mandiant / heyserialLinks
Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types
☆144Updated 2 years ago
Alternatives and similar repositories for heyserial
Users that are interested in heyserial are comparing it to the libraries listed below
Sorting:
- Determine the Palo Alto PAN-OS software version of a remote GlobalProtect portal or management interface.☆128Updated last year
- This script is a multi-threaded Okta password sprayer.☆72Updated last year
- ☆67Updated 6 years ago
- A Red Team tool for exfiltrating sensitive data from Confluence pages.☆112Updated 2 years ago
- A list of "secrets" from JWT sample code and readme files.☆56Updated 4 years ago
- ☆90Updated 3 years ago
- ☆54Updated 4 years ago
- Lookup for interesting stuff in SMB shares☆149Updated 2 years ago
- Slackhound allows red and blue teams to perform fast reconnaissance on Slack workspaces/organizations to quickly search user profiles, lo…☆82Updated last week
- A Red Team tool for exfiltrating sensitive data from Jira tickets.☆85Updated 2 years ago
- Posts about different topics☆36Updated last year
- nse script to inject jndi payloads☆46Updated 3 years ago
- Static code analysis tool based on Elasticsearch☆129Updated 4 years ago
- BurpSuite Extension: A one-stop pen testing checklist and logger tool☆75Updated 2 years ago
- Terraform resources for building HTTP, DNS, phishing, and mail server red team infrastructure☆95Updated 6 years ago
- Enumerate AD through LDAP with a collection of helpfull scripts being bundled☆145Updated 2 weeks ago
- GoldenSAML Attack Libraries and Framework☆73Updated last year
- C# and Impacket implementation (here with Kerberos auth support) of PrintNightmare CVE-2021-1675/CVE-2021-34527☆29Updated 4 years ago
- Determine the running software version of a remote F5 BIG-IP management interface.☆67Updated last year
- Find the remote website version based on a git repository☆125Updated 4 years ago
- Zuthaka is an open source application designed to assist red-teaming efforts, by simplifying the task of managing different APTs and othe…☆177Updated 2 years ago
- User enumeration and password spraying tool for testing Azure AD☆70Updated 3 years ago
- ☆36Updated 5 years ago
- A Python implementation of dafthack's MSOLSpray. A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if …☆91Updated last year
- cvet is a Python utility for pulling actionable vulnerabilities from cvetrends.com☆39Updated 2 years ago
- Brute force attack tool for Azure AD Autologon/Seamless SSO - Source: https://arstechnica.com/information-technology/2021/09/new-azure-ac…☆103Updated last year
- ☆117Updated 4 years ago
- Any presentation we've given at FortyNorth Security☆34Updated 3 years ago
- Vulnerable thick client applications used as examples in the Introduction to Hacking Desktop Applications blog series☆102Updated last year
- Dynamic Labs is an open source tool aimed at red teamers and pentesters for the quick deployment of flexible, transient and cloud-hosted …☆61Updated last year