• Stars
    star
    2,568
  • Rank 17,852 (Top 0.4 %)
  • Language
  • Created over 3 years ago
  • Updated 5 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

OSWE, OSEP, OSED, OSEE

OSCE³ Study Guide Awesome

OSWE

Content

  • Web security tools and methodologies
  • Source code analysis
  • Persistent cross-site scripting
  • Session hijacking
  • .NET deserialization
  • Remote code execution
  • Blind SQL injections
  • Data exfiltration
  • Bypassing file upload restrictions and file extension filters
  • PHP type juggling with loose comparisons
  • PostgreSQL Extension and User Defined Functions
  • Bypassing REGEX restrictions
  • Magic hashes
  • Bypassing character restrictions
  • UDF reverse shells
  • PostgreSQL large objects
  • DOM-based cross site scripting (black box)
  • Server side template injection
  • Weak random token generation
  • XML External Entity Injection
  • RCE via database Functions
  • OS Command Injection via WebSockets (BlackBox)

Study Materials

  1. timip-GitHub- Reference guide
  2. noraj-GitHub - Reference guide
  3. wetw0rk-Github - Reference guide
  4. kajalNair-Github - Reference guide
  5. s0j0hn-Github - Reference guide
  6. deletehead-Github - Reference guide
  7. z-r0crypt - Reference guide
  8. rayhan0x01 - Reference guide
  9. Nathan-Rague - Reference guide
  10. Joas Content - Reference guide
  11. Lawlez-Github - Reference guide

Vulnerabilities (https://github.com/AzyzChayeb)

  1. XXE Injection
  2. CSRF
  3. Cross-Site Scripting Exploitation
  4. Cross-Site Scripting (XSS)
  5. Unrestricted File Upload
  6. Open Redirect
  7. Remote File Inclusion (RFI)
  8. HTML Injection
  9. Path Traversal
  10. Broken Authentication & Session Management
  11. OS Command Injection
  12. Multiple Ways to Banner Grabbing
  13. Local File Inclusion (LFI)
  14. Netcat for Pentester
  15. WPScan:WordPress Pentesting Framework
  16. WordPress Pentest Lab Setup in Multiple Ways
  17. Multiple Ways to Crack WordPress login
  18. Web Application Pentest Lab Setup on AWS
  19. Web Application Lab Setup on Windows
  20. Web Application Pentest Lab setup Using Docker
  21. Web Shells Penetration Testing
  22. SMTP Log Poisoning
  23. HTTP Authentication
  24. Understanding the HTTP Protocol
  25. Broken Authentication & Session Management
  26. Apache Log Poisoning through LFI
  27. Beginner’s Guide to SQL Injection (Part 1)
  28. Boolean Based
  29. How to Bypass SQL Injection Filter
  30. Form Based SQL Injection
  31. Dumping Database using Outfile
  32. IDOR

Reviews

  1. OSWE Review - Portuguese Content
  2. 0xklaue
  3. greenwolf security
  4. Cristian R
  5. 21y4d - Exam Reviews
  6. Marcin Szydlowski
  7. Nathan Rague
  8. Elias Dimopoulos
  9. OSWE Review - Tips & Tricks - OSWE Review - Tips & Tricks
  10. Alex-labs
  11. niebardzo Github - Exam Review
  12. Marcus Aurelius
  13. yakuhito
  14. donavan.sg
  15. Alexei Kojenov
  16. (OSWE)-Journey & Review - Offensive Security Web Expert (OSWE) - Journey & Review
  17. Patryk Bogusz
  18. svdwi GitHub - OSWE Labs POC
  19. Werebug.com - OSWE and OSEP
  20. jvesiluoma
  21. ApexPredator
  22. Thomas Peterson
  23. NOH4TS
  24. Alex
  25. RCESecurity

Extra Content

  1. OSWE labs - OSWE labs and exam's review/guide
  2. HTB Machine
  3. Deserialization
  4. B1twis3
  5. jangelesg GitHub
  6. rootshooter

OSEP

Content

  • Operating System and Programming Theory
  • Client Side Code Execution With Office
  • Client Side Code Execution With Jscript
  • Process Injection and Migration
  • Introduction to Antivirus Evasion
  • Advanced Antivirus Evasion
  • Application Whitelisting
  • Bypassing Network Filters
  • Linux Post-Exploitation
  • Kiosk Breakouts
  • Windows Credentials
  • Windows Lateral Movement
  • Linux Lateral Movement
  • Microsoft SQL Attacks
  • Active Directory Exploitation
  • Combining the Pieces
  • Trying Harder: The Labs

Study Materials

Reviews

Labs

OSED

Content

  • WinDbg tutorial
  • Stack buffer overflows
  • Exploiting SEH overflows
  • Intro to IDA Pro
  • Overcoming space restrictions: Egghunters
  • Shellcode from scratch
  • Reverse-engineering bugs
  • Stack overflows and DEP/ASLR bypass
  • Format string specifier attacks
  • Custom ROP chains and ROP payload decoders

Study Materials

Reviews

Labs

Our Social Network

Joas Antonio - Linkedin

CyberSceurityUP- GitHub

C0d3Cr4zy - Twitter

Filipi Pires - Linkedin

Filipi Pires - GitHub

Filipi Pires - Twitter

More Repositories

1

Awesome-Red-Team-Operations

1,260
star
2

Guide-CEH-Practical-Master

1,168
star
3

Cloud-Security-Attacks

Azure and AWS Attacks
1,043
star
4

Awesome-Cloud-PenTest

676
star
5

Red-Team-Management

HTML
627
star
6

Offensivesecurity-Checklists

Checklists for Testing Security environment
545
star
7

Awesome-Malware-and-Reverse-Engineering

379
star
8

eWPTX-Preparation

325
star
9

Python-for-Security

HTML
303
star
10

Awesome-Hardware-and-IoT-Hacking

246
star
11

GCP-Pentest-Checklist

213
star
12

OSCP-Survival-Guide

208
star
13

information-security-relatory

Reports from various areas of information security
188
star
14

PNPT-Preparation-Guide

PNPT Exam Preparation - TCM Security
154
star
15

eWPT-Preparation

148
star
16

Red-Team-Exercises

C++
139
star
17

awesome-flipperzero2

Compilation of contents about Flipper Zero
127
star
18

Awesome-PenTest-Practice

Hackthebox, Vulnhub, TryHackMe and Real World PenTest
101
star
19

eCXD-Preparation

eLearnSecurity Certified Exploit Development
98
star
20

Awesome-Blue-Team-Operations

96
star
21

PenTest-Consulting-Creator

Repository with some necessary information for you to create your PenTest consultancy
91
star
22

PenTest-Certifications-Roadmap

83
star
23

Buffer-Overflow-Labs

Practice Labs
80
star
24

Awesome-Exploit-Development

73
star
25

OSCP-in-one-month

72
star
26

RedTeam-Scripts

PowerShell
71
star
27

BadPDF-Generator

Python
64
star
28

Template-CherryTree-PenTest

62
star
29

Adversary-Emulation-Matrix

59
star
30

Web-PenTest-Checklist

48
star
31

Windows-API-for-Red-Team

Python
48
star
32

Facial-Recognition-PenTest-Checklist

47
star
33

PenTest-Report-Collection

41
star
34

CyberSecurityUP

Hack
40
star
35

CyberSecurity-LinkedIn-Materials

34
star
36

Information-Security-Certifications-Map

29
star
37

Powershell-for-PenTest

28
star
38

smart-contracts-audit-checklist

25
star
39

Hackthebox-Privilege-Escalation

24
star
40

Osint-Social-Mapping

OSINT mapping using Twitter, Ficklr, Shodan and Insecam
Python
22
star
41

AV-Bypass-codes

Python, C++ and Go
C++
21
star
42

Windows-Defender-DLL-Hijacking

C++
20
star
43

PhantomsGate

PhantomsGate: Advanced Shellcode Injection Technique
C++
20
star
44

Bug-Bounty-Dorks-Vulns

19
star
45

python-for-hackers

Python
19
star
46

Cybersecurity-Certifications-Guide

19
star
47

Web-PenTest-Resume-Tips

19
star
48

Fuxsociety

Fuxsociety Mr Robot 2.1
Python
18
star
49

CRPYA

Challenge Python
Python
18
star
50

Mitre-Attack-Matrix

17
star
51

Cracking-The-Perimeter-Framework

New Framework Red Team Operations
17
star
52

shellcode-runner-rust

Simple Shellcode Runner in Rust Language
Rust
17
star
53

AWS-Cloud-Practicioner-Notes

15
star
54

PyDorkGPT

Google Hacking using Prompt ChatGPT
Python
14
star
55

Trevorfuscation

A tool that automates the trevorc2 powershell agent obfuscation process with the pyfuscation tool
Shell
14
star
56

Adversary-Emulation-Guide

14
star
57

Cyber-Security-Contents

14
star
58

Physical-PenTest-Methodology

Basic guide for performing a Physical PenTest - Nist 800-12, 800-53, 800-115, 800-152
14
star
59

GCP-Adversary-Emulator

Comprehensive adversary emulation tool for security testing on Google Cloud Platform (GCP) environments.
Python
14
star
60

OSWP-Automated-tools

Shell
13
star
61

Python-Introduction

Python
13
star
62

backup-fu

Automatic cloud backup of Kali Linux data
Shell
12
star
63

Harden-Fu

Shell
11
star
64

C2Matrix-Automation

C2Matrix Automation
Shell
11
star
65

HermitPurple-Maltegoce

Finding Missing People, extract information in Dark Web and Surfaceweb Investigation and Human Trafficking Support
Python
11
star
66

k8senumeration

Kubernetes, Clusters and Dockers Enumeration in GCP and AWS environments
Python
11
star
67

LiesGate

C++
11
star
68

HunterX

King of Bug Bounty Tips Simple Tool
Shell
10
star
69

Malware-Analysis-Exercises

10
star
70

ISO-27002-Document

10
star
71

Ransomware-Codes

Educational repository with source code examples
10
star
72

RansomwarePy

Ransomware Python
Python
7
star
73

TTPs-Mitre-Attack

7
star
74

Red-Team-Operations-Framework

Red Team Operations Framework
7
star
75

study-TI

Auxilios nos seus estudos e planejamento
6
star
76

Challenges

Challenge Inmetrics
HTML
6
star
77

Documentation-of-information-security

6
star
78

stalkfacebook1.0

Python
6
star
79

AWS-Cloud-Architect-Associate-Notes

6
star
80

Simple-Ransomwares

C++
6
star
81

AhmiaDomainExtractor-Maltegoce

Python
6
star
82

Application-Vulnerable

6
star
83

ProcessKiller-BYOVD

BYOVD Technique Example using viragt64 driver
C++
5
star
84

shellcode-templates

Assembly
5
star
85

Standards-and-Controls

5
star
86

facebookstalking2.0

Python
5
star
87

block-website

Bloqueador de website feito em python
Python
5
star
88

Suicide-Prevention-Map

Suicide Prevention Map using Google Place API and Google Search API
Python
5
star
89

SafeBuddy

APK Suicide Prevention
Java
5
star
90

MacInjector-Automated

MacInjector is a tool that lists macOS applications, checks code-signing vulnerabilities, and injects a dynamic library (dylib) into a vulnerable application.
Python
5
star
91

ReconFu

Scripts made in python to automate recognition
Python
5
star
92

DeepFakeDetect-URL

Detect if a photo is deepfake by passing the URL and analyzing
Python
5
star
93

JWTK-Exploits

Python
4
star
94

SilverEye-Twitter-Scraping

A tool created to scrape twitter using its own API
Python
4
star
95

Snake-AI

Edition Code for Python the AI
Python
4
star
96

owasp-asvs-checklist-portugues

4
star
97

reversescripts

Scripts para Engenharia Reversa
Python
4
star
98

CRTO-Study

Zeropoint Course CRTO
HTML
4
star
99

My-CVEs

4
star
100

SyscallHookDetector

C++
4
star