mTLS-Encrypted Back-Connect SOCKS5 Proxy enabling secure tunneled connections through NAT systems.
SoaPy is a Proof of Concept tool for conducting offensive interaction with Active Directory Web Services from Linux hosts.
A Burp Suite plugin designed for automated fuzz testing of file upload vulnerabilities with over 500 payloads.
A powerful authorization enforcement detection extension for Burp Suite that reduces false positives with AI assistance.
ZigStrike is a powerful Payload Delivery Pipeline developed in Zig, offering various injection techniques and anti-sandbox features.
EWSTool is a post-exploitation tool for Exchange mail servers, enabling email list retrieval, email search, and email download.
Promptfoo is a local tool for testing LLM applications with security evaluations and performance comparisons.
Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike!
BrowserBruter is a powerful web form fuzzing automation tool designed for web security professionals and penetration testers.
A PowerShell tool for dominating Active Directory, inspired by CrackMapExec and NetExec.
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
A tool for brute forcing weak passwords on FTP, SSH, MySQL, MSSQL, etc.