<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>pentest</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/296/feed"/>
    <updated>2026-09-15T08:39:53+00:00</updated>
    <id>https://links.biapy.com/guest/tags/296/feed</id>
            <entry>
            <id>https://links.biapy.com/links/13865</id>
            <title type="text"><![CDATA[AgentHound]]></title>
            <link rel="alternate" href="https://agenthound.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13865"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Offensive security for agentic infrastructure.
 The red team framework for AI agent infrastructure.

Drop one static collector on a compromised host. One active scan captures configs and raw credentials, discovers MCP, A2A and AI services, reuses compatible secrets, proves concrete access, and checkpoints the evidence before the foothold disappears. Ingest later for full graph analysis. 

Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.

- [AgentHound @ GitHub](https://github.com/adithyan-ak/AgentHound).]]>
            </summary>
            <updated>2026-09-10T11:41:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13774</id>
            <title type="text"><![CDATA[Airgorah]]></title>
            <link rel="alternate" href="https://github.com/martin-olivier/airgorah" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13774"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A WiFi security auditing software mainly based on aircrack-ng tools suite.

Airgorah is a WiFi security auditing software that can capture nearby WiFi traffic, discover clients connected to access points, perform deauthentication attacks, capture handshakes, and crack the password of access points.]]>
            </summary>
            <updated>2026-09-03T18:58:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13772</id>
            <title type="text"><![CDATA[iwa-tools]]></title>
            <link rel="alternate" href="https://iwa-tools.pkilla.pw/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13772"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Offensive AD tradecraft in a browser tab.

A suite of Active Directory attack tools built as Chrome Isolated Web Apps. Raw TCP straight from a signed web app via the Direct Sockets API — no loader, no PE, no third-party libraries. Kerberos, TLS and DCE-RPC hand-rolled in JavaScript.]]>
            </summary>
            <updated>2026-09-03T18:54:41+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13770</id>
            <title type="text"><![CDATA[Pentest Harness]]></title>
            <link rel="alternate" href="https://github.com/S1N6H/pentest-harness" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13770"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Pentest Harness — Heaven for Hackers. A self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Bring your own AI model API; sessions stay local.

An open-source, dark-first AI agent harness for authorized penetration tests, bug bounty research, security labs, and CTF engagements. Built on a plugin architecture where every layer — model adapters, tools, sessions, settings, and credentials — is replaceable from configuration.

Works with any AI model API. Bring your own key from OpenAI, Anthropic, DeepSeek, Google, Mistral, Groq, OpenRouter, Azure OpenAI, or any OpenAI-compatible gateway — one click auto-discovers your models and you&amp;#039;re running.]]>
            </summary>
            <updated>2026-09-03T18:50:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13726</id>
            <title type="text"><![CDATA[secfiles]]></title>
            <link rel="alternate" href="https://github.com/edoardottt/secfiles" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13726"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[My useful files for penetration tests, security assessments, bug bounty and other security related stuff.]]>
            </summary>
            <updated>2026-08-24T08:46:41+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13704</id>
            <title type="text"><![CDATA[A.I.G (AI-Infra-Guard) :cn:]]></title>
            <link rel="alternate" href="https://tencent.github.io/AI-Infra-Guard/?menu=index_openSource_en" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13704"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A.I.G (AI-Infra-Guard) is a comprehensive, intelligent, and user-friendly AI Red Teaming security testing platform developed by Tencent Zhuque Lab.

- [A.I.G (AI-Infra-Guard) @ GitHub](https://github.com/Tencent/AI-Infra-Guard).]]>
            </summary>
            <updated>2026-08-21T12:11:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13651</id>
            <title type="text"><![CDATA[HexStrike AI MCP Agents]]></title>
            <link rel="alternate" href="https://github.com/0x4m4/hexstrike-ai" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13651"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Advanced AI-powered penetration testing MCP framework with 150+ security tools and 12+ autonomous AI agents.

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

Related contents:

- [Episode 680: Go Hack Yourself @ Linux Unplugged](https://linuxunplugged.com/680).]]>
            </summary>
            <updated>2026-08-17T07:01:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13466</id>
            <title type="text"><![CDATA[Recon Skills]]></title>
            <link rel="alternate" href="https://github.com/uphiago/recon-skills" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13466"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An evolving recon &amp;amp; pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested.

A curated pack of security skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting.]]>
            </summary>
            <updated>2026-07-31T11:36:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13348</id>
            <title type="text"><![CDATA[ADPathFinder]]></title>
            <link rel="alternate" href="https://github.com/NetSPI/AD-PathFinder" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13348"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

ADPathFinder is an attack mapping tool for pentesters and red teamers. It analyses SharpHound data and unifies it with OpenGraph plugins to surface attack paths to high-value targets such as Domain Admins and Domain Controllers, starting from low-privileged users and computers. MSSQLHound and ConfigManBearPig are supported natively, extending coverage across AD, ADCS, SCCM, and MSSQL.

Related contents:

- [ADPathFinder: OpenGraph Attack Path Mapping in BloodHound CE @ NetSPI](https://www.netspi.com/blog/technical-blog/network-pentesting/adpathfinder-opengraph-attack-path-mapping-in-bloodhound-ce/).]]>
            </summary>
            <updated>2026-07-20T15:33:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13291</id>
            <title type="text"><![CDATA[Nox]]></title>
            <link rel="alternate" href="https://kernelstub.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13291"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Modular Go framework for attack surface management, reconnaissance, and vulnerability scanning. 

NOX is a modular, Go based attack surface management and vulnerability scanning framework. It ships with 300 built in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and deep active vulnerability testing across injection, authentication, authorization, client side, cloud, API, and business logic vulnerability classes.

- [Nox @ GitHub](https://github.com/kernelstub/Nox).]]>
            </summary>
            <updated>2026-07-15T07:50:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13227</id>
            <title type="text"><![CDATA[T3MP3ST]]></title>
            <link rel="alternate" href="https://github.com/elder-plinius/T3MP3ST" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13227"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[autonomous red teaming platform; multi-agent offensive-security meta-harness.

A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.]]>
            </summary>
            <updated>2026-07-06T11:34:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/13120</id>
            <title type="text"><![CDATA[Strix]]></title>
            <link rel="alternate" href="https://www.strix.ai/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/13120"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Autonomous Security for the AI Era.

Open-source AI hackers to find and fix your app’s vulnerabilities. 
Strix are autonomous AI agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proof-of-concepts. Built for developers and security teams who need fast, accurate security testing without the overhead of manual pentesting or the false positives of static analysis tools.

- [Strix @ GitHub](https://github.com/usestrix/strix).

Related contents:

- [Strix : le pentester IA open-source à l&amp;#039;épreuve de la souveraineté @ DevSecOps :fr:](https://blog.stephane-robert.info/post/strix-pentester-ia-souverainete/).]]>
            </summary>
            <updated>2026-06-26T09:52:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12877</id>
            <title type="text"><![CDATA[ghosttype]]></title>
            <link rel="alternate" href="https://github.com/xFreed0m/ghosttype" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12877"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
 
Local forensic scanner that extracts and verifies credentials from AI tool conversation history. Detection + verification powered by TruffleHog.]]>
            </summary>
            <updated>2026-06-01T15:50:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12765</id>
            <title type="text"><![CDATA[Sn1per]]></title>
            <link rel="alternate" href="https://sn1persecurity.com/wordpress/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12765"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The offensive-security platform for modern teams.

Recon, scanning, exploitation, and reporting in a single workspace — whether you&amp;#039;re a solo pentester or a global SOC. 

- [Sn1per @ GitHub](https://github.com/1N3/Sn1per).]]>
            </summary>
            <updated>2026-05-15T13:24:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12689</id>
            <title type="text"><![CDATA[GTFOBins]]></title>
            <link rel="alternate" href="https://gtfobins.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12689"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

The project collects legitimate functions of Unix-like executables that can be abused to get the f**k break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate other post-exploitation tasks.

- [GTFOBins @ GitHub](https://github.com/GTFOBins/GTFOBins.github.io).

Related contents:

- [GTFOBins - 478 binaires Unix qui font tomber root @ Korben :fr:](https://korben.info/gtfobins-binaires-unix-escalade-privileges.html).]]>
            </summary>
            <updated>2026-05-14T09:09:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12662</id>
            <title type="text"><![CDATA[MSSQLHound]]></title>
            <link rel="alternate" href="https://github.com/SpecterOps/MSSQLHound" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12662"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Go (formerly PowerShell) collector for adding MSSQL attack paths to BloodHound with OpenGraph.

A collector for adding MSSQL attack paths to BloodHound with OpenGraph by Chris Thompson at SpecterOps. Available as both a PowerShell script and a cross-platform Go binary (with concurrent collection, SOCKS5 proxy support, and streaming output).

Related contents:

- [MSSQLHound Now Available in Go @ SpecterOps](https://specterops.io/blog/2026/04/23/mssqlhound-now-available-in-go/).]]>
            </summary>
            <updated>2026-04-30T11:27:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12659</id>
            <title type="text"><![CDATA[DorkEye]]></title>
            <link rel="alternate" href="https://xploits3c.github.io/DorkEye/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12659"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated Google Dorking Tool. Generates and runs advanced search queries for exposed files. It also test Vulns, Analyzes and extracts metadata.

- [DorkEye @ GitHub](https://github.com/xPloits3c/DorkEye).]]>
            </summary>
            <updated>2026-04-30T11:23:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12658</id>
            <title type="text"><![CDATA[claude-red]]></title>
            <link rel="alternate" href="https://github.com/SnailSploit/Claude-Red" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12658"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.]]>
            </summary>
            <updated>2026-04-30T11:21:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12657</id>
            <title type="text"><![CDATA[SmokedMeat]]></title>
            <link rel="alternate" href="https://github.com/boostsecurityio/smokedmeat" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12657"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A CI/CD Red Team Framework for demonstrating Build Pipeline security risks. 

SmokedMeat is a post-exploitation framework for CI/CD pipelines. Point it at a GitHub organization, let it find vulnerable workflows, deploy an implant to a compromised runner, then pivot through cloud providers, extract secrets, and map the blast radius - all from a terminal UI.

Related contents:

- [SmokedMeat: A Red Team Tool to Hack Your Pipelines First @ Boost Security Labs](https://labs.boostsecurity.io/articles/introducing-smokedmeat/).]]>
            </summary>
            <updated>2026-04-30T11:21:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12610</id>
            <title type="text"><![CDATA[Gopacket]]></title>
            <link rel="alternate" href="https://github.com/mandiant/gopacket/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12610"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Gopacket is a clean Go implementation of Impacket, a library intended for working with network protocols. 

A complete Go implementation of Impacket - 63 tools and 24 library packages for Windows network protocol interaction, Active Directory enumeration, and attack execution. Built as a native Go framework so you can compile once and run anywhere without Python dependencies.]]>
            </summary>
            <updated>2026-04-23T13:55:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12556</id>
            <title type="text"><![CDATA[Goauld]]></title>
            <link rel="alternate" href="https://hazegard.github.io/Goauld-doc/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12556"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Goauld is a post-exploitation and remote access tool designed for use in restricted environments.

During penetration tests, operators may be required to work from a client-provided laptop behind VPNs, authenticated egress proxies, or restrictive network controls. In other cases, gaining remote code execution on a system still requires establishing a stable and fully interactive access channel.

Goauld solves these problems by providing a tunneling and access framework that allows operators to interact with remote agents through multiple transport protocols while maintaining a secure SSH-based architecture.

- [Goauld @ GitHub](https://github.com/Hazegard/Goauld).

Related contents:

- [\#72 - Microsoft et Adobe corrigent une vulnérabilité déjà exploitée @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-72-microsoft-et-adobe-corrigent-une-vuln-rabilit-d-j-exploit-e).]]>
            </summary>
            <updated>2026-04-16T11:41:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12524</id>
            <title type="text"><![CDATA[PentAGI]]></title>
            <link rel="alternate" href="https://pentagi.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12524"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PentAGI: Advanced AI-Powered Penetration Testing

Fully autonomous AI Agent that performs complicated penetration testing tasks using terminal, browser, editor, and external search system.

- [PentAGI @ GitHub](https://github.com/vxcontrol/pentagi).]]>
            </summary>
            <updated>2026-04-13T04:06:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12396</id>
            <title type="text"><![CDATA[JamfHound]]></title>
            <link rel="alternate" href="https://github.com/SpecterOps/JamfHound" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12396"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by outputting data as JSON for ingestion into BloodHound. 

Related contents:

- [JamfHound v1.1 Update: SSO Attack Paths and Okta Additions @ Specter OPS](https://specterops.io/blog/2026/03/31/jamfhound-v1-1-update-sso-attack-paths-and-okta-additions/).]]>
            </summary>
            <updated>2026-04-03T13:50:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12393</id>
            <title type="text"><![CDATA[VICE]]></title>
            <link rel="alternate" href="https://github.com/Webba-Creative-Technologies/vice" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12393"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Security auditing CLI for web applications.

VICE is a security auditing CLI tool that finds vulnerabilities in your web applications. It has two modes:

Remote scan gives it a URL. It crawls your site with a real browser, extracts secrets from JS bundles, tests your login for brute force and SQL injection, scans your VPS ports, checks your Supabase RLS, and more. Like an attacker would, but on your own systems.

Local audit points it at your project directory. It reads your source code, checks your .env files, runs npm audit, analyzes your Supabase migrations for missing RLS, finds SQL injections and XSS in your code, and tells you exactly what to fix.]]>
            </summary>
            <updated>2026-04-03T13:26:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12335</id>
            <title type="text"><![CDATA[Anthropic Cybersecurity Skills]]></title>
            <link rel="alternate" href="https://www.mahipal.engineer/Anthropic-Cybersecurity-Skills/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12335"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[734 Cybersecurity Skills for AI Agents.
734+ AI-Ready Skills for Claude Code &amp;amp; More.

The largest open-source library of structured cybersecurity skills following the agentskills.io standard. Deploy instantly to Claude Code, GitHub Copilot, Cursor, and 26+ platforms. 

- [Anthropic Cybersecurity Skills @ GitHub](https://github.com/mukul975/Anthropic-Cybersecurity-Skills).]]>
            </summary>
            <updated>2026-03-28T11:55:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12236</id>
            <title type="text"><![CDATA[Nord Stream]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/nord-stream" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12236"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab. 

Related contents:

- [CI/CD secrets extraction, tips and tricks @ Synacktiv](https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks).]]>
            </summary>
            <updated>2026-03-23T14:24:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12186</id>
            <title type="text"><![CDATA[VMkatz]]></title>
            <link rel="alternate" href="https://github.com/nikaiw/VMkatz" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12186"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Extract Windows credentials directly from VM memory snapshots and virtual disks]]>
            </summary>
            <updated>2026-03-19T14:35:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12094</id>
            <title type="text"><![CDATA[Lab4PurpleSec]]></title>
            <link rel="alternate" href="https://github.com/0xMR007/Lab4PurpleSec" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12094"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense + Suricata, and a Wazuh SIEM. It provides a realistic, open-source training environment for web exploitation, pivoting, Active Directory attacks, and Blue Team detection.]]>
            </summary>
            <updated>2026-03-12T11:11:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12021</id>
            <title type="text"><![CDATA[redStack]]></title>
            <link rel="alternate" href="https://github.com/BaddKharma/redStack" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12021"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Boot-to-Breach red team lab on AWS. Mythic, Sliver, and Havoc C2 behind a production-style Apache redirector. Deployed via Terraform. 

Related contents:

- [\#66 @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-66).]]>
            </summary>
            <updated>2026-03-05T12:12:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12006</id>
            <title type="text"><![CDATA[bettercap]]></title>
            <link rel="alternate" href="https://www.bettercap.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12006"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Swiss Army knife for WiFi, Bluetooth Low Energy, wireless HID hijacking, CAN-bus and IPv4 and IPv6 networks reconnaissance and MITM attacks.

bettercap is a powerful, easily extensible and portable framework written in Go which aims to offer to security researchers, red teamers and reverse engineers an easy to use, all-in-one solution with all the features they might possibly need for performing reconnaissance and attacking WiFi networks, Bluetooth Low Energy devices, CAN-bus, wireless HID devices and Ethernet networks.

- [bettercap @ GitHub](https://github.com/bettercap/bettercap).]]>
            </summary>
            <updated>2026-03-04T08:22:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12001</id>
            <title type="text"><![CDATA[Red Team Leaders C2 Framework (RTLC2)]]></title>
            <link rel="alternate" href="https://github.com/CyberSecurityUP/RTLC2" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12001"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Advanced Command and Control Framework for Authorized Red Team Operations]]>
            </summary>
            <updated>2026-03-03T16:23:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11975</id>
            <title type="text"><![CDATA[AirSnitch]]></title>
            <link rel="alternate" href="https://github.com/vanhoefm/airsnitch" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11975"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Testing Wi-Fi Client Isolation.

a set of attacks that enable a guest user to bypass Wi-Fi client isolation. Or put differently, it allows an adverary who can connect to your network, either as a malicious insider or by connecting to a co-located open network, to &amp;#039;bypass Wi-Fi encryption&amp;#039;.

Related contents:

- [AirSnitch @ GitHub](https://github.com/zhouxinan/airsnitch).
- [AirSnitch - L&amp;#039;isolation client WiFi ne vous protège pas @ Korben :fr:](https://korben.info/airsnitch-isolation-client-wifi-contournee.html). 
- [AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks @ NDSS](https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/).]]>
            </summary>
            <updated>2026-03-05T12:19:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11968</id>
            <title type="text"><![CDATA[MCP Hammer]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/MCPHammer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11968"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[MCP security testing framework for evaluating Model Context Protocol server vulnerabilities.

A Model Context Protocol (MCP) server built with FastMCP that provides various tools including Claude AI integration, text injection capabilities, and server information utilities. It is definitely super secure, you should definitely send confidential data through it, and definitely take everything it says as fact.

Related contents:

- [MCP Server Security: The Hidden AI Attack Surface @ Praetorian](https://www.praetorian.com/blog/mcp-server-security-the-hidden-ai-attack-surface).]]>
            </summary>
            <updated>2026-03-02T06:48:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11927</id>
            <title type="text"><![CDATA[Brutus]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/brutus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11927"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Modern credential testing tool in pure Go.

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native fingerprintx/naabu pipeline integration. 

Brutus is a multi-protocol authentication testing tool designed to address a critical gap in offensive security tooling: efficient credential validation across diverse network services. While HTTP-focused tools are abundant, penetration testers and red team operators frequently encounter databases, SSH, SMB, and other network services that require purpose-built authentication testing capabilities.]]>
            </summary>
            <updated>2026-02-26T11:12:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11926</id>
            <title type="text"><![CDATA[RedAmon]]></title>
            <link rel="alternate" href="https://github.com/samugit83/redamon" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11926"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Unmask the hidden before the world does.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.]]>
            </summary>
            <updated>2026-02-26T11:11:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11905</id>
            <title type="text"><![CDATA[Augustus]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/augustus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11905"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[LLM Vulnerability Scanner.

Test large language models against 210+ adversarial attacks covering prompt injection, jailbreaks, encoding exploits, and data extraction.

Related contents:

- [Digest \#202: Terraform Claude Skills, FinOps FOCUS 1.2, AI Fatigue for Cloud Engineers, and MCP for Web Data Extraction @ DevOps Bulletin](https://www.devopsbulletin.com/p/digest-202-terraform-claude-skills).]]>
            </summary>
            <updated>2026-02-24T07:13:40+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11857</id>
            <title type="text"><![CDATA[ROADtools]]></title>
            <link rel="alternate" href="https://github.com/dirkjanm/ROADtools" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11857"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[(Rogue Office 365 and Azure (active) Directory tools)

A collection of Azure AD/Entra tools for offensive and defensive security purposes.

ROADtools is a framework to interact with Azure AD. It consists of a library (roadlib) with common components, the ROADrecon Azure AD exploration tool and the ROADtools Token eXchange (roadtx) tool.

Related contents:

- [STOP THE CAP: Making Entra ID Conditional Access Make Sense Offline @ SpecterOps](https://specterops.io/blog/2026/02/17/stop-the-cap-making-entra-id-conditional-access-make-sense-offline/).]]>
            </summary>
            <updated>2026-02-19T12:38:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11789</id>
            <title type="text"><![CDATA[DumpGuard]]></title>
            <link rel="alternate" href="https://github.com/bytewreck/DumpGuard" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11789"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems. 

Related contents:

- [Cracking Credential Guard with DumpGuard @ The Weekly Purple Team&amp;#039;s YouTube](https://www.youtube.com/watch?v=wCM2R6cMrkA).]]>
            </summary>
            <updated>2026-02-12T09:55:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11788</id>
            <title type="text"><![CDATA[Julius]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/julius" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11788"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[LLM Service Fingerprinting Tool.

Simple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 30+ other AI services in seconds.

Julius is an LLM service fingerprinting tool for security professionals. It detects which AI server software is running on network endpoints during penetration tests, attack surface discovery, and security assessments.

Unlike model fingerprinting tools that identify which LLM generated text, Julius identifies the server infrastructure: Is that endpoint running Ollama? vLLM? LiteLLM? A Hugging Face deployment? Julius answers in seconds.

Related contents:

- [Erreur 403 | \#63 :fr:](https://newsletter.erreur403.fr/p/erreur-403-63).
- [Introducing Julius: Open Source LLM Service Fingerprinting @ Praetorian](https://www.praetorian.com/blog/introducing-julius-open-source-llm-service-fingerprinting/).]]>
            </summary>
            <updated>2026-02-12T09:36:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11787</id>
            <title type="text"><![CDATA[Burp AI Agent]]></title>
            <link rel="alternate" href="https://burp-ai-agent.six2dez.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11787"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The bridge between Burp Suite and modern AI.

Burp AI Agent is an extension for Burp Suite that integrates AI capabilities into your security workflow.

 Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more 

- [Burp AI Agent @ GitHub](https://github.com/six2dez/burp-ai-agent).

Related contents:

- [Erreur 403 | \#63 :fr:](https://newsletter.erreur403.fr/p/erreur-403-63).]]>
            </summary>
            <updated>2026-02-12T09:34:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11777</id>
            <title type="text"><![CDATA[Shannon]]></title>
            <link rel="alternate" href="https://github.com/KeygraphHQ/shannon" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11777"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Shannon is your fully autonomous AI pentester.

Shannon’s job is simple: break your web app before anyone else does.
The Red Team to your vibe-coding Blue team.
Every Claude (coder) deserves their Shannon.

 Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark.

Related contents:

- [Shannon - L&amp;#039;IA qui pentest votre code toute seule @ Korben :fr:](https://korben.info/shannon-pentester-ia-autonome.html).]]>
            </summary>
            <updated>2026-02-16T09:34:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11720</id>
            <title type="text"><![CDATA[God&amp;#039;s Eye]]></title>
            <link rel="alternate" href="https://github.com/Vyntral/god-eye" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11720"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI-powered subdomain enumeration tool with local LLM analysis via Ollama - 100% private, zero API costs.

God&amp;#039;s Eye is a powerful, ultra-fast subdomain enumeration and reconnaissance tool written in Go. It combines multiple passive sources with active DNS brute-forcing and comprehensive security checks to provide a complete picture of a target&amp;#039;s attack surface.

Related contents:

- [Newsletter du 19 Janvier 2026 @ Rudeops :fr:](https://www.rudeops.com/newsletter/2026-01-19-rudeops-newsletter/).]]>
            </summary>
            <updated>2026-02-06T10:17:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11704</id>
            <title type="text"><![CDATA[Supabase Exposure Check]]></title>
            <link rel="alternate" href="https://github.com/bscript/supabase-exposure-check" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11704"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scan websites for exposed Supabase JWTs, enumerate accessible tables, and detect sensitive data exposure automatically. 

A Python script that scans websites for exposed Supabase JWT tokens, enumerates accessible database tables, and analyzes them for sensitive data exposure. The script automatically detects sensitive information (emails, passwords, API keys, PII, financial data, etc.) and classifies vulnerability levels to identify which tables pose security risks.]]>
            </summary>
            <updated>2026-02-05T10:24:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11701</id>
            <title type="text"><![CDATA[Offensive Security MCP Servers]]></title>
            <link rel="alternate" href="https://github.com/FuzzingLabs/mcp-security-hub" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11701"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Production-ready, Dockerized MCP (Model Context Protocol) servers for offensive security tools. Enable AI assistants like Claude to perform security assessments, vulnerability scanning, and binary analysis.]]>
            </summary>
            <updated>2026-02-05T09:50:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11662</id>
            <title type="text"><![CDATA[Tangled]]></title>
            <link rel="alternate" href="https://tangled.gitbook.io/tangled-docs/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11662"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing. 

Tangled is a phishing platform designed from an offensive security perspective.
It automates many of the aspects of social engineering campaigns delivery and weaponizes iCalendar rendering features in Microsoft Outlook &amp;amp; Gmail (Google Workspace) to deliver spoofed meeting invites that are automatically added to a user&amp;#039;s calendar without interaction.

- [Tangled @ GitHub](https://github.com/ineesdv/Tangled).]]>
            </summary>
            <updated>2026-02-02T06:30:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11520</id>
            <title type="text"><![CDATA[Vulnerable MCP Servers Lab]]></title>
            <link rel="alternate" href="https://github.com/appsecco/vulnerable-mcp-servers-lab" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11520"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers. 

This repository contains intentionally vulnerable implementations of Model Context Protocol (MCP) servers (both local and remote). Each server lives in its own folder and includes a dedicated README.md with full details on what it does, how to run it, and how to demonstrate/attack the vulnerability.]]>
            </summary>
            <updated>2026-01-19T06:49:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11346</id>
            <title type="text"><![CDATA[PentestAgent]]></title>
            <link rel="alternate" href="https://github.com/GH05TCREW/pentestagent" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11346"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI Penetration Testing.

PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.]]>
            </summary>
            <updated>2025-12-31T07:54:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11280</id>
            <title type="text"><![CDATA[CamXploit]]></title>
            <link rel="alternate" href="https://github.com/spyboy-productions/CamXploit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11280"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find, analyze, and check for exposed IP cameras with open ports, known vulnerabilities, and weak login credentials. 

CamXploit is a reconnaissance tool designed to help researchers and security enthusiasts check if an IP address is hosting an exposed CCTV camera. It scans common camera ports, checks for login pages, tests default credentials, and provides useful search links for further investigation.]]>
            </summary>
            <updated>2025-12-23T06:35:40+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11068</id>
            <title type="text"><![CDATA[&amp;quot;Two-Face&amp;quot; Rust Linux binary]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/twoface" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11068"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An executable file that runs a harmless program most of the time, but will run a different, hidden code if deployed on a specific target host.

Related contents:

- [TwoFace - Quand les sandbox deviennent inutiles @ Korben :fr:](https://korben.info/twoface-sandboxes-inutiles-malware-contextuel.html).]]>
            </summary>
            <updated>2025-11-24T08:49:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/11029</id>
            <title type="text"><![CDATA[Sirius]]></title>
            <link rel="alternate" href="https://github.com/SiriusScan/Sirius" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/11029"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Sirius is an open-source comprehensive vulnerability scanner that leverages community-driven security intelligence and automated penetration testing capabilities.]]>
            </summary>
            <updated>2025-11-21T06:29:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10941</id>
            <title type="text"><![CDATA[Strix]]></title>
            <link rel="alternate" href="https://usestrix.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10941"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The AI Penetration Testing Agent.
Penetration testing done in hours, not weeks.
Strix finds and fixes vulnerabilities before they reach production. 

- [Strix @ GitHub](https://github.com/usestrix/strix).]]>
            </summary>
            <updated>2025-11-12T14:32:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10755</id>
            <title type="text"><![CDATA[Red AI Range (RAR)]]></title>
            <link rel="alternate" href="https://github.com/ErdemOzgen/RedAiRange" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10755"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI Red Teaming Range.

Red AI Range (RAR) is a comprehensive security platform designed specifically for AI red teaming and vulnerability assessment. It creates realistic environments where security professionals can systematically discover, analyze, and mitigate AI vulnerabilities through controlled testing scenarios.]]>
            </summary>
            <updated>2025-10-22T06:19:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10718</id>
            <title type="text"><![CDATA[HoneyBee]]></title>
            <link rel="alternate" href="https://github.com/yaaras/honeybee" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10718"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[HoneyBee.  Create honeypots for cloud environments.

HoneyBee is a tool for creating misconfigured environments to test vulnerabilities in technologies like Jenkins, Jupyter Notebook, and more.]]>
            </summary>
            <updated>2025-10-20T06:12:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10661</id>
            <title type="text"><![CDATA[Al-Khaser]]></title>
            <link rel="alternate" href="https://github.com/ayoubfaouzi/al-khaser" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10661"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

al-khaser is a PoC &amp;quot;malware&amp;quot; application with good intentions that aims to stress your anti-malware system. It performs a bunch of common malware tricks with the goal of seeing if you stay under the radar.

Related contents:

- [Al-khaser - L&amp;#039;outil qui fait transpirer votre solution de cybersécurité @ Korben :fr:]().]]>
            </summary>
            <updated>2025-10-15T09:39:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10429</id>
            <title type="text"><![CDATA[wister]]></title>
            <link rel="alternate" href="https://github.com/cycurity/wister" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10429"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A wordlist generator tool, that allows you to supply a set of words, giving you the possibility to craft multiple variations from the given words, creating a unique and ideal wordlist to use regarding a specific target.]]>
            </summary>
            <updated>2025-09-29T06:30:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10421</id>
            <title type="text"><![CDATA[HexStrike AI]]></title>
            <link rel="alternate" href="https://www.hexstrike.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10421"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Revolutionary AI-Powered Offensive Security Framework.

 HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities. 

- [HexStrike AI MCP Agents v6.0 @ GitHub](https://github.com/0x4m4/hexstrike-ai).]]>
            </summary>
            <updated>2025-09-29T05:46:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10232</id>
            <title type="text"><![CDATA[Bruce Firmware]]></title>
            <link rel="alternate" href="https://bruce.computer/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10232"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The powerful open-source ESP32 firmware designed for offensive security and Red Team operations.

Bruce is meant to be a versatile ESP32 firmware that supports a ton of offensive features focusing on facilitating Red Team operations. It also supports m5stack products and works great with Cardputer, Sticks, M5Cores, T-Decks and T-Embeds.

- [Bruce Firmware @ GitHub](https://github.com/pr3y/Bruce).]]>
            </summary>
            <updated>2025-09-16T08:45:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10231</id>
            <title type="text"><![CDATA[CapibaraZero]]></title>
            <link rel="alternate" href="https://capibarazero.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10231"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A cheap alternative to FlipperZero™ based on Espressif and SBC boards.

CapibaraZero aim to be a cheap alternative to FlipperZero™. It&amp;#039;s based on ESP32 boards especially on ESP32-S3 but we want to port firmware to all ESP family boards.

- [CapibaraZero @ GitHub](https://github.com/CapibaraZero/).]]>
            </summary>
            <updated>2025-09-16T08:44:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10134</id>
            <title type="text"><![CDATA[sandmap]]></title>
            <link rel="alternate" href="https://github.com/trimstray/sandmap" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10134"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles. 

sandmap is a tool supporting network and system reconnaissance using the massive Nmap engine. It provides a user-friendly interface, automates and speeds up scanning and allows you to easily use many advanced scanning techniques.]]>
            </summary>
            <updated>2025-09-11T13:42:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10044</id>
            <title type="text"><![CDATA[WiFi password stealer]]></title>
            <link rel="alternate" href="https://github.com/AleksaMCode/WiFi-password-stealer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10044"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password). 

Have you ever seen a movie where a hacker plugs a seemingly ordinary USB drive into a computer and instantly steals data? Today, you&amp;#039;ll be building a device that does exactly that.

Related contents:

- [Transformer un Raspberry Pi Pico à 4€ en outil de récupération de mots de passe WiFi @ Korben :fr:](https://korben.info/transformer-raspberry-pico-outil-recuperation-mots.html).]]>
            </summary>
            <updated>2025-09-08T10:23:07+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10038</id>
            <title type="text"><![CDATA[BruteForceAI]]></title>
            <link rel="alternate" href="https://github.com/MorDavid/BruteForceAI" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10038"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Advanced LLM-powered brute-force tool combining AI intelligence with automated login attacks.

Related contents:

- [BruteForceAI - L&amp;#039;IA qui cracke vos mots de passe @ Korben :fr:](https://korben.info/bruteforceai.html).
- [BruteForceAI: Free AI-powered login brute force tool @ Help Net Security](https://www.helpnetsecurity.com/2025/09/03/bruteforceai-free-ai-powered-login-brute-force-tool/).]]>
            </summary>
            <updated>2025-09-08T10:03:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10037</id>
            <title type="text"><![CDATA[PassGAN]]></title>
            <link rel="alternate" href="https://github.com/brannondorsey/PassGAN" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10037"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Deep Learning Approach for Password Guessing.

Related contents:

- [BruteForceAI - L&amp;#039;IA qui cracke vos mots de passe @ Korben :fr:](https://korben.info/bruteforceai.html).
- [BruteForceAI: Free AI-powered login brute force tool @ Help Net Security](https://www.helpnetsecurity.com/2025/09/03/bruteforceai-free-ai-powered-login-brute-force-tool/).]]>
            </summary>
            <updated>2025-09-08T10:01:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/138</id>
            <title type="text"><![CDATA[OdooMap]]></title>
            <link rel="alternate" href="https://github.com/MohamedKarrab/odoomap" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/138"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A penetration testing tool for odoo applications. 

OdooMap is a reconnaissance, enumeration, and security testing tool for Odoo applications.

Related contents:

- [OdooMap - L&amp;#039;outil de pentest qui fait trembler les installations Odoo mal sécurisées @ Korben :fr:](https://korben.info/odoomap-outil-pentest-fait-trembler-installations.html).]]>
            </summary>
            <updated>2025-10-16T12:06:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/206</id>
            <title type="text"><![CDATA[Autoswagger]]></title>
            <link rel="alternate" href="https://github.com/intruder-io/autoswagger/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/206"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[detect API auth weaknesses.

Autoswagger is a command-line tool designed to discover, parse, and test for unauthenticated endpoints using Swagger/OpenAPI documentation. It helps identify potential security issues in unprotected endpoints of APIs, such as PII leaks and common secret exposures.

Related contents:

- [AutoSwagger - L&amp;#039;outil gratuit qui trouve les failles d&amp;#039;API que les hackers adorent @ Korben :fr:](https://korben.info/autoswagger-outil-gratuit-trouve-failles-api.html).]]>
            </summary>
            <updated>2025-10-27T15:09:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/281</id>
            <title type="text"><![CDATA[💀 Sploitus]]></title>
            <link rel="alternate" href="https://sploitus.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/281"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Exploit &amp;amp; Hacktool Search Engine.

Related contents:

- [Sploitus - Le Google des exploits et des outils de hacking @ Korben :fr:](https://korben.info/sploitus-google-exploits-outils-hacking.html).]]>
            </summary>
            <updated>2025-11-12T16:24:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/399</id>
            <title type="text"><![CDATA[Cameradar]]></title>
            <link rel="alternate" href="https://github.com/Ullaakut/cameradar" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/399"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cameradar hacks its way into RTSP videosurveillance cameras.

Related contents:

- [Cameradar - L&amp;#039;outil qui trouve et accède aux caméras de surveillance mal sécurisées @ Korben :fr:](https://korben.info/cameradar-scanner-rtsp-cameras-surveillance-test-securite.html).]]>
            </summary>
            <updated>2026-02-11T07:15:12+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/887</id>
            <title type="text"><![CDATA[Patrowl :fr:]]></title>
            <link rel="alternate" href="https://patrowl.io/en/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/887"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SaaS External Security Posture Management.

Related contents:

- [Patrowl, prix du FIC 2025 @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/patrowl-prix-du-fic-2025/).]]>
            </summary>
            <updated>2025-08-28T18:26:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1081</id>
            <title type="text"><![CDATA[GPOddity]]></title>
            <link rel="alternate" href="https://github.com/synacktiv/GPOddity" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1081"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).

Related contents:

- [GPOddity: Et si vos GPO devenaient votre pire cauchemar Active Directory ? @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_%F0%9D%97%9A%F0%9D%97%A3%F0%9D%97%A2%F0%9D%97%B1%F0%9D%97%B1%F0%9D%97%B6%F0%9D%98%81%F0%9D%98%86-et-si-vos-gpo-devenaient-activity-7313070210100387840-ouHJ/).]]>
            </summary>
            <updated>2025-08-28T18:56:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1189</id>
            <title type="text"><![CDATA[Writeup NoobOps :fr:]]></title>
            <link rel="alternate" href="https://writeup.noobops.fr/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1189"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Wr1t3Up d3 Hip5kull

Joueur de CTF sur diverses plateformes, l’idée de ce site est de mettre à disposition de tous, les diverses résolutions de machines effectuées.
Passionné par la cybersécurité et l’IT, les CTFs me permettent d’apprendre énormément sur les failles et l’exploitation de ces dernières.]]>
            </summary>
            <updated>2025-08-28T19:14:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1541</id>
            <title type="text"><![CDATA[PEASS-ng]]></title>
            <link rel="alternate" href="https://github.com/peass-ng/PEASS-ng/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1541"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Privilege Escalation Awesome Scripts SUITE new generation.

Here you will find privilege escalation tools for Windows and Linux/Unix* and MacOS.

These tools search for possible local privilege escalation paths that you could exploit and print them to you with nice colors so you can recognize the misconfigurations easily.

- [🚨 LinPEAS + LLMs = GAME 𝖮̶𝖵̶𝖤̶𝖱̶ CHANGER pour la cybersécurité ? @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_pentest-cybersecurity-ethicalhacking-activity-7297517717606072320-6jRP/).]]>
            </summary>
            <updated>2025-08-28T20:13:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1553</id>
            <title type="text"><![CDATA[WPProbe]]></title>
            <link rel="alternate" href="https://github.com/Chocapikk/wpprobe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1553"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A fast WordPress plugin enumeration tool.

WPProbe is a fast and efficient WordPress plugin scanner that leverages REST API enumeration (?rest_route) to detect installed plugins without brute-force.

Unlike traditional scanners that hammer websites with requests, WPProbe takes a smarter approach by querying the exposed REST API. This technique allows us to identify plugins stealthily, reducing detection risks and speeding up the scan process.]]>
            </summary>
            <updated>2025-08-28T20:15:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1608</id>
            <title type="text"><![CDATA[Lucille]]></title>
            <link rel="alternate" href="https://github.com/jasonxtn/Lucille" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1608"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Information Gatherer &amp;amp; Webapps Exploiter. a Python-based tool to streamline and centralize some pentesting tasks.

Lucille is a comprehensive web application security testing tool designed for cybersecurity professionals. built with Python, Lucille offers a suite of user-friendly tools, it aims to provide an efficient and practical tools streamlining pentesting tasks and centralizing various audit and exploitation techniques.

- [ 🚀 Cet outil transforme n’importe qui en expert du pentest web ! 🚀 @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_github-pentest-cybersecurity-activity-7294973494876938240-tKFt/).]]>
            </summary>
            <updated>2025-08-28T20:24:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1616</id>
            <title type="text"><![CDATA[HExHTTP]]></title>
            <link rel="alternate" href="https://github.com/c0dejump/HExHTTP" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1616"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Header Exploitation HTTP.

HExHTTP is a tool designed to perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors.

Related contents:

- [ 🔥 HExHTTP : Le Couteau Suisse du Hack HTTP ! 🔥 @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_pentest-bugbounty-cybersecurity-activity-7294273741864198144-0V8a/).]]>
            </summary>
            <updated>2025-08-28T20:25:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1661</id>
            <title type="text"><![CDATA[SploitScan]]></title>
            <link rel="alternate" href="https://github.com/xaitax/SploitScan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1661"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SploitScan is a sophisticated cybersecurity utility designed to provide detailed information on vulnerabilities and associated exploits. 

SploitScan is a powerful and user-friendly tool designed to streamline the process of identifying exploits for known vulnerabilities and their respective exploitation probability. Empowering cybersecurity professionals with the capability to swiftly identify and apply known and test exploits. It&amp;#039;s particularly valuable for professionals seeking to enhance their security measures or develop robust detection strategies against emerging threats.]]>
            </summary>
            <updated>2025-08-28T20:32:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1676</id>
            <title type="text"><![CDATA[BlackStone]]></title>
            <link rel="alternate" href="https://github.com/micro-joan/BlackStone" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1676"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Pentesting Reporting Tool.

BlackStone project or &amp;quot;BlackStone Project&amp;quot; is a tool created in order to automate the work of drafting and submitting a report on audits of ethical hacking or pentesting.

In this tool we can register in the database the vulnerabilities that we find in the audit, classifying them by internal, external audit or wifi, in addition, we can put your description and recommendation, as well as the level of severity and effort for its correction. This information will then help us generate in the report a criticality table as a global summary of the vulnerabilities found.

Related contents:

- [BlackStone, la pépite des rapports de test d&amp;#039;intrusions @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_osint-pentest-saezcuritaeznumaezrique-activity-7289225295671296001-9DsA/).]]>
            </summary>
            <updated>2025-08-28T20:35:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1693</id>
            <title type="text"><![CDATA[promptfoo]]></title>
            <link rel="alternate" href="https://www.promptfoo.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1693"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Secure &amp;amp; reliable LLMs.
Test &amp;amp; secure your LLM apps.
Open-source LLM testing used by 51,000+ developers.

 Test your prompts, agents, and RAGs. Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration. 

- [promptfoo @ GitHub](https://github.com/promptfoo/promptfoo).

Related contents:

- [L’IA Deepseek censurée à propos de la Chine ? @ Choses à Savoir TECH :fr:](https://shows.acast.com/choses-a-savoir-technologie/episodes/lia-deepseek-censuree-a-propos-de-la-chine).
- [Promptfoo - Fini le doigt mouillé pour tester vos LLM @ Korben :fr:](https://korben.info/promptfoo-tester-evaluer-llm.html).]]>
            </summary>
            <updated>2026-03-23T15:24:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1699</id>
            <title type="text"><![CDATA[SocialBox]]></title>
            <link rel="alternate" href="https://github.com/Cyb0r9/SocialBox" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1699"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SocialBox is a Bruteforce Attack Framework [ Facebook , Gmail , Instagram ,Twitter ] , Coded By Belahsan Ouerghi]]>
            </summary>
            <updated>2025-08-28T20:39:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1711</id>
            <title type="text"><![CDATA[NucleiFuzzer]]></title>
            <link rel="alternate" href="https://github.com/0xKayala/NucleiFuzzer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1711"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[NucleiFuzzer is a robust automation tool designed for efficiently detecting web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration techniques.

Related contents:

- [ 🚀 Bug Bounty &amp;amp; Pentest : Ce tool va booster vos scans comme JAMAIS ! @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_saezcuritaez-bugbounty-websec-activity-7291719505393709056--jIU/).]]>
            </summary>
            <updated>2025-08-28T20:41:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1772</id>
            <title type="text"><![CDATA[ShadowHound]]></title>
            <link rel="alternate" href="https://github.com/Friends-Security/ShadowHound" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1772"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirectory module (ADWS) or System.DirectoryServices class (LDAP). 

ShadowHound is a set of PowerShell scripts for Active Directory enumeration without the need for introducing known-malicious binaries like SharpHound. It leverages native PowerShell capabilities to minimize detection risks and offers two methods for data collection.

Related contents:

- [🚨 Pentester d&amp;#039;Active Directory: cet outil est pour toi ! 🚨 @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_pentest-activedirectory-bloodhound-activity-7290016018054213632-X1yy/).]]>
            </summary>
            <updated>2025-08-28T20:51:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1824</id>
            <title type="text"><![CDATA[Kraken]]></title>
            <link rel="alternate" href="https://github.com/jasonxtn/kraken" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1824"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[All-in-One Toolkit for BruteForce Attacks.

A Python-based tool to centralize and streamline BruteForce Attacks.

Related contents:

- [ 🚨 PENTEST: Kraken, le GAME CHANGER de la Cybersécurité en Python ! 🚨 @ Laurent Biagiotti&amp;#039;s LinkedIn](https://www.linkedin.com/posts/laurent-biagiotti-19779284_cybersaezcuritaez-innovation-pythontool-activity-7289569552508534784-NR25/).]]>
            </summary>
            <updated>2025-08-28T21:00:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1854</id>
            <title type="text"><![CDATA[linWinPwn]]></title>
            <link rel="alternate" href="https://github.com/lefayjey/linWinPwn" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1854"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[linWinPwn is a bash script that wraps a number of Active Directory tools for enumeration (LDAP, RPC, ADCS, MSSQL, Kerberos), vulnerability checks (noPac, ZeroLogon, MS17-010, MS14-068), object modifications (password change, add user to group, RBCD, Shadow Credentials) and password dumping (secretsdump, lsassy, nanodump, DonPAPI). The script streamlines the use of a large number of tools: impacket, bloodhound, netexec, enum4linux-ng, ldapdomaindump, lsassy, smbmap, kerbrute, adidnsdump, certipy, silenthound, bloodyAD, DonPAPI and many others.

Related contents:

- [ 🚨 LinWinPwn : Testez votre Active Directory! 🚨 @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_cybersecurity-kalilinux-pentesting-activity-7288473430792826880-ADc-/).]]>
            </summary>
            <updated>2025-08-28T21:04:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1886</id>
            <title type="text"><![CDATA[🔍 LFIer]]></title>
            <link rel="alternate" href="https://github.com/Cybersecurity-Ethical-Hacker/lfier" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1886"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🔍 LFIer is a powerful and efficient tool for detecting Local File Inclusion (LFI) vulnerabilities in web applications. 

🔍 LFIer is a tool engineered to detect Local File Inclusion (LFI) vulnerabilities in web applications. It scans URLs with parameters, injects various payloads, and checks for indicators in the responses to identify potential LFI vulnerabilities. Leveraging asynchronous programming, LFIer ensures efficient and accurate scanning, even in environments protected by WAFs or cloud-based defenses.

Related contents:

- [ 🚀 𝗟𝗙𝗜𝗲𝗿 : L’outil INDISPENSABLE pour détecter les failles LFI ! @ Laurent Biagiotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_cybersaezcuritaez-pentest-lfier-activity-7287034791554633728-dELj/).]]>
            </summary>
            <updated>2025-08-28T21:12:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1925</id>
            <title type="text"><![CDATA[Mellivora]]></title>
            <link rel="alternate" href="https://github.com/Nakiami/mellivora?tab=readme-ov-file" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1925"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mellivora is a CTF engine written in PHP.]]>
            </summary>
            <updated>2025-08-28T21:17:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1948</id>
            <title type="text"><![CDATA[fsociety]]></title>
            <link rel="alternate" href="https://fsociety.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1948"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Modular Penetration Testing Framework.

- [fsociety @ GitHub](https://github.com/fsociety-team/fsociety).
- [Fsociety Hacking Tools Pack @ GitHub](https://github.com/Manisso/fsociety).]]>
            </summary>
            <updated>2025-08-28T21:21:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1956</id>
            <title type="text"><![CDATA[Kraken]]></title>
            <link rel="alternate" href="https://github.com/jasonxtn/Kraken" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1956"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[All-in-One Toolkit for BruteForce Attacks.
A Python-based tool to centralize and streamline BruteForce Attacks.

Kraken is a powerful, Python-based tool designed to centralize and streamline various brute-forcing tasks. Kraken provides a suite of tools for cybersecurity professionals to efficiently perform brute-force attacks across a range of protocols and services.]]>
            </summary>
            <updated>2025-08-28T21:22:07+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1988</id>
            <title type="text"><![CDATA[LackSynth]]></title>
            <link rel="alternate" href="https://github.com/aielte-research/HackSynth" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1988"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[LLM Agent and Evaluation Framework for Autonomous Penetration Testing.

We introduce HackSynth, a novel Large Language Model (LLM)-based agent capable of autonomous penetration testing. HackSynth&amp;#039;s dual-module architecture includes a Planner and a Summarizer, which enable it to generate commands and process feedback iteratively. To benchmark HackSynth, we propose two new Capture The Flag (CTF)-based benchmark sets utilizing the popular platforms PicoCTF and OverTheWire. These benchmarks include two hundred challenges across diverse domains and difficulties, providing a standardized framework for evaluating LLM-based penetration testing agents.]]>
            </summary>
            <updated>2025-08-28T21:28:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1989</id>
            <title type="text"><![CDATA[MLOKit]]></title>
            <link rel="alternate" href="https://github.com/xforcered/MLOKit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1989"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[MLOps Attack Toolkit

MLOKit is a toolkit that can be used to attack MLOps platforms by taking advantage of the available REST API. This tool allows the user to specify an attack module, along with specifying valid credentials (API key or stolen access token) for the respective MLOps platform. The attack modules supported include reconnaissance, data extraction and model extraction. MLOKit was built in a modular approach, so that new modules can be added in the future by the information security community.]]>
            </summary>
            <updated>2025-08-28T21:28:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2107</id>
            <title type="text"><![CDATA[ARM - AttackRuleMap]]></title>
            <link rel="alternate" href="https://attackrulemap.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2107"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mapping of open-source detection rules and atomic tests. 

The goal of this project is to bridge the gap between Atomic Red Team&amp;#039;s adversary simulations and open-source detection rules. By doing so, this project aims to help security professionals simulate attacks and evaluate their detection strategies more effectively. 🔒

- [AttackRuleMap @ GitHub](https://github.com/krdmnbrk/AttackRuleMap).]]>
            </summary>
            <updated>2025-08-28T21:48:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2113</id>
            <title type="text"><![CDATA[onesixtyone]]></title>
            <link rel="alternate" href="https://github.com/trailofbits/onesixtyone" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2113"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fast SNMP Scanner.

onesixtyone takes a different approach to SNMP scanning. It takes advantage of the fact that SNMP is a connectionless protocol and sends all SNMP requests as fast as it can. Then the scanner waits for responses to come back and logs them, in a fashion similar to Nmap ping sweeps. By default onesixtyone waits for 10 milliseconds between sending packets, which is adequate for 100MBs switched networks. The user can adjust this value via the -w command line option. If set to 0, the scanner will send packets as fast as the kernel would accept them, which may lead to packet drop.]]>
            </summary>
            <updated>2025-08-28T21:48:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2117</id>
            <title type="text"><![CDATA[CF-Hero]]></title>
            <link rel="alternate" href="https://github.com/musana/CF-Hero" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2117"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications]]>
            </summary>
            <updated>2025-08-28T21:49:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2130</id>
            <title type="text"><![CDATA[Ethical Hacking and Penetration Testing]]></title>
            <link rel="alternate" href="https://github.com/tomwechsler/Ethical_Hacking_and_Penetration_Testing" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2130"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This repository is all about tips on ethical hacking and penetration testing!]]>
            </summary>
            <updated>2025-08-28T21:52:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2131</id>
            <title type="text"><![CDATA[Resolver]]></title>
            <link rel="alternate" href="https://github.com/Jo-spec849/Resolver" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2131"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fast Enumeration Tool using Shodan.

This is a Python script developed to assist in the reconnaissance process during penetration testing.

Related contents:

- [ 🚀 Resolver : Accélérez votre reconnaissance avec Shodan ! 🚀 @ Maori S.&amp;#039; LinkedIn :fr:](https://www.linkedin.com/posts/maory-schroder_osint-pentesting-cybersecurity-activity-7282637206253416449-YDs7/).]]>
            </summary>
            <updated>2025-08-28T21:52:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2138</id>
            <title type="text"><![CDATA[D4TA-HUNTER]]></title>
            <link rel="alternate" href="https://github.com/micro-joan/D4TA-HUNTER" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2138"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[D4TA-HUNTER is a tool created in order to automate the collection of information about the employees of a company that is going to be audited for ethical hacking.

In addition, in this tool we can find in the &amp;quot;search company&amp;quot; section by inserting the domain of a company, emails of employees, subdomains and IP&amp;#039;s of servers.]]>
            </summary>
            <updated>2025-08-28T21:52:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2151</id>
            <title type="text"><![CDATA[Group3r]]></title>
            <link rel="alternate" href="https://github.com/Group3r/Group3r" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2151"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Find vulnerabilities in AD Group Policy, but do it better than Grouper2 did.

Like its ancestors, Group3r is a tool for pentesters and red teamers to rapidly enumerate relevant settings in AD Group Policy, and to identify exploitable misconfigurations in same. It does this by talking LDAP to Domain Controllers, parsing GPO config files off the domain SYSVOL share, and also by looking at other files (usually on file shares) that are referenced within GPOs, like scripts, MSI packages, exes, etc.]]>
            </summary>
            <updated>2025-08-28T21:54:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2153</id>
            <title type="text"><![CDATA[vulnerable-AD]]></title>
            <link rel="alternate" href="https://github.com/safebuffer/vulnerable-AD" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2153"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Create a vulnerable active directory that&amp;#039;s allowing you to test most of the active directory attacks in a local lab]]>
            </summary>
            <updated>2025-08-28T21:56:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2190</id>
            <title type="text"><![CDATA[GoSearch]]></title>
            <link rel="alternate" href="https://github.com/ibnaleem/gosearch" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2190"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🔍 OSINT tool for searching people&amp;#039;s digital footprint and leaked passwords across various social networks, written in Go. 

Related contents:

 - [GoSearch - 18 milliards de mots de passe compromis à portée de terminal @ Korben :fr:](https://korben.info/gosearch-milliards-mots-passe-compromis-portee.html).]]>
            </summary>
            <updated>2025-08-28T22:01:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2211</id>
            <title type="text"><![CDATA[Skuld Stealer]]></title>
            <link rel="alternate" href="https://github.com/hackirby/skuld" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2211"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Go-written Malware targeting Windows systems, extracting User Data from Discord, Browsers, Crypto Wallets and more, from every user on every disk. (PoC. For Educational Purposes only).

Next-Gen Stealer written in Go. Stealing from Discord, Chromium-Based &amp;amp; Firefox-Based Browsers, Crypto Wallets and more, from every user on every disk. (PoC. For educational purposes only)]]>
            </summary>
            <updated>2025-08-28T22:04:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2227</id>
            <title type="text"><![CDATA[jwt-cli]]></title>
            <link rel="alternate" href="https://github.com/mike-engel/jwt-cli" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2227"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A super fast CLI tool to decode and encode JWTs built in Rust.

jwt-cli is a command line tool to help you work with JSON Web Tokens (JWTs). Like most JWT command line tools out there, you can decode almost any JWT header and claims body. Unlike any that I&amp;#039;ve found, however, jwt-cli allows you to encode a new JWT with nearly any piece of data you can think of. Custom header values (some), custom claim bodies (as long as it&amp;#039;s JSON, it&amp;#039;s game), and using any secret you need.]]>
            </summary>
            <updated>2025-08-28T22:08:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2291</id>
            <title type="text"><![CDATA[Pentoo]]></title>
            <link rel="alternate" href="https://www.pentoo.ch/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2291"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Pentoo is a Live CD and Live USB designed for penetration testing and security assessment. Based off Gentoo Linux, Pentoo is provided both as 32 and 64 bit installable livecd.]]>
            </summary>
            <updated>2025-08-28T22:18:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2292</id>
            <title type="text"><![CDATA[BlackArch Linux]]></title>
            <link rel="alternate" href="https://blackarch.org/index.html" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2292"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Penetration Testing Distribution.

BlackArch Linux is an Arch Linux-based penetration testing distribution for penetration testers and security researchers. The repository contains 2828 tools. You can install tools individually or in groups. BlackArch Linux is compatible with existing Arch installs.]]>
            </summary>
            <updated>2025-08-28T22:18:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2293</id>
            <title type="text"><![CDATA[Mobile Security Framework (MobSF)]]></title>
            <link rel="alternate" href="https://mobsf.github.io/docs/#/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2293"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. 

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. MobSF can be used for a variety of use cases such as mobile application security, penetration testing, malware analysis, and privacy analysis. The Static Analyzer supports popular mobile app binaries like APK, IPA, APPX and source code. Meanwhile, the Dynamic Analyzer supports both Android and iOS applications and offers a platform for interactive instrumented testing, runtime data and network traffic analysis. MobSF seamlessly integrates with your DevSecOps or CI/CD pipeline, facilitated by REST APIs and CLI tools, enhancing your security workflow with ease.

- [Mobile Security Framework (MobSF) @ GitHub](https://github.com/MobSF/Mobile-Security-Framework-MobSF).]]>
            </summary>
            <updated>2025-08-28T22:18:40+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2487</id>
            <title type="text"><![CDATA[brainstorm]]></title>
            <link rel="alternate" href="https://github.com/Invicti-Security/brainstorm/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2487"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery.

This tool enhances traditional web fuzzing by using local AI language models (via Ollama) to generate intelligent guesses for potential paths and filenames. 

- [Brainstorm tool release: Optimizing web fuzzing with local LLMs @ invicti](https://www.invicti.com/blog/security-labs/brainstorm-tool-release-optimizing-web-fuzzing-with-local-llms/).]]>
            </summary>
            <updated>2025-08-28T22:50:57+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2488</id>
            <title type="text"><![CDATA[burpference]]></title>
            <link rel="alternate" href="https://github.com/dreadnode/burpference" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2488"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A research project to add some brrrrrr to Burp.

&amp;quot;burpference&amp;quot; started as a research idea of offensive agent capabilities and is a fun take on Burp Suite and running inference. The extension is open-source and designed to capture in-scope HTTP requests and responses from Burp&amp;#039;s proxy history and ship them to a remote LLM API in JSON format. It&amp;#039;s designed with a flexible approach where you can configure custom system prompts, store API keys and select remote hosts from numerous model providers as well as the ability for you to create your own API configuration. The idea is for an LLM to act as an agent in an offensive web application engagement to leverage your skills and surface findings and lingering vulnerabilities. By being able to create your own configuration and model provider allows you to also host models locally via Ollama to prevent potential high inference costs and potential network delays or rate limits.]]>
            </summary>
            <updated>2026-02-12T12:58:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2495</id>
            <title type="text"><![CDATA[Coercer]]></title>
            <link rel="alternate" href="https://github.com/p0dalirius/Coercer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2495"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods. 

- [🎄CyberAdvent Day 12: Force SMB and HTTP authentications with Coercer! @ Rémi Gascou (Podalirius)&amp;#039;s LinkedIn](https://www.linkedin.com/posts/remigascou_cyberadvent-day-12-force-smb-and-http-activity-7272872352550457344-gSDP/).]]>
            </summary>
            <updated>2025-08-28T22:52:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2515</id>
            <title type="text"><![CDATA[watchTowr]]></title>
            <link rel="alternate" href="https://watchtowr.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2515"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Your Persistent Adversary.
Real Attack Surface Management, within the watchTowr Platform.
The future of Continuous Automated Red Teaming and Attack Surface Management.

- [ 🚨 PoC Exploit 🚨 L&amp;#039;exploit zero-day et PoC de Mitel MiCollab dévoilé @ Almamy Diakho&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/almamy-diakho-63397b146_micollab-mitel-exploit-activity-7270701198809169920-c87L/).]]>
            </summary>
            <updated>2025-08-28T22:56:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2531</id>
            <title type="text"><![CDATA[ChainReactor]]></title>
            <link rel="alternate" href="https://github.com/ucsb-seclab/chainreactor" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2531"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[ChainReactor is a research project that leverages AI planning to discover exploitation chains for privilege escalation on Unix systems. The project models the problem as a sequence of actions to achieve privilege escalation from initial access to a target system. 

- [ChainReactor: Automated Privilege Escalation Chain Discovery via AI Planning @ Usenix association](https://www.usenix.org/conference/usenixsecurity24/presentation/de-pasquale).]]>
            </summary>
            <updated>2025-08-28T22:58:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2552</id>
            <title type="text"><![CDATA[Tamanoir]]></title>
            <link rel="alternate" href="https://github.com/pythops/tamanoir" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2552"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A KeyLogger using eBPF 🐝]]>
            </summary>
            <updated>2025-08-28T23:02:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2561</id>
            <title type="text"><![CDATA[Oversight]]></title>
            <link rel="alternate" href="https://github.com/user1342/Oversight" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2561"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Completely Modular LLM Reverse Engineering, Red Teaming, and Vulnerability Research Framework.]]>
            </summary>
            <updated>2025-08-28T23:03:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2604</id>
            <title type="text"><![CDATA[PEASS-ng]]></title>
            <link rel="alternate" href="https://github.com/peass-ng/PEASS-ng" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2604"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Privilege Escalation Awesome Scripts SUITE (with colors).
Privilege Escalation Awesome Scripts SUITE new generation.

Here you will find privilege escalation tools for Windows and Linux/Unix* and MacOS.

These tools search for possible local privilege escalation paths that you could exploit and print them to you with nice colors so you can recognize the misconfigurations easily.]]>
            </summary>
            <updated>2025-08-28T23:10:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2629</id>
            <title type="text"><![CDATA[enum4linux-ng]]></title>
            <link rel="alternate" href="https://github.com/cddmp/enum4linux-ng" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2629"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.

enum4linux-ng.py is a rewrite of Mark Lowe&amp;#039;s (former Portcullis Labs now Cisco CX Security Labs) enum4linux.pl, a tool for enumerating information from Windows and Samba systems, aimed for security professionals and CTF players. The tool is mainly a wrapper around the Samba tools nmblookup, net, rpcclient and smbclient.]]>
            </summary>
            <updated>2025-08-28T23:14:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2659</id>
            <title type="text"><![CDATA[Game Of Active Directory]]></title>
            <link rel="alternate" href="https://orange-cyberdefense.github.io/GOAD/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2659"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Game Of Active Directory is a free pentest active directory LAB(s) project.

The purpose of this tool is to give pentesters a vulnerable Active directory environment ready to use to practice usual attack techniques. The idea behind this project is to give you an environment where you can try and train your pentest skills without having the pain to build all by yourself. This repository was build for pentest practice 🙂

- [Game Of Active Directory @ GitHub](https://github.com/Orange-Cyberdefense/GOAD).

Related contents:

- [Dracarys @ Mayfly](https://mayfly277.github.io/posts/Dracarys-lab/).]]>
            </summary>
            <updated>2026-03-12T11:10:28+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2679</id>
            <title type="text"><![CDATA[NachoVPN]]></title>
            <link rel="alternate" href="https://github.com/AmberWolfCyber/NachoVPN" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2679"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A tasty, but malicious SSL-VPN server 🌮

NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients, using a rogue VPN server.

It uses a plugin-based architecture so that support for additional SSL-VPN products can be contributed by the community. It currently supports various popular corporate VPN products, such as Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect, and Ivanti Connect Secure.

- [Introducing NachoVPN: One VPN Server to Pwn Them All @ AmberWolf](https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/).]]>
            </summary>
            <updated>2025-08-28T23:23:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2695</id>
            <title type="text"><![CDATA[zscan]]></title>
            <link rel="alternate" href="https://github.com/zcyberseclab/zscan" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2695"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A fast, customizable service detection tool powered by a flexible fingerprint system. It helps you identify services, APIs, and network configurations across your infrastructure.]]>
            </summary>
            <updated>2025-08-28T23:25:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2712</id>
            <title type="text"><![CDATA[garak]]></title>
            <link rel="alternate" href="https://github.com/NVIDIA/garak" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2712"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[the LLM vulnerability scanner. Generative AI Red-teaming &amp;amp; Assessment Kit

garak checks if an LLM can be made to fail in a way we don&amp;#039;t want. garak probes for hallucination, data leakage, prompt injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses. If you know nmap, it&amp;#039;s nmap for LLMs.]]>
            </summary>
            <updated>2025-08-28T23:29:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2776</id>
            <title type="text"><![CDATA[OpenAEV]]></title>
            <link rel="alternate" href="https://openaev.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2776"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open Adversary Exposure Validation Platform. Formerly OpenBAS (Open Breach and Attack Simulation Platform).

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests.

- [OpenBas Documentation](https://docs.openbas.io/latest/)
- [OpenAEV @ GitHub](https://github.com/OpenAEV-Platform/openaev).]]>
            </summary>
            <updated>2025-09-08T08:31:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2792</id>
            <title type="text"><![CDATA[Nuke It From Orbit]]></title>
            <link rel="alternate" href="https://github.com/lkarlslund/nifo" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2792"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[remove AV/EDR with physical access.
tl;dr: unprivileged user -&amp;gt; Defender removal on physical machine.

With a precision of a brain surgeon wielding a chainsaw, nifo can obliterate most AV/EDR products from endpoints or servers running the worlds most popular operating system, even if they&amp;#039;re BitLocker protected - if you have physical access to the device and it&amp;#039;s not totally locked down (BIOS password + SecureBoot + Harddrive Password + No USB Boot).]]>
            </summary>
            <updated>2025-08-28T23:41:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2794</id>
            <title type="text"><![CDATA[GoCrack]]></title>
            <link rel="alternate" href="https://github.com/mandiant/gocrack" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2794"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GoCrack is a management frontend for password cracking tools written in Go.

GoCrack provides APIs to manage password cracking tasks across supported cracking engines.]]>
            </summary>
            <updated>2025-08-28T23:42:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2801</id>
            <title type="text"><![CDATA[GitDorker]]></title>
            <link rel="alternate" href="https://github.com/obheda12/GitDorker" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2801"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Python program to scrape secrets from GitHub through usage of a large repository of dorks. 

GitDorker is a tool that utilizes the GitHub Search API and an extensive list of GitHub dorks that I&amp;#039;ve compiled from various sources to provide an overview of sensitive information stored on github given a search query.

The Primary purpose of GitDorker is to provide the user with a clean and tailored attack surface to begin harvesting sensitive information on GitHub. GitDorker can be used with additional tools such as GitRob or Trufflehog on interesting repos or users discovered from GitDorker to produce best results.]]>
            </summary>
            <updated>2025-08-28T23:43:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2845</id>
            <title type="text"><![CDATA[Leonidas]]></title>
            <link rel="alternate" href="https://github.com/WithSecureLabs/leonidas" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2845"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated Attack Simulation in the Cloud, complete with detection use cases. 

This is the repository containing Leonidas, a framework for executing attacker actions in the cloud. It provides a YAML-based format for defining cloud attacker tactics, techniques and procedures (TTPs) and their associated detection properties. These definitions can then be compiled into:]]>
            </summary>
            <updated>2025-08-28T23:50:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2846</id>
            <title type="text"><![CDATA[CloudBrute]]></title>
            <link rel="alternate" href="https://github.com/0xsha/cloudbrute" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2846"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Awesome cloud enumerator

A tool to find a company (target) infrastructure, files, and apps on the top cloud providers (Amazon, Google, Microsoft, DigitalOcean, Alibaba, Vultr, Linode). The outcome is useful for bug bounty hunters, red teamers, and penetration testers alike.]]>
            </summary>
            <updated>2025-08-28T23:50:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2862</id>
            <title type="text"><![CDATA[EvilnoVNC]]></title>
            <link rel="alternate" href="https://github.com/JoelGMSec/EvilnoVNC" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2862"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[EvilnoVNC is a Ready to go Phishing Platform.

Unlike other phishing techniques, EvilnoVNC allows 2FA bypassing by using a real browser over a noVNC connection.

In addition, this tool allows us to see in real time all of the victim&amp;#039;s actions, access to their downloaded files and the entire browser profile, including cookies, saved passwords, browsing history and much more.]]>
            </summary>
            <updated>2025-08-28T23:53:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2872</id>
            <title type="text"><![CDATA[AuditForge]]></title>
            <link rel="alternate" href="https://auditforge.feriadesoftware.cl/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2872"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automate Your Audit Reports with AuditForge.

AuditForge is a pentest reporting application making it simple and easy to write your findings and generate a customizable report. 
Save time, increase efficiency, and maintain data confidentiality with our open-source auditing software.

- [AuditForge @ GitHub](https://github.com/caverav/auditforge).]]>
            </summary>
            <updated>2025-08-28T23:55:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2895</id>
            <title type="text"><![CDATA[Bjorn]]></title>
            <link rel="alternate" href="https://github.com/infinition/Bjorn" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2895"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Bjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.]]>
            </summary>
            <updated>2025-08-28T23:58:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2897</id>
            <title type="text"><![CDATA[SQLMap Command Generator]]></title>
            <link rel="alternate" href="https://acorzo1983.github.io/SQLMapCG/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2897"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A web-based tool to easily generate customizable SQLMap commands for testing SQL injection vulnerabilities. Features include target configuration, connection options, detection levels, and various SQL injection techniques. Perfect for penetration testers and security enthusiasts. 

- [SQLMap Command Generator @ GitHub](https://github.com/acorzo1983/SQLMapCG/).]]>
            </summary>
            <updated>2025-08-28T23:59:31+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2901</id>
            <title type="text"><![CDATA[🦊 CloudFox 🦊]]></title>
            <link rel="alternate" href="https://github.com/BishopFox/cloudfox" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2901"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automating situational awareness for cloud penetration tests.

CloudFox helps you gain situational awareness in unfamiliar cloud environments. It’s an open source command line tool created to help penetration testers and other offensive security professionals find exploitable attack paths in cloud infrastructure.

- [Introducing CloudFox @ Bishop Fox](https://bishopfox.com/blog/introducing-cloudfox).]]>
            </summary>
            <updated>2025-08-28T23:59:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2956</id>
            <title type="text"><![CDATA[vulnerable-apps]]></title>
            <link rel="alternate" href="https://github.com/vulnerable-apps" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2956"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Over 100 forks of deliberately vulnerable web applications and APIs.]]>
            </summary>
            <updated>2025-08-29T00:09:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2958</id>
            <title type="text"><![CDATA[GTFOBins]]></title>
            <link rel="alternate" href="https://gtfobins.github.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2958"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.

- [GTFOBins @ GitHub](https://github.com/GTFOBins/GTFOBins.github.io).
- [GTFOBins : Evitez les erreurs de configuration dangereuses sous Linux @ IT-Connect :fr:](https://www.it-connect.fr/gtfobins-evitez-les-erreurs-de-configuration-dangereuses-sous-linux/).]]>
            </summary>
            <updated>2025-08-29T00:09:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3055</id>
            <title type="text"><![CDATA[Ligolo-ng]]></title>
            <link rel="alternate" href="https://github.com/nicocha30/ligolo-ng" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3055"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface. 

Ligolo-ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection using a tun interface (without the need of SOCKS).

- [How to Tunnel and Pivot Networks using Ligolo-ng @ Software Sinner&amp;#039;s Medium](https://software-sinner.medium.com/how-to-tunnel-and-pivot-networks-using-ligolo-ng-cf828e59e740).
- [Pivoting réseau avec #ligolo-ng Comprendre le #pivoting @ Frozenk&amp;#039;s YouTube :fr:](https://www.youtube.com/watch?v=ggwL9a9tP9g).]]>
            </summary>
            <updated>2025-08-29T00:25:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3072</id>
            <title type="text"><![CDATA[pwnlook]]></title>
            <link rel="alternate" href="https://github.com/amjcyber/pwnlook" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3072"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it.]]>
            </summary>
            <updated>2025-08-29T00:28:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3112</id>
            <title type="text"><![CDATA[LOST - Living Off Security Tools]]></title>
            <link rel="alternate" href="https://0xanalyst.github.io/Project-Lost/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3112"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Living Off The Land Security Tools is a curated list of Security Tools used by adversaries to bypass security controls and carry out attacks. 

- [Living Off Security Tools (LOST) @ GitHub](https://github.com/0xAnalyst/Project-Lost).]]>
            </summary>
            <updated>2025-08-29T00:36:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3124</id>
            <title type="text"><![CDATA[LTESniffer]]></title>
            <link rel="alternate" href="https://github.com/SysSec-KAIST/LTESniffer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3124"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An Open-source LTE Downlink/Uplink Eavesdropper.

LTESniffer is a tool that can capture the LTE wireless messages that are sent between a cell tower and smartphones connected to it. LTESniffer supports capturing the messages in both directions, from the tower to the smartphones, and from the smartphones back to the cell tower.

It first decodes the Physical Downlink Control Channel (PDCCH) to obtain the Downlink Control Informations (DCIs) and Radio Network Temporary Identifiers (RNTIs) of all active users. Using decoded DCIs and RNTIs, LTESniffer further decodes the Physical Downlink Shared Channel (PDSCH) and Physical Uplink Shared Channel (PUSCH) to retrieve uplink and downlink data traffic.]]>
            </summary>
            <updated>2025-08-29T00:37:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3178</id>
            <title type="text"><![CDATA[Argus]]></title>
            <link rel="alternate" href="https://github.com/jasonxtn/Argus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3178"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Ultimate Information Gathering Toolkit. A Python-based toolkit for Information Gathering and Reconnaissance.

Argus is an all-in-one, Python-powered toolkit designed to streamline the process of information gathering and reconnaissance. With a user-friendly interface and a suite of powerful modules, Argus empowers you to explore networks, web applications, and security configurations efficiently and effectively.]]>
            </summary>
            <updated>2025-08-29T00:46:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3224</id>
            <title type="text"><![CDATA[CapibaraZero]]></title>
            <link rel="alternate" href="https://github.com/CapibaraZero/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3224"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CapibaraZero aim to be a cheap alternative to FlipperZero™. It&amp;#039;s based on ESP32 boards especially on ESP32-S3 but we want to port firmware to all ESP family boards.]]>
            </summary>
            <updated>2025-08-29T00:53:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3235</id>
            <title type="text"><![CDATA[Halberd]]></title>
            <link rel="alternate" href="https://www.vectra.ai/blog/halberd-the-open-source-tool-democratizing-multi-cloud-security-testing" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3235"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Open-Source Tool Democratizing Multi-Cloud Security Testing by Arpan Sarkar.

Multi-Cloud Security Testing Tool to execute a comprehensive array of attack techniques across multiple surfaces via a simple web interface. 

Halberd is a powerful, multi-cloud security testing tool. Born out of the need for a unified, easy-to-use tool, Halberd enables you to proactively assess your cloud defenses by executing a comprehensive array of attack techniques across Entra ID, M365, Azure, and AWS. With its intuitive web interface, you can simulate real-world attacks, generate valuable telemetry, and validate your security controls with ease &amp;amp; speed.

- [Halberd @ GitHub](https://github.com/vectra-ai-research/Halberd).]]>
            </summary>
            <updated>2025-08-29T00:56:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3236</id>
            <title type="text"><![CDATA[Gato]]></title>
            <link rel="alternate" href="https://github.com/praetorian-inc/gato" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3236"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Gato, or GitHub Attack Toolkit, is an enumeration and attack tool that allows both blue teamers and offensive security practitioners to identify and exploit pipeline vulnerabilities within a GitHub organization&amp;#039;s public and private repositories.]]>
            </summary>
            <updated>2025-08-29T00:56:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3237</id>
            <title type="text"><![CDATA[VulnAPI]]></title>
            <link rel="alternate" href="https://vulnapi.cerberauth.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3237"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[API Security Vulnerability Scanner designed to help you secure your APIs. 

Your First Line of Defense in API Security. Scan your APIs for vulnerabilities with VulnAPI.

Help developers and security professionals quickly and efficiently scan their APIs for security vulnerabilities and weaknesses.

- [VulnAPI @ GitHub](https://github.com/cerberauth/vulnapi)]]>
            </summary>
            <updated>2025-08-29T00:56:53+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3257</id>
            <title type="text"><![CDATA[The JSON Web Token Toolkit]]></title>
            <link rel="alternate" href="https://github.com/ticarpi/jwt_tool" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3257"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens 

- [Dans +80% des cas où je teste la sécurité d&amp;#039;API, je trouve des problèmes de droit ou d&amp;#039;autorisation. Alors voici 2 plugins Burpsuite à connaître 👇 @ Corentin M.&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/corentin-margraff_dans-80-des-cas-o%C3%B9-je-teste-la-s%C3%A9curit%C3%A9-activity-7251857443847073792-tMUS/).]]>
            </summary>
            <updated>2025-08-29T01:00:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3258</id>
            <title type="text"><![CDATA[autorize]]></title>
            <link rel="alternate" href="https://github.com/PortSwigger/autorize" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3258"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests.

- [Dans +80% des cas où je teste la sécurité d&amp;#039;API, je trouve des problèmes de droit ou d&amp;#039;autorisation. Alors voici 2 plugins Burpsuite à connaître 👇 @ Corentin M.&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/corentin-margraff_dans-80-des-cas-o%C3%B9-je-teste-la-s%C3%A9curit%C3%A9-activity-7251857443847073792-tMUS/).]]>
            </summary>
            <updated>2025-08-29T01:00:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3259</id>
            <title type="text"><![CDATA[AuthMatrix]]></title>
            <link rel="alternate" href="https://github.com/PortSwigger/auth-matrix" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3259"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

- [Dans +80% des cas où je teste la sécurité d&amp;#039;API, je trouve des problèmes de droit ou d&amp;#039;autorisation. Alors voici 2 plugins Burpsuite à connaître 👇 @ Corentin M.&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/corentin-margraff_dans-80-des-cas-o%C3%B9-je-teste-la-s%C3%A9curit%C3%A9-activity-7251857443847073792-tMUS/).]]>
            </summary>
            <updated>2025-08-29T01:00:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3285</id>
            <title type="text"><![CDATA[discover]]></title>
            <link rel="alternate" href="https://github.com/leebaird/discover" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3285"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Custom bash scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux.]]>
            </summary>
            <updated>2025-08-29T01:04:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3346</id>
            <title type="text"><![CDATA[Ax Framework]]></title>
            <link rel="alternate" href="https://ax-framework.gitbook.io/wiki" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3346"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Control Your Infrastructure, Scale Your Scanning—On Your Terms. Easily distribute arbitrary binaries and scripts using any of our seven supported cloud providers.

The Ax Framework is a free and open-source tool utilized by Bug Hunters and Penetration Testers to efficiently operate in multiple cloud environments. It helps build and deploy repeatable infrastructure tailored for offensive security purposes.

- [Ax Framework @ GitHub](https://github.com/attacksurge/ax).]]>
            </summary>
            <updated>2025-08-29T01:13:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3436</id>
            <title type="text"><![CDATA[CloudShovel]]></title>
            <link rel="alternate" href="https://github.com/saw-your-packet/CloudShovel" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3436"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CloudShovel is a tool designed to search for sensitive information within public or private Amazon Machine Images (AMIs). It automates the process of launching instances from target AMIs, mounting their volumes, and scanning for potential secrets or sensitive data.]]>
            </summary>
            <updated>2025-08-29T01:29:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3561</id>
            <title type="text"><![CDATA[Athena OS]]></title>
            <link rel="alternate" href="https://athenaos.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3561"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Dive into a new Pentesting Experience with Athena OS!

Athena OS is an open-source, NixOS-based distribution intended to build a new concept of pentesting operating system. Its purpose is to offer a different experience than the most used pentesting distributions by providing reproducibility, flexibility, isolation, default packages that fit with the user needs, diverse hacking resources and learning materials.

- [Athena OS @ GitHub](https://github.com/Athena-OS).]]>
            </summary>
            <updated>2025-08-29T01:50:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3564</id>
            <title type="text"><![CDATA[Spraykatz]]></title>
            <link rel="alternate" href="https://github.com/aas-n/spraykatz" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3564"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Credentials gathering tool automating remote procdump and parse of lsass process. 

Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.

It simply tries to procdump machines and parse dumps remotely in order to avoid detections by antivirus softwares as much as possible.

- [Spraykatz, alat penguji Windows @ ZdanSec](https://zidansec.com/spraykatz-alat-penguji-windows).]]>
            </summary>
            <updated>2025-08-29T01:50:12+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3578</id>
            <title type="text"><![CDATA[linux-smart-enumeration]]></title>
            <link rel="alternate" href="https://github.com/diego-treitos/linux-smart-enumeration" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3578"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Linux enumeration tool for pentesting and CTFs with verbosity levels.

This shell script will show relevant information about the security of the local Linux system, helping to escalate privileges. From version 2.0 it is mostly POSIX compliant and tested with shellcheck and posh.

It can also monitor processes to discover recurrent program executions. It monitors while it is executing all the other tests so you save some time. By default it monitors during 1 minute but you can choose the watch time with the -p parameter.]]>
            </summary>
            <updated>2025-08-29T01:53:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3591</id>
            <title type="text"><![CDATA[ASNmap]]></title>
            <link rel="alternate" href="https://github.com/projectdiscovery/asnmap" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3591"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Go CLI and Library for quickly mapping organization network ranges using ASN information.]]>
            </summary>
            <updated>2025-08-29T01:55:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3594</id>
            <title type="text"><![CDATA[Secator]]></title>
            <link rel="alternate" href="https://docs.freelabz.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3594"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[secator is a task and workflow runner used for security assessments. It supports dozens of well-known security tools and is designed to improve productivity for pentesters and security researchers.

- [Secator @ GitHub](https://github.com/freelabz/secator).]]>
            </summary>
            <updated>2025-08-29T01:55:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3658</id>
            <title type="text"><![CDATA[hackingtool]]></title>
            <link rel="alternate" href="https://github.com/Z4nzu/hackingtool" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3658"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[ALL IN ONE Hacking Tool For Hackers.]]>
            </summary>
            <updated>2025-08-29T02:06:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3781</id>
            <title type="text"><![CDATA[SSHamble]]></title>
            <link rel="alternate" href="https://github.com/runZeroInc/sshamble" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3781"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Unexpected Exposures in SSH. SSHamble is a research tool for SSH implementations.

SSHamble simulates potential attack scenarios, including unauthorized remote access due to unexpected state transitions, remote command execution in post-session login implementations, and information leakage through unlimited high-speed authentication requests. The SSHamble interactive shell provides raw access to SSH requests in the post-session (but pre-execution) environment, allowing for simple testing of environment controls, signal processing, port forwarding, and more.

- [SSHamble @ runZero](https://www.runzero.com/sshamble/).]]>
            </summary>
            <updated>2025-08-29T02:26:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3927</id>
            <title type="text"><![CDATA[macro_pack]]></title>
            <link rel="alternate" href="https://github.com/sevagas/macro_pack" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3927"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to fin… 

- [Episode #466 consacré à BallisKit Avec Emeric Nasi @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/balliskit/).]]>
            </summary>
            <updated>2025-08-29T02:50:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3928</id>
            <title type="text"><![CDATA[BallisKit]]></title>
            <link rel="alternate" href="https://www.balliskit.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3928"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A companion toolkit for Pentesters &amp;amp; Red Teams.

BallisKit helps by providing automation and weaponization of payload generation. Our products are also equipped with multiple security solution bypasses and ready to use templates to cover any scenarios the RedTeam may face. BallisKit is an array of tools and services developed to help Red Teams and Pentesters in their mission. Capabilities include, among other, penetration testing, demos and social engineering campaigns (email, USB key, etc.).

- [Episode #466 consacré à BallisKit Avec Emeric Nasi @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/balliskit/).]]>
            </summary>
            <updated>2025-08-29T02:51:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4016</id>
            <title type="text"><![CDATA[edr-internals]]></title>
            <link rel="alternate" href="https://github.com/outflanknl/edr-internals/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4016"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Tools for analyzing EDR agents.

- [EDR Internals for macOS and Linux @ Outflank](https://www.outflank.nl/blog/2024/06/03/edr-internals-macos-linux/).]]>
            </summary>
            <updated>2025-08-29T03:05:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4037</id>
            <title type="text"><![CDATA[PurpleLab:]]></title>
            <link rel="alternate" href="https://github.com/Krook9d/PurpleLab" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4037"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PurpleLab is an efficient and readily deployable lab solution, providing a swift setup for cybersecurity professionals to test detection rules, simulate logs, and undertake various security tasks, all accessible through a user-friendly web interface.

- [⭕Envie de manipuler du lab à gogo, alors cette repository devrait vous plaire @ Laurent Minne&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-minne_security-cybersecurity-purpleteam-activity-7216335289726726144--fnP).]]>
            </summary>
            <updated>2025-08-29T03:09:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4176</id>
            <title type="text"><![CDATA[AD Miner]]></title>
            <link rel="alternate" href="https://github.com/AD-Security/AD_Miner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4176"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses.

ADMiner is an Active Directory audit tool that leverages cypher queries to crunch data from the BloodHound graph database (neo4j) and gives you a global overview of existing weaknesses through a web-based static report, including detailed listing, dynamic graphs, key indicators history, along with risk ratings.

- [AD Miner - Analyse Active Directory — Emilien Vannier, Jean-Michel Besnard, Tanguy Boisset @ SSTIC :fr:](https://www.sstic.org/2024/presentation/AD_Miner_Active_Directory_Audit_Control/).
- [Episode \#461 consacré à ADMiner avec Jean-Michel BESNARD @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/adminer/).
- [Not All Paths are Created Equal -- Attackers&amp;#039; Economy (Part 1) @ Riccardo Ancarani - Red Team Adventures](https://riccardoancarani.github.io/2019-11-08-not-all-paths-are-equal/).
- [Graph theory to assess Active Directory : Smartest vs. Shortest Control Paths @ Jean-Michel BESNARD&amp;#039;s LinkedIn](https://www.linkedin.com/pulse/graph-theory-assess-active-directory-smartest-vs-shortest-besnard-0qgle/).]]>
            </summary>
            <updated>2025-08-29T03:34:07+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4203</id>
            <title type="text"><![CDATA[Vulhub]]></title>
            <link rel="alternate" href="https://vulhub.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4203"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Docker-Compose file for vulnerability environment.

Vulhub is an open-source collection of pre-built vulnerable docker environments. No pre-existing knowledge of docker is required, just execute two simple commands and you have a vulnerable environment.

- [Vulhub @ GitHub](https://github.com/vulhub/vulhub).

Related contents:

- [Vulhub Playground @ GitHub](https://github.com/supdevinci/vulhub-labs/).
- [ 🎯 ON A CRÉÉ NOTRE LAB DE VULNÉRABILITÉS SUR DOCKER 🎯 @ Laurent Biagotti&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/laurent-biagiotti-19779284_on-a-cr%C3%A9%C3%A9-notre-lab-de-vuln%C3%A9rabilit%C3%A9s-activity-7282644725168238593-k9nl/).]]>
            </summary>
            <updated>2025-08-29T03:38:10+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4246</id>
            <title type="text"><![CDATA[WebCopilot]]></title>
            <link rel="alternate" href="https://github.com/h4r5h1t/webcopilot" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4246"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[WebCopilot is an automation tool designed to enumerate subdomains of the target and detect bugs using different open-source tools.

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

- [WebCopilot : L’ultime outil d’automatisation pour les chasseurs de bugs 🚀 @ Korben :fr:](https://korben.info/webcopilot-outil-automatisation-chasseurs-bugs.html).]]>
            </summary>
            <updated>2025-08-29T03:44:14+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4283</id>
            <title type="text"><![CDATA[Awesome Testing Tools]]></title>
            <link rel="alternate" href="https://github.com/ZoranPandovski/awesome-testing-tools" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4283"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[🚀 A curated list of awesome testing tools 🚀]]>
            </summary>
            <updated>2025-08-29T03:50:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4358</id>
            <title type="text"><![CDATA[Mantis]]></title>
            <link rel="alternate" href="https://phonepe.github.io/mantis/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4358"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning. 

Mantis is a command-line framework designed to automate the workflow of asset discovery, reconnaissance, and scanning. It takes the top-level domains as input, then seamlessly progresses to discovering corresponding assets, including subdomains and certificates. The tool performs reconnaissance on active assets and concludes with a comprehensive scan for vulnerabilities, secrets, misconfigurations and phishing domains - all powered by a blend of open-source and custom tools.

- [Mantis @ GitHub](https://github.com/PhonePe/mantis).]]>
            </summary>
            <updated>2025-08-29T04:03:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4380</id>
            <title type="text"><![CDATA[Red Team Tools]]></title>
            <link rel="alternate" href="https://github.com/A-poc/RedTeam-Tools" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4380"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Tools and Techniques for Red Team / Penetration Testing.

This github repository contains a collection of 130+ tools and resources that can be useful for red teaming activities.
Some of the tools may be specifically designed for red teaming, while others are more general-purpose and can be adapted for use in a red teaming context.]]>
            </summary>
            <updated>2025-08-29T04:06:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4632</id>
            <title type="text"><![CDATA[CATSploit🐈]]></title>
            <link rel="alternate" href="https://github.com/catsploit/catsploit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4632"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[CATSploit is an automated penetration testing tool using Cyber Attack Techniques Scoring (CATS) method that can be used without pentester.]]>
            </summary>
            <updated>2025-08-29T04:48:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4633</id>
            <title type="text"><![CDATA[AngryOxide]]></title>
            <link rel="alternate" href="https://github.com/Ragnt/AngryOxide" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4633"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[802.11 Attack Tool.

The overall goal of this tool is to provide a single-interface survey capability with advanced automated attacks that result in valid hashlines you can crack with Hashcat.]]>
            </summary>
            <updated>2025-08-29T04:48:48+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4692</id>
            <title type="text"><![CDATA[Rubeus]]></title>
            <link rel="alternate" href="https://github.com/GhostPack/Rubeus" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4692"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Trying to tame the three-headed dog.
Rubeus is a C# toolset for raw Kerberos interaction and abuses.]]>
            </summary>
            <updated>2025-08-29T04:58:57+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4693</id>
            <title type="text"><![CDATA[Chisel]]></title>
            <link rel="alternate" href="https://github.com/jpillora/chisel" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4693"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A fast TCP/UDP tunnel over HTTP.

Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. Single executable including both client and server. Written in Go (golang). Chisel is mainly useful for passing through firewalls, though it can also be used to provide a secure endpoint into your network.]]>
            </summary>
            <updated>2025-08-29T04:58:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4695</id>
            <title type="text"><![CDATA[Arsenal]]></title>
            <link rel="alternate" href="https://github.com/Orange-Cyberdefense/arsenal" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4695"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Arsenal is just a quick inventory and launcher for hacking programs.

This project written by pentesters for pentesters simplify the use of all the hard-to-remember commands

- [Avec arsenal, créez un inventaire de vos commandes Linux favorites et gagnez en efficacité @ IT-Connect.fr :fr:](https://www.it-connect.fr/linux-inventaire-commandes-favorites-outil-arsenal/).]]>
            </summary>
            <updated>2025-08-29T04:58:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4702</id>
            <title type="text"><![CDATA[SessionProbe]]></title>
            <link rel="alternate" href="https://github.com/dub-flow/sessionprobe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4702"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applications by taking a session token and checking access across a list of URLs, highlighting potential authorization issues. 

- [SessionProbe: Open-source multi-threaded pentesting tool @ Help Net Security](https://www.helpnetsecurity.com/2023/12/05/sessionprobe-open-source-multi-threaded-pentesting-tool/).]]>
            </summary>
            <updated>2025-08-29T05:00:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4710</id>
            <title type="text"><![CDATA[changeme]]></title>
            <link rel="alternate" href="https://github.com/ztgrace/changeme" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4710"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A default credential scanner.

changeme picks up where commercial scanners leave off. It focuses on detecting default and backdoor credentials and not necessarily common credentials. It&amp;#039;s default mode is to scan HTTP default credentials, but has support for other credentials.]]>
            </summary>
            <updated>2025-08-29T05:02:55+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4711</id>
            <title type="text"><![CDATA[RouterSploit]]></title>
            <link rel="alternate" href="https://github.com/threat9/routersploit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4711"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Exploitation Framework for Embedded Devices. It consists of various modules that aid penetration testing operations.]]>
            </summary>
            <updated>2025-08-29T05:02:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4749</id>
            <title type="text"><![CDATA[Bluetooth LE Spam]]></title>
            <link rel="alternate" href="https://github.com/simondankelmann/Bluetooth-LE-Spam" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4749"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This project focuses on utilizing the built-in Bluetooth Low Energy (BLE) functionality of Android smartphones to create Phantom Bluetooth Device Advertisements, similar to what is known, for instance, in the case of the Flipper Zero. While there are other apps available that provide similar functionality, the objective of this app is to enhance convenience and user-friendliness in the process.

- [Comme le Flipper Zero, cette app Android peut inonder de notifications les appareils à proximité @ IT-Connect.fr :fr:](https://www.it-connect.fr/comme-le-flipper-zero-cette-app-android-peut-inonder-de-notifications-les-appareils-a-proximite/).]]>
            </summary>
            <updated>2025-08-29T05:07:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4751</id>
            <title type="text"><![CDATA[vulscan.nse]]></title>
            <link rel="alternate" href="https://www.computec.ch/projekte/vulscan/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4751"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Advanced vulnerability scanning with Nmap NSE.

Vulscan is a module which enhances nmap to a vulnerability scanner. The nmap option -sV enables version detection per service which is used to determine potential flaws according to the identified product. The data is looked up in an offline version of VulDB.

- [vulscan @ GitHub](https://github.com/scipag/vulscan).
- [Nmap Vulnerability Scan: How to Find Weak Systems Easily @ StationX](https://www.stationx.net/nmap-vulnerability-scan/).]]>
            </summary>
            <updated>2025-08-29T05:08:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4752</id>
            <title type="text"><![CDATA[mimikatz]]></title>
            <link rel="alternate" href="https://github.com/gentilkiwi/mimikatz" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4752"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A little tool to play with Windows security.

mimikatz extract plaintexts passwords, hash, PIN code and kerberos tickets from memory. mimikatz can also perform pass-the-hash, pass-the-ticket or build Golden tickets.

Related contents:

- [The Mimikatz Missing Manual @ GitHub](https://github.com/darkoperator/mimikatz-missing-manual).
- [mimikatz @ Blog de Gentil Kiwi :fr:](https://blog.gentilkiwi.com/mimikatz).
- [Pass the Hash With Mimikatz: Compromise Hashes With Ease @ StationX](https://www.stationx.net/pass-the-hash-with-mimikatz/).]]>
            </summary>
            <updated>2026-02-19T12:34:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4753</id>
            <title type="text"><![CDATA[PolarDNS]]></title>
            <link rel="alternate" href="https://github.com/oryxlabs/PolarDNS" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4753"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PolarDNS is a specialized authoritative DNS server suitable for penetration testing and vulnerability research. 

PolarDNS is a specialized authoritative DNS server written in Python 3.x, which allows the operator to produce fully custom DNS responses, suitable for DNS protocol testing purposes.

- [PolarDNS: Open-source DNS server tailored for security evaluations @ Help Net Security](https://www.helpnetsecurity.com/2023/11/21/polardns-open-source-dns-server/).
- [PolarDNS – A Free DNS Server For Vulnerability Research &amp;amp; Pentesting @ Cyber Security News](https://cybersecuritynews.com/polardns-a-free-dns-server/).]]>
            </summary>
            <updated>2025-08-29T05:08:57+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4789</id>
            <title type="text"><![CDATA[MAAD Attack Framework]]></title>
            <link rel="alternate" href="https://github.com/vectra-ai-research/MAAD-AF" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4789"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An attack tool for simple, fast &amp;amp; effective security testing of M365 &amp;amp; Azure AD. 

MAAD-AF is designed to make cloud security testing simple, fast and effective. Through its virtually no-setup requirement and easy to use interactive attack modules, security teams can test their security controls, detection and response capabilities easily and swiftly.]]>
            </summary>
            <updated>2025-08-29T05:15:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4812</id>
            <title type="text"><![CDATA[hashcat]]></title>
            <link rel="alternate" href="https://hashcat.net/hashcat/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4812"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[World&amp;#039;s fastest and most advanced password recovery utility.

hashcat is the world&amp;#039;s fastest and most advanced password recovery utility, supporting five unique modes of attack for over 300 highly-optimized hashing algorithms. hashcat currently supports CPUs, GPUs, and other hardware accelerators on Linux, Windows, and macOS, and has facilities to help enable distributed password cracking.

- [hashcat @ GitHub](https://github.com/hashcat/hashcat).

Related contents:

- [Cybersécurité : les erreurs courantes de configuration réseau @ Silicon (fr)](https://www.silicon.fr/cybersecurite-erreurs-courantes-configuration-reseau-cisa-nsa-472094.html).]]>
            </summary>
            <updated>2025-08-29T05:19:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4813</id>
            <title type="text"><![CDATA[SharpShares]]></title>
            <link rel="alternate" href="https://github.com/djhohnstein/SharpShares" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4813"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Enumerate all network shares in the current domain. Also, can resolve names to IP addresses.

Quick and dirty binary to list network share information from all machines in the current domain and if they&amp;#039;re readable. Can also translate all computer names to ip addresses.

- [Cybersécurité : les erreurs courantes de configuration réseau @ Silicon (fr)](https://www.silicon.fr/cybersecurite-erreurs-courantes-configuration-reseau-cisa-nsa-472094.html).]]>
            </summary>
            <updated>2025-08-29T05:19:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4814</id>
            <title type="text"><![CDATA[Snaffler]]></title>
            <link rel="alternate" href="https://github.com/SnaffCon/Snaffler" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4814"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Snaffler is a tool for pentesters and red teamers to help find delicious candy needles (creds mostly, but it&amp;#039;s flexible) in a bunch of horrible boring haystacks (a massive Windows/AD environment).

- [Cybersécurité : les erreurs courantes de configuration réseau @ Silicon (fr)](https://www.silicon.fr/cybersecurite-erreurs-courantes-configuration-reseau-cisa-nsa-472094.html).
- [Analysez vos partages de fichiers Active Directory avec Snaffler pour protéger vos données @ IT-Connect :fr:](https://www.it-connect.fr/snaffler-recherche-des-informations-sensibles-dans-les-partages-fichiers-active-directory/).]]>
            </summary>
            <updated>2025-08-29T05:19:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4845</id>
            <title type="text"><![CDATA[jSQL Injection]]></title>
            <link rel="alternate" href="https://github.com/ron190/jsql-injection" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4845"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[jSQL Injection is a Java application for automatic SQL database injection.]]>
            </summary>
            <updated>2025-08-29T05:24:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4872</id>
            <title type="text"><![CDATA[AttackForge - Pentest Management and Reporting Tool]]></title>
            <link rel="alternate" href="https://attackforge.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4872"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Pentest Management and Reporting Made Easy.

A Platform Built for Productivity, Collaboration and Visibility.

[Attack Forge @ GitHub](https://github.com/attackforge).]]>
            </summary>
            <updated>2025-08-29T05:29:05+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4887</id>
            <title type="text"><![CDATA[VAmPI]]></title>
            <link rel="alternate" href="https://github.com/erev0s/VAmPI" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4887"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Vulnerable REST API with OWASP top 10 vulnerabilities for security testing.

VAmPI is a vulnerable API made with Flask and it includes vulnerabilities from the OWASP top 10 vulnerabilities for APIs. It was created as I wanted a vulnerable API to evaluate the efficiency of tools used to detect security issues in APIs. It includes a switch on/off to allow the API to be vulnerable or not while testing. This allows to cover better the cases for false positives/negatives. VAmPI can also be used for learning/teaching purposes. You can find a bit more details about the vulnerabilities in erev0s.com.]]>
            </summary>
            <updated>2025-08-29T05:31:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4908</id>
            <title type="text"><![CDATA[ADCSKiller]]></title>
            <link rel="alternate" href="https://github.com/grimlockx/ADCSKiller" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4908"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer.

ADCSKiller is a Python-based tool designed to automate the process of discovering and exploiting Active Directory Certificate Services (ADCS) vulnerabilities. It leverages features of Certipy and Coercer to simplify the process of attacking ADCS infrastructure. Please note that the ADCSKiller is currently in its first drafts and will undergo further refinements and additions in future updates for sure.]]>
            </summary>
            <updated>2025-08-29T05:35:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4949</id>
            <title type="text"><![CDATA[zphisher]]></title>
            <link rel="alternate" href="https://github.com/htr-tech/zphisher" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4949"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An automated phishing tool with 30+ templates. This Tool is made for educational purpose only ! Author will not be responsible for any misuse of this toolkit ! 

Related contents:

- [Nexphisher @ GitHub](https://github.com/htr-tech/nexphisher).]]>
            </summary>
            <updated>2025-08-29T05:41:26+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4967</id>
            <title type="text"><![CDATA[Black Hat Arsenal Security Tools]]></title>
            <link rel="alternate" href="https://toolswatch.org/category/arsenal/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4967"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Official Black Hat Arsenal Security Tools Repository.

[Black Hat Arsenal Security Tools @ GitHub](https://github.com/toolswatch/blackhat-arsenal-tools):
This github account maps to the Black Hat Arsenal tools since its inception in 2011. For readibility, the tools are classified by category and not by session.]]>
            </summary>
            <updated>2025-08-29T05:45:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4970</id>
            <title type="text"><![CDATA[The Penetration Testing Execution Standard (PTES)]]></title>
            <link rel="alternate" href="http://www.pentest-standard.org/index.php/Main_Page" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4970"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The penetration testing execution standard consists of seven (7) main sections.

These cover everything related to a penetration test - from the initial communication and reasoning behind a pentest, through the intelligence gathering and threat modeling phases where testers are working behind the scenes in order to get a better understanding of the tested organization, through vulnerability research, exploitation and post exploitation, where the technical security expertise of the testers come to play and combine with the business understanding of the engagement, and finally to the reporting, which captures the entire process, in a manner that makes sense to the customer and provides the most value to it.]]>
            </summary>
            <updated>2025-08-29T05:45:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4974</id>
            <title type="text"><![CDATA[Caldera]]></title>
            <link rel="alternate" href="https://caldera.mitre.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4974"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Scalable, Automated Adversary Emulation Platform

Caldera™ is a cybersecurity framework developed by MITRE that empowers cyber practitioners to save time, money, and energy through automated security assessments.

- [Caldera @ GitHub](https://github.com/mitre/caldera).

Related contents:

- [MITRE Caldera v5 - Basics playlist @ MITRE Caldera&amp;#039;s YouTube](https://www.youtube.com/playlist?list=PLF2bj1pw7-ZvLTjIwSaTXNLN2D2yx-wXH).]]>
            </summary>
            <updated>2025-08-29T05:47:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4984</id>
            <title type="text"><![CDATA[Reaper]]></title>
            <link rel="alternate" href="https://ghostsecurity.github.io/reaper/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4984"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Reaper is a reconnaissance and attack proxy, built to be a modern, lightweight, and efficient equivalent to Burp Suite/ZAP etc. This is an attack proxy with a heavy focus on automation, collaboration, and building universally distributable workflows.

[Reaper @ GitHub](https://github.com/ghostsecurity/reaper).]]>
            </summary>
            <updated>2025-08-29T05:47:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4986</id>
            <title type="text"><![CDATA[Exegol]]></title>
            <link rel="alternate" href="https://exegol.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4986"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[professional hacking setup.

Exegol is a community-driven hacking environment, powerful and yet simple enough to be used by anyone in day to day engagements. Exegol is the best solution to deploy powerful hacking environments securely, easily, professionally. No more unstable, not-so-security-focused systems lacking major offensive tools. Kali Linux (and similar alternatives) are great toolboxes for learners, students and junior pentesters. But professionals have different needs, and their context require a whole new design.

- [Exegol @ Read the Docs](https://exegol.readthedocs.io/en/latest/).
- [Exegol @ GitHub](https://github.com/ThePorgs/Exegol).

Related contents:

- [ Exegol, un modèle autour d&amp;#039;un environnement pour les Pentesters et Redteamers ? Charlie Bromberg @ BeCyber&amp;#039;s YouTube :fr:](https://www.youtube.com/watch?v=lwZCziWpTcA).
- [Découverte d’Exegol : un environnement dédié à la sécurité offensive @ IT-Connect :fr:](https://www.it-connect.fr/exegol-un-environnement-dedie-a-la-securite-offensive/).
- [Episode \#527 consacré à Exegol @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/exegol/).]]>
            </summary>
            <updated>2026-01-21T06:48:25+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5006</id>
            <title type="text"><![CDATA[SysReptor Pentest Report Creator]]></title>
            <link rel="alternate" href="https://sysreptor.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5006"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Fully customisable, offensive security reporting solution designed for pentesters, red teamers and other security-related people alike. 

SysReptor is a fully customisable, offensive security reporting solution designed for pentesters, red teamers and other security-related people alike. You can create designs based on simple HTML and CSS, write your reports in user-friendly Markdown and convert them to PDF with just a single click, in the cloud or self-hosted!

- [SysReptor documentation](https://docs.sysreptor.com/).
- [SysReptor @ GitHub](https://github.com/Syslifters/sysreptor).]]>
            </summary>
            <updated>2026-01-12T08:00:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5016</id>
            <title type="text"><![CDATA[NtRemoteLoad]]></title>
            <link rel="alternate" href="https://github.com/florylsk/NtRemoteLoad" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5016"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Remote Shellcode Injector.

Remote shellcode injector, based on HWSyscalls by ShorSec, leveraging undetectable (currently) indirect native syscalls to inject shellcode into another process, creating a thread and executing it.]]>
            </summary>
            <updated>2025-08-29T05:53:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5018</id>
            <title type="text"><![CDATA[PwnDoc]]></title>
            <link rel="alternate" href="https://pwndoc.github.io/pwndoc/#/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5018"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Pentest Report Generator.

PwnDoc is a pentest reporting application making it simple and easy to write your findings and generate a customizable Docx report.
The main goal is to have more time to Pwn and less time to Doc by mutualizing data like vulnerabilities between users.

- [PwnDoc @ GitHub](https://github.com/pwndoc/pwndoc).

Related contents:

- [Episode \#498 consacré à la société Patrowl, lauréate du Grand Prix de la Startup au FIC 2025 @ NoLimitSecu :fr:](https://www.nolimitsecu.fr/patrowl-prix-du-fic-2025/).]]>
            </summary>
            <updated>2025-08-29T05:53:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5051</id>
            <title type="text"><![CDATA[OverTheWire: Wargames]]></title>
            <link rel="alternate" href="https://overthewire.org/wargames/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5051"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The wargames offered by the OverTheWire community can help you to learn and practice security concepts in the form of fun-filled games.]]>
            </summary>
            <updated>2025-08-29T05:59:23+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5080</id>
            <title type="text"><![CDATA[Gophish]]></title>
            <link rel="alternate" href="https://getgophish.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5080"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open-Source Phishing Framework

Gophish is a powerful, open-source phishing framework that makes it easy to test your organization&amp;#039;s exposure to phishing.

- [Gophish @ GitHub](https://github.com/gophish/gophish)

Sources:

- [Sensibilisation des utilisateurs : création d’une campagne de phishing avec Gophish et Microsoft 365 @ IT-Connect :fr:](https://www.it-connect.fr/sensibilisation-creation-campagne-de-phishing-avec-gophish-et-microsoft-365/).
- [Déployer un reverse proxy Nginx et un certificat Let’s Encrypt pour Gophish @ IT-Connect :fr:](https://www.it-connect.fr/gophish-reverse-proxy-nginx-et-certificat-lets-encrypt/).]]>
            </summary>
            <updated>2025-08-29T06:03:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5149</id>
            <title type="text"><![CDATA[Merlin]]></title>
            <link rel="alternate" href="https://github.com/Ne0nd0g/merlin" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5149"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Merlin is a cross-platform post-exploitation Command &amp;amp; Control server and agent written in Go.]]>
            </summary>
            <updated>2025-08-29T06:15:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5164</id>
            <title type="text"><![CDATA[OpenBullet]]></title>
            <link rel="alternate" href="https://openbullet.github.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5164"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OpenBullet is a webtesting suite that allows to perform requests towards a target webapp and offers a lot of tools to work with the results. This software can be used for scraping and parsing data, automated pentesting, unit testing through selenium and much more.

[OpenBullet @ GitHub](https://github.com/openbullet/openbullet)]]>
            </summary>
            <updated>2025-08-29T06:17:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5230</id>
            <title type="text"><![CDATA[WinPrefetchView]]></title>
            <link rel="alternate" href="https://www.nirsoft.net/utils/win_prefetch_view.html" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5230"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[View the content of Windows Prefetch (.pf) files.

WinPrefetchView is a small utility that reads the Prefetch files stored in your system and displays the information stored in them. By looking in these files, you can learn which files every application is using, and which files are loaded on Windows boot.]]>
            </summary>
            <updated>2025-08-29T06:28:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5231</id>
            <title type="text"><![CDATA[PECmd]]></title>
            <link rel="alternate" href="https://github.com/EricZimmerman/PECmd" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5231"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Windows Prefetch Explorer Command Line]]>
            </summary>
            <updated>2025-08-29T06:28:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5247</id>
            <title type="text"><![CDATA[PowerLessShell]]></title>
            <link rel="alternate" href="https://github.com/Mr-Un1k0d3r/PowerLessShell" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5247"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach.]]>
            </summary>
            <updated>2025-08-29T06:31:41+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5305</id>
            <title type="text"><![CDATA[RedCloud OS]]></title>
            <link rel="alternate" href="https://github.com/RedTeamOperations/RedCloud-OS" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5305"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[RedCloud OS is a Debian based Cloud Adversary Simulation Operating System for Red Teams to assess the security of leading Cloud Service Providers (CSPs). It includes tools optimized for adversary simulation tasks within Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP).]]>
            </summary>
            <updated>2025-08-29T06:40:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5352</id>
            <title type="text"><![CDATA[Exodia · OS For Cyber Security]]></title>
            <link rel="alternate" href="https://exodia-os.github.io/exodia-website/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5352"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A highly customized arch-based distro For All Cybersecurity fields.

[Exodia OS @ GitHub](https://github.com/Exodia-OS)]]>
            </summary>
            <updated>2025-08-29T06:48:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5375</id>
            <title type="text"><![CDATA[pyrdp]]></title>
            <link rel="alternate" href="https://github.com/GoSecure/pyrdp" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5375"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact.
PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library.]]>
            </summary>
            <updated>2025-08-29T06:52:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5392</id>
            <title type="text"><![CDATA[OWASP Mutillidae II]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-mutillidae-ii/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5392"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. With dozens of vulnerabilities and hints to help the user; this is an easy-to-use web hacking environment designed for labs, security enthusiast, classrooms, CTF, and vulnerability assessment tool targets.

[OWASP Mutillidae II @ GitHub](https://github.com/so-sc/OWASP-mutillidae-2).]]>
            </summary>
            <updated>2025-08-29T06:56:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5415</id>
            <title type="text"><![CDATA[Nuclei]]></title>
            <link rel="alternate" href="https://nuclei.projectdiscovery.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5415"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Community Powered Vulnerability Scanner


[Nuclei @ GitHub](https://github.com/projectdiscovery/nuclei).]]>
            </summary>
            <updated>2025-08-29T06:59:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5489</id>
            <title type="text"><![CDATA[HackBrowserData]]></title>
            <link rel="alternate" href="https://github.com/moonD4rk/HackBrowserData" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5489"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Decrypt passwords/cookies/history/bookmarks from the browser.

HackBrowserData is a command-line tool for decrypting and exporting browser data ( passwords, history, cookies, bookmarks, credit cards, download records, localStorage and extension ) from the browser. It supports the most popular browsers on the market and runs on Windows, macOS and Linux.]]>
            </summary>
            <updated>2025-08-29T07:12:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5598</id>
            <title type="text"><![CDATA[pwndrop]]></title>
            <link rel="alternate" href="https://github.com/kgretzky/pwndrop" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5598"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

pwndrop is a self-deployable file hosting service for sending out red teaming payloads or securely sharing your private files over HTTP and WebDAV.]]>
            </summary>
            <updated>2025-08-29T07:30:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5630</id>
            <title type="text"><![CDATA[kali-automation-install:]]></title>
            <link rel="alternate" href="https://github.com/sKillseries/kali-automation-install" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5630"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Script permettant de créer automatiquement une VM Kali VirtualBox ou VMware avec l&amp;#039;installation de tous les outils nécessaires de pentest.

L&amp;#039;outil kali-automation-install est un projet qui a pour vocation d&amp;#039;aider les pentester à créer de façon automatique des VM Kali Linux avec tous les outils nécessaires à la réalisation de la mission confiés. C&amp;#039;est une vitrine de mes compétences acquises dans le monde opérationnel en tant qu&amp;#039;Administrateur/Ingénieur Système Réseaux et Sécurité avec des compétences dite DevOps pour le monde offensive cyber dans lequel je m&amp;#039;oriente.]]>
            </summary>
            <updated>2025-08-29T07:36:13+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5638</id>
            <title type="text"><![CDATA[trackerjacker]]></title>
            <link rel="alternate" href="https://github.com/calebmadrigal/trackerjacker" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5638"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Like nmap for mapping wifi networks you&amp;#039;re not connected to. Maps and tracks wifi networks and devices through raw 802.11 monitoring.]]>
            </summary>
            <updated>2025-08-29T07:36:22+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5673</id>
            <title type="text"><![CDATA[Scapy]]></title>
            <link rel="alternate" href="https://scapy.net/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5673"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Scapy is a powerful interactive packet manipulation libary written in Python. Scapy is able to forge or decode packets of a wide number of protocols, send them on the wire, capture them, match requests and replies, and much more. 

[Scapy @ GitHub](https://github.com/secdev/scapy).]]>
            </summary>
            <updated>2025-08-29T07:42:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5916</id>
            <title type="text"><![CDATA[Atomic Red Team]]></title>
            <link rel="alternate" href="https://atomicredteam.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5916"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Atomic Red Team™ is a library of tests mapped to the MITRE ATT&amp;amp;CK® framework. Security teams can use Atomic Red Team to quickly, portably, and reproducibly test their environments.

[Atomic Red Team @ GitHub](https://github.com/redcanaryco/atomic-red-team).]]>
            </summary>
            <updated>2025-08-29T08:22:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5930</id>
            <title type="text"><![CDATA[TeamFiltration]]></title>
            <link rel="alternate" href="https://github.com/Flangvik/TeamFiltration" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5930"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts.]]>
            </summary>
            <updated>2025-08-29T08:25:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5940</id>
            <title type="text"><![CDATA[KeePwn]]></title>
            <link rel="alternate" href="https://github.com/Orange-Cyberdefense/KeePwn" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5940"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A python script to help red teamers discover KeePass instances and extract secrets.]]>
            </summary>
            <updated>2025-08-29T08:26:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5950</id>
            <title type="text"><![CDATA[Hack The Box]]></title>
            <link rel="alternate" href="https://www.hackthebox.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5950"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hacking Training For The Best | Individuals &amp;amp; Companies. A Massive Hacking Playground.

Join a dynamically growing hacking community and take your cybersecurity skills to the next level through the most captivating, gamified, hands-on training experience!]]>
            </summary>
            <updated>2025-08-29T08:28:41+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6004</id>
            <title type="text"><![CDATA[The Hacker Tools]]></title>
            <link rel="alternate" href="https://tools.thehacker.recipes/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6004"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This project is aimed at providing technical guides on various hacking tools.
Keep in mind that these guides are maintained by non-omniscient security enthusiasts in their spare time. You will probably find things missing or mistakes.

[The Hacker Tools @ GitHub](https://github.com/ShutdownRepo/The-Hacker-Tools)]]>
            </summary>
            <updated>2025-08-29T08:37:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6005</id>
            <title type="text"><![CDATA[The Hacker Recipes]]></title>
            <link rel="alternate" href="https://www.thehacker.recipes/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6005"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This project is aimed at providing technical guides on various hacking topics.

[The Hacker Recipes @ GitHub](https://github.com/ShutdownRepo/The-Hacker-Recipes).]]>
            </summary>
            <updated>2025-08-29T08:37:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6011</id>
            <title type="text"><![CDATA[p0wny@shell:~#]]></title>
            <link rel="alternate" href="https://github.com/flozz/p0wny-shell" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6011"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Single-file PHP shell.
p0wny@shell:~# is a very basic, single-file, PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server.]]>
            </summary>
            <updated>2025-08-29T08:38:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6026</id>
            <title type="text"><![CDATA[Ddosify]]></title>
            <link rel="alternate" href="https://ddosify.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6026"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[High Performance Distributed Observability Platform.
No Code Distributed Observability Platform.
Performance Impact Analysis Software.

[Ddosify @ GitHub](https://github.com/ddosify/ddosify)]]>
            </summary>
            <updated>2025-08-29T08:41:44+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6183</id>
            <title type="text"><![CDATA[Bettercap]]></title>
            <link rel="alternate" href="https://github.com/bettercap/bettercap" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6183"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Swiss Army knife for 802.11, BLE, IPv4 and IPv6 networks reconnaissance and MITM attacks.
bettercap is a powerful, easily extensible and portable framework written in Go which aims to offer to security researchers, red teamers and reverse engineers an easy to use, all-in-one solution with all the features they might possibly need for performing reconnaissance and attacking WiFi networks, Bluetooth Low Energy devices, wireless HID devices and Ethernet networks.]]>
            </summary>
            <updated>2025-08-29T09:08:59+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6540</id>
            <title type="text"><![CDATA[Stowaway -- Multi-hop Proxy Tool for pentesters]]></title>
            <link rel="alternate" href="https://github.com/ph4ntonn/Stowaway" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6540"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Stowaway is a Multi-hop proxy tool for security researchers and pentesters

Users can easily proxy their network traffic to intranet nodes (multi-layer),break the restrction and manipulate all the nodes that under your control XD]]>
            </summary>
            <updated>2025-08-29T10:07:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6567</id>
            <title type="text"><![CDATA[AORT: All in One Recon Tool for Bug Bounty]]></title>
            <link rel="alternate" href="https://github.com/D3Ext/AORT" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6567"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[This script allows you to do recognition around a domain name. 
AORT makes it possible to detect the sub-domains, the DNS, the possibility of a domain name transfer, the type of WAF in place (firewall application), the Whois information, the open ports, as well as various endpoints or mailboxes.]]>
            </summary>
            <updated>2025-08-29T10:11:33+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6568</id>
            <title type="text"><![CDATA[Burp Suite]]></title>
            <link rel="alternate" href="https://portswigger.net/burp" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6568"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Application Security Testing Software.
Free, lightweight web application security scanning for CI/CD.
manual tools to start web security testing.

Related contents:

- [Untangling Microsoft Graph&amp;#039;s $batch requests in Burp @ Katie Knowles](https://kknowl.es/posts/untangling-microsoft-batch/).]]>
            </summary>
            <updated>2026-03-05T12:23:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6569</id>
            <title type="text"><![CDATA[crlfuzz]]></title>
            <link rel="alternate" href="https://github.com/dwisiswant0/crlfuzz" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6569"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A fast tool to scan CRLF vulnerability written in Goc]]>
            </summary>
            <updated>2025-08-29T10:13:34+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6570</id>
            <title type="text"><![CDATA[XSRFProbe]]></title>
            <link rel="alternate" href="https://github.com/0xInfection/XSRFProbe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6570"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.
XSRFProbe is an advanced Cross Site Request Forgery (CSRF/XSRF) Audit and Exploitation Toolkit. Equipped with a powerful crawling engine and numerous systematic checks, it is able to detect most cases of CSRF vulnerabilities, their related bypasses and futher generate (maliciously) exploitable proof of concepts with each found vulnerability. For more info on how XSRFProbe works, see XSRFProbe Internals on wiki.]]>
            </summary>
            <updated>2025-08-29T10:13:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6571</id>
            <title type="text"><![CDATA[XSStrike]]></title>
            <link rel="alternate" href="https://github.com/s0md3v/XSStrike" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6571"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Most advanced XSS scanner.
XSStrike is a Cross Site Scripting detection suite equipped with four hand written parsers, an intelligent payload generator, a powerful fuzzing engine and an incredibly fast crawler.]]>
            </summary>
            <updated>2025-08-29T10:13:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6572</id>
            <title type="text"><![CDATA[InQL]]></title>
            <link rel="alternate" href="https://github.com/doyensec/inql" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6572"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A Burp Extension for GraphQL Security Testing.
A security testing tool to facilitate GraphQL technology security auditing efforts.]]>
            </summary>
            <updated>2025-08-29T10:13:36+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6573</id>
            <title type="text"><![CDATA[Commix]]></title>
            <link rel="alternate" href="https://github.com/commixproject/commix" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6573"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated All-in-One OS Command Injection Exploitation Tool.
Commix (short for [comm]and [i]njection e[x]ploiter) is an open source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities.]]>
            </summary>
            <updated>2025-08-29T10:13:37+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6679</id>
            <title type="text"><![CDATA[Cobalt Strike]]></title>
            <link rel="alternate" href="https://www.cobaltstrike.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6679"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Software for Adversary Simulations and Red Team Operations.
Adversary Simulations and Red Team Operations are security assessments that replicate the tactics and techniques of an advanced adversary in a network. While penetration tests focus on unpatched vulnerabilities and misconfigurations, these assessments benefit security operations and incident response.]]>
            </summary>
            <updated>2025-08-29T10:30:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6718</id>
            <title type="text"><![CDATA[Auth Analyzer]]></title>
            <link rel="alternate" href="https://github.com/portswigger/auth-analyzer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6718"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Burp extension helps you to find authorization bugs. Just navigate through the web application with a high privileged user and let the Auth Analyzer repeat your requests for any defined non-privileged user. With the possibility to define Parameters the Auth Analyzer is able to extract and replace parameter values automatically. With this for instance, CSRF tokens or even whole session characteristics can be auto extracted from responses and replaced in further requests. Each response will be analyzed and tagged on its bypass status.]]>
            </summary>
            <updated>2025-08-29T10:37:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6736</id>
            <title type="text"><![CDATA[EDRSandblast]]></title>
            <link rel="alternate" href="https://github.com/wavestone-cdt/EDRSandblast" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6736"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Notify Routine callbacks, Object Callbacks and ETW TI provider) and LSASS protections. Multiple userland unhooking techniques are also implemented to evade userland monitoring.

As of release, combination of userland (--usermode) and Kernel-land (--kernelmode) techniques were used to dump LSASS memory under EDR scrutiny, without being blocked nor generating &amp;quot;OS Credential Dumping&amp;quot;-related events in the product (cloud) console. The tests were performed on 3 distinct EDR products and were successful in each case.]]>
            </summary>
            <updated>2025-08-29T10:39:49+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6749</id>
            <title type="text"><![CDATA[Impacket]]></title>
            <link rel="alternate" href="https://github.com/SecureAuthCorp/impacket" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6749"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself. Packets can be constructed from scratch, as well as parsed from raw data, and the object-oriented API makes it simple to work with deep hierarchies of protocols. The library provides a set of tools as examples of what can be done within the context of this library.]]>
            </summary>
            <updated>2025-08-29T10:41:54+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6940</id>
            <title type="text"><![CDATA[OWASP WebGoat]]></title>
            <link rel="alternate" href="https://owasp.org/www-project-webgoat/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6940"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[WebGoat is a deliberately insecure application that allows interested developers just like you to test vulnerabilities commonly found in Java-based applications that use common and popular open source components.

- [OWASP WebGoat @ GitHub](https://github.com/WebGoat/WebGoat).

Related contents:

- [WebGoat - Pour vous former au hacking éthique @ Korben :fr:](https://korben.info/webgoat-owasp-apprendre-hacking-ethique.html).]]>
            </summary>
            <updated>2025-09-29T10:19:08+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6942</id>
            <title type="text"><![CDATA[RasPwn OS]]></title>
            <link rel="alternate" href="https://raspwn.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6942"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Welcome to RasPwn OS, The intentionally vulnerable image for the Raspberry Pi.

Raspwn OS is a GNU/Linux distro in the spirit of Damn Vulnerable Linux and uses a Raspberry Pi 2B or 3 to emulate a vulnerable Linux Server. RasPwn was designed as a training tool and exists only to be attacked and pwned. Everything from the OS itself to the daemons and services to the web applications installed are all vulnerable to some degree. The idea is to provide a &amp;#039;safe&amp;#039; (relatively) and affordable training environment and playground for hackers and pen-testers. By loading Raspwn OS and connecting to the Raspberry Pi via WiFi, one can practice pen-testing as well as both offensive and defensive hacking techniques without ever even getting on the internet for only around $50.]]>
            </summary>
            <updated>2025-08-29T11:14:11+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6946</id>
            <title type="text"><![CDATA[AutoPWN Suite]]></title>
            <link rel="alternate" href="https://kaangultekin.net/projects/autopwn-suite/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6946"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

- [AutoPWN Suite @ GitHub](https://github.com/GamehunterKaan/AutoPWN-Suite).]]>
            </summary>
            <updated>2026-03-27T11:15:03+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7099</id>
            <title type="text"><![CDATA[OWASP ZAP]]></title>
            <link rel="alternate" href="https://www.zaproxy.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7099"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The world&amp;#039;s most widely used web app scanner. Free and open source. Actively maintained by a dedicated international team of volunteers.

- [ZAP @ GitHub](https://github.com/zaproxy/zaproxy).

Related  contents:

- [Automating OWASP PTK with ZAP (Phase 1) @ ZAP](https://www.zaproxy.org/blog/2026-05-06-automating-owasp-ptk-with-zap-phase-1/).
- [Automating OWASP PTK with ZAP (Phase 2) @ ZAP](https://www.zaproxy.org/blog/2026-06-05-automating-owasp-ptk-with-zap-phase-2/).
- [Building a Scanner and a Community with Zed Attack Proxy - Simon Bennetts - ASW #254  @ YouTube](https://www.youtube.com/watch?v=alIBoz7AooI).
- [Strengthening Your Web Application Security: Integrating OWASP ZAP with GitHub Actions @ System Weakness](https://systemweakness.com/strengthening-your-web-application-security-integrating-owasp-zap-with-github-actions-2c177545f21d).]]>
            </summary>
            <updated>2026-06-11T06:09:27+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7555</id>
            <title type="text"><![CDATA[Parrot Security OS]]></title>
            <link rel="alternate" href="https://www.parrotsec.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7555"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cloud oriented pentesting distribution.

Related contents:

- [ 💡💡Parrot 6.3 est sorti avec une sécurité améliorée et de nouveaux outils de piratage @ Almamy Diakho&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/almamy-diakho-63397b146_parrotos-linux-update-activity-7292460460526727170-7dMq/).]]>
            </summary>
            <updated>2025-08-29T12:57:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7679</id>
            <title type="text"><![CDATA[Hackazon]]></title>
            <link rel="alternate" href="https://github.com/rapid7/hackazon" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7679"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Hackazon is a free, vulnerable test site that is an online storefront built with the same technologies used in today’s rich client and mobile applications. Hackazon has an AJAX interface, strict workflows and RESTful API’s used by a companion mobile app providing uniquely-effective training and testing ground for IT security professionals. And, it’s full of your favorite vulnerabilities like SQL Injection, cross-site scripting and so on.]]>
            </summary>
            <updated>2025-08-29T13:17:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7680</id>
            <title type="text"><![CDATA[DVWA - Damn Vulnerable Web Application]]></title>
            <link rel="alternate" href="http://www.dvwa.co.uk/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7680"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and aid teachers/students to teach/learn web application security in a class room environment.]]>
            </summary>
            <updated>2025-08-29T13:17:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7825</id>
            <title type="text"><![CDATA[SQLmap]]></title>
            <link rel="alternate" href="http://sqlmap.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7825"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[automatic SQL injection and database takeover tool.

SQLmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.

- [SQLmap @ GitHub](https://github.com/sqlmapproject/sqlmap).
- [How To Attack Sql Injection Using [SQLMAP] Via Method [POST] @ System Weakness](https://systemweakness.com/how-to-attack-sql-injection-using-sqlmap-via-method-post-cae19495319f).]]>
            </summary>
            <updated>2025-08-29T13:41:30+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/7952</id>
            <title type="text"><![CDATA[Kali Linux]]></title>
            <link rel="alternate" href="https://www.kali.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/7952"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The most advanced Penetration Testing Distribution.

Kali Linux is an open-source, Debian-based Linux distribution geared towards various information security tasks, such as Penetration Testing, Security Research, Computer Forensics and Reverse Engineering.]]>
            </summary>
            <updated>2025-08-29T14:03:42+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8288</id>
            <title type="text"><![CDATA[HackaServer]]></title>
            <link rel="alternate" href="http://hackaserver.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8288"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Crowd Source Audit Platform for Manual PenTest]]>
            </summary>
            <updated>2025-08-29T15:00:15+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/8535</id>
            <title type="text"><![CDATA[BlackArch]]></title>
            <link rel="alternate" href="http://www.blackarch.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/8535"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[BlackArch Linux is an Arch-based GNU/Linux distribution for pentesters and security researchers. The BlackArch package repository is compatible with existing Arch installs.]]>
            </summary>
            <updated>2025-08-29T15:40:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9030</id>
            <title type="text"><![CDATA[Wifite]]></title>
            <link rel="alternate" href="https://github.com/derv82/wifite2" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9030"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[automated wireless auditor.

To attack multiple WEP, WPA, and WPS encrypted networks in a row. This tool is customizable to be automated with only a few arguments. Wifite aims to be the &amp;quot;set it and forget it&amp;quot; wireless auditing tool.

It&amp;#039;s a Python script for auditing wireless networks.
Wifite runs existing wireless-auditing tools for you. Stop memorizing command arguments &amp;amp; switches!
Wifite is designed to use all known methods for retrieving the password of a wireless access point (router).]]>
            </summary>
            <updated>2025-08-29T17:03:20+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/9475</id>
            <title type="text"><![CDATA[Nikto]]></title>
            <link rel="alternate" href="http://cirt.net/nikto2" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/9475"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Nikto web server scanner.

Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers.

It also checks for server configuration items such as the presence of multiple index files, HTTP server options, and will attempt to identify installed web servers and software. Scan items and plugins are frequently updated and can be automatically updated.

- [Nikto @ GitHub](https://github.com/sullo/nikto).
- [Nikto : outil pour scanner la sécurité d’un serveur web @ Memo-Linux.com](https://memo-linux.com/nikto-outil-scanner-de-securite-serveur-web/).
- [ La version 2.5 de Nikto est sortie @ Stéphane MORICO&amp;#039;s LinkedIn](https://www.linkedin.com/posts/stephane-morico_la-version-25-de-nikto-est-sortie-nikto-activity-7137480505309937665-jQDK/).]]>
            </summary>
            <updated>2025-08-29T18:18:00+00:00</updated>
        </entry>
    </feed>
