disclose / research-threats
Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg
☆294Updated 2 months ago
Alternatives and similar repositories for research-threats:
Users that are interested in research-threats are comparing it to the libraries listed below
- CQ, a code security scanner☆100Updated 10 months ago
- Private key usage verification☆432Updated 3 months ago
- Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration☆293Updated this week
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆210Updated 4 years ago
- An open source intelligence tool to crawl the graph of certificate Alternate Names☆348Updated last year
- QEMU setup for emulating satellite firmware for Hack-A-Sat final event☆87Updated 2 years ago
- An extensively configurable tool providing a summary of the changes between two files or directories, ignoring all the fluff you don't ca…☆202Updated 2 years ago
- ☆45Updated 3 years ago
- Burp with Friends☆102Updated 2 years ago
- A small collection of potentially useful contract templates☆386Updated 3 years ago
- One-stop TLS traffic inspection and manipulation using dynamic instrumentation☆243Updated 2 years ago
- Database of polyglot files. By polyglot, we mean files readable in multiple formats☆132Updated 6 years ago
- ☆77Updated 10 months ago
- Search exposed EBS volumes for secrets☆297Updated last year
- A curated list of awesome browser security learning material.☆140Updated 2 years ago
- Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki☆203Updated 5 months ago
- ☆229Updated last year
- A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation☆230Updated 4 years ago
- A Passive SSH back-end and scanner.☆102Updated last month
- Trail of Bits Testing Handbook☆69Updated this week
- An Open Letter to the OWASP Board☆106Updated last year
- Minimal code to connect to a CEF debugger.☆204Updated 4 years ago
- Binary Golf Grand Prix☆111Updated last year
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆122Updated last year
- Open a DNS server that knows no records but records every request. Used for DNS exfiltration.☆68Updated 3 years ago
- App that simplifies building decision trees to model adverse scenarios☆205Updated 8 months ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆350Updated 4 years ago
- Tools for investigating Log4j CVE-2021-44228☆94Updated 3 years ago
- A tool to hunt for credentials in github wild AKA git*hunt☆294Updated 2 years ago
- Attack Surface Management since before Attack Surface Management was a thing☆639Updated this week