Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.
Why should I care?
RPC is the underlying mechanism which is used for numerous lateral movement techniques, reconnaissance, relay attacks, or simply to exploit vulnerable RPC services.
DCSync attack? over RPC. Remote DCOM? over RPC. WMIC? over RPC. SharpHound? over RPC. PetitPotam? over RPC...
HawkScan
Security Tool for Reconnaissance and Information Gathering on a website. (python 2.x & 3.x)
This script uses “WafW00f” to detect the WAF in the first step.
This script uses “Sublist3r” to scan subdomains.
This script uses “waybacktool” to check in the waybackmachine.
Features...
What is Spray365?
Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). How is Spray365 different from the many other password spraying tools that are already available? Spray365 enables passwords to be sprayed from an “execution...
With the right YouTube channel management tool, you can get a complete overview of your channel and all its analytics and data. You can easily spot which videos work best and which ones need more work. And it’s completely free!
VidIQ is a revolutionary YouTube tool that was designed to make it...
Fierce is a DNS reconnaissance tool for locating non-contiguous IP space.
Useful links:
Domain Name System (DNS)
Domain Names – Concepts and Facilities
Domain Names – Implementation and Specification
Threat Analysis of the Domain Name System (DNS)
Name...
Yet another content discovery tool written in python.
What makes this tool different than others:
It is written to work asynchronously which allows reaching to maximum limits. So it is very fast.
Calibration mode, applies filters on its own
Has bunch of flags that helps you fuzz in...
A high-speed & unique multithreaded dictionary attack implementation that attacks a supported hash with a "chunkified" user-defined dictionary file to find the string candidate that corresponds to the supplied hash.
Hidden content
What is DalFox
Just, XSS Scanning and Parameter Analysis tool. I previously developed XSpear, a Ruby-based XSS tool, and this time, a full change occurred during the process of porting with golang!!! and created it as a new project. The basic concept is to analyze parameters, find XSS, and...
AWS Recon
A multi-threaded AWS inventory collection tool.
The creators of this tool have a recurring need to be able to efficiently collect a large amount of AWS resource attributes and metadata to help clients understand their cloud security posture.
There are a handful of tools (e.g. AWS...
Kit Hunter: A basic phishing kit detection tool
Version 2.6.0
28 September 2021
Testing and development took place on Python 3.7.3 (Linux)
What is Kit Hunter?
Kit Hunter is a personal project to learn Python, and a basic scanning tool that will search directories and locate phishing...
HawkScan
Security Tool for Reconnaissance and Information Gathering on a website. (python 2.x & 3.x)
This script uses “WafW00f” to detect the WAF in the first step.
This script uses “Sublist3r” to scan subdomains.
This script uses “waybacktool” to check in the waybackmachine.
Features...
SMM Matrix is a social media marketing tool. This software includes almost everything for you need to do a social media marketing business. It has services lined up for every social media platform and hence is a very versatile platform. Be it likes, followers, views, or even general engagement...
gh-dork – Github dorking tool
Supply a list of dorks and, optionally, one of the following:
a user (-u)
a file with a list of users (-uf)
an organization (-org)
a file with a list of organizations (-of)
a repo (-r)
You can also pass:
an output directory to store...
4-ZERO-3 Tool to bypass 403/401. This script contains all the possible techniques to do the same.
NOTE: If you see multiple [200 Ok]/bypasses as output, you must check the Content-Length. If the content-length is the same for multiple [200 Ok]/bypasses means false positive. Reason can be...
Jektor Toolkit v1.0
This utility focuses on shellcode injection techniques to demonstrate methods that malware may use to execute shellcode on a victim system
Dynamically resolves API functions to evade IAT inclusion
Includes usage of undocumented NT Windows API functions
...
What is Spray365?
Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). How is Spray365 different from the many other password spraying tools that are already available? Spray365 enables passwords to be sprayed from an “execution...
The Trident project is an automated password spraying tool developed to meet the following requirements:
the ability to be deployed on several cloud platforms/execution providers
the ability to schedule spraying campaigns in accordance with a target’s account lockout policy
the...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.