Skip to content

stonespheres/h4k-sore

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 
 
 

Repository files navigation

h4k-sore

A Collection of Pentesting Tools and Resources.

hackerman

Index

Categories Notes
OPPSEC (Operational Security)
OSINT (Open Source Intelligence)
CTF Resources Tutorials, playgrounds and more.
News News curation
Pentesting Resources
Reversing Resources
Malware Analysis
Anonymisers Hide your identity
Honeypots Traps, etc.
Network Defence
Operating Systems Windows, Linux.
Other Collections Links to other lists and curations.
References

OPPSEC

The following references were composed with OPPSEC and Sock Puppet generation in mind.

OSINT

CTF and Skill Development

CTF sites

CTF Resources

CTF Tools

Reversing

News and Info

Pentesting Resources

Exploit Information and Resources

Web Tools

  • BurpSuite - A graphical tool to testing website security.
  • Commix - Automated All-in-One OS Command Injection and Exploitation Tool.
  • Hackbar - Firefox addon for easy web exploitation.
  • CyberChef - Web app for data analysis; great for CTFs.

Pentesting Tools

Scripts

  • CTF Tools - Setup scripts to install various security research tools.

Reversing

RE Tools

  • radare2 - RE toolkit and cutter.
  • IDA - Disassembly and Debugging Toolkit.
  • Ghidra - Toolkit developed by the NSA.

Malware Analysis

Information Aquisition

Forensic Tools

  • USBRip - Track USB events on GNU/Linux.
  • Volatility - Open Source memory dump investigation toolset.
  • Wireshark - Used to analyze pcap.
  • Sleuthkit - CLI tools for forensic investigation.
  • Autopsy - GUI for the Sleuthkit.

Sandboxes

Play with danger

Anonymisers

Conceal your identity

  • Privoxy - An open source proxy server with some privacy features. 2
  • Tor - The Onion Router, for browsing the web without leaving traces of the client IP.
  • Mullvad - Highly Anonoymous VPN. Cash, Monero and Bitcoin accepted.
  • I2P - Invisible Internet Project.

Honeypots

Treats too good to resist

  • Honeyd - Virtual honeynet.
  • CanaryTokens - Self-hostable honeytoken generator and reporting dashboard; demo version available at CanaryTokens.org.
  • Kushtaka - Sustainable all-in-one honeypot and honeytoken orchestrator for under-resourced blue teams.
  • Manuka - Open-sources intelligence (OSINT) honeypot that monitors reconnaissance attempts by threat actors and generates actionable intelligence for Blue Teamers.

Network Perimeter Defense

  • Gatekeeper - First open source Distributed Denial of Service (DDoS) protection system. 2
  • fwknop - Protects ports via Single Packet Authorization in your firewall. 2
  • ssh-audit - Simple tool that makes quick recommendations for improving an SSH server's security posture. 2

Detection

  • Snort - Widely-deployed, Free Software IPS capable of real-time packet analysis, traffic logging, and custom rule-based triggers.
  • Suricata - Free, cross-platform, IDS/IPS.
  • Wireshark - The free and open-source packet analyzer

Security and Pentesting Operating Systems

Other Cybersecurity Collections

References

Footnotes

  1. Awesome Pentest https://github.com/enaqx/awesome-pentest

  2. Awesome Cybersecurity Blueteam https://github.com/fabacab/awesome-cybersecurity-blueteam 2 3 4 5 6 7 8

About

Collection of Pentesting Tools

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published