TerraGoat was built to enable DevSecOps design and implement a sustainable misconfiguration prevention strategy. It can be used to test a policy-as-code framework like Bridgecrew & Checkov, inline-linters, pre-commit hooks or other code scanning methods. TerraGoat follows the tradition of existing *Goat projects that provide a baseline training ground to practice implementing secure…
-
-
LDAP Monitor = Monitor creation, deletion and changes to LDAP objects
[vc_row][vc_column][vc_column_text] LDAP Monitor Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! With this tool you can quickly see if your attack worked and if it changed LDAP attributes of the target object. Features Feature Python (.py) CSharp (.exe) Powershell (.ps1) LDAPS support ✔️…
-
Xerxes – DoS Tool Enhanced
[vc_row][vc_column][vc_column_text]Xerxes dos tool enhanced with many features for stress testing. Features Xerxes has many features, some of these features are: TLS Support HTTP header randomization Useragent randomization Multiprocessing support Multiple Attack vectors etc… Not only that but also we are aggressively developing it and adding a lot more features and…
-
iCloudBrutter -AppleID Bruteforce Attack
iCloudBrutter is a simple python (3.x) script to perform basic bruteforce attack againts AppleID. Usage of iCloudBrutter for attacking targets without prior mutual consent is illegal. iCloudBrutter developer not responsible to any damage caused by iCloudBrutter. Installation $ git clone https://github.com/m4ll0k/iCloudBrutter.git $ cd iCloudBrutter $ pip3 install requests,urllib3,socks $…
-
Exploitation Tools - Pentesting Tools - PHP and Website Security - Python - Security Assessment Tool - Vulnerability Scanner - Web Application
XSStrike v2.0 – An Advanced XSS Detection And Exploitation Suit
XSStrike is an advanced XSS detection suite. It has a powerful fuzzing engine and provides zero false positive result using fuzzy matching. XSStrike is the first XSS scanner to generate its own payloads. It is intelligent enough to detect and break out of various contexts. Features: Powerful fuzzing engine Context…
-
Sn1per – Automated Pentest Recon Scanner
Sn1per – is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities, the tools include the following well-known tools like: nmap, arachni, amap, cisco-torch, dnsenum, enum4linux, golismero, hydra, metasploit-framework, nbtscan, nmap smtp-user-enum, sqlmap, sslscan, theharvester, w3af, wapiti, whatweb, whois, nikto, wpscan and…
-
idb – iOS App Security Assessment Tool
idb is a tool to simplify some common tasks for iOS app security assessments and research. Please see the Documentationfor a more detailed summary of each function. Features Assessment Setup SSH port forwarding Installation of helper utilities App Information Bundle information Registered URL Schemes Platform and SDK Versions Data folder…


