Andy (@ZephrFish)
  • Stars
    star
    3,031
  • Global Rank 9,489 (Top 0.4 %)
  • Followers 1,053
  • Following 104
  • Registered over 10 years ago
  • Most used languages
    Python
    44.9 %
    Shell
    24.5 %
    PowerShell
    14.3 %
    HTML
    4.1 %
    Lua
    2.0 %
    Batchfile
    2.0 %
    Go
    2.0 %
    YARA
    2.0 %
    Visual Basic
    2.0 %
    C#
    2.0 %
  • Location πŸ‡¬πŸ‡§ United Kingdom
  • Country Total Rank 496
  • Country Ranking
    YARA
    5
    Batchfile
    11
    Lua
    42
    Shell
    92
    Visual Basic
    110
    Python
    296
    C#
    788
    Go
    958
    HTML
    1,298

Top repositories

1

GoogD0rker

Note: Going through a full re-write of the tooling so the current versions in the repo do not work!
Python
374
star
2

BugBountyTemplates

A collection of templates for bug bounty reporting
312
star
3

CVE-2020-1350_HoneyPoC

HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
PowerShell
280
star
4

DockerAttack

Various Tools and Docker Images
Shell
277
star
5

Wordlists

Various Payload wordlists
224
star
6

Bloodhound-CustomQueries

Custom Queries - Brought Up to BH4.1 syntax
191
star
7

static-tools

Static compiled binaries + scripts ready to use on systems
Lua
151
star
8

BurpFeed

Hacked together script for feeding urls into Burp's Sitemap
Python
89
star
9

AzureAttackKit

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information
PowerShell
70
star
10

XSSPayloads

Cross Site Scripting Payloads -- Variations
68
star
11

F5-CVE-2022-1388-Exploit

Exploit and Check Script for CVE 2022-1388
Python
58
star
12

RandomScripts

Random Shell Scripts and other ideas I have along the way
PowerShell
51
star
13

CVE-2021-22893_HoneyPoC2

DO NOT RUN THIS.
Shell
48
star
14

AttackDeploy

Scripts for Deploying new server
Shell
44
star
15

WindowsHardeningScript

Some settings stolen from multiple scripts @ZephrFish
Batchfile
43
star
16

GoogD0rk

Python
43
star
17

Stompy

Timestomp Tool to flatten MAC times with a specific timestamp
C#
42
star
18

AutoHoneyPoC

AutoPoC Generator HoneyPoC
Python
32
star
19

CVE-2023-20198-Checker

CVE-2023-20198 & 0Day Implant Scanner
Python
30
star
20

Exch-CVE-2021-26855

CVE-2021-26855: PoC (Not a HoneyPoC for once!)
Python
27
star
21

CVE-2020-16898

HoneyPoC 2.0: Proof-of-Concept (PoC) script to exploit IPv6 (CVE-2020-16898).
20
star
22

Blog_Backup

A repository with various tutorials on how to do things in Pentesting, setup environments and other things
19
star
23

CVE-2021-41773-PoC

Python
18
star
24

SandboxSpy

Code for profiling sandboxes - Initially an idea to profile sandboxes, the code is written to take enviromental variables and send them back in a Base32 string over HTTP to an endpoint.
Go
17
star
25

NessusPreFlight

Nessus Preflight(NPF) Check for local and remote systems. Essentially sets three registry keys and restarts a service to allow nessus to scan a machine
PowerShell
17
star
26

PotUtils

Python
14
star
27

CVE-2021-28480_HoneyPoC3

DO NOT RUN THIS.
Shell
11
star
28

MoveIT-WebShellCheck

Python
11
star
29

Autopeeper

Automated Screenshot Tool
Python
10
star
30

XSS

A collection of XSS Attack vectors
9
star
31

MediaCenterSetup

A setup script for Plex, Sonarr, Radarr & Jackett
Shell
9
star
32

xss-proxy

BeEF-inspired XSS proxy service
HTML
9
star
33

NotProxyShellScanner

Python implementation for NotProxyShell aka CVE-2022-40140 & CVE-2022-41082
Python
8
star
34

PurpleTeamWorkshop-LabManual

Purple Team Workshop by @jorgeorchilles
8
star
35

HeadlessBounties

A shell script that bundles Eyewitness and Sublist3r to create a great fingerprinting tool
Shell
7
star
36

ZephrFish

7
star
37

LogsSteelcon

6
star
38

CSVInjectionPayloads

A list of various ways of injecting payloads for CSV Injection
6
star
39

OldGold

Sysadmin Tools
HTML
5
star
40

PS-Scripts

Useful scripts for labs
PowerShell
5
star
41

DoNotRunMe

4
star
42

Random-Yara-Rules

A collection of yara rules I've gathered over the years :-)
YARA
4
star
43

CVE-2021-22986_Check

CVE-2021-22986 Checker Script in Python3
Python
4
star
44

Exch-CVE-2021-26855_Priv

patched to work
Python
4
star
45

Mailgun-python

Python Wrapper for sending email with mailgun
Python
4
star
46

LegacyResearch

Python
4
star
47

zephrfish.github.io

zsec backup blog
3
star
48

WebSocketsAreFun

FAFO with WebSockets
PowerShell
3
star
49

csc_cypher

Cyber Security Challenge Cipher Challenge
3
star
50

rengine

reNgine is an automated reconnaissance framework meant for gathering information during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information.
JavaScript
3
star
51

ghostDebian

GhostDeployment Script for Debian
Shell
2
star
52

redsocial

Shell
2
star
53

SSH_Notify

Different Scripts for SSH hardening blog
Python
2
star
54

Writeups

Various write-ups from CTFs, fixes for things and others
2
star
55

CTF-Solutions

2
star
56

cloudathost-debian

Provision Script for Debian on CAC
Shell
2
star
57

Bootspeed

Check the boot speed of a windows machine
Visual Basic
2
star
58

FSMF-BurpExtension

Find Subdomains MoFo - Burp Extension WIP
Python
2
star
59

Sub2CDN

Python
2
star
60

VPNConnectScript

VPN Connection Menu Script, Created in Bash
Shell
2
star
61

LearnTheRopes

An outline as to how to get the basics nailed down before approaching information security as a career
2
star
62

Kali_Setup

Epic Kali Script, oracle and other thinfs need to be added soon.
Shell
2
star
63

subroot

Another subdomain bruteforcer
2
star
64

LTR101

Repository for Breaking into Information Security: Learning the Ropes 101 (https://leanpub.com/ltr101-breaking-into-infosec)
2
star
65

HoffPwn

Hoff in Style
1
star
66

IncomeTaxCalc

A basic python script that takes your weekly wage and works out how much tax you pay
Python
1
star
67

UnlmtdCalc

A python application that takes the Value of a Cineworld Unlimited card and then works out if it's worth while you getting one based upon your film choices
Python
1
star
68

LearningThings

1
star
69

CVE-2024-3400-Canary

Have we not learnt from HoneyPoC?
Python
1
star
70

xfer

ingress tooling
1
star
71

AzureHound

PowerShell
1
star
72

configFiles

zsh stuffs
Shell
1
star
73

SH

PowerShell
1
star
74

MultiPotato

C++
1
star