Git Product home page Git Product logo

🔑 Intro:

Andy has been consulting in offensive security for over a decade, focusing on red teaming and simulated attacks with a side of threat intelligence and purple teaming. Leading engagements of varying sizes and lengths, helping grow teams and encouraging risk-driven understanding.

image

✔️ Projects:

⌨️ Blog:

I post most of my research and other interesting tutorials on my blog

📚 Book:

For those that don't know Andy, he is a firm believer in passing knowledge on and supporting the infosec community he does this by providing tutorials on his blog running his local DEF CON Chapter & has also published two books Breaking into Information Security and LTR102. He also helps out at DEF CON as a SOC Goon (Red Shirt) too each year (since DC25), assisting the SOC with operations and people flow.

🎤 Talks:

2024

2023

2022

2021

2020

2019

2018

🏆 Bug Bounty:

📛 Badges

Andy has been in the IT security industry for just over 15 years, a decade of which has been dedicated to security and offensive operations. He previously held CREST’s CCT Infrastructure certification, which is highly sought-after, and CHECK Team Leader status. In addition to his years in the industry, he holds several other certifications and accolades, including CRTO, OSCP, and OSWP.

Andy | ZephrFish's Projects

googd0rker icon googd0rker

Note: Going through a full re-write of the tooling so the current versions in the repo do not work!

h5sc icon h5sc

HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors

headlessbounties icon headlessbounties

A shell script that bundles Eyewitness and Sublist3r to create a great fingerprinting tool

helpcolor icon helpcolor

Agressor script that lists available Cobalt Strike beacon commands and colors them based on their type

httppwnly icon httppwnly

"Repeater" style XSS post-exploitation tool for mass browser control. Primarily a PoC to show why HttpOnly flag isn't a complete protection against session hijacking via XSS

incometaxcalc icon incometaxcalc

A basic python script that takes your weekly wage and works out how much tax you pay

inlineexecute-assembly icon inlineexecute-assembly

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module

invoke-hivenightmare icon invoke-hivenightmare

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer

irecon icon irecon

Of the thousands of lazy reconnaissance scripts, this one is by far the one in this repository.

jsa icon jsa

Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.

kali_setup icon kali_setup

Epic Kali Script, oracle and other thinfs need to be added soon.

khepri icon khepri

🔥🔥🔥Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++, the architecture and usage like Cobalt Strike

ladon icon ladon

大型内网渗透扫描器&Cobalt Strike,Ladon7.2内置94个模块,包含信息收集/存活主机/IP扫描/端口扫描/服务识别/网络资产/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010、SMBGhost、Weblogic、ActiveMQ、Tomcat、Struts2系列,密码口令爆破(Mysql、Oracle、MSSQL)、FTP、SSH(Linux)、VNC、Windows(IPC、WMI、SMB、Netbios、LDAP、SmbHash、WmiHash、Winrm),远程执行命令(wmiexe/psexec/atexec/sshexec/webshell),降权提权Runas、GetSystem,Poc/Exploit,支持Cobalt Strike 3.X-4.0

lazyrecon icon lazyrecon

This script is intended to automate your reconnaissance process in an organized fashion

learntheropes icon learntheropes

An outline as to how to get the basics nailed down before approaching information security as a career

linkedint icon linkedint

LinkedInt: A LinkedIn scraper for reconnaissance during adversary simulation

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.