#tools
#OSINT
#WLAN_Security
iSniff GPS - Passive sniffing tool for capturing and visualising WiFi location data disclosed by iOS devices
https://github.com/hubert3/iSniff-GPS
#OSINT
#WLAN_Security
iSniff GPS - Passive sniffing tool for capturing and visualising WiFi location data disclosed by iOS devices
https://github.com/hubert3/iSniff-GPS
❤1
SEARCH ENGINES FOR PENTESTERS
01. shodan.io —> (Server , Vulnerabilities)
02. google.com —> (Dorks)
03. wigle.net —> (Wifi Networks)
04. grep.app —> (Codes Search)
05. app.binaryedge.io —> (Threat Intelligence)
06. onyphe.io —> (Server)
07. viz.greynoise.io —> (Threat Intelligence)
08. censys.io —> (Server)
09. hunter.io —> (Email Addresses)
10. fofa.info —> (Threat Intelligence)
11. zoomeye.org —> (Threat Intelligence)
12. leakix.net —> (Threat Intelligence)
13. intelx.io —> (OSINT)
14. app.netlas.io —> (Attack Surface)
15. searchcode.com —> (Code Search)
16. urlscan.io —> (Threat Intelligence)
17. publicwww.com —> (Code Search)
18. fullhunt.io —> (Attack Surface)
19. socradar.io —> (Threat
Intelligence)
20. binaryedge.io —> (Attack Surface)
21. ivre.rocks —> (Server)
22. crt.sh —> (Certificate Search)
23. vulners.com —> (Vulnerabilities)
24. pulsedive.com —> (Threat Intelligence)
01. shodan.io —> (Server , Vulnerabilities)
02. google.com —> (Dorks)
03. wigle.net —> (Wifi Networks)
04. grep.app —> (Codes Search)
05. app.binaryedge.io —> (Threat Intelligence)
06. onyphe.io —> (Server)
07. viz.greynoise.io —> (Threat Intelligence)
08. censys.io —> (Server)
09. hunter.io —> (Email Addresses)
10. fofa.info —> (Threat Intelligence)
11. zoomeye.org —> (Threat Intelligence)
12. leakix.net —> (Threat Intelligence)
13. intelx.io —> (OSINT)
14. app.netlas.io —> (Attack Surface)
15. searchcode.com —> (Code Search)
16. urlscan.io —> (Threat Intelligence)
17. publicwww.com —> (Code Search)
18. fullhunt.io —> (Attack Surface)
19. socradar.io —> (Threat
Intelligence)
20. binaryedge.io —> (Attack Surface)
21. ivre.rocks —> (Server)
22. crt.sh —> (Certificate Search)
23. vulners.com —> (Vulnerabilities)
24. pulsedive.com —> (Threat Intelligence)
❤1
APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains (Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing).
https://github.com/brinhosa/apidetector
https://github.com/brinhosa/apidetector
GitHub
GitHub - brinhosa/apidetector: APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports…
APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testin...
EasySpider
EasySpider is a visual tool designed for data collection, testing and web scraping, without the need to write code.
Users can easily create and complete tasks through a graphical interface by selecting elements on a web page and following prompts, without the need for coding.
The program also supports executing tasks via the command line, which makes it convenient for integration into other systems.
https://github.com/NaiboWang/EasySpider
EasySpider is a visual tool designed for data collection, testing and web scraping, without the need to write code.
Users can easily create and complete tasks through a graphical interface by selecting elements on a web page and following prompts, without the need for coding.
The program also supports executing tasks via the command line, which makes it convenient for integration into other systems.
https://github.com/NaiboWang/EasySpider
GitHub
GitHub - NaiboWang/EasySpider: A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别…
A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别名:ServiceWrapper面向Web应用的智能化服务封装系统。 - NaiboWang/EasySpider
5GBaseChecker: a security analysis framework that helps to hunt for 5G vulnerabilities
https://github.com/SyNSec-den/5GBaseChecker
https://github.com/SyNSec-den/5GBaseChecker
GitHub
GitHub - SyNSec-den/5GBaseChecker
Contribute to SyNSec-den/5GBaseChecker development by creating an account on GitHub.
#DriverJack: Turning #NTFS and Emulated Read-only Filesystems in an Infection and Persistence Vector
Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths
https://github.com/klezVirus/DriverJack
Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths
https://github.com/klezVirus/DriverJack
GitHub
GitHub - klezVirus/DriverJack: Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links…
Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths - klezVirus/DriverJack
Welcome to this new #workshop focused on the #Windows DLL Loading internals.
https://github.com/OtterHacker/Conferences/tree/main/Defcon32
https://github.com/OtterHacker/Conferences/tree/main/Defcon32
C2 Cloud - The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised backdoors, just like accessing an EC2 instance in the AWS cloud. It can manage several simultaneous backdoor sessions with a user-friendly interface.
https://github.com/govindasamyarun/c2-cloud?tab=readme-ov-file#application-setup
https://github.com/govindasamyarun/c2-cloud?tab=readme-ov-file#application-setup
GitHub
GitHub - govindasamyarun/c2-cloud: The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration…
The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised backdoors, just like accessing an EC2 instance in the AWS...
UnpromptedControl
Unprompted Control is a utility that allows you to automatically remove objects from images and repair corrupted images using deep learning and blending techniques.
The Control Net Model and Stable Diffusion Inpaint Pipeline play a key role in this process, guiding the restoration and ensuring that the results blend naturally with the surrounding image content.
However, this method has limitations, especially when processing images of people's faces and bodies, and may require masking not only the subject but also its shadows to achieve optimal results.
Despite these challenges, the repository provides a valuable tool for seamless object recovery and deletion.
https://github.com/vijishmadhavan/UnpromptedControl
Unprompted Control is a utility that allows you to automatically remove objects from images and repair corrupted images using deep learning and blending techniques.
The Control Net Model and Stable Diffusion Inpaint Pipeline play a key role in this process, guiding the restoration and ensuring that the results blend naturally with the surrounding image content.
However, this method has limitations, especially when processing images of people's faces and bodies, and may require masking not only the subject but also its shadows to achieve optimal results.
Despite these challenges, the repository provides a valuable tool for seamless object recovery and deletion.
https://github.com/vijishmadhavan/UnpromptedControl
GitHub
GitHub - vijishmadhavan/UnpromptedControl: Remove unwanted objects and restore images without prompts, powered by ControlNet.
Remove unwanted objects and restore images without prompts, powered by ControlNet. - vijishmadhavan/UnpromptedControl
❤1👍1
Manipulating Shim and Office for Code Injection
Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.
Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.
DefCon Presentation
https://github.com/deepinstinct/ShimMe
Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.
Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.
DefCon Presentation
https://github.com/deepinstinct/ShimMe
👍1
Search by image
Browser extension for Chrome, Edge and Safari.
Allows to take a screenshot of part of your screen and search for it in 45 different reverse image search engines.
Also search for an image via a link or downloaded from computer.
https://github.com/dessant/search-by-image
Browser extension for Chrome, Edge and Safari.
Allows to take a screenshot of part of your screen and search for it in 45 different reverse image search engines.
Also search for an image via a link or downloaded from computer.
https://github.com/dessant/search-by-image
❤1
SurfSense
SurfSense is a tool that helps users remember and organize content saved while browsing the Internet.
It works as a personal knowledge graph, allowing you to save, search, and interact with your web browser history using natural language queries.
The platform supports self-hosting, integrates with Neo4j for database management, and uses OpenAI's GPT models to improve search.
To get started with SurfSense, users must set up the backend, install the necessary dependencies, and run the Chrome extension, which captures and saves web content directly from the browser.
The extension allows you to save snapshots of web pages and later request the saved content.
https://github.com/MODSetter/SurfSense
SurfSense is a tool that helps users remember and organize content saved while browsing the Internet.
It works as a personal knowledge graph, allowing you to save, search, and interact with your web browser history using natural language queries.
The platform supports self-hosting, integrates with Neo4j for database management, and uses OpenAI's GPT models to improve search.
To get started with SurfSense, users must set up the backend, install the necessary dependencies, and run the Chrome extension, which captures and saves web content directly from the browser.
The extension allows you to save snapshots of web pages and later request the saved content.
https://github.com/MODSetter/SurfSense
GitHub
GitHub - MODSetter/SurfSense: Open-source NotebookLM alternative. Research the open web with live data(Reddit, YT, IG, TikTok,…
Open-source NotebookLM alternative. Research the open web with live data(Reddit, YT, IG, TikTok, Indeed, Google Search, Maps etc) through one platform, API or MCP server. Join our Discord: https://...
💔1
Archive of APT phishing campaigns
This repository contains papers on APT groups, which include examples of emails used in the phishing campaigns. Often, papers on APT group attacks do not provide email examples, which prompted me to create a repository that specifically includes on papers containing phishing emails. This list will be gradually expanded. Contributions are welcome. For reliability, each link has been duplicated through web archive.
https://github.com/wddadk/Phishing-campaigns
This repository contains papers on APT groups, which include examples of emails used in the phishing campaigns. Often, papers on APT group attacks do not provide email examples, which prompted me to create a repository that specifically includes on papers containing phishing emails. This list will be gradually expanded. Contributions are welcome. For reliability, each link has been duplicated through web archive.
https://github.com/wddadk/Phishing-campaigns
GitHub
GitHub - wddadk/Phishing-campaigns
Contribute to wddadk/Phishing-campaigns development by creating an account on GitHub.
Virtual machine focused on research in the field of OSINT. It has rich functionality and many up-to-date tools. In addition to the software, you will find a rich set of various cheat sheets, browser extensions (Mozilla and GH) and other necessary resources that will help you in your investigation.
https://github.com/midnit3Z0mbi3/Kali-Linux-OSINT-VM
https://github.com/midnit3Z0mbi3/Kali-Linux-OSINT-VM
❤1
IoT_cwe.pdf
420.3 KB
#IoT_Security
"Towards Weaknesses and Attack Patterns Prediction for IoT Devices", 2024.
]-> IoT CWE/CAPEC Datasets:
https://github.com/criveraalvarez/IoT_CWE-CAPEC_Dataset
"Towards Weaknesses and Attack Patterns Prediction for IoT Devices", 2024.
]-> IoT CWE/CAPEC Datasets:
https://github.com/criveraalvarez/IoT_CWE-CAPEC_Dataset
#exploit
1. CVE-2022-22265:
Samsung NPU driver
https://soez.github.io/posts/CVE-2022-22265-Samsung-npu-driver
2. Streaming vulnerabilities from Windows Kernel - Proxying to Kernel
https://devco.re/blog/2024/08/23/streaming-vulnerabilities-from-windows-kernel-proxying-to-kernel-part1-en
1. CVE-2022-22265:
Samsung NPU driver
https://soez.github.io/posts/CVE-2022-22265-Samsung-npu-driver
2. Streaming vulnerabilities from Windows Kernel - Proxying to Kernel
https://devco.re/blog/2024/08/23/streaming-vulnerabilities-from-windows-kernel-proxying-to-kernel-part1-en
👍1
Deep-HLR - the script retrieves social network accounts subscribed to the number (Amazon, Badoo, Bumble, Microsoft, Skype, Telegram, Twitter, Uber, Xiaomi, Bukalapak, Google Duo, Kakaotalk, TikTok, Google Account, Linkedin, Battlenet, Instagram, CallerID, Yandex, VK, Economic Times, WhatsApp, Line, NextDoor, Remind, Flipkart, JD, Viber and Venmo), checks availability, connectivity, portability and assesses risk, extracts operator, checks if it is included in data leaks, Retrieves geographic location and device information associated with a phone number in json format. It uses the Defastra Deep Phone HLR Check API to work.
➡️https://github.com/e-m3din4/deep-hlr
➡️https://github.com/e-m3din4/deep-hlr
GitHub
GitHub - e-m3din4/deep-hlr: Obtain a Phone Number full profile including HLR, Reputation, Carrier, Social Media Accounts, Geolocation…
Obtain a Phone Number full profile including HLR, Reputation, Carrier, Social Media Accounts, Geolocation, Validation, Availabilty, Portability and more. - e-m3din4/deep-hlr
🔥2👍1