Skip to content

5thphlame/Tools-of-the-Trade

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

70 Commits
Β 
Β 

Repository files navigation

Tools-of-the-Trade

Arsenal

You find link to tools you need here

Documents

https://github.com/CyberSecurityUP/information-security-relatory(Cybersecurity-Documentations)

https://github.com/mttaggart/shell-setup

https://start.me/p/AD57Rr/dfir-jedi

SOC

https://github.com/tguard-soc-package/nusantara (SOC in One)

https://www.joesandbox.com/ (Sandbox)

https://any.run/ (Sandbox)

https://www.virustotal.com/

Recon

https://github.com/rohitcoder/hawk-eye [HAWK Eye - Uncover Secrets and PII Across All Platforms in Minutes!]

https://app.netlas.io/

https://github.com/lc/gau (GetALlUrls)

https://github.com/CyberSecurityUP/Digital-Footprint-Checklist/blob/main/checklist-english-version.md (Digital Footprint)

https://en.fofa.info/

https://www.shodan.io/

https://github.com/jasonxtn/argus (Reccommened)

https://github.com/loxy0dev/RedTiger-Tools (New Tool)

https://github.com/skahwah/SQLRecon

https://github.com/1N3/Sn1per

https://github.com/RedSiege/EyeWitness

https://github.com/xaitax/SploitScan

https://github.com/ANG13T/skytrack

https://github.com/Lissy93/web-check (https://web-check.xyz/) WEB OSINT

https://github.com/neonprimetime/PhishingKitTracker/blob/master/2020-05_PhishingKitTracker.csv (Phishing)

https://github.com/htr-tech/zphisher (Phishing)

https://github.com/gophish/gophish/releases (Phishing Recommended) Install in a VPS you can use Digital Ocean

Scanning

https://github.com/arminc/clair-scanner (Docker Vulnerability Scanner)

https://github.com/Cybersecurity-Ethical-Hacker/xssdynagen

Exploitation

https://github.com/XiaoliChan/wmiexec-Pro

https://github.com/brightio/penelope (Reverse Shell tool)

https://github.com/osamaavvan/NTLM-Stealer-PDF/tree/main (NTLM Stealer pdf version)

Post Exploitation

https://github.com/outflanknl/RedELK (Red Team SIEM)

https://github.com/nicocha30/ligolo-ng (Tunnelling)

https://github.com/LasCC/HackTools

Password Bruteforce Tool

https://github.com/dievus/BlackLister

Active Directory

https://github.com/Pennyw0rth/NetExec

https://github.com/ropnop/kerbrute.git (AD Bruteforce)

https://github.com/GhostPack/Seatbelt (Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.)

Active Directory Enumeration

https://github.com/PlumHound/PlumHound.git

https://github.com/SnaffCon/Snaffler?tab=readme-ov-file

https://github.com/daniellowrie/ActiveDirectory-Pentest-Resources/blob/main/README.md

Bug Bounty

https://github.com/search?q=nuclei&type=repositories

https://github.com/projectdiscovery/subfinder

https://github.com/netsecurity-as/subfuz

https://github.com/blackhatethicalhacking/DDoSlayer.git (Denial Of Service Tool)

https://github.com/Stuub/Helios (XSS Scan Tool)

https://github.com/mandatoryprogrammer/xsshunter-express (Blind XSS)

https://github.com/blacklanternsecurity/bbot(Recommended subdomain finder)

https://github.com/projectdiscovery/httpx

CheckLists

https://github.com/CyberSecurityUP/Offensivesecurity-Checklists

Resources

https://evotec.pl/the-only-powershell-command-you-will-ever-need-to-find-out-who-did-what-in-active-directory/

https://github.com/pentestmonkey/php-reverse-shell/blob/master/php-reverse-shell.php

https://github.com/reswob10/HomeLabResources

https://github.com/Az0x7/vulnerability-Checklist

https://github.com/Tylous/FaceDancer?tab=readme-ov-file#how-to-use

https://github.com/0xrajneesh/Ethical-Hacking-Projects-for-beginners

https://github.com/0xrajneesh/Incident-Response-Projects-for-Beginners

https://github.com/0xrajneesh/Web-Pentesting-Projects-For-Beginners

https://github.com/hafiz-ng/beetlebug (Android Hacking)

https://github.com/securitytemplates/sectemplates/tree/main/incident-response/v1

Cheatsheets

https://highon.coffee/blog/penetration-testing-tools-cheat-sheet/

https://github.com/xxooxxooxx/xxooxxooxx.github.io/wiki/OSCP-Survival-Guide

https://github.com/RustyShackleford221/OSCP-Prep.git

https://guide.offsecnewbie.com/

https://gist.github.com/kkirsche/75a8b48e58f80223f4a73c18739446dd

https://github.com/swisskyrepo/PayloadsAllTheThings (Payloads)

https://room362.com/post/2011/2011-05-16-dumping-hashes-on-win2k8-r2-x64-with-metasploit/

https://netsec.ws/?p=457

https://scund00r.com/all/oscp/2018/02/25/passing-oscp.html#enumeration

https://github.com/rewardone/OSCPRepo/tree/master/KeepNotes/BookmarkList

https://sushant747.gitbooks.io/total-oscp-guide/

https://ptestmethod.readthedocs.io/en/latest/index.html

https://blog.ropnop.com/practical-usage-of-ntlm-hashes/

https://github.com/burntmybagel/OSCP-Prep

http://pwnwiki.io/#

https://exploitedbunker.com/articles/pentest-cheatsheet/

https://github.com/moshekaplan/pentesting_notes/

https://forum.hackthebox.eu/discussion/612/oscp-practice

https://www.hypn.za.net/blog/2017/08/27/compiling-exploit-764-c-in-2017/

https://github.com/Snifer/security-cheatsheets

http://www.lifeoverpentest.com/

https://hausec.com/pentesting-cheatsheet/#_Toc475368977

https://www.netsecfocus.com/oscp/2019/03/29/The_Journey_to_Try_Harder-_TJNulls_Preparation_Guide_for_PWK_OSCP.html#tips-to-participate-in-the-proctored-oscp-exam

https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet/blob/master/README.md

https://github.com/uppusaikiran/awesome-ctf-cheatsheet#awesome-ctf-cheatsheet-

Cybersecurity RoadMap Suggestion

https://github.com/brcyrr/CyberSecurityRoadmapSuggestions

Fuzzing word lists

https://github.com/netsecurity-as/subfuz/blob/master/subdomain_megalist.txt

https://github.com/danielmiessler/SecLists/tree/master/Discovery/DNS

https://github.com/TCM-Security/pnpt-wordlists

Mobile

https://github.com/Cy-clon3/awesome-ios-security

https://danaepp.com/hacking-modern-android-apps-with-burpsuite (Mobile App Pentest)

Cloud Projects

github.com/RyanJarv/awesome-cloud-sec

https://github.com/iknowjason/Awesome-CloudSec-Labs

https://github.com/RedTeamOperations/RedCloud-OS

Exam Prep

https://github.com/CyberSecurityUP/OSCE3-Complete-Guide

https://github.com/CyberSecurityUP/Red-Team-Exercises

https://t.co/b9Gds7MTx4 (OSCP)

π‘πžπ π“πžπšπ¦ 𝐓𝐨𝐨π₯𝐬

πŸ”΄ RECONNAISSANCE:

πŸ”΄ INITIAL ACCESS:

πŸ”΄ DELIVERY:

πŸ”΄ COMMAND AND CONTROL:

πŸ”΄ CREDENTIAL DUMPING:

πŸ”΄ PRIVILEGE ESCALATION:

πŸ”΄ DEFENSE EVASION:

πŸ”΄ PERSISTENCE:

πŸ”΄ LATERAL MOVEMENT:

πŸ”΄ EXFILTRATION:

NB The repo keeps getting updated

About

Arsenal

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published