Github tools
2.74K subscribers
33 photos
2 videos
58 files
361 links
Github useful scripts and tools
Download Telegram
Burp Pro 2022.2 +
#soft #burp #web‌‌


Burp Pro 2022.2 + detailed installation instructions inside


#soft #burp #web‌‌
BurpBountyData.zip
205.5 KB
+ profiles for Burp Bounty‌‌
THE EVOLUTION OF EVIL CORP (2022).pdf
15.8 MB
EvilCorp

#malware #report‌‌


A cool analysis of the tools of the sensational group EvilCorp

#malware #report‌‌
Cylera Labs Kwampirs Shamoon Technical Report (2022).pdf
19 MB
This document details the tactics and tools of APT Orangeworm and Shamoon, as well as the connections between the groups.

#apt #malware #report‌‌
Delegating Kerberos to bypass Kerberos delegation limitation.



#ad #pentest #redteam #blueteam‌‌
Insomnihack 2022 - Delegating Kerberos.pdf
14.4 MB
Insomnihack 2022 - Delegating Kerberos.pdf

😵‍💫 Phishing. Browser within a browser.

No, today we will not
talk about a well-known meme, today we will talk about a new method of phishing attacks.

🖖🏻 Hello use
r_name.

• Back in 2020, Ragnar Locker (ransomware) was installed on the victim's PC using a virtual machine. Those. the locker dragged a full-fledged virtual machine to the attacked host, in which it was launched, then it got access to the host file system and encrypted the data. Perfect bypass of anti-virus protection, isn't it? By the way, Ragnar Locker was aimed at business. An example is the attack on the electricity supplier Energias de Portugal. Presumably, 10 terabytes of data were stolen from them, and the attackers demanded 1,580 bitcoins for decryption.

• But today we will talk about something else, although the direction and idea of ​​such attacks will be similar to the style described above. The essence of this method is to simulate a browser window in a browser, for example, to phish authentication data.

• Suppose that the victim goes to a certain resource, wants to log in using a Google/Microsoft/Apple account, clicks on the appropriate button, then a window with a login form appears, the victim looks at the address bar and checks the legitimacy of the resource, enters data and they are successfully sent to the attacker ...

• Thanks to the
magic of HTML, CSS and JavaScript, it is almost impossible to distinguish between a real and a phishing window (example), including the URL: https://mrd0x.com/browser-in-the-browser-phishing-attack/

• If you are interested in this method, then you can download various login forms (for different services) on GitHub, the repo includes various templates for Windows and Mac, and has several design options (dark and light mode). Will be useful for social engineers and Red Team: https://github.com/mrd0x/BITB

Your S.E. #SI #Phishing‌‌


Such posts are only posted in our github channel
2

🔐 We encrypt the correspondence. openkeychain.

“Without encryption, we will lose all privacy. This is our new battlefield."
- Edward
Snowden

🖖🏻 Hello user_name.

Protecting your data from prying eyes - in some cases it can be a matter of life and death, and relying on others in this matter means trusting them with your data. The useful OpenKeychain application for your #Android device will help protect your correspondence from prying eyes on your own.

#OpenKeychain is open source, security tested by Cure53, seamlessly integrates with K-9 Mail, Conversations Jabber, and can even transfer encrypted files to the EDS (Encrypted Data Store) application. All you need is to generate a key and send it to whoever you want to exchange messages with.

• How to install and configure Conversations/OpenKeychain can be found here: https://t.me/tvoijazz/391

• Homepage: http://www.openkeychain.org
• GitHub: https://github.com/open-keychain/open-keychain
• F-Droid: https://f-droid.org/en/packages/org.sufficientlysecure.keychain/
• 4PDA: https://4pda.to/forum/index.php?showtopic=772103

Your S.E.‌‌

🔖 A selection of useful information and resources.

💬 Hello user_name.

📌
Today I have collected enough useful information for you to study in various fields. Hope you find what you've been looking for. Add to favorites so as not to lose.

More than 100K resources on various topics. Starting from books on programming, ending with various blogs of software developers.
https://github.com/sindresorhus/awesome

https://tw
itter.com/awesome__re

A huge n
umber of resources on the topic of searching and collecting information from open sources.
https://github.com/jivoi/awesome-osint

Information security, forensics, cryptography, CTF, etc.
https://github.com/carpedm20/awesome-hacking

List o
f Honeypots (Traps for hackers). Manuals, tools, instructions, etc.
https://github.com/paralax/awesome-honeypots

List of tools and
resources for malware analysis.
https://github.com/rshipp/awesome-malware-analysis

List of frameworks, libraries, so
ftware and resources related to Python.
https://github.com/vinta/a
wesome-python

List of various PHP libr
aries, resources and cheat sheets.
https://github.com/zia
doz/awesome-php

List of CTFs, librar
ies, resources, software and tutorials.
https://github.com/apsdehal/awesome-ctf

A collection of
resources related to Android security + software and various guides.
https://github.com/ashishb/android-security-awesome

https://githu
b.com/JStumpp/awesome-android

Web applica
tion security. XSS, CSV and SQL Injection, ClickJacking and hundreds more.
https://github.com/qazbnm456/awesome-web-security

List of the best a
pplications and tools for Windows.
https://github.com/Awesome-Windows/Awesome

List of application
s and tools for Linux.
https://github.com/aleksandar-todorovic/awesome-linux

A collection of Raspbe
rry Pi tools, projects and resources.
https://github.com/
thibmaek/awesome-raspberry-pi

A collection of p
entest resources, from tools to books.
https://github.com/enaqx/awesome-pentest

P.S. This list does
not claim to be complete, if you have something to add to this list, write to the feedback bot in the channel description. Well, I remind you that you can find other useful information by hashtags in our group #Selection #Linux #Anonymity #Book #Course #Pentest #CTF #Raspberry #Android #Forensics

Share with your friends and stay with us.

Such posts are only posted on our github channel

T.me/githubx

🔖 A selection of useful information and resources. Part 2.

🖖🏻 Hello user_name.

💬
The previous post collected a lot of reposts and views, thanks to your feedback and activity, we will supplement this list so that our other subscribers can find the necessary information in various areas in the field of information security.

• A list of hacking training resources where you can legally and safely practice your cybersecurity skills. The list includes a lot of resources, from remote banking systems that contain common vulnerabilities to a collection of web applications that are vulnerable to command injection.

https://github.com/joe-shenouda/awesome-cyber-skil
ls

• A list of tips for protecting your digital sec
urity and privacy, with links to additional resources.

https://github.com/Lissy93/personal-security-checklist

• Lis
t of tools for network traffic research: Traffic Capture
, Traffic Analysis / Inspection, DNS Utilities, File Extraction and more...

https://github.com/caesar0301/awesome-pcaptools

• Web hacking. The list i
s intended for anyone who wants to learn about we
b application security, but does not have enough experience and knowledge in this area.

https://github.com/infoslack/awesome-web-hacking

• A hug
e list of software, libraries, documents, books, r
esources and interesting things about security.

https://github.com/sbilly/awesome-security

• C
ollection of resources, tools and other usef
ul materials for Cybersecurity Blue Team.

https://github.com/fabacab/awesome-cybersecurity-blue
team

• Our list of literature, courses, articles and use
ful materials that are published in the second channel, there is a convenient menu for convenience and finding the right material on a specific topic.

https://github.com/SE-adm/Book

• Com
pleting the selection is a list 
of must-see films for anyone interested in the subject of information security. Personally, I recommend that you get acquainted with documentaries.

https://github.com/k4m4/movies-for-hackers

‼️
 The list does not claim to be complete, onc
e a month we will supplement this collection with new material. Share with friends and save to your favorites so you don't lose. You can find other useful information by hashtags in our group #Compilation #Linux #Anonymity #Book #Course #Pentest #CTF #Raspberry #Android #Forensic‌‌

Tomorrow i will add on list 3.

This is only exclusive to our new channel t.me/githubx
CompTIA Network+ Practice Tests Exam N10-008, 2nd Edition.pdf
9 MB
📖 CompTIA Network+ Practice Tests: Exam N10-008, 2nd Edition.

• Дата выхода: 26 Октября 2021 года.
• Рейтинг: ⭐️⭐️⭐️⭐️⭐️ (5 out of 5)
• Цена в онлайн магазине: 35$

VT.

In the freshly revised Second Edition of CompTIA Network+ Practice Tests Exam N10-008, IT expert and author Craig Zacker delivers a set of accessible and useful practice tests for the updated Network+ Exam N10-008. You’ll prepare for the exam, learn the information you need in an industry interview, and get ready to excel in your first networking role.

These practice tests will gauge your skills in deploying wired and wireless devices; understanding network documentation and the purpose of network services; work with datacenter, cloud, and virtual networking concepts; monitor network activity; and more.

🧩 Софт для чтения.

#CompTIA #Network #Eng
2022_Vulnerability.pdf
14.9 MB
2022_Vulnerability.pdf

🔖 A selection of useful information and resources. Part 3

🖖🏻 Hello user_name.

💬 W
e continue to publish unique collections on various topics. Thanks to this information, you can improve your skill and get the necessary information - for free. Save to your favorites and check out the previous collections if for some reason you missed them:

• Starting our lis
t with Awesome Shodan Search Queries - The list contains ready-made queries for searching control systems, webcams, printers , IoT devices, and much more...

https://github.com/jakejarvis/awesome-shodan-queries

• Wi-Fi Arsenal - Everything that affects the subject of Wi-Fi. A lot of useful software for all occasions. General information, tools for auditing Wi-Fi networks, monitoring, collecting information and dozens of other sections:

https://github.com/techge/wifi-arsenal

https://github.com/edelahozuah/awesome-wifi-security/

• List of information for hacking IoT devices. The list contains a collection of articles that deal with hacking various devices, from smart light bulbs to smart door locks:

https://github.com/nebgnahz/awesome-iot-hacks

• Forensics. Free open source tools and resources. Includes useful tools, books, articles and various resources:

https://github.com/Cugu/awesome-forensics

• Repository with a list of useful resources for the system administrator:

https://github.com/kahun/awesome-sysadmin

• Additional information on Cobalt Strike. And also, do not forget about our selection related to this framework.

https://github.com/zer0yu/Awesome-CobaltStrike

‼️ The list does not claim to be complete, as we find useful material, we will supplement this collection. Share with friends and save to your favorites so you don't lose. You can find other useful information by hashtags in our group #Selection #Linux #Anonymity #Book #Course #Pentest #CTF #Raspberry #Android #Forensic. Your S.E.‌‌

Such information is only published in our github channel.
t.me/githubx