sdcampbell / nmapurls
Nmapurls parses Nmap xml reports from either piped input or command line arg and outputs a list of http(s) URL's to be used in an automation pipeline.
☆39Updated last year
Alternatives and similar repositories for nmapurls:
Users that are interested in nmapurls are comparing it to the libraries listed below
- Generate password spraying lists based on the pwdLastSet-attribute of users.☆55Updated last year
- Source code and examples for PassiveAggression☆55Updated 8 months ago
- A Moodle Scanner☆39Updated 3 months ago
- Small Script that permits to enumerate folders in Windows Defender Exclusion List with no Administrative privileges☆21Updated 3 months ago
- Contexter - A secondary context path traversal / server-side parameter pollution testing tool written in Python 3☆21Updated 6 months ago
- Check for CVE-2024-22024 vulnerability in Ivanti Connect Secure☆29Updated last year
- A script to automatically dump all URLs present in /server-status to a file locally.☆23Updated last week
- A tool to abuse weak permissions of Active Directory Discretionary Access Control Lists (DACLs) and Access Control Entries (ACEs)☆52Updated 2 months ago
- A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.☆81Updated last year
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆39Updated 8 months ago
- HTTP flyover tool based on the httpx library by ProjectDiscovery☆34Updated 5 months ago
- exfiltration/infiltration toolkit☆23Updated last year
- Dump Kerberos tickets from the KCM database of SSSD☆49Updated 5 months ago
- this script adds the ability to encode shellcode (.bin) in XOR,chacha20, AES. You can choose between 2 loaders (Myph / 221b)☆78Updated last year
- .NET deserialization hunter☆76Updated 7 months ago
- Tool to perform GCP Domain Wide Delegation abuse and access Gmail and Drive data☆44Updated last year
- User enumeration and password spraying tool for testing Azure AD☆69Updated 2 years ago
- Enumerate valid users within Microsoft Teams and OneDrive with clean output.☆57Updated 2 weeks ago
- Azure Service Subdomain Enumeration☆52Updated 5 months ago
- Duplicate not owned Token from Running Process☆72Updated last year
- ☆54Updated 3 months ago
- A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it☆48Updated 11 months ago
- Pre-Auth Exploit for CVE-2024-40711☆39Updated 5 months ago
- Uses rpcdump to locate the ADCS server, and identify if ESC8 is vulnerable from unauthenticated perspective.☆78Updated 5 months ago
- Deduplicate custom BloudHound queries from different datasets and merge them in one customqueries.json file.☆36Updated 10 months ago
- ☆52Updated last year
- CVE-2023-34362: MOVEit Transfer Unauthenticated RCE☆62Updated 10 months ago
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆57Updated last year
- ☆25Updated last year
- Proof of Concept Exploit for CVE-2024-9465☆28Updated 4 months ago