nccgroup / whalescanLinks
Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable packages on the container
☆156Updated 2 years ago
Alternatives and similar repositories for whalescan
Users that are interested in whalescan are comparing it to the libraries listed below
Sorting:
- Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, an…☆144Updated 2 years ago
- SNIcat☆128Updated 4 years ago
- ☆70Updated 2 years ago
- automated password spraying tool☆147Updated 4 years ago
- Script to export Nessus results to a relational database for use in reports, analysis, or whatever else.☆70Updated 7 months ago
- Network assessment tool for various UDP Services covering both IPv4 and IPv6 protocols☆116Updated 5 years ago
- nse script to inject jndi payloads☆45Updated 3 years ago
- A Docker container for remote penetration testing.☆141Updated 4 years ago
- Scan your EC2 instance to find its vulnerabilities using Vuls (https://vuls.io/en/)☆89Updated 3 years ago
- ☆139Updated 2 years ago
- Open source tools, libraries, and datasets related to the runZero product and associated research☆124Updated 4 months ago
- d(ockerp)wn - a docker pwn tool manager☆155Updated 4 years ago
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆210Updated 5 years ago
- PatrowlHears - Vulnerability Intelligence Center / Exploits☆165Updated this week
- Terraform resources for building HTTP, DNS, phishing, and mail server red team infrastructure☆94Updated 6 years ago
- Fast offline auditing of Active Directory passwords using Python.☆165Updated last year
- Malicious actors often reuse code to deploy their malware, phishing website or CNC server. As a result, similiaries can be found on URLs …☆75Updated 2 years ago
- Script samples from the book Pentesting Azure Applications (2018, No Starch Press)☆88Updated 6 years ago
- ☆126Updated last year
- PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Pac…☆95Updated 4 years ago
- Boomerang is a tool to expose multiple internal servers to web/cloud. Agent & Server are pretty stable and can be used in Red Team for Mu…☆226Updated 4 years ago
- LLMNR/NBNS/mDNS Spoofing Detection Toolkit☆60Updated 3 years ago
- Cloud Security Operations Orchestrator☆188Updated last year
- Hayat is a script for report and analyze Google Cloud Platform resources.☆81Updated 5 years ago
- ☆36Updated 5 years ago
- Identify IP addresses owned by public cloud providers☆127Updated last year
- Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.☆257Updated 3 years ago
- Microsoft Azure Exploitation Framework☆59Updated 4 years ago
- Repository of resources for configuring a Red Team SIEM using Elastic☆102Updated 7 years ago
- Active Directory Lab for Penetration Testing☆52Updated 4 months ago