Cybersecurity
Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.
358 articles
Cybersecurity
Prompt Engineering for Red Teams: How ChatGPT Became an Offensive Security Multiplier
Cybersecurity
Responder: Weaponizing Windows Name Resolution to Harvest Domain Credentials
Cybersecurity
PowerTools: The Deprecated PowerShell Arsenal That Shaped Modern Red Team Operations
Cybersecurity
IIS-ShortName-Scanner: Exploiting a 13-Year-Old Vulnerability Microsoft Won't Fix
Cybersecurity
Inside mubix/post-exploitation: A Time Capsule of Red Team Command-Line Tradecraft
Cybersecurity
PowerSploit: The PowerShell Framework That Taught Defenders What to Fear
Cybersecurity
GetHead: The Browser-Based HTTP Header Security Scanner That Fits in Your Bookmarks Bar
Cybersecurity
Python Pentest Tools: A Curated Gateway to Security Testing's Hidden Arsenal
Cybersecurity
Commix: Automating Command Injection Exploitation with Polymorphic Payloads
Cybersecurity
dirsearch: How Smart Wordlist Handling Makes or Breaks Web Path Discovery
Cybersecurity
Watchtower: When HTML5 LocalStorage Became a Security Audit Database
Cybersecurity
Building a Self-Documenting Security Remediation Pipeline: Lessons from AvP
Cybersecurity
Inside Cockatrice: Building a Cheat-Proof Virtual Tabletop with Qt and Server-Authoritative Design
Cybersecurity
PCC: The Two-Day Self-Destructing PHP Security Audit
Cybersecurity
XSS ChEF: The Chrome Extension Exploitation Framework That Revealed a Security Crisis
Cybersecurity
Netflix's Sleepy Puppy Docker: Why This Deprecated XSS Hunter Works Only Over HTTP
Cybersecurity
Sleepy Puppy: How Netflix Built a Callback-Based XSS Detection System That Tracked Payloads Across Time and Applications
Cybersecurity
Wifiphisher: Building Convincing Rogue Access Points for Red Team Engagements
Cybersecurity
Pupy: The Python C2 Framework That Lives Entirely in Memory
Cybersecurity
IntruderPayloads: The Bug Bounty Hunter's Arsenal for Burp Suite
Cybersecurity
Evilarc: The 200-Line Python Script That Breaks Archive Extraction Everywhere
Cybersecurity
SSVL: OWASP's Attempt to Solve the Vulnerability Data Babel Problem
Cybersecurity
Inspeckage: The Xposed Module That Taught Android Security Engineers How to See Through Apps
Cybersecurity