Skip to content
View zebracherry's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report zebracherry

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
zebracherry/README.md

ZCherry

Security researcher — web application testing and open-source vulnerability research. I build offensive security tooling and publish it.

Write-ups at noob2root.com.


Tooling

Project What it does Stack
ZScan Single-file network scanner with 58 embedded NSE-equivalent scripts. Air-gap safe, zero installs. Python · PowerShell
RHELGuard RHEL security audit against CIS Benchmarks and DISA STIG, plus air-gap isolation checks. Bash · Python
WinGuard Windows Server audit against CIS Benchmarks, DISA STIG and the Microsoft Security Baseline, plus air-gap isolation checks. Runs non-admin. PowerShell
RustRecon OSCP-focused async recon framework — classifies a target, then runs only the relevant tool chain. Rust
ADReaper Active Directory and Windows privilege-escalation recon over LDAP. Enumeration only, no exploitation. Python

Labs and practice targets

Project What it does Stack
PurpleForest An Active Directory purple-team lab that detects the attacks run against it and records them. PowerShell · Ansible
VaultPay Intentionally vulnerable Android wallet — every OWASP Mobile Top 10 (2024) risk, mapped to MASVS v2.1.0. Kotlin
VaultPay-iOS The iOS counterpart, same coverage using iOS-native insecure primitives. Swift

All projects are MIT licensed.

The VaultPay apps are deliberately insecure — read the NOTICE before building, and run them only on an emulator, simulator or a dedicated test device.

For authorised security testing only. Only test systems you own or have explicit written permission to assess.

Popular repositories Loading

  1. PurpleForest PurpleForest Public

    An Active Directory purple-team lab that fights back — and records everything. Four VMs via Vagrant and Ansible: Windows Server 2022 domain, Vector telemetry, Graylog detection. Run the attack, rea…

    PowerShell 3

  2. Rustrecon Rustrecon Public

    OSCP-focused async recon framework — auto-classifies Linux, Windows & Active Directory targets and runs the right tool chain for each.

    Rust 1

  3. ADReaper ADReaper Public

    Python-based Active Directory & Windows PrivEsc recon tool for OSCP. Enumerates AD attack surface via LDAP — Kerberoasting, ASREPRoasting, delegation, ACLs, trusts, GPOs — and generates ranked find…

    Python 1

  4. RHELGuard RHELGuard Public

    Red Hat Enterprise Linux Security Audit Tool.

    Python 1

  5. ZScan ZScan Public

    Single-file network scanner — 58 NSE-equivalent scripts, air-gap safe. TCP/SYN/UDP/FIN/NULL/XMAS scans, OS detection, version fingerprinting. Pure Python (Linux/Windows) + Pure PowerShell (Windows)…

    Python 1

  6. VaultPay VaultPay Public

    VaultPay is scaffolded—a modern wallet app with all ten 2024 risks planted and cross-mapped to MASVS v2.1.0.

    Kotlin 1