Projects in Awesome Lists by SpiderLabs
A curated list of projects in awesome lists by SpiderLabs .
https://github.com/spiderlabs/responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Last synced: 16 Dec 2025
https://github.com/SpiderLabs/Responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Last synced: 07 Apr 2025
https://github.com/SpiderLabs/owasp-modsecurity-crs
OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)
Last synced: 09 Apr 2025
https://github.com/spiderlabs/owasp-modsecurity-crs
OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)
Last synced: 16 Dec 2025
https://github.com/spiderlabs/hosthunter
HostHunter a recon tool for discovering hostnames using OSINT techniques.
bugbounty hacking hacking-tool hosthunter hostnames ip network-security open-source osint penetration-testing pentest pentest-tool pentesting recon reconnaissance scoping security-tools tool virtual-hosts
Last synced: 16 May 2025
https://github.com/SpiderLabs/HostHunter
HostHunter a recon tool for discovering hostnames using OSINT techniques.
bugbounty hacking hacking-tool hosthunter hostnames ip network-security open-source osint penetration-testing pentest pentest-tool pentesting recon reconnaissance scoping security-tools tool virtual-hosts
Last synced: 30 Mar 2025
https://github.com/SpiderLabs/MCIR
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Last synced: 16 Nov 2025
https://github.com/spiderlabs/dohc2
DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH).
Last synced: 02 Apr 2025
https://github.com/spiderlabs/mcir
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Last synced: 13 May 2025
https://github.com/spiderlabs/scavenger
scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as "interesting" files containing sensitive information.
Last synced: 03 Sep 2025
https://github.com/spiderlabs/sharpcompile
SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing using beacon's 'execute-assembly' in seconds.
Last synced: 02 Apr 2025
https://github.com/SpiderLabs/SharpCompile
SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing using beacon's 'execute-assembly' in seconds.
Last synced: 13 May 2025
https://github.com/spiderlabs/malware-analysis
A repository of tools and scripts related to malware analysis
Last synced: 03 Apr 2025
https://github.com/SpiderLabs/CryptOMG
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
Last synced: 24 Mar 2025
https://github.com/spiderlabs/cryptomg
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
Last synced: 03 May 2025
https://github.com/SpiderLabs/jboss-autopwn
A JBoss script for obtaining remote shell access
Last synced: 27 Mar 2025
https://github.com/spiderlabs/airachnid-burp-extension
A Burp Extension to test applications for vulnerability to the Web Cache Deception attack
Last synced: 24 Jul 2025
https://github.com/spiderlabs/beef_injection_framework
Inject beef hooks into HTTP traffic and track hooked systems from cmdline
Last synced: 03 May 2025
https://github.com/spiderlabs/iocs-idps
This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)
Last synced: 07 Mar 2026
https://github.com/spiderlabs/cve_server
Simple REST-style web service for the CVE searching
api api-rest api-server cpe cve cve-server cvss cvssv2 cvssv3 database nvd ruby
Last synced: 18 Aug 2025
https://github.com/SpiderLabs/cve_server
Simple REST-style web service for the CVE searching
api api-rest api-server cpe cve cve-server cvss cvssv2 cvssv3 database nvd ruby
Last synced: 12 Jul 2025
https://github.com/SpiderLabs/burplay
Burplay is a Burp Extension allowing for replaying any number of requests using same modifications definition. Its main purpose is to aid in searching for Privilege Escalation issues.
Last synced: 12 Mar 2025
https://github.com/spiderlabs/burplay
Burplay is a Burp Extension allowing for replaying any number of requests using same modifications definition. Its main purpose is to aid in searching for Privilege Escalation issues.
Last synced: 03 May 2025
https://github.com/SpiderLabs/BurpNotesExtension
Burp Notes Extension is a plugin for Burp Suite that adds a Notes tab. The tool aims to better organize external files that are created during penetration testing.
Last synced: 19 Apr 2025
https://github.com/spiderlabs/burpnotesextension
Burp Notes Extension is a plugin for Burp Suite that adds a Notes tab. The tool aims to better organize external files that are created during penetration testing.
Last synced: 03 May 2025
https://github.com/spiderlabs/korelogic-rules
Updated version of the 2010 KoreLogic password cracking rules for John the Ripper
Last synced: 05 Mar 2026
https://github.com/spiderlabs/thicknet
TCP session interception and injection framework
Last synced: 06 Oct 2025
https://github.com/spiderlabs/modsecurity-log-utilities
Set of CLI tools to transform ModSecurity logs into a meaningful information, given a context.
Last synced: 08 Sep 2025
https://github.com/spiderlabs/upnp-request-generator
A tool to parse UPnP descriptor XML files and generate SOAP control requests for use with Burp Suite or netcat
Last synced: 03 May 2025
https://github.com/spiderlabs/ackack
A program to monitor network traffic and detect unauthorized sessions.
Last synced: 03 May 2025
https://github.com/spiderlabs/batchydns
A reconnaissance tool that can quickly discover hostnames from a list of IP addresses.
Last synced: 11 Jun 2025
https://github.com/SpiderLabs/deblaze
Performs method enumeration and interrogation against flash remoting end points.
Last synced: 27 Mar 2025
https://github.com/spiderlabs/net-tns
Net::TNS, a Ruby library for connecting to Oracle databases.
Last synced: 03 May 2025
https://github.com/spiderlabs/owasp-distributed-web-honeypots
Repository for the OWASP/WASC Distributed Web Honeypots Project -
Last synced: 04 Oct 2025
https://github.com/spiderlabs/deface
A Java Server Faces (JSF) testing tool for decoding view state and creating view state attack vectors.
Last synced: 03 May 2025
https://github.com/spiderlabs/oracle_pwd_tools
Oracle Database 12c password brute forcer
Last synced: 03 May 2025
https://github.com/spiderlabs/yara-ruby
Ruby bindings for the yara file analysis and classification library
Last synced: 19 Jul 2025
https://github.com/spiderlabs/modsecurity-pcap
The ModSecurity Pcap Connector
Last synced: 03 May 2025
https://github.com/spiderlabs/jorogumo
Red Team Stored XSS SVG phishing-companion tool with the ability to serve a malicious login page, or clone an html page and implement custom javascript. It then generates a relevant SVG.
cve-2021-45919 exploits phishing stored-xss-exploit
Last synced: 03 May 2025
https://github.com/spiderlabs/modsecurity-mlogc-ng
Next generation remote logging tool for ModSecurity, supporting native and JSON format.
Last synced: 09 Sep 2025
https://github.com/spiderlabs/modsec-sdbm-util
Utility to manipulate SDBM files used by ModSecurity. With that utility it is possible to _shrink_ SDBM databases. It is also possible to list the SDBM contents with filters such as: expired or invalid items only.
Last synced: 27 Oct 2025
https://github.com/spiderlabs/xssmh
XSSmh - A configurable Cross-Site Scripting testbed
Last synced: 24 Jun 2025
https://github.com/spiderlabs/shellol
A configurable OS shell command injection vulnerability testbed
Last synced: 03 May 2025
https://github.com/spiderlabs/secrules-language-evaluation
Set of Python scripts to perform SecRules language evaluation on a given http request.
Last synced: 23 Jul 2025
https://github.com/spiderlabs/masher
multiple password 'asher using Python’s hashlib
Last synced: 03 May 2025
https://github.com/spiderlabs/nrfdump
Python script for dumping firmware from read-back protected nRF51 chips
Last synced: 03 May 2025
https://github.com/spiderlabs/keystone
This repository contains the scripts released under the "Keystone Rocks" series of the SpiderLabs blog
Last synced: 03 May 2025
https://github.com/spiderlabs/twsl2011-007_ios_code_workaround
Workaround for the vulnerability identified by TWSL2011-007 or CVE-2008-0228 - iOS x509 Certificate Chain Validation Vulnerability
Last synced: 11 Oct 2025
https://github.com/spiderlabs/revil_config
Configuration file for REvil / Kaseya July campaign
Last synced: 26 Feb 2026
https://github.com/spiderlabs/grandoreiro-decryptor
Grandoreiro decryptor and DGA generator (26.May.2022)
Last synced: 10 Jun 2026
https://github.com/spiderlabs/misc
A repository for miscellaneous files shared by SpiderLabs
Last synced: 03 Mar 2026