Skip to content

Entry

GTFOBins

Appears in 4 awesome lists

GTFOBins is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.

Open gtfobins.github.io

Found in these lists

Awesome Hacker Search Engines

Section: Exploits · Curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems

FreshScore 91

Awesome Penetration Testing

Section: Privilege Escalation Tools · Curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.

ActiveScore 83

Awesome Privilege Escalation

Section: SUDO and SUID · GTFOBins is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions.

SlowScore 64

Awesome Hacking

Section: Other Useful Repositories · A curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions

ActiveScore 82

Exploit Database

(search and pick the exploits, which have respective apps available for download, reproduce the exploit by using fuzzer of your choice)

In 8 listsDetails

CVE PoC Search

Search public GitHub repositories containing proof-of-concept exploit code, indexed by CVE identifier

In 4 listsDetails

Sploitus

Sploitus is a everyday tool that helps security researchers find exploits and tools.

In 4 listsDetails

Vulmon

Search anything related to vulnerabilities on Vulmon, from products to vulnerability types. Start your journey to free vulnerability intelligence.

In 3 lists

LOLBAS

Documents binaries, scripts, and libraries that can be used for "Living Off The Land" techniques, i.e., binaries that can be used by an attacker to perform actions beyond their original purpose.

In 3 lists

LinEnum

This tool is great at running through a heap of things you should check on a Linux system in the post exploit process. This include file permissions, cron jobs if visible, weak credentials etc.(@Rebootuser)

In 3 lists

pspy

Unprivileged Linux process sniffer that monitors commands and cron jobs as they execute via procfs scans and inotify.

In 3 lists

Rapid7 - DB

Technical details for over 180,000 vulnerabilities and 4,000 exploits are available for security professionals and researchers to review.

In 2 lists