WHOEVER BUILT THIS WAS TIRED OF INSTALLING 50 DIFFERENT HACKING TOOLS
Someone turned 183+ penetration testing and OSINT tools into ONE command line toolkit.
—> Recon.
—> Vulnerability scanning.
—> Web app testing.
—> iOS security.
—> OSINT.
All sitting behind a single CLI menu.
Instead of spending hours installing tools, configuring dependencies and jumping between terminals, you can manage the whole stack from one place.
And because it’s open source, you can actually inspect it, modify it and build your own workflows around it.
Cybersecurity students are going to have a field day with this.
Just remember: use it on systems you own or have explicit permission to test.
This is basically a Swiss Army knife for security researchers.
REPO BELOW
Robin automates dark web OSINT by refining queries with LLMs, filtering results across multiple search engines via Tor, and producing investigation summaries.
https://t.co/cJLgLWTmSx
MailAccess is a free, self-hostable OSINT platform for investigating email addresses that aggregates data from breach databases, social networks, and DNS without requiring API keys.
https://t.co/EGbL4wwrzK
Sn1per is a platform for automated penetration testing and attack surface management that orchestrates over 90 third-party tools for reconnaissance, scanning, and exploitation.
https://t.co/rLgJQlnEzt
JUST DROPPED: NIST SP 1347 - Final - Cybersecurity Framework 2.0: Informative References Quick-Start Guide
Maps references to Categories of controls with Implementation Examples
https://t.co/KhakJLKPyI
Claude-AD
Active Directory pentest methodology for Claude Code.
Skills, agents and commands that give Claude the playbook for an internal Active Directory assessment: the phase order, the environment constraints that break your tooling, the telemetry each technique leaves behind, and how a finding maps to a compliance control
Resource/Credit: https://t.co/m2CSH1EUhw
Awesome OSINT Arsenal provides a one-command installation for over 750 open-source intelligence tools across 50 security categories.
https://t.co/svB2CzyjB9
Powershell for Hackers - Basics
We updated our article on Powershell for Hackers. There we cover essential commands and show you tricks.
There is a bonus trick in the end that you might like.
https://t.co/gxKRABUQVJ
You may not want to believe it but it doesn’t make it any less true. You absolutely can defend Active Directory. Start by doing this:
Part 1 - Disabling NTLMv1
Part 2 - Removing SMBv1
Part 3 - Enforcing LDAP Signing
Part 4 - Enforcing AES for Kerberos
Part 5 - Enforcing LDAP Channel Binding
Part 6 - Enforcing SMB Signing
Part 7 - Implementing Least Privilege
Link to all articles 👇
https://t.co/JNDMfVqoDP
I built BloodBash to help me pass my OSCP+ with more confidence
It worked
The most surreal thing I experienced at DefCon 34 though was random people telling me they used it to pass their OSCP also.
If you have feedback please share it. I want to make it the best tool we can
@offsectraining@defcon #hacktheplanet #activedirectory #oscp #redteam #pentetrationtesting
https://t.co/edG3FePUB6
Spent the week at @defcon with hackers building tools to detect Flock cameras, IMSI catchers, Bluetooth trackers, and everything else quietly watching us.
No one is coming to save us.
It's up to all of us to build the resistance.
https://t.co/08s4mB8uIW
https://t.co/1ZrEGRIwgM
DEF CON 32 - Anyone can hack IoT- Beginner's Guide to Hacking Your First IoT Device by Andrew Bellini @d1gitalandrew
TLDR:- An Walkthrough covering the methodology, tools, tactics and a <$100 toolkit to find your first IoT vulnerability.
If you're an IT admin and you’re after quick wins, low hanging fruit and security hygiene-related items, these are some great tools to start with. https://t.co/SvuNZuV7dX
GoProxy is a high-performance proxy server supporting HTTP, HTTPS, Socks5, and SS protocols. It facilitates proxy load balancing, TCP and UDP port mapping, and SSH tunneling. The tool can also function as a reverse proxy to expose local services located behind NATs or firewalls.
https://t.co/HEgHc5XebS
[NEW] @SANSInstitute just released something I've been wanting to exist since the Hugging Face incident: a Readiness Check with the nine things every security team should be able to answer before an AI-run attack hits their environment.
These came straight out of the Hugging Face incident debrief where they walked 700 security leaders through the response. Roughly 90 questions came up. Those questions became the post-mortem we wrote with the @cloudsa CISO community, and now they're a diagnostic your team can take to figure out your IR gaps.
My favorite: if a slow, automated attack starts at 2 a.m. on a Saturday and blends into the automation already running in your environment, does anyone get paged within the hour?
You answer all nine on the page (nothing to download) and see where you are relative to the six factors that defined the incident:
Whether your SOC would see the attack
Whether you could investigate 20,000 commands
Whose model you'd use when frontier models refuse your attack data
Whether your credentials and rebuild process hold
Whether you know your AI surface
What you ask the board to fund
That second one is the honest test. For an IR consultant, 20,000 commands is a Tuesday. For teams that don't do this daily, it's daunting, and finding that out mid-incident is the expensive way.
Over the last 20 years, defenders have dealt with many of the same core attack techniques used in the Hugging Face attack. AI changed how many could be attempted, combined, and executed autonomously at the same time... and which controls fail first. You will have gaps, and this diagnostic can inform what you address first.
Take the AI-Run Attack Readiness Check into your next staff meeting and send me your score. (I don't expect to see a nine-for-nine. Prove me wrong.)
https://t.co/yEgkAFeh8M