The pentester's Swiss knife

cryptographic services

themis: open-source high-level cryptographic services library

themis Themis is an open-source high-level cryptographic services library for mobile and server platforms, which provides secure data exchange and storage.   Themis provides four important cryptographic services: Secure Message: a simple encrypted messaging...

wordlists

bopscrk: generate smart and powerful wordlists

Bopscrk Bopscrk (Before Outset PaSsword CRacKing) is a tool to generate smart and powerful wordlists. Included in BlackArch Linux pentesting distribution and Rawsec’s Cybersecurity Inventory since August 2019.   The first idea was inspired by Cupp and Crunch. We could say...

pentest reporting application

auditforge: A pentest reporting application

AuditForge AuditForge (PwnDoc fork) is a pentest reporting application making it simple and easy to write your findings and generate a customizable Docx report. The main goal is to have more time to search...

database protection

Acra: database protection suite

What is Acra Acra helps you easily secure your databases in distributed, microservice-rich environments. It allows you to selectively encrypt sensitive records with strong multi-layer cryptography, detect potential intrusions and SQL injections and cryptographically compartmentalize...

Antivirus Bypass

EDR & Antivirus Bypass to Gain Shell Access

EDR-Antivirus-Bypass-to-Gain-Shell-Access This repository contains a proof-of-concept (PoC) for bypassing EDR and antivirus solutions using a memory injection technique. The code executes shellcode that spawns a reverse shell, successfully evading detection by various security mechanisms. This project...

macOS firewall

LuLu: free open-source macOS firewall

LuLu is the free open-source macOS firewall that aims to block unauthorized (outgoing) network traffic unless explicitly approved by the user:   Full details and usage instructions can be found here. Feature  100% free As...

DNS reconnaissance

fierce: A DNS reconnaissance tool

Fierce Fierce is a DNS reconnaissance tool for locating non-contiguous IP space. Fierce is a semi-lightweight scanner that helps locate non-contiguous IP space and hostnames against specified domains. It’s really meant as a pre-cursor to...