Gray Hat™
Open in Telegram
🚩 Channel was restricted by Telegram
Show moreNo data
Subscribers
-824 hours
-367 days
-2630 days
Posts Archive
Repost from InfoSec Insider
RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging.
https://github.com/DarkSpaceSecurity/RunAs-Stealer
#InfoSecInsider
Repost from InfoSec Insider
/Phone : a mobile phone forensic framework for security researchers and forensic experts.
It's now available on github, follow the instructions and you will get it up and running successfully.
https://github.com/cyb3rfortr3ss/Phone
Together, we are stronger. Happy International Women's Day to all the amazing women out there!
#grayhats
Repost from InfoSec Insider
RustRedOps is a repository for advanced Red Team techniques and offensive malware, focused on Rust.
https://github.com/joaoviictorti/RustRedOps
Repost from InfoSec Insider
A powerful Remote Administration Tool for Android OS hacking, working on Android 7 to Android 15!
Features Include:
Remote control
Pattern+PIN+Passcode stealer
Auto unlock screen with recorded pattern
Hidden control (blank victim’s screen)
SMS & contacts stealer
Hide notifications & mute volume
File manager
Camera & microphone access
Keylogger
Install apps remotely
GUID+dropper & more!
https://github.com/hidden9090/AndroidRat-Android-Rat-AndroRat-Android-stealer-OS-hacking-Android-hacking-RAT-Dangerous-RAT-botnet?tab=readme-ov-file
#HackersForum
Repost from InfoSec Insider
Run your own AI cluster at home with everyday devices.
https://github.com/exo-explore/exo
Repost from 𝗛𝗮𝗰𝗸𝗲𝗿𝘀 𝗙𝗮𝗰𝘁𝗼𝗿𝘆
#GitHub #Tools
Wazuh — Unsafe Deserialization RCE (CVE-2025-24016)
An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses
https://github.com/0xjessie21/CVE-2025-24016
Tool for monitor Active Directory changes in real time without getting all objects. Instead of this it use replication metadata and Update Sequence Number (USN) to filter current properties of objects.
https://github.com/DrunkF0x/ADSpider
Morgan is a powerful tool designed to help security researchers, developers, and security auditors identify sensitive information, vulnerabilities, and potential risks within JavaScript files on websites.
https://GitHub.com/VFA250/Morgan
#HackersFactory
Repost from 𝗛𝗮𝗰𝗸𝗲𝗿𝘀 𝗙𝗮𝗰𝘁𝗼𝗿𝘆
#GitHub #Tools
Wazuh — Unsafe Deserialization RCE (CVE-2025-24016)
An unsafe deserialization vulnerability in Wazuh servers allows remote code execution through unsanitized dictionary injection in DAPI requests/responses
https://github.com/0xjessie21/CVE-2025-24016
Tool for monitor Active Directory changes in real time without getting all objects. Instead of this it use replication metadata and Update Sequence Number (USN) to filter current properties of objects.
https://github.com/DrunkF0x/ADSpider
Morgan is a powerful tool designed to help security researchers, developers, and security auditors identify sensitive information, vulnerabilities, and potential risks within JavaScript files on websites.
https://GitHub.com/VFA250/Morgan
#HackersFactory
Repost from 𝗛𝗮𝗰𝗸𝗲𝗿𝘀 𝗙𝗮𝗰𝘁𝗼𝗿𝘆
Tool for monitor Active Directory changes in real time without getting all objects. Instead of this it use replication metadata and Update Sequence Number (USN) to filter current properties of objects.
https://github.com/DrunkF0x/ADSpider
#HackersFactory
Repost from 𝗛𝗮𝗰𝗸𝗲𝗿𝘀 𝗙𝗮𝗰𝘁𝗼𝗿𝘆
Top Secret Detection Tools
Powerful tools designed to detect secret leaks
https://github.com/trufflesecurity/trufflehog
https://github.com/newrelic/rusty-hog
https://github.com/Yelp/detect-secrets
https://github.com/gitleaks/gitleaks
https://github.com/awslabs/git-secrets
https://github.com/tillson/git-hound
https://github.com/secretlint/secretlint
#HackersFactory
Repost from InfoSec Insider
An inventory of tools and resources about CyberSecurity.
https://inventory.raw.pm/resources.html
#HackersForum
Repost from InfoSec Insider
JavaScript URLs form a text file and search for any keywords like API, API KEY, Access Token, Password, Secret,….. and more
https://github.com/brosck/mantra
Repost from InfoSec Insider
Search from hundreds of pentest terms
https://github.com/AmanuelCh/pentest-terms
Sensitive Files by Fuzzing Key .git Paths.
/.git
/.gitkeep
/.git-rewrite
/.gitreview
/.git/HEAD
/.gitconfig
/.git/index
/.git/logs
/.svnignore
/.gitattributes
/.gitmodules
/.svn/entries
#grayhats
Repost from 𓂆 La Princesa Fantasma
🌙 Ramadan Kareem! 🌙
As the blessed month of Ramadhan begins, @GhostPrincess wishes you and your loved ones a month full of blessings. May our fasting and prayers bring us closer to Allah and fill our hearts with peace. #GhostsofPs #GhostsOfPalestine
Why Coding is Essential for Bug Bounty Hunters
Having strong programming skills can elevate any bug bounty hunter’s game. It’s not just about identifying vulnerabilities—it’s about truly understanding how they come to exist. Being able to read and write code allows you to dive deep into web applications, pinpoint subtle flaws, and design custom exploits that others might overlook. Moreover, coding knowledge empowers you to automate tedious processes and build your own tools, boosting both efficiency and effectiveness. Simply put, the more you understand the code, the better equipped you’ll be to uncover and exploit its weaknesses.
#grayhats
Top 25 JavaScript Path Files used to store sensitive information in Web Application
01. /js/config.js
02. /js/credentials.js
03. /js/secrets.js
04. /js/keys.js
05. /js/password.js
06. /js/api_keys.js
07. /js/auth_tokens.js
08. /js/access_tokens.js
09. /js/sessions.js
10. /js/authorization.js
11. /js/encryption.js
12. /js/certificates.js
13. /js/ssl_keys.js
14. /js/passphrases.js
15. /js/policies.js
16. /js/permissions.js
17. /js/privileges.js
18. /js/hashes.js
19. /js/salts.js
20. /js/nonces.js
21. /js/signatures.js
22. /js/digests.js
23. /js/tokens.js
24. /js/cookies.js
25. /js/topsecr3tdonotlook.js
#grayhats
Repost from CyberDilara
Four ways to search Google for sites in a particular country (all work roughly):
1. Search by domain:
site:.ps
2. Change language settings:
Add to &hl=fr to URL
3. Search by IP range:
site:101.99.*.*
4. Use http://isearchfrom.com. Is a custom Google Search tool that allows users to modify various search parameters, such as language, country, city location, device type, and personalization settings. This tool is particularly useful for previewing how Google search results and ads appear in different locations or under specific conditions.
#CyberDilara
Repost from CyberDilara
A project that detects malicious capabilities in executable files.
https://github.com/mandiant/capa
#CyberDilara
