Monthly Shaarli

All links of one month in a single page.

September, 2023

tldraw
thumbnail

A free and instant collaborative diagramming tool.

GitHub - Pennyw0rth/NetExec: The Network Execution Tool
thumbnail

The Network Execution Tool. Contribute to Pennyw0rth/NetExec development by creating an account on GitHub.

OAuth Tools
thumbnail

Tools for exploring and testing OAuth and OpenID Connect flows. With this free tool you can learn and explore the inner workings of OpenID Connect and OAuth.

Blocking Visual Studio Code embedded reverse shell before it's too late
thumbnail

Visual studio code tunnel Introduction Since July 2023, Microsoft is offering the perfect reverse shell, embedded inside Visual Studio Code, a widely used …

NocoDB | Turns your SQL database into a Nocode platform. Free & Open Source.

Free & Open Source Airtable alternative. Turns any SQL database into a smart spreadsheet. Supports MySQL, Postgres, SQL server, MariaDB & SQLite.

GitHub - gentilkiwi/mimikatz: A little tool to play with Windows security
thumbnail

A little tool to play with Windows security. Contribute to gentilkiwi/mimikatz development by creating an account on GitHub.

RedTeam_CheatSheet.ps1 · GitHub
thumbnail

GitHub Gist: instantly share code, notes, and snippets.

Commando VM: The First of Its Kind Windows Offensive Distribution | Mandiant
thumbnail
GitHub - securisec/chepy: Chepy is a python lib/cli equivalent of the awesome CyberChef tool.
thumbnail

Chepy is a python lib/cli equivalent of the awesome CyberChef tool. - GitHub - securisec/chepy: Chepy is a python lib/cli equivalent of the awesome CyberChef tool.

GitHub - BishopFox/unredacter: Never ever ever use pixelation as a redaction technique
thumbnail

Never ever ever use pixelation as a redaction technique - GitHub - BishopFox/unredacter: Never ever ever use pixelation as a redaction technique

Introduction - NetExec
thumbnail

Learn to use NetExec

Let’s Go (VS) Code - Red Team style

Let’s Go (VS) Code - Red Team style or the Microsoft signed and hosted Reverse Shell TL;DR; MS is offering a signed binary (code.exe), which will establish a Command&Control channel via an official Microsoft domain https://vscode.dev. The C2 communication itself is going to https://global.rel.tunnels.api.visualstudio.com over WebSockets. An attacker only needs an Github account.

GitHub - pwnwriter/kanha: 🦚 A web-app pentesting suite written in rust .
thumbnail

🦚 A web-app pentesting suite written in rust . Contribute to pwnwriter/kanha development by creating an account on GitHub.

Windows Local Privilege Escalation - HackTricks
thumbnail
GitHub - noraj/OSCP-Exam-Report-Template-Markdown: :orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report
thumbnail

:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report - GitHub - noraj/OSCP-Exam-Report-Template-Markdown: :orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report

GitHub - sensepost/BiLE-suite: The Bi-directional Link Extractor.
thumbnail

The Bi-directional Link Extractor. Contribute to sensepost/BiLE-suite development by creating an account on GitHub.

Reco | Flathub
thumbnail

Record talks to remember the contents later

KnockKnock - Enumerate Valid Users Within Microsoft Teams And OneDrive With Clean Output
thumbnail

KnockKnock - Enumerate Valid Users Within Microsoft Teams And OneDrive With Clean Output http://www.kitploit.com/2023/09/knockknock-enumerate-valid-users-within.html

MarkDownload - Markdown Web Clipper – Get this Extension for 🦊 Firefox (en-GB)
thumbnail

Download MarkDownload - Markdown Web Clipper for Firefox. This extension works like a web clipper, but it downloads articles in a markdown format. Turndown and Readability.js are used as core libraries. It is not guaranteed to work with all websites.

Home - Freeplane Documentation
GitHub - pwnwriter/haylxon: ⚡ Blazing-fast tool to grab screenshots of your domain list right from terminal.
thumbnail

⚡ Blazing-fast tool to grab screenshots of your domain list right from terminal. - GitHub - pwnwriter/haylxon: ⚡ Blazing-fast tool to grab screenshots of your domain list right from terminal.

Dll Hijacking - HackTricks
thumbnail
Unofficial OSCP Approved Tools. The following is a list of OSCP…
thumbnail

The following is an unofficial list of OSCP approved tools that were posted in the PWK/OSCP Prep Discord Server ( https://discord.gg/eG6Nt4x ) and found on the internet. Please note it is by no means…

BloodHound: Six Degrees of Domain Admin — BloodHound 4.3.1 documentation
GitHub - eza-community/eza: A modern, maintained replacement for ls
thumbnail

A modern, maintained replacement for ls. Contribute to eza-community/eza development by creating an account on GitHub.

How to Hack Through a Pass-Back Attack: MFP Hacking Guide
thumbnail

Is that printer in your office vulnerable to a pass-back attack? Why Multi-Function Peripheral (MFP) Hacking an important tool in the pen tester's arsenal.