en
Feedback
Gray Hat™

Gray Hat™

Open in Telegram
No data
Subscribers
-824 hours
-367 days
-2630 days
Posts Archive
Repost from InfoSec Insider
RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging. https://github.com/DarkSpaceSecurity/RunAs-Stealer #InfoSecInsider

Repost from InfoSec Insider
/Phone : a mobile phone forensic framework for security researchers and forensic experts. It's now available on github, follow the instructions and you will get it up and running successfully. https://github.com/cyb3rfortr3ss/Phone

Together, we are stronger. Happy International Women's Day to all the amazing women out there! #grayhats

Repost from InfoSec Insider
RustRedOps is a repository for advanced Red Team techniques and offensive malware, focused on Rust. https://github.com/joaoviictorti/RustRedOps

Repost from InfoSec Insider
A powerful Remote Administration Tool for Android OS hacking, working on Android 7 to Android 15! Features Include: Remote control Pattern+PIN+Passcode stealer Auto unlock screen with recorded pattern Hidden control (blank victim’s screen) SMS & contacts stealer Hide notifications & mute volume File manager Camera & microphone access Keylogger Install apps remotely GUID+dropper & more! https://github.com/hidden9090/AndroidRat-Android-Rat-AndroRat-Android-stealer-OS-hacking-Android-hacking-RAT-Dangerous-RAT-botnet?tab=readme-ov-file #HackersForum

Repost from InfoSec Insider
Run your own AI cluster at home with everyday devices. https://github.com/exo-explore/exo

#GitHub #Tools Wazuh — Unsafe Deserialization RCE (CVE-2025-24016) An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses https://github.com/0xjessie21/CVE-2025-24016 Tool for monitor Active Directory changes in real time without getting all objects. Instead of this it use replication metadata and Update Sequence Number (USN) to filter current properties of objects. https://github.com/DrunkF0x/ADSpider Morgan is a powerful tool designed to help security researchers, developers, and security auditors identify sensitive information, vulnerabilities, and potential risks within JavaScript files on websites. https://GitHub.com/VFA250/Morgan #HackersFactory

#GitHub #Tools Wazuh — Unsafe Deserialization RCE (CVE-2025-24016) An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses https://github.com/0xjessie21/CVE-2025-24016 Tool for monitor Active Directory changes in real time without getting all objects. Instead of this it use replication metadata and Update Sequence Number (USN) to filter current properties of objects. https://github.com/DrunkF0x/ADSpider Morgan is a powerful tool designed to help security researchers, developers, and security auditors identify sensitive information, vulnerabilities, and potential risks within JavaScript files on websites. https://GitHub.com/VFA250/Morgan #HackersFactory

Tool for monitor Active Directory changes in real time without getting all objects. Instead of this it use replication metadata and Update Sequence Number (USN) to filter current properties of objects. https://github.com/DrunkF0x/ADSpider #HackersFactory

Repost from InfoSec Insider
An inventory of tools and resources about CyberSecurity. https://inventory.raw.pm/resources.html #HackersForum

Repost from InfoSec Insider
JavaScript URLs form a text file and search for any keywords like API, API KEY, Access Token, Password, Secret,….. and more https://github.com/brosck/mantra

Repost from InfoSec Insider
Search from hundreds of pentest terms https://github.com/AmanuelCh/pentest-terms

Sensitive Files by Fuzzing Key .git Paths. /.git /.gitkeep /.git-rewrite /.gitreview /.git/HEAD /.gitconfig /.git/index /.git/logs /.svnignore /.gitattributes /.gitmodules /.svn/entries #grayhats

🌙 Ramadan Kareem! 🌙 As the blessed month of Ramadhan begins, @GhostPrincess wishes you and your loved ones a month full of blessings. May our fasting and prayers bring us closer to Allah and fill our hearts with peace. #GhostsofPs #GhostsOfPalestine

Ramadan Kareem brothers and sisters! 🌙

Why Coding is Essential for Bug Bounty Hunters Having strong programming skills can elevate any bug bounty hunter’s game. It’s not just about identifying vulnerabilities—it’s about truly understanding how they come to exist. Being able to read and write code allows you to dive deep into web applications, pinpoint subtle flaws, and design custom exploits that others might overlook. Moreover, coding knowledge empowers you to automate tedious processes and build your own tools, boosting both efficiency and effectiveness. Simply put, the more you understand the code, the better equipped you’ll be to uncover and exploit its weaknesses. #grayhats

Top 25 JavaScript Path Files used to store sensitive information in Web Application 01. /js/config.js 02. /js/credentials.js 03. /js/secrets.js 04. /js/keys.js 05. /js/password.js 06. /js/api_keys.js 07. /js/auth_tokens.js 08. /js/access_tokens.js 09. /js/sessions.js 10. /js/authorization.js 11. /js/encryption.js 12. /js/certificates.js 13. /js/ssl_keys.js 14. /js/passphrases.js 15. /js/policies.js 16. /js/permissions.js 17. /js/privileges.js 18. /js/hashes.js 19. /js/salts.js 20. /js/nonces.js 21. /js/signatures.js 22. /js/digests.js 23. /js/tokens.js 24. /js/cookies.js 25. /js/topsecr3tdonotlook.js #grayhats

Repost from CyberDilara
Four ways to search Google for sites in a particular country (all work roughly): 1. Search by domain: site:.ps 2. Change language settings: Add to &hl=fr to URL 3. Search by IP range: site:101.99.*.* 4. Use http://isearchfrom.com. Is a custom Google Search tool that allows users to modify various search parameters, such as language, country, city location, device type, and personalization settings. This tool is particularly useful for previewing how Google search results and ads appear in different locations or under specific conditions. #CyberDilara

Repost from CyberDilara
A project that detects malicious capabilities in executable files. https://github.com/mandiant/capa #CyberDilara