Giter Club home page Giter Club logo

whoami

Compilation of projects from my spare time. Built for pentests, red teams, and analysis.

Tools generally released with accompanying blog posts, can be found here: https://whynotsecurity.com/tags/#knavesec

Tool list:

  • CredMaster (Blog1) (Blog2) - Password spraying tool using FireProx AWS APIs to rotate request IP on every attempt. Full opsec considerations applied to not leak information
  • Max (Blog1) (Blog2) (Blog3)- BloodHound utility tool for data import/export, Domain Password Audit Tool (DPAT), analytics
  • External Email Warning Bypass (Blog) - POC to obfuscate "external email warning" banners on phishing emails via CSS injection
  • EyeWitnessTheFitness (Blog) - Generates a single FireProx API to be used for multiple pass through API hosts. Nice to be used for large EyeWitness files without generating a unique FireProx API per host
  • DPS - Distributed port scanning tool, generates high number of AWS Lambdas with unique IPs to scan hosts. Configurable to sleep between scan hosts to bypass scan prevention
  • Reverse-DNS-Info - Reverse search WHOIS records by keywords to enumerate potential alternate client root domains
  • o365fedenum (Blog)- Office365 Federated user enumeration script, based off correlated HTTP response analysis

Conference Talks:

Ellis Springe's Projects

axiom icon axiom

The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!

bbot icon bbot

OSINT automation for hackers.

check_mdi icon check_mdi

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

confused icon confused

Tool to check for dependency confusion vulnerabilities in multiple package management systems

credking icon credking

Password spraying using AWS Lambda for IP rotation

credmaster icon credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

ctfr icon ctfr

Abusing Certificate Transparency logs for getting HTTPS websites subdomains.

dps icon dps

Distributed Port Scanner (Damage-Per-Second)

firehaus icon firehaus

Collection of tools refactored to add FireProx support to bypass rate-limiting

gato icon gato

GitHub Actions Pipeline Enumeration and Attack Tool

max icon max

Maximizing BloodHound. Max is a good boy.

nuclei icon nuclei

Fast and customizable vulnerability scanner based on simple YAML based DSL.

nuclei-templates icon nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

o365fedenum icon o365fedenum

Federated Office365 user enumeration based on correlated response trend analysis

roadtools icon roadtools

A collection of Azure AD tools for offensive and defensive security purposes

spoof-phisher icon spoof-phisher

DNS spoofing with ARP poisoning. End goal: using DNS and ARP spoofing, automatically clone a website, harvest credentials, then redirect to the legitimate website making the phish undetectable

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.