revised" License
      22112Updated Aug 13, 2026Aug 13, 2026
    • A utility to convert OCI IAM Policy Statements and Dynamic Group Matching Rules to serialized JSON output.
      Python
      BSD 3-Clause "New" or "Revised" License
      0320Updated Aug 12, 2026Aug 12, 2026
    • Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
      Python
      BSD 3-Clause "New" or "Revised" License
      99710Updated Aug 9, 2026Aug 9, 2026
    • The Java Burp Extension version of @intrudir's BypassFuzzer tool
      Java
      MIT License
      4100Updated Aug 1, 2026Aug 1, 2026
    • Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and f…
      Python
      BSD 3-Clause "New" or "Revised" License
      34701Updated Jul 30, 2026Jul 30, 2026
    • A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a process as possible
      Shell
      44000Updated Jul 23, 2026Jul 23, 2026
    • confused

      Public
      Tool to check for dependency confusion vulnerabilities in multiple package management systems
      Go
      MIT License
      109000Updated Jul 8, 2026Jul 8, 2026
    • A collection of scripts for assessing Microsoft Azure security
      PowerShell
      BSD 3-Clause "New" or "Revised" License
      3382.4k32Updated Jun 29, 2026Jun 29, 2026
    • This is a wiki for Azure pentesting techniques. Powered by Zensical and GitHub Pages
      HTML
      BSD 3-Clause "New" or "Revised" License
      0100Updated Jun 23, 2026Jun 23, 2026
    • Used for testing NetSPI Platform MCP. Can be deleted after July 2026.
      TypeScript
      MIT License
      19k004Updated Jun 21, 2026Jun 21, 2026
    • Automatically run and save ffuf scans for multiple IPs
      Python
      Other
      268200Updated Jun 5, 2026Jun 5, 2026
    • Demonstrating UEFI emulation techniques for identifying security vulnerabilities in extracted firmware binaries.
      Python
      0000Updated May 20, 2026May 20, 2026
    • efiSeek

      Public
      Ghidra analyzer for UEFI firmware.
      Java
      Apache License 2.0
      39000Updated Apr 27, 2026Apr 27, 2026
    • Go
      0000Updated Apr 3, 2026Apr 3, 2026
    • A wiki focusing on aggregating and documenting various SQL injection methods
      HTML
      14779523Updated Apr 1, 2026Apr 1, 2026
    • NetSPI PowerShell Scripts
      PowerShell
      10834401Updated Feb 10, 2026Feb 10, 2026
    • BOF-PE

      Public
      An example reference design for a proposed BOF PE
      C++
      BSD 3-Clause "New" or "Revised" License
      3423802Updated Jan 23, 2026Jan 23, 2026
    • bambdas

      Public
      Bambdas collection for Burp Suite Professional and Community.
      Java
      GNU Lesser General Public License v3.0
      86001Updated Dec 12, 2025Dec 12, 2025
    • NetSIP

      Public
      NetSIP is a Python-powered SIP repeater that lets you craft, replay, and inspect SIP traffic.
      Python
      GNU General Public License v3.0
      0200Updated Nov 6, 2025Nov 6, 2025
    • FuncoPop

      Public
      Tools for attacking Azure Function Apps
      PowerShell
      Other
      118911Updated Oct 28, 2025Oct 28, 2025
    • PXEThief

      Public
      PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager
      Python
      GNU General Public License v3.0
      71000Updated Oct 28, 2025Oct 28, 2025
    • PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
      PowerShell
      Other
      1161k130Updated Oct 15, 2025Oct 15, 2025
    • A Burp extension for generic extraction and reuse of data within HTTP requests and responses.
      Java
      3410083Updated Oct 7, 2025Oct 7, 2025
    • Whois parser for domain whois information parsing in Go(Golang).
      Go
      Apache License 2.0
      102000Updated Sep 25, 2025Sep 25, 2025
    • ATEAM

      Public
      Python
      BSD 3-Clause "New" or "Revised" License
      1514921Updated Sep 9, 2025Sep 9, 2025
    • Snaffler

      Public
      a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
      C#
      GNU General Public License v3.0
      282100Updated Sep 8, 2025Sep 8, 2025
    • Allows testing all egress ports, an updated version of egressbuster
      0000Updated Sep 4, 2025Sep 4, 2025
    • PowerShell collector for adding MSSQL attack paths to BloodHound with OpenGraph
      PowerShell
      GNU General Public License v3.0
      20100Updated Jul 30, 2025Jul 30, 2025
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.