From 976e840817b23ec4df8954e1190ad05f42cd25e1 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: thispersondoesnotexist - generate fake faces in one click - endless possibilities.
:small_orange_diamond: thispersondoesnotexist - generate fake faces in one click - endless possibilities.
- :small_orange_diamond: Intigriti Redirector - open redirect/SSRF payload generator.
:small_orange_diamond: AI Generated Photos - 100.000 AI generated faces.
+ :small_orange_diamond: Intigriti Redirector - open redirect/SSRF payload generator.
:small_orange_diamond: AI Generated Photos - 100.000 AI generated faces.
+ :small_orange_diamond: fakeface - fake faces browser.
:small_orange_diamond: Intigriti Redirector - open redirect/SSRF payload generator.
:small_orange_diamond: CIS Benchmarks - are secure configuration settings for over 100 technologies, available as a free PDF download.
:small_orange_diamond: Security Harden CentOS 7 - this walks you through the steps required to security harden CentOS.
:small_orange_diamond: CentOS 7 Server Hardening Guide - great guide for hardening CentOS; familiar with OpenSCAP.
+ :small_orange_diamond: awesome-security-hardening - is a collection of security hardening guides, tools and other resources.
:small_orange_diamond: The Practical Linux Hardening Guide - provides a high-level overview of hardening GNU/Linux systems.
:small_orange_diamond: OWASP-VWAD - comprehensive and well maintained registry of all known vulnerable web applications.
:small_orange_diamond: DVWA - PHP/MySQL web application that is damn vulnerable.
+ :small_orange_diamond: metasploitable2 - vulnerable web application amongst security researchers.
+ :small_orange_diamond: metasploitable3 - is a VM that is built from the ground up with a large amount of security vulnerabilities.
:small_orange_diamond: DSVW - is a deliberately vulnerable web application written in under 100 lines of code.
:small_orange_diamond: OWASP Mutillidae II - free, open source, deliberately vulnerable web-application.
:small_orange_diamond: OWASP Juice Shop Project - the most bug-free vulnerable application in existence.
@@ -1293,13 +1295,6 @@ AWS deployment tool.
:small_orange_diamond: RootTheBox - a Game of Hackers (CTF Scoreboard & Game Manager).
- :small_orange_diamond: metasploitable 2 - vulnerable web application amongst security researchers.
- :small_orange_diamond: metasploitable3 - is a VM that is built from the ground up with a large amount of security vulnerabilities.
-
From 98a1d7e73f6bffee4bd839fb70e720d3bf5d34ef Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: Don't use VPN services - which is what every third-party "VPN provider" does.
:small_orange_diamond: awesome-yara - a curated list of awesome YARA rules, tools, and people.
:small_orange_diamond: macOS-Security-and-Privacy-Guide - guide to securing and improving privacy on macOS.
+ :small_orange_diamond: awesome-sec-talks - is a collected list of awesome security talks.
:small_orange_diamond: Movies for Hackers - list of movies every hacker & cyberpunk must watch.
-
+
@@ -4152,3 +4152,33 @@ shell> GetASN 1.1.1.1
shell> GetASN 0.0.0.0
Unsuccessful ASN gathering.
```
+
+## Contributors
+
+### Code Contributors
+
+This project exists thanks to all the people who contribute. [[Contribute](CONTRIBUTING.md)].
+
+
+### Financial Contributors
+
+Become a financial contributor and help us sustain our community. [[Contribute](https://opencollective.com/the-book-of-secret-knowledge/contribute)]
+
+#### Individuals
+
+
+
+#### Organizations
+
+Support this project with your organization. Your logo will show up here with a link to your website. [[Contribute](https://opencollective.com/the-book-of-secret-knowledge/contribute)]
+
+
+
+
+
+
+
+
+
+
+
From 494827eded0c92f148f6ee1eab16b4ee82259111 Mon Sep 17 00:00:00 2001
From: trimstray
-
+
@@ -82,6 +82,44 @@ Before adding a pull request, please see the **[contributing guidelines](.github
All **suggestions/PR** are welcome!
+### Code Contributors
+
+This project exists thanks to all the people who contribute.
+
+
+
+### Financial Contributors
+
+
:small_orange_diamond: GhostProject? - search by full email address or username.
:small_orange_diamond: databreaches - was my email affected by data breach?
:small_orange_diamond: We Leak Info - world's fastest and largest data breach search engine.
+ :small_orange_diamond: Pulsedive - scans of malicious URLs, IPs, and domains, including port scans and web requests.
:small_orange_diamond: scylla - db dumps and more.
:small_orange_diamond: Buckets by Grayhatwarfar - database with public search for Open Amazon S3 Buckets and their contents.
:small_orange_diamond: Vigilante.pw - the breached database directory.
From ad9093d27da9a07e7bacc8899b03a792508bdfd3 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: ctf-tools - some setup scripts for security research tools.
:small_orange_diamond: pwntools - CTF framework and exploit development library.
:small_orange_diamond: security-tools - collection of small security tools created mostly in Python. CTFs, pentests and so on.
+ :small_orange_diamond: pentestpackage - is a package of Pentest scripts.
:small_orange_diamond: python-pentest-tools - python tools for penetration testers.
:small_orange_diamond: fuzzdb - dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
:small_orange_diamond: syzkaller - is an unsupervised, coverage-guided kernel fuzzer.
From 0b25c89a3ddaefdde38e8471909a078c61255405 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: maltrail - malicious traffic detection system.
:small_orange_diamond: security_monkey - monitors AWS, GCP, OpenStack, and GitHub orgs for assets and their changes over time.
:small_orange_diamond: firecracker - secure and fast microVMs for serverless computing.
+ :small_orange_diamond: streisand - sets up a new server running your choice of WireGuard, OpenSSH, OpenVPN, Shadowsocks, and many more.
:small_orange_diamond: Netcraft - detailed report about the site, helping you to make informed choices about their integrity.*
:small_orange_diamond: Netcraft - detailed report about the site, helping you to make informed choices about their integrity.*
+ :small_orange_diamond: smtp-tls-checker - check an email domain for SMTP TLS support.
:small_orange_diamond: sysadmin-util - tools for Linux/Unix sysadmins.
:small_orange_diamond: smtp-tls-checker - check an email domain for SMTP TLS support.
:small_orange_diamond: fd - is a simple, fast and user-friendly alternative to find.
+ :small_orange_diamond: Packet Sender - is a networking utility for packet generation and built-in UDP/TCP/SSL client and servers with an easy to use GUI.
- :small_orange_diamond: RIPE NCC - not-for-profit membership association, a Regional Internet Registry and the secretariat for the RIPE.
+ :small_orange_diamond: RIPE NCC Atlas - a global, open, distributed Internet measurement platform, consisting of thousands of measurement devices that measure Internet connectivity in real time.
:small_orange_diamond: Robtex - uses various sources to gather public information about IP numbers, domain names, host names, routes etc.
:small_orange_diamond: Security Trails - APIs for Security Companies, Researchers and Teams.
:small_orange_diamond: Online Curl - curl test, analyze HTTP Response Headers.
From 58ac1c1b3d1ddeb1cd7ac244ace38ccf4ac7edac Mon Sep 17 00:00:00 2001
From: T89
- :small_orange_diamond: RIPE NCC Atlas - a global, open, distributed Internet measurement platform, consisting of thousands of measurement devices that measure Internet connectivity in real time.
+ :small_orange_diamond: RIPE NCC Atlas - a global, open, distributed Internet measurement platform.
:small_orange_diamond: Robtex - uses various sources to gather public information about IP numbers, domain names, host names, routes etc.
:small_orange_diamond: Security Trails - APIs for Security Companies, Researchers and Teams.
:small_orange_diamond: Online Curl - curl test, analyze HTTP Response Headers.
From 9af92bff5e29bb5171c8d3bafea39c169b8a9101 Mon Sep 17 00:00:00 2001
From: digitalmine <34872176+digitalmine@users.noreply.github.com>
Date: Sun, 29 Dec 2019 09:18:27 +0000
Subject: [PATCH 17/43] Update README.md
https://inteltechniques.com/menu.html lands you with 404 error
---
README.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/README.md b/README.md
index 37dce4a..e62b7ea 100644
--- a/README.md
+++ b/README.md
@@ -584,7 +584,7 @@ performance of any of your sites from across the globe.
:small_orange_diamond: binaryedge - it scan the entire internet space and create real-time threat intelligence streams and reports.
:small_orange_diamond: wigle - is a submission-based catalog of wireless networks. All the networks. Found by Everyone.
:small_orange_diamond: PublicWWW - find any alphanumeric snippet, signature or keyword in the web pages HTML, JS and CSS code.
- :small_orange_diamond: IntelTechniques - this repository contains hundreds of online search utilities.
+ :small_orange_diamond: IntelTechniques - this repository contains hundreds of online search utilities.
:small_orange_diamond: Hackle - search engine for hackers and security professionals.*
:small_orange_diamond: hunter - lets you find email addresses in seconds and connect with the people that matter for your business.
:small_orange_diamond: GhostProject? - search by full email address or username.
From db34a5ddb866561040d2f383311d47751c718024 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: massdns - is a high-performance DNS stub resolver for bulk lookups and reconnaissance.
:small_orange_diamond: knock - is a tool to enumerate subdomains on a target domain through a wordlist.
+ :small_orange_diamond: dnsperf - DNS performance testing tools.
:small_orange_diamond: dnscrypt-proxy 2 - a flexible DNS proxy, with support for encrypted DNS protocols.
:small_orange_diamond: dnsdbq - API client providing access to passive DNS database systems (pDNS at Farsight Security, CIRCL pDNS).
:small_orange_diamond: grimd - fast dns proxy, built to black-hole internet advertisements and malware servers.
From ade6b02bad4765efc489a49c21a6ce383a41ec7e Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: commander.js - minimal CLI creator in JavaScript.
:small_orange_diamond: gron - make JSON greppable!
+ :small_orange_diamond: bed - binary editor written in Go.
:small_orange_diamond: MX Toolbox - all of your MX record, DNS, blacklist and SMTP diagnostics in one integrated tool.
:small_orange_diamond: blacklistalert - checks to see if your domain is on a Real Time Spam Blacklist.
:small_orange_diamond: MultiRBL - complete IP check for sending Mailservers.
From d5185bc7e9de65bc69f3aa7c6a98a72e1c4fb3e4 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: ThreatHunter-Playbook - to aid the development of techniques and hypothesis for hunting campaigns.
:small_orange_diamond: PayloadsAllTheThings - a list of useful payloads and bypass for Web Application Security and Pentest/CTF.
:small_orange_diamond: payloads - git all the Payloads! A collection of web attack payloads.
+ :small_orange_diamond: command-injection-payload-list - command injection payload list.
:small_orange_diamond: AwesomeXSS - is a collection of Awesome XSS resources.
:small_orange_diamond: php-webshells - common php webshells.
:small_orange_diamond: Pentesting Tools Cheat Sheet - a quick reference high level overview for typical penetration testing engagements.
From 70c1ec7fb45512b9436d7e59bdd3843ddcf7ca21 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: incron - is an inode-based filesystem notification technology.
+ :small_orange_diamond: lsyncd - synchronizes local directories with remote targets (Live Syncing Daemon).
:small_orange_diamond: GRV - is a terminal based interface for viewing Git repositories.
:small_orange_diamond: Tig - text-mode interface for Git.
:small_orange_diamond: tldr - simplified and community-driven man pages.
From 6af87608a451ff767dc055befa1d7689ee4e56f1 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: Nikto2 - web server scanner which performs comprehensive tests against web servers for multiple items.
:small_orange_diamond: sqlmap - tool that automates the process of detecting and exploiting SQL injection flaws.
:small_orange_diamond: Recon-ng - is a full-featured Web Reconnaissance framework written in Python.
+ :small_orange_diamond: AutoRecon - is a network reconnaissance tool which performs automated enumeration of services.
:small_orange_diamond: Faraday - an Integrated Multiuser Pentest Environment.
:small_orange_diamond: Photon - incredibly fast crawler designed for OSINT.
:small_orange_diamond: XSStrike - most advanced XSS detection suite.
From 5820ff74598b6108fbfef64dd0bc46b3ce76e855 Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: OWASP ASVS 4.0 - is a list of application security requirements or tests.
:small_orange_diamond: OWASP Testing Guide v4 - includes a "best practice" penetration testing framework.
:small_orange_diamond: OWASP Dev Guide - this is the development version of the OWASP Developer Guide.
+ :small_orange_diamond: OWASP API Security Project - focuses specifically on the top ten vulnerabilities in API security.
:small_orange_diamond: Mozilla Web Security - help operational teams with creating secure web applications.
:small_orange_diamond: security-bulletins - security bulletins that relate to Netflix Open Source.
:small_orange_diamond: API-Security-Checklist - security countermeasures when designing, testing, and releasing your API.
From cc532f037cb65ecbb567af3fade1f798ba86910b Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: How to build a 8 GPU password cracker - any "black magic" or hours of frustration like desktop components do.
:small_orange_diamond: CERN Data Centre - 3D visualizations of the CERN computing environments (and more).
:small_orange_diamond: How fucked is my database - evaluate how fucked your database is with this handy website.
- :small_orange_diamond: Five Whys - you know what the problem is, but you cannot solve it?
+ :small_orange_diamond: Five Whys - you know what the problem is, but you cannot solve it?
:small_orange_diamond: howhttps.works - how HTTPS works ...in a comic!
:small_orange_diamond: howdns.works - a fun and colorful explanation of how DNS works.
:small_orange_diamond: MX Toolbox - all of your MX record, DNS, blacklist and SMTP diagnostics in one integrated tool.
+ :small_orange_diamond: Secure Email - complete email test tools for email technicians.
:small_orange_diamond: blacklistalert - checks to see if your domain is on a Real Time Spam Blacklist.
:small_orange_diamond: MultiRBL - complete IP check for sending Mailservers.
:small_orange_diamond: DKIM SPF & Spam Assassin Validator - checks mail authentication and scores messages with Spam Assassin.
From 30d7c1e35d968751f4ea0e4d8973812ec628b815 Mon Sep 17 00:00:00 2001
From: Cookizza <1787216+Cookizza@users.noreply.github.com>
Date: Thu, 23 Jan 2020 09:46:18 +0000
Subject: [PATCH 29/43] Added Spacemacs to Text Editors section
Spacemacs is a popular and fast growing emacs distribution that lets users work within an emacs or vim workflow. More than an add-on for emacs spacemacs is preconfigured to get developers quickly up and running, including the famous org-mode from emacs for writing documentation, educational papers, etc.
---
README.md | 1 +
1 file changed, 1 insertion(+)
diff --git a/README.md b/README.md
index 6620639..f69d8b0 100644
--- a/README.md
+++ b/README.md
@@ -179,6 +179,7 @@ Only main chapters:
:small_orange_diamond: emacs - is an extensible, customizable, free/libre text editor - and more.
:small_orange_diamond: micro - is a modern and intuitive terminal-based text editor.
:small_orange_diamond: neovim - is a free open source, powerful, extensible and usable code editor.
+ :small_orange_diamond: spacemacs - community-driven Emacs distribution that merges features and workflows of both vim and emacs.
:small_orange_diamond: Useless CSP - public list about CSP in some big players (might make them care a bit more).
:small_orange_diamond: Why No HTTPS? - list of the world's top 100 websites by Alexa rank not automatically redirecting insecure requests.
- :small_orange_diamond: cipherli.st - strong ciphers for Apache, Nginx, Lighttpd and more.
+ :small_orange_diamond: TLS Cipher Suite Search
+ :small_orange_diamond: cipherli.st - strong ciphers for Apache, Nginx, Lighttpd and more.*
:small_orange_diamond: dhtool - public Diffie-Hellman parameter service/tool.
:small_orange_diamond: badssl.com - memorable site for testing clients against bad SSL configs.
:small_orange_diamond: tlsfun.de - registered for various tests regarding the TLS/SSL protocol.
From 954423bc42be344ce8773f32c0ecdfeaea2678f6 Mon Sep 17 00:00:00 2001
From: Abdul Rauf
:small_orange_diamond: Crackmes - download crackmes to help improve your reverse engineering skills.
:small_orange_diamond: DomGoat - DOM XSS security learning and practicing platform.
:small_orange_diamond: Stereotyped Challenges - upgrade your web hacking techniques today!
- :small_orange_diamond: OverTheWire - can help you to learn and practice security concepts in the form of fun-filled games.
:small_orange_diamond: Vulnhub - allows anyone to gain practical 'hands-on' experience in digital security.
:small_orange_diamond: W3Challs - is a penetration testing training platform, which offers various computer challenges.
:small_orange_diamond: RingZer0 CTF - offers you tons of challenges designed to test and improve your hacking skills.
From b6715fe64df176b3992c09863a0e2a3b8cae02bb Mon Sep 17 00:00:00 2001
From: Alex van den Hoogen
+ :small_orange_diamond: ncdu - is an easy to use, fast disk usage analyzer.
:small_orange_diamond: Performance Co-Pilot - a system performance analysis toolkit.
:small_orange_diamond: hexyl - a command-line hex viewer.
+ :small_orange_diamond: nmon - a single executable for performance monitoring and data analysis.
:small_orange_diamond: mylg - is an open source utility which combines the functions of the different network probes in one diagnostic tool.
:small_orange_diamond: netcat - is a networking utility which reads and writes data across network connections, using the TCP/IP protocol.
+ :small_orange_diamond: Packet Sender - is a networking utility for packet generation and built-in UDP/TCP/SSL client and servers with an easy to use GUI.
:small_orange_diamond: tcpdump - is a powerful command-line packet analyzer.
:small_orange_diamond: tshark - is a tool that allows us to dump and analyze network traffic (wireshark cli).
:small_orange_diamond: Termshark - is a simple terminal user-interface for tshark.
@@ -389,6 +390,7 @@ Only main chapters:
##### :black_small_square: Network
:small_orange_diamond: Wireshark - is the world’s foremost and widely-used network protocol analyzer.
:small_orange_diamond: Ettercap - is a comprehensive network monitor tool.
:small_orange_diamond: EtherApe - is a graphical network monitoring solution.
From 72cf00a546e75ec2689ea7bf88e56b1bea26cc8b Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: glances - cross-platform system monitoring tool written in Python.
:small_orange_diamond: htop - interactive text-mode process viewer for Unix systems. It aims to be a better 'top'.
+ :small_orange_diamond: nmon - a single executable for performance monitoring and data analysis.
:small_orange_diamond: atop - ASCII performance monitor. Includes statistics for CPU, memory, disk, swap, network, and processes.
:small_orange_diamond: lsof - displays in its output information about files that are opened by processes.
:small_orange_diamond: FlameGraph - stack trace visualizer.
:small_orange_diamond: lsofgraph - small utility to convert Unix lsof output to a graph showing FIFO and UNIX interprocess communication.
:small_orange_diamond: rr - is a lightweight tool for recording, replaying and debugging execution of applications.
- :small_orange_diamond: Performance Co-Pilot - a system performance analysis toolkit.
+ :small_orange_diamond: Performance Co-Pilot - a system performance analysis toolkit.
:small_orange_diamond: hexyl - a command-line hex viewer.
- :small_orange_diamond: nmon - a single executable for performance monitoring and data analysis.
:small_orange_diamond: Buckets by Grayhatwarfar - database with public search for Open Amazon S3 Buckets and their contents.
:small_orange_diamond: Vigilante.pw - the breached database directory.
:small_orange_diamond: builtwith - find out what websites are built with.
- :small_orange_diamond: NerdyData - find where any technology is used, across millions of sites.
+ :small_orange_diamond: NerdyData - search the web's source code for technologies, across millions of sites.
:small_orange_diamond: Mamont's open FTP Index - if a target has an open FTP site with accessible content it will be listed here.
:small_orange_diamond: OSINT Framework - focused on gathering information from free tools or resources.
:small_orange_diamond: maltiverse - is a service oriented to cybersecurity analysts for the advanced analysis of indicators of compromise.
@@ -614,7 +614,6 @@ performance of any of your sites from across the globe.
:small_orange_diamond: malc0de - malware search engine.
:small_orange_diamond: Cybercrime Tracker - monitors and tracks various malware families that are used to perpetrate cyber crimes.
:small_orange_diamond: shhgit - find GitHub secrets in real time.
- :small_orange_diamond: NerdyData - search source code across 65 million websites.
:small_orange_diamond: searchcode - helping you find real world examples of functions, API's and libraries.
:small_orange_diamond: Insecam - the world biggest directory of online surveillance security cameras.
:small_orange_diamond: index-of - contains great stuff like: security, hacking, reverse engineering, cryptography, programming etc.
From 531ae95b5fdc1b0b9196839b276f4980026a95e0 Mon Sep 17 00:00:00 2001
From: Kalle
:small_orange_diamond: wigle - is a submission-based catalog of wireless networks. All the networks. Found by Everyone.
:small_orange_diamond: PublicWWW - find any alphanumeric snippet, signature or keyword in the web pages HTML, JS and CSS code.
:small_orange_diamond: IntelTechniques - this repository contains hundreds of online search utilities.
- :small_orange_diamond: Hackle - search engine for hackers and security professionals.*
:small_orange_diamond: hunter - lets you find email addresses in seconds and connect with the people that matter for your business.
:small_orange_diamond: GhostProject? - search by full email address or username.
:small_orange_diamond: databreaches - was my email affected by data breach?
From 68441cccab81d93f8f0a7f0c12e35bb55453b06c Mon Sep 17 00:00:00 2001
From: trimstray
:small_orange_diamond: Project-Based-Tutorials-in-C - is a curated list of project-based tutorials in C.
:small_orange_diamond: The-Documentation-Compendium - various README templates & tips on writing high-quality documentation.
:small_orange_diamond: awesome-python-applications - free software that works great, and also happens to be open-source Python.
+ :small_orange_diamond: awesome-public-datasets - a topic-centric list of HQ open datasets.
- :small_orange_diamond: Packet Sender - is a networking utility for packet generation and built-in UDP/TCP/SSL client and servers with an easy to use GUI.
:small_orange_diamond: Wireshark - is the world’s foremost and widely-used network protocol analyzer.
:small_orange_diamond: Ettercap - is a comprehensive network monitor tool.
:small_orange_diamond: EtherApe - is a graphical network monitoring solution.
+ :small_orange_diamond: Packet Sender - is a networking utility for packet generation and built-in UDP/TCP/SSL client and servers.
:small_orange_diamond: JMeter™ - open source software to load test functional behavior and measure performance.
:small_orange_diamond: locust - scalable user load testing tool written in Python.