Penetration Testing Practice Profile Certifications Papers Software Mindmaps Gallery FaveApps Links Blog Resources for practicing penetration testing. Please give your feedback / suggestions / comments at My Feedback Page. Alternatively you can also send an email to dev@amanhardikar.com Name Download URL UltimateLAMP http://www.amanhardikar.com/practice/UltimateLAMP-0.2.zip PHDays iBank CTF http://blog.phdays.com/2012/05/once-again-about-remote-banking.html http://downloads.phdays.com/phdays_ibank_vm.zip Backup of Others (work in progress) Applications Infrastructure Misc Copyright © Aman Hardikar. All rights reserved.
FEATURES
ALTERNATIVES
Chameleon aids in evading proxy categorization to bypass internet filters.
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang for efficient and secure communication.
A blog post about abusing exported functions and exposed DCOM interfaces for pass-thru command execution and lateral movement
A CVE compliant archive of public exploits and corresponding vulnerable software, and a categorized index of Internet search engine queries designed to uncover sensitive information.
Skyhook facilitates obfuscated HTTP file transfers to bypass IDS detections, enhancing secure data exchange.
A cheat sheet providing examples of creating reverse shells for penetration testing.
Interactive online malware sandbox for real-time analysis and threat intelligence
A collaborative, multi-platform, red teaming framework for simulating attacks and testing defenses.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Check Point CloudGuard WAF
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.