Showing 12 open source projects for "defensive attack"

View related business solutions
  • $300 Free Credits to Build on Google Cloud Icon
    $300 Free Credits to Build on Google Cloud

    New customers can spin up VMs, build with AI, and query data at no cost.

    Put your $300 in credit toward real workloads, then keep building with free monthly usage for 20+ products. No commitment and no charge until you upgrade.
    Start Free
  • Demo Series - Small Business Backup By Veeam Icon
    Demo Series - Small Business Backup By Veeam

    Learn how to protect your Microsoft 365 data, with simple, actionable tips today.

    Watch this on-demand demo series and learn how to protect your Microsoft 365 data with clear, simple, actionable steps that are easy to implement for businesses of all sizes.
    Watch Demo Series
  • 1
    Cloud Security Attacks

    Cloud Security Attacks

    Azure and AWS Attacks

    Cloud Security Attacks is a curated reference collection focused on offensive and defensive security research for major cloud platforms. Its primary sections organize material around Amazon Web Services and Microsoft Azure. The repository links to research on identity and access management, privilege escalation, cloud storage, containers, authentication, and common configuration weaknesses. It also includes material on cloud-specific attack paths, security testing methodologies, and documented vulnerabilities. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • 2
    RedSun

    RedSun

    The Red Sun vulnerability repository

    ...It highlights flaws in endpoint protection logic and emphasizes how race conditions and file system interactions can be abused. The project is not designed as a full framework but as a focused demonstration of a real-world vulnerability. It serves as a stark example of how defensive systems can be turned into attack vectors.
    Downloads: 16 This Week
    Last Update:
    See Project
  • 3
    FISSURE

    FISSURE

    The RF and reverse engineering framework for everyone

    ...It is designed as a practical environment for researchers and operators who need to move from raw spectrum observation to structured investigation without stitching together too many separate utilities by hand. The platform supports workflows related to signal discovery, demodulation, packet inspection, fuzzing, and attack simulation, making it useful for both defensive research and controlled lab testing. Its architecture is oriented toward extensibility, so users can integrate additional hardware, signal-processing components, and protocol-specific modules depending on their needs.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 4
    PowerUpSQL

    PowerUpSQL

    A PowerShell toolkit for attacking SQL Server

    PowerUpSQL is a PowerShell toolkit focused on auditing, discovering, and post-exploitation activities for Microsoft SQL Server environments. It bundles a wide range of functions that help enumerate SQL Server instances, configuration settings, and potentially risky features so operators and testers can quickly understand an instance's security posture. The project is aimed at internal penetration testers and red-teamers but is also useful for database administrators and defenders who want to...
    Downloads: 0 This Week
    Last Update:
    See Project
  • MongoDB Atlas runs apps anywhere Icon
    MongoDB Atlas runs apps anywhere

    Deploy in 115+ regions with the modern database for every enterprise.

    MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
    Start Free
  • 5
    HTML5 Security Cheatsheet

    HTML5 Security Cheatsheet

    A collection of HTML5 related XSS attack vectors

    H5SC, or the HTML5 Security Cheatsheet, is a public reference collection for researching browser-based cross-site scripting behavior. It catalogs HTML5-related XSS vectors so security professionals can compare how markup, browser features, and parsing behavior affect injection risks. The repository also includes supporting files intended for controlled XSS testing. A collection of lesser-known browser behaviors helps researchers investigate edge cases that ordinary checklists may miss....
    Downloads: 0 This Week
    Last Update:
    See Project
  • 6

    CyberPrint-Server

    Alpine Linux + CUPS print-server VM for cybersecurity training labs

    CyberPrint-Server is a lightweight Alpine Linux + CUPS virtual machine for cybersecurity and IT training labs. It includes CUPS/IPP on port 631, SSH/SFTP access, and a ready-to-use Generic Text-Only printer for practising secure printing, service hardening, and defensive monitoring. The vulnerable lab version includes scenarios for CVE-2024-47176, a CUPS/cups-browsed issue used in the Evil CUPS attack chain, and CVE-2026-31431, also known as Copy Fail, a Linux local privilege escalation vulnerability. For full setup instructions, lab scenarios, and updates, visit the GitHub repository: https://github.com/kaledaljebur/CyberPrint-Server Regards, Kaled Aljebur.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 7
    Evilginx 3.0

    Evilginx 3.0

    Standalone man-in-the-middle attack framework

    Evilginx 3.0 is a standalone security-testing framework that demonstrates reverse-proxy phishing attacks against modern web authentication systems. It sits between a browser and a legitimate service to study how credentials and authenticated session data can be intercepted in adversary-in-the-middle scenarios. Because session tokens can remain valid after multifactor authentication, the project highlights limitations of some traditional 2FA deployments. The current implementation is written...
    Downloads: 11 This Week
    Last Update:
    See Project
  • 8
    Sn1per

    Sn1per

    Automated penetration testing & attack surface management platform

    ...Commercial editions add a graphical dashboard, workspace navigation, report exports, integrations, and a JSON API, while the repository contains the Community Edition. It is intended only for authorized penetration tests, attack-surface management, and defensive security validation.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 9
    Slipstream

    Slipstream

    NAT Slipstreaming allows an attacker to remotely access any TCP/UDP

    Slipstream (also referred to as “NAT Slipstreaming”) is a proof-of-concept exploit framework that allows an attacker to remotely access any TCP or UDP service running on a victim machine inside a NAT (behind a router/firewall) simply by tricking the target to visit a malicious website. It works by abusing the NAT’s Application Level Gateway (ALG) logic and connection tracking, combined with browser capabilities like WebRTC, precise packet fragmentation or boundary control, and packet...
    Downloads: 0 This Week
    Last Update:
    See Project
  • Earn up to 16% annual interest with Nexo. Icon
    Earn up to 16% annual interest with Nexo.

    Access competitive interest rates on your digital assets.

    Generate interest, borrow against your crypto, and trade a range of cryptocurrencies — all in one platform. Geographic restrictions, eligibility, and terms apply.
    Get started with Nexo.
  • 10
    Warborg is wargame running on network writed with Ada and Gtkada over MS Windows and Gnu/Linux. Version 2020 in development La partie démare en vérifiant si le joueur à une partie en cours et a perdu ou pas ; C'est la phase DEFCON_1 ; On passe à DEFCON 5. Le jeu commence alors ou continu en proposant une boite de dialogue qui servira à instruire le programme selon ses besoins. Après avoir choisi la position du WOPR, -- Debut : Dialogues dialog_1 : choix de la cible principale....
    Downloads: 0 This Week
    Last Update:
    See Project
  • 11
    Evilginx v.1.1.0

    Evilginx v.1.1.0

    Man-in-the-middle attack framework used for phishing credentials

    Evilginx v.1.1.0 is the original version of a man-in-the-middle phishing research framework created to demonstrate risks in web authentication systems. It used a customized Nginx configuration to proxy traffic between a browser and a legitimate web service. The framework was designed to study how credentials and authenticated session cookies could be intercepted during authorized security assessments. Site-specific templates defined how supported services were proxied and modified. A Python...
    Downloads: 4 This Week
    Last Update:
    See Project
  • 12
    Metasploit Framework

    Metasploit Framework

    Metasploit Framework

    Metasploit Framework is a comprehensive penetration-testing and exploit development platform that streamlines the process of discovering, validating, and demonstrating vulnerabilities. It provides a modular architecture—payloads, encoders, exploits, auxiliaries, and post-exploitation modules—so security professionals can piece together complex attack chains or test defensive controls in realistic ways. Built-in features include an exploit database, network scanners, credential harvesters, and frameworks to craft reliable payload delivery while handling target nuances like mitigation bypasses and platform differences. Beyond raw exploitation, the framework includes post-exploitation tooling for lateral movement, persistence, data exfiltration simulations, and evidence collection, enabling red teams to exercise detection and incident response workflows.
    Downloads: 30 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • Next