> cat /dev/github | grep security-tools

Exploit

netsentinel

2026-08-31 Python ★ 16
NetSentinel is a comprehensive network management tool designed for discovering devices, diagnosing connectivity issues, and monitoring network health. It features rogue device detection, detailed device inventory, bandwidth monitoring, a root cause correlator, and automated reporting capabilities, all while ensuring complete data privacy with a fully local, open-source architecture. With its extensive functionality, NetSentinel serves as a powerful aide for network administrators and users seeking to enhance both security and reliability in their network environments.

mole

2026-08-31 Python ★ 84
Mole is a Binary Ninja plugin that facilitates the identification of significant execution paths within binaries through backward slicing of variables, leveraging the Medium Level Intermediate Language (MLIL) in Static Single Assignment (SSA) form for static taint analysis. Its primary use case lies in vulnerability detection, where it allows users to define source and sink functions, visualize paths, and analyze them using AI integration for classifying potential vulnerabilities. Notable features include operational flexibility, extensive path exploration options, customizable path grouping strategies, persistence of analysis progress, and inter-procedural variable slicing.

CTFlearn-Writeups

2026-08-31 Python ★ 171
CTFlearn-Writeups is a compilation of detailed solutions for various Capture The Flag challenges across multiple domains such as Cryptography, Forensics, and Web security. The tool serves as a reference for practitioners and enthusiasts looking to enhance their skills in cybersecurity challenge-solving. Notable features include categorized writeups that cover a range of problem types, providing structured insights into methodologies and techniques used in each challenge.

cwv-scanner

2026-08-31 Python ★ 27
cwv-scanner is a Python-based tool designed to identify common web application vulnerabilities by scanning specified URLs or IP addresses. It checks for 36 types of vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), and Remote Code Execution, facilitating website owners and security researchers in enhancing their application's security posture. Notable features include a straightforward installation and usage process, allowing for quick deployment in vulnerability assessments.

Android-Hacking

2026-08-30 ★ 10
Android-Hacking is a comprehensive toolkit designed for rooting and unlocking the bootloader of Android devices, specifically targeting devices like the Redmi A5. The repository offers detailed tutorials in both Portuguese and English, providing users with step-by-step instructions for exploiting vulnerabilities in Unisoc chipsets. Notable features include language-translated guidance and specific exploitation techniques applicable to Android devices.

Blaze-Signal-Forge

2026-08-30 HTML ★ 55
OrbitPilot is an advanced automation tool tailored for online betting that enhances user engagement through a context-aware decision-making layer. By utilizing a robust Selenium foundation and a modular plugin architecture, it offers intelligent action sequencing, multi-platform responsiveness, and native multilingual logging, while also providing innovative features like a 24/7 sentinel monitoring system and detailed session analytics. This tool enables users to transform repetitive tasks into strategic workflows, allowing for a more informed and efficient betting experience.

crash-pattern-analyzer

2026-08-30 HTML ★ 55
PatternScope is a predictive drift analysis tool designed for simulated probability environments, enabling users to identify and visualize behavioral patterns in outcomes that initially appear random. By leveraging features such as Sequence Archetype Extraction (SAE) and Drift Velocity Index (DVI), the tool provides a scientific approach to understanding probability landscapes, allowing analysts to build comprehensive historical profiles and observe shifts in real-time. The platform also facilitates multi-session analysis through 3D visualizations and maintains an encrypted comparative corpus to enhance predictive accuracy across varied session parameters.

Crossy-Road-Eternal

2026-08-30 HTML ★ 55
The Arcade Ascension Toolkit is a modular performance enhancer designed for retro-style endless hopper games, providing real-time aids that improve gameplay without diminishing the core skill challenge. Key features include predictive pathfinding overlays to enhance spatial awareness, adaptive timing calibration for responsive controls, and session performance analytics to help players learn from their gameplay. With a game-agnostic framework and a sleek, immersive UI, it also offers multi-language support and a vibrant community for continuous support.

nightfall-cpvp-enhancements

2026-08-30 HTML ★ 55
BlackOut: The Shadowforge Toolkit for Meteor Client is an advanced Minecraft modification designed to enhance Crystal PvP (CPVP) gameplay through a system of contextual automation and precise combat tools. Notable features include predictive combat algorithms, advanced movement mechanics tailored for aerial combat, and a customizable user interface that supports multilanguage interactions, providing players with an edge in competitive scenarios. The toolkit aims to elevate gameplay by automating critical actions with high precision, making it a vital asset for serious players in the 2026 competitive scene.

process-orchestrator-win32

2026-08-30 HTML ★ 55
MindBridge Orchestrator is a behavioral framework for managing and interacting with external Windows processes through an event-driven architecture. It facilitates adaptive process discovery, seamless communication with GUI elements, and robust event handling, enabling applications to effectively converse with both legacy and modern systems. Notable features include dynamic enumeration of processes, a unified interaction vocabulary for UI elements, and resilience mechanisms such as process resurrection and session rehydration.

0sec

2026-08-30 TypeScript ★ 47
0sec is an open and extensible AI-driven cybersecurity tool that automates vulnerability discovery, exploitation, and remediation across various layers, including web applications, APIs, source code, and network infrastructure. It supports multi-model and multi-agent capabilities to address complex security challenges, emphasizes continuous security over point-in-time assessments, and includes a command-line interface for streamlined interactions and automation of pentesting workflows. Notable features include the ability to find a wide range of vulnerabilities, integration with various environments and systems, and a focus on supply chain security and other emerging threat vectors.

system-programming-roadmap

2026-08-29 ★ 590
The System Programming Roadmap is an educational framework designed to guide users through the fundamentals of compiler development, malware reverse engineering, and kernel development. It emphasizes a structured approach to mastering system programming languages such as C, Rust, and C++, while also covering essential concepts in computer architecture and assembly language. Notable features include a curated list of resources and prerequisites to enhance the learning experience and ensure a comprehensive understanding of low-level programming.

r3ngine

2026-08-28 Python ★ 10
r3ngine v3.7.4 is an advanced web reconnaissance and vulnerability scanning tool that facilitates comprehensive security assessments through its Target Report Generation feature, allowing users to generate detailed multi-scan PDF reports with historical vulnerability tracking. Key features include an Attack Path Modeling Engine aligned with MITRE ATT&CK, integration with WPScan/WPTaint for static analysis, and enhanced infrastructure for scalability and reliability using Django and PostgreSQL. This enterprise-grade platform is designed for thorough and efficient security analysis while ensuring operational security and ease of use.

VeltCLI

2026-08-28 Python ★ 15
VeltCLI is a terminal-based OSINT and defensive security research toolkit that consolidates multiple reconnaissance and analysis tasks into a single interface. Its primary use case includes vulnerability assessment, DNS checks, web security analysis, and various research workflows across social media, emails, IP intelligence, and more, all while supporting data export in formats such as JSON, CSV, and Markdown. Notable features include comprehensive vulnerability scanning, domain and cloud analysis, and detailed reporting capabilities, streamlining the security research process for users.

R3d-Buck3T

2026-08-28 SCSS ★ 135
R3d-Buck3T is a comprehensive repository designed for penetration testing and red teaming activities, featuring an extensive collection of tools and commands across multiple security domains, including web application, cloud, network, and wireless security. Notable characteristics include detailed sections on Active Directory and vulnerability research, alongside a dedicated wiki for easy navigation and resource access. This tool serves as a vital asset for security professionals aiming to enhance their offensive security skills and methodologies.

red-clippy

2026-08-28 Rust ★ 19
Red Clippy is an open-source penetration testing management tool designed to integrate with AI agents for streamlined test engagements. It retains detailed records of assets, observations, and findings, ensuring that testing sessions can progress smoothly without loss of information, while enforcing protocols for data verification and reporting. Notable features include a web-based interface for managing test data, customizable engagement rules, and the ability to connect to AI agents for enhanced testing efficiency.

stratum-c2

2026-08-28 Rust ★ 39
Stratum C2 is a cloud persistence framework designed to maintain command-and-control (C2) communication through trusted cloud storage providers like Dropbox and OneDrive, thus avoiding detection by traditional security defenses. Its notable features include end-to-end encryption with RSA and AES, the ability to switch between multiple cloud providers seamlessly, and a structurally unblockable channel that makes it difficult for security operations centers to intercept. The framework supports multiple agent formats for both Windows and Linux without requiring additional dependencies.

Vulnogram

2026-08-27 JavaScript ★ 245
Vulnogram is a comprehensive tool designed for reserving, managing, and publishing Common Vulnerabilities and Exposures (CVE) information, facilitating collaboration between vendors and security researchers. It offers both solo and team modes, allowing users to edit JSON documents that conform to specified schemas, with enhanced features such as real-time collaboration, version control, and a customizable plugin architecture for various tracking needs. Notable features include a web-based frontend, integration with MongoDB for persistent storage, and security-focused configurations to ensure the integrity of vulnerability data.

hermes-cybersec-lab

2026-08-27 Shell ★ 12
Hermes Cybersecurity Lab is a comprehensive cybersecurity toolkit designed for the Hermes Agent, encompassing 2,077 skills, 131+ tools, and 28 frameworks, systematically organized across multiple repositories. Its primary use case includes security research, pentesting, forensics, and threat intelligence, with notable features like a preconfigured installation script, tool inventory awareness, and a structured methodology for tackling various phases of cybersecurity engagements. This ecosystem ensures continuous updates and knowledge accumulation, enhancing both operational efficiency and effectiveness in security practices.

awesome-security-agent-harnesses

2026-08-27 ★ 16
Awesome Security Agent Harnesses provides a collection of AI-driven tools designed for penetration testing, code auditing, fuzzing, vulnerability discovery, and reverse engineering. The primary use case is to enhance security assessments through a variety of harnesses, sandboxes, and evaluation frameworks that streamline the detection and validation of vulnerabilities while minimizing false positives. Notable features include multi-agent collaboration, independent validation of findings, and integration with various coding agent methodologies to automate and enhance security processes.

Reverse-Shell-Whatsapp

2026-08-26 ★ 21
Reverse Shell WhatsApp is a tool that exploits the WhatsApp Desktop application on Windows to enable remote code execution via a crafted `.pyz` file. When the victim opens the file, it is executed directly by the Python interpreter without any security prompts, allowing the attacker to gain full control of the victim's machine through privilege escalation. Notable features include bypassing multiple layers of security, such as Windows Defender and UAC, and operating discreetly within a trusted application context.

Acunetix-Premium-Web-Scanner

2026-08-26 ★ 15
Acunetix Premium Web Scanner - Practical Windows release with complete modules and an easy first launch.

IFDA

2026-08-26 Go ★ 43
IFDA is a tool designed for automated reverse engineering and vulnerability discovery in IoT firmware binaries, supporting the analysis of ELF files and extracted firmware trees. It features a bilingual web UI, integrates with existing tools like Capstone and PyELFTools for disassembly and ELF parsing, and offers a structured output for findings, including severity and vulnerability classifications. The architecture includes a Python analysis core and a Go service layer for orchestration, ensuring efficient task management and live progress tracking.

RPC-Triage

2026-08-26 Python ★ 12
RPC-Triage is a static analysis tool designed to assess the Windows RPC attack surface by analyzing compiled PE binaries to identify registered RPC servers and their corresponding method signatures, security flags, and transport bindings. It uniquely ranks interfaces based on a composite score of reachability and danger, providing detailed receipts for transparency in scoring. Notably, the tool operates without the need for symbol files, making it effective on stripped binaries found in production environments.

patchbot

2026-08-26 Python ★ 19
Patchbot is a comprehensive vulnerability scanning tool that integrates with existing scanners and threat feeds to automate the patching process in software repositories. It specializes in inventorying packages, identifying vulnerabilities, and applying fixes—either through version bumps or more complex code changes—while ensuring that each change is verified and re-scanned prior to the creation of pull requests. Notable features include the ability to utilize custom threat feeds and scanners, as well as the capability to operate independently of CI environments, thereby providing flexibility in deployment and usage.

Ingram-Pro

2026-08-26 Python ★ 12
Ingram-Pro is an enhanced network camera vulnerability scanner that builds upon the original Ingram framework, providing extensive coverage of over 40 proof of concept (POC) exploits for CVEs from 2017 to 2024, alongside brand-specific weak-password detection for more than 15 camera brands. Key features include authenticated and unauthenticated remote code execution (RCE), high concurrency scanning using gevent, and the ability to capture live snapshots from vulnerable devices. The tool is designed for authorized security assessments and facilitates rapid vulnerability detection across large IP ranges.

pagezero

2026-08-26 HTML ★ 13
PageZero is a JavaScript-based browser exploitation and command-and-control (C2) framework that integrates features from both Evilginx and BeEF. It allows security professionals to deploy phishing attacks without the need for complex configurations, enabling live sessions to execute over 40 modules including credential theft, keylogging, and LAN scanning from a web admin panel. The tool is designed for authorized penetration testing and operates using a simple hook that grants persistent control over the victim's browser context.

senior-securityengineer-cybersecuritybookmarks

2026-08-26 ★ 15
The repository provides a comprehensive collection of cybersecurity bookmarks curated by a senior information security engineer, focusing on critical topics such as OSINT, exploitation, privilege escalation, and malware analysis. It features over 40 tools for reconnaissance, privacy, and attack methodologies, along with curated news sources, making it a valuable resource for cybersecurity professionals looking to enhance their operational security and situational awareness. Notable features include categorized tools for specific cybersecurity tasks and a visually engaging presentation of the content.

ZeroBurst

2026-08-26 Python ★ 17
ZeroBurst is an advanced command-line application security testing framework designed for ethical hacking and vulnerability assessment. With over 55 specialized modules, it enables users to conduct thorough reconnaissance, injection testing, and auditing of web applications, focusing on various attack vectors such as server-side request forgery and SQL injection. Notable features include automated vulnerability detection across multiple tiers, advanced auditing capabilities, and comprehensive mapping tools for application infrastructure.

search_vulns

2026-08-25 Python ★ 93
search_vulns is a modular tool designed for searching known vulnerabilities, exploits, and other related information across various data sources. Its primary use case is to facilitate vulnerability assessments by allowing users to query a local database with inputs such as product titles or vulnerability IDs, while supporting integration of additional data sources through its modular architecture. Notable features include a command-line interface for automated workflows, a web server for enhanced functionality, and the ability to accommodate diverse input formats.

Network-Scanner

2026-08-25 Python ★ 22
Network Scanner is an open-source security tool designed for vulnerability assessments and penetration testing, enhancing traditional methodologies with AI capabilities for intelligent analysis and detailed reporting. Tailored for a diverse user base including beginners and professionals, it offers functionalities such as automated reconnaissance, various scan types (subdomain, port, DNS), and an AI assistant for context-sensitive support. Notable features include report generation in PDF/HTML formats, an educational learning mode, and API readiness for seamless integration.

prestascansecurity

2026-08-25 PHP ★ 61
PrestaScan Security is a PrestaShop module designed to scan PrestaShop websites for malware and known vulnerabilities in both the core and its modules. It features an intuitive installation process, regular vulnerability alerts, and is compatible with multiple PrestaShop versions, ensuring comprehensive security for e-commerce sites. This free and open-source tool is supported by a dedicated team of security experts who continually monitor and audit for potential threats.

bex-security

2026-08-25 TypeScript ★ 40
Bex Security is an open-source tool designed to facilitate security workflows for coding agents and models, maintaining compatibility with OpenAI's Codex Security. This tool enables users to run consistent, evidence-driven security scans while supporting multiple coding agents through the Agent Client Protocol (ACP). Notable features include a CLI that integrates with various inference providers, a repeatable upstream merge workflow, and an emphasis on security outcomes from discovery to remediation.

public-skills-builder

2026-08-25 Python ★ 225
Public Skills Builder is a tool designed to generate Claude Code bug bounty skills from publicly available HackerOne reports and GitHub writeups, specifically without requiring access to private reports. It processes over 500 disclosed reports to create 18 structured skill files for various vulnerability classes, each containing real-world techniques, payloads, and bypass patterns, thereby providing users with resourceful training data for vulnerability hunting. Notable features include support for multiple sources, including public feeds, and the ability to customize output based on specified vulnerability types.

CVE-2026-18963-Exploit

2026-08-25 Python ★ 37
The CVE-2026-18963-Exploit tool allows users to test for a critical security vulnerability in Keycloak versions 26.0.0 to 26.7.1, which enables unauthenticated attackers to reset passwords without victim interaction. It features a safe detection mode that requires only the base URL and realm settings, avoiding any impact on the target system. Additionally, it includes a lab environment for practical demonstration of the exploit and its remediation.

ruoyi-scan

2026-08-25 Python ★ 19
Ruoyi-Scan is a specialized vulnerability scanning tool designed for RuoYi applications, featuring a plugin-based architecture and three-state assessment (CONFIRMED / SAFE / UNKNOWN) for vulnerability status. It supports bulk scanning, multiple report formats, WAF bypass techniques, and offers enterprise-level functionalities such as API integration and a robust plugin ecosystem for various common vulnerabilities. Noteworthy capabilities include automated AI-based POC generation, extensive reporting options, and compatibility with various operating environments.

Agentic-Bug-Hunter

2026-08-24 Python ★ 4634
BugHunter is an AI-powered bug bounty toolkit designed for effective vulnerability assessment and reporting directly from the terminal. It automates the processes from reconnaissance to reporting, generating submission-ready documents for various platforms while utilizing an intelligent session management feature that retains discovered patterns across targets. This tool can operate independently without a subscription, enhancing accessibility for users in the cybersecurity domain.

PwnRM

2026-08-24 Python ★ 87
PwnRM is an advanced WinRM post-exploitation tool designed for conducting authorized security assessments in Windows Active Directory environments. It features an interactive PowerShell runspace, support for various authentication methods, stealthy payload delivery, and a built-in Active Directory triage engine, enabling users to perform a wide range of assessment tasks through a command-line interface as well as via a Python library. Notable functionalities include file transfer capabilities, remote command execution, and comprehensive AD enumeration and session management features.

vex8s

2026-08-23 Go ★ 20
Vex8s is a tool that generates VEX documents by analyzing container vulnerabilities and correlating them with Kubernetes security settings to assess the exploitability of CVEs within workloads. It utilizes machine learning models to classify vulnerabilities and determine mitigable conditions based on Kubernetes configurations, offering both passive and active scanning modes for versatility. Notable features include integration with existing vulnerability scanners like Trivy and Grype, facilitating the suppression of reported vulnerabilities based on real-time assessments.

plugin-ghidra

2026-08-22 Java ★ 188
The RevEng.AI Ghidra Plugin integrates with Ghidra to facilitate AI-assisted binary analysis, enabling users to upload binaries for analysis and perform Binary Code Similarity operations. Its notable features include automatic function renaming based on confidence thresholds and the ability to display similar function names, which assist in reverse engineering stripped binaries. This tool is particularly useful for security researchers and software developers involved in binary analysis and reverse engineering tasks.

ansible-security-scanner

2026-08-22 Python ★ 10
The Ansible Security Scanner is a static analysis tool designed for evaluating Ansible playbooks, roles, and related files to identify security vulnerabilities including malicious code and unauthorized access risks. It features a comprehensive reporting mechanism that generates outputs in various formats such as SARIF and CycloneDX SBOM, while providing remediation guidance and mapping findings to established security frameworks like OWASP and MITRE ATT&CK.

Oxide-communityedition-v8.7.2

2026-08-22 Rust ★ 13
OXIDE is a precision-forged vulnerability scanner developed in Rust, designed primarily for authorized penetration testing and security research. It features a unique combination of traditional scanning methods and machine learning-based anomaly detection, along with integrations for tools like Burp Suite, and offers a modular architecture for extensibility. Notable features include a headless DOM, WAF evasion capabilities, and enhanced security with an embedded TLS certificate, making it suitable for use in both lab environments and real-world assessments.

IndustrialXPL-Forge

2026-08-22 Python ★ 10
IndustrialXPL-Forge (IXF) is an extensive Python-based security assessment and exploitation framework designed specifically for Operational Technology (OT), Industrial Control Systems (ICS), and related environments. It encompasses the entire attack lifecycle from reconnaissance to reporting, and it features over 1,190 modular tools, support for more than 50 protocols, and extensive integration with the MITRE ATT&CK for ICS framework, along with a significant library of vulnerabilities, offering a comprehensive resource for cybersecurity professionals in the industrial sector.

exploitdb-mcp-server

2026-08-21 JavaScript ★ 29
The ExploitDB MCP Server is a Model Context Protocol server designed to provide AI assistants with access to security exploit and vulnerability data from ExploitDB. Its primary use case is to enhance cybersecurity research and threat intelligence through functionalities like searching for exploits by various criteria, retrieving detailed exploit information, and tracking newly added exploits, all while supporting automatic database updates to ensure up-to-date information. Notable features include comprehensive search and analysis tools, statistics on exploit distribution, and batch retrieval capabilities for efficient data access.

Offensive-Linux-Privilege-Escalation

2026-08-21 ★ 21
The Offensive Linux Privilege Escalation tool serves as a comprehensive guide to help users escalate from low-privileged Linux access to root, covering various techniques such as sudo and SUID abuse, kernel exploits, and credential mining. Its primary use case is educational, providing detailed methodology, enumeration scripts, and a structured approach to experience in privilege escalation while emphasizing lawful and authorized testing. Notable features include over 50 documented techniques, automated enumeration scripts, a methodology checklist, and practical lab setups for hands-on learning.

Offensive-File-Transfer-Techniques

2026-08-21 ★ 21
Offensive File Transfer Techniques is an extensive guide designed for transferring files to and from target systems during security engagements, emphasizing staging payloads and exfiltrating data. It covers a diverse range of transport mechanisms, including HTTP, SMB, FTP, TFTP, and more obscure methods like base64 encoding, while also providing detection and defense mappings for each technique. The tool features organized notes with ready-to-use commands for both client and server setups, ensuring comprehensive coverage of file transfer methods in offensive security contexts.

Offensive-Windows-Privilege-Escalation

2026-08-21 ★ 22
Offensive Windows Privilege Escalation is a comprehensive guide designed for escalating privileges from a low-privileged Windows environment to Administrator or SYSTEM level, utilizing various techniques such as service misconfigurations, registry exploits, UAC bypass, and token-privilege abuse. The tool emphasizes an offensive security methodology, offering over 75 structured notes complete with hands-on exploitation and detection guidance, alongside ready-to-use commands and methodology checklists. It serves as an educational resource exclusively for authorized testing scenarios, ensuring ethical use in cybersecurity practices.

Ethical-Hacking

2026-08-21 PHP ★ 49
The Ethical-Hacking repository provides a comprehensive step-by-step guide for learning cybersecurity and ethical hacking using Kali Linux. It covers foundational knowledge in networking and Linux commands, introduces tools like Nmap and Metasploit, and offers practice platforms for hands-on experience. Notable features include recommended resources, structured learning paths, and additional guidance on specialized areas like web application security and certifications.

fnprint

2026-08-20 Rust ★ 34
fnprint is a binary analysis tool that uniquely identifies functions in stripped executables by analyzing their behavioral side effects rather than relying on byte signatures or control-flow graphs. It emulates function execution with fabricated inputs to generate behavior-based fingerprints, allowing for more resilient matches across different compiler optimizations and versions. Key features include indexing known binaries for function identification, differential analysis to detect behavioral changes between builds, and a triage capability to assess potential vulnerabilities based on function behavior comparison.

Consortium

2026-08-20 Python ★ 328
Consortium is a modern, extensible command and control (C2) framework that supports both asynchronous multi-client interactions and language-agnostic listener-agent designs, enabling users to develop custom agents and listeners efficiently. Key features include a robust REST API for automation, role-based access control for user management, and modular architecture that allows for extensive customization and collaboration among users. Currently in the alpha phase, the framework emphasizes a high degree of flexibility while still under rapid development.

Cybermes

2026-08-20 Python ★ 674
Cybermes is an advanced autonomous security research framework designed for offensive security tasks, including bug bounty hunting and red teaming. It features over 50 specialized modules for in-depth reconnaissance, attack surface analysis, and vulnerability validation, leveraging a unique integration of modern LLM reasoning and automated workflows. Notable capabilities include dynamic attack planning, multi-source knowledge retrieval, and programmatic validation of findings to ensure zero false positives.

darksword-kexploit

2026-08-20 Objective-C ★ 11
darksword-kexploit is an Objective-C tool designed to facilitate the execution of the DarkSword kernel exploit on iOS devices running up to version 26.0.1 via a straightforward Windows setup process. Notable features include a clear, step-by-step interface suitable for non-technical users, easy integration of local release files, and basic logging to monitor progress. The tool simplifies the requirements for successfully running the exploit by guiding users through connection and configuration steps.

roblox-robux-generator-2026

2026-08-20 ★ 30
The Roblox Robux Generator 2026 is a tool designed to add Robux to any Roblox account through the exploitation of a group payout vulnerability, claiming to facilitate the addition of 400–10,000 Robux per day without requiring user passwords. It supports both Roblox Premium and free accounts, necessitating only the account username and a verification step to mitigate abuse. Notable features include compatibility with Windows 10/11, and the ability to function without needing root or jailbreak access.

roblox-robux-hack-script-2026

2026-08-20 ★ 18
The Roblox Robux Hack Script 2026 is a tool designed to exploit the developer exchange API of Roblox, enabling users to transfer Robux from compromised developer accounts. Its primary use case is the automated scanning for vulnerable accounts and facilitating stealthy transfers of Robux in small increments to avoid detection. Notable features include the ability to export scanned account lists to CSV, support for accounts with at least 10,000 Robux, and an operational stealth mode to minimize the risk of detection by Roblox.

safer-dependencies

2026-08-19 Python ★ 33
Safer Dependencies is a security tool designed to enhance the integrity of package installations in AI-assisted coding environments like Claude. It automatically intercepts package addition requests to perform checks for known vulnerabilities, maintainability, and risks such as typosquats, while ensuring that only safe versions are installed across multiple ecosystems including npm, PyPI, and Maven. Notable features include its proactive blocking of vulnerable installations, automatic correction of risky dependencies, and a streamlined integration that operates in the background without user intervention.

wprecon

2026-08-19 Go ★ 20
WPRecon is a WordPress reconnaissance and vulnerability scanning tool that leverages a YAML-driven template architecture for efficient vulnerability detection and configuration assessment in WordPress installations. Notable features include parallel scanning with configurable worker pools, a library of over 150 templates for comprehensive coverage, and dynamic variable resolution, offering flexibility for security engineers to extend capabilities without recompilation. The tool supports both command-line and API interfaces, allowing for versatile integration into security workflows.

awinrm

2026-08-19 Ruby ★ 10
AWINRM is an advanced WinRM post-exploitation framework designed specifically for red teams and offensive research, implemented in Ruby. Its primary use case revolves around facilitating efficient post-exploitation activities with features like built-in tool staging, automated AMSI/ETW bypasses, stealth file transfers, and automatic loot extraction, addressing common challenges encountered in traditional WinRM tools. The framework provides a streamlined operator-centric workflow that enhances operational security and supports automated reconnaissance and credential gathering.

roblox-arceus-x-pc

2026-08-19 ★ 20
Arceus X PC is a Roblox executor designed for Windows that allows users to run Lua scripts and access a built-in script hub, facilitating game modifications for popular titles such as Blox Fruits and Arsenal. It features over 500 pre-loaded scripts, including an auto-farm for Blox Fruits and aimbot and ESP scripts for Arsenal, with one-click execution and regular updates to ensure compatibility with Roblox patches. This tool is a port from the mobile version, maintaining the core functionalities while catering to PC users.

roblox-infinite-yield-gui

2026-08-19 ★ 21
Roblox Infinite Yield Admin Script GUI is a powerful tool designed for managing and manipulating gameplay in Roblox, featuring over 300 admin commands accessible through a full graphical user interface. Key functionalities include player teleportation, speed and gravity adjustments, server information access, and ESP commands, all of which operate without requiring in-game administrative rights. Compatible with various high-level script executors, the tool enhances the gaming experience by offering extensive control and flexibility.

sonar-bypass

2026-08-19 Java ★ 11
Sonar Bypass is a Node.js script designed to circumvent the Sonar 2.1.x anti-bot verification mechanism for Minecraft servers by mimicking legitimate client behavior through raw socket communication. The tool operates without the need for captcha solving or manual interaction, handling various verification stages by copying the exact interactions of a real player, documented in its accompanying research files. Key features include automated packet responses and support for multiple server environments, making it effective for bypassing bot protections in targeted servers.

getsploit

2026-08-18 Python ★ 1815
Getsploit is a tool designed for searching and downloading public exploits from the Vulners database, facilitating both online searches and fully offline operations via a local SQLite index. Its notable features include a comprehensive query capability across multiple exploit collections, local query support without internet connectivity, and robust JSON and tab-separated output formats, all while maintaining data privacy and integrity. The tool is compatible with Python 3.11 and above, ensuring reliable performance across various platforms.

nmap-vulners

2026-08-18 Lua ★ 3418
nmap-vulners is a set of Nmap scripts designed to enhance network vulnerability assessments by converting service scan results into a detailed list of known Common Vulnerabilities and Exposures (CVEs) along with their respective CVSS scores and exploits. Notable features include three independent scripts that can perform various vulnerability lookups—one leveraging the public Vulners database, another utilizing the Vulners API for advanced scoring, and a regex-based script that identifies web software through HTTP headers. This tool aims to streamline the process of gathering security-related information during Nmap scans, improving the effectiveness of vulnerability management.

osv.net

2026-08-16 C# ★ 12
OSV.NET is a .NET library designed to interact with the Open Source Vulnerabilities (OSV) API and schema, specifically supporting version 1.7.0. Its primary use case is to facilitate querying for vulnerabilities in open source packages, and it provides flexible integration options through manual instantiation or dependency injection, making it straightforward to incorporate into .NET applications. Notable features include asynchronous querying capabilities and customizable HTTP client settings for enhanced configurability.

MassAcre

2026-08-16 Python ★ 10
MassAcre is a tool designed to exploit a zero-day vulnerability in the masscan banner scanning utility, causing it to enter an infinite loop and consume 100% CPU by sending a specially crafted TLS handshake record. Its primary use case is to demonstrate a remote, unauthenticated Denial of Service (DoS) attack that stalls the banner processing of masscan, leading to lost scan results. Notably, the attack is executed with a minimal payload and targets a specific flaw in masscan's certificate handling logic.

vuln-report-skill

2026-08-16 ★ 54
The vuln-report-skill tool automates the generation of submission-ready DOCX vulnerability reports for security response centers, focusing on verified vulnerabilities with clear proof of concept (PoC). It employs a structured workflow that includes layered verification gates to ensure report quality, enforces strict screenshot requirements, and maintains a consistent document layout. Designed for technical accuracy and dual readability, the tool facilitates a rigorous review process to enhance report acceptance on various platforms.

Aimbot-V3

2026-08-16 Lua ★ 89
Aimbot V3 is a universal aim-locking module designed for games using the default character model, offering enhanced optimization and efficiency over its predecessor, Aimbot V2. It features a simplified and organized code structure, allowing for easy integration and customization via a Lua scripting interface. This tool is primarily intended for use with exploit environments like Synapse X and Electron and includes customizable settings for enhanced gameplay precision.

Exunys-ESP

2026-08-16 Lua ★ 20
Exunys ESP is a visual enhancement tool designed for gaming, offering features such as tracers, ESP, boxes, and head dots to provide players with an advantage in gameplay. Utilizing Synapse X's Drawing Library, it ensures undetectability while allowing modular support for NPCs and customizable user configurations via a GUI. The tool is optimized for performance and stability, making it a reliable choice for users seeking advanced visibility options in their gaming experience.

CVE-2026-9830

2026-08-16 Python ★ 394
The CVE-2026-9830 tool is a Python-based proof of concept designed for assessing the unauthenticated exposure of the BookingPress Pro REST API in WordPress installations. It enables authorized users to validate potential vulnerabilities by normalizing target URLs, checking API endpoints for sensitive data exposure, and providing configurable options such as timeouts and filtering. Notable features include the ability to save API responses to JSON files while emphasizing the responsible handling of personal data in compliance with authorized assessment protocols.

HEAVEN-Autonomous-Penetration-Testing

2026-08-16 Python ★ 88
HEAVEN is an autonomous penetration-testing framework designed to streamline and automate various stages of the penetration testing process, including reconnaissance, vulnerability detection, exploitation, risk scoring via machine learning, and reporting. It features a robust interface with 55 CLI commands, 77 API routes, and multiple scan modes, facilitating comprehensive assessments while allowing users to focus on critical decision-making tasks. Notably, it incorporates a CVSS machine learning predictor with a high correlation score, ensuring accurate risk evaluation.

ExploiterX

2026-08-16 Python ★ 16
ExploiterX 3.0 is an enterprise-grade web vulnerability scanner designed for security professionals and developers, capable of detecting a wide range of vulnerabilities including XSS, SQL Injection, and CSRF. Its notable features include advanced scanning capabilities with over 20 XSS payload variants, concurrency support for parallel scanning, intelligent HTML form parsing, and comprehensive reporting in multiple formats. Additionally, the tool emphasizes resilience with built-in retry mechanisms, robust error handling, and secure reporting to prevent common security vulnerabilities in output.

Aivist-Verify

2026-08-15 Python ★ 13
Aivist Verify is an access-control confirmation engine designed to eliminate false positives in testing for Broken Object Level Access (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities. It utilizes a dual approach where an AI model proposes potential vulnerabilities based on traffic analysis, while deterministic code gates decisively validate these findings, ensuring that only fully verified threats are reported. Notably, Aivist Verify guarantees zero false positives, supported by a reproducible evidence chain that enhances the reliability of its outcomes.

ERC.net

2026-08-15 C# ★ 19
ERC.Net is a robust library designed for debugging Windows applications, specifically focused on analyzing application crashes and memory vulnerabilities. It supports both 32-bit and 64-bit applications, provides functionality for parsing executable headers, identifying process information, and generating specific testing patterns. Notable features include the ability to read thread Environment Block (TEB) information, detect memory vulnerabilities, and a comprehensive testing framework that verifies memory searching and parsing capabilities.

MalwareAnalysis-in-PDF

2026-08-15 ★ 237
The Malware Analysis tool focuses on dissecting and evaluating the risk associated with PDF-based malware (maldoc). It provides an in-depth exploration of PDF structures, including headers and encoding techniques, making it a valuable resource for security researchers aiming to understand and analyze malicious code embedded within PDFs. Notable features include detailed explanations of malware behaviors, obfuscation techniques, and how to identify command and control (C&C) mechanisms within PDF binaries.

vulnerability-poc

2026-08-15 Python ★ 59
The Vulnerability PoC Repository offers curated Proof-of-Concept code, test labs, and prevention rules targeting high-severity CVEs for authorized security testing, penetration testing, CTF challenges, and security research. Key features include detection-only PoC scripts, Docker test labs with both vulnerable and patched applications, and bilingual documentation in English and Korean, ensuring comprehensive resources for cybersecurity professionals.

jadx-mcp-server

2026-08-14 Java ★ 29
JADX MCP Server is a pure-Java Model Context Protocol server that facilitates the reverse engineering of Android APK files utilizing the JADX decompiler. Designed for security researchers and developers, it enables detailed analysis through features such as APK loading, code decompilation, component extraction, and comprehensive manifest analysis, all while maintaining cross-platform compatibility and requiring no external dependencies.

clipwire

2026-08-14 C ★ 18
Clipwire is a kernel exploit development harness specifically designed for the iPhone 11 series running iOS 26.1, aimed at demonstrating vulnerabilities discovered through patch diffing between versions 26.1 and 26.6 of Apple's XNU kernel. It exploits two identified bugs: one related to unlocked operations in the copy-on-write (COW) submap fault path, and the other concerning insufficient bounds checks in memory object management, allowing for potential privilege escalation and memory corruption. Notable features include a structured source code layout for various exploit stages, as well as tools for physical memory read/write operations and object discovery, catering to researchers in exploit development.

opencode-pentester

2026-08-14 Shell ★ 21
opencode-pentester is an AI-powered penetration testing and security audit framework designed to automate bug bounty hunting and vulnerability assessments. It orchestrates 12 specialized AI agents across 69 attack categories and 17 OWASP security audits, enabling comprehensive offensive and defensive testing. Notable features include the ability to run automated tests, generate professional reports, and integrate a wide array of security tools, making it suitable for security researchers, penetration testers, and DevSecOps engineers.

hacker-bob

2026-08-14 JavaScript ★ 98
Hacker Bob is a local MCP (Managed Control Panel) workflow tool designed for authorized offensive security testing within CI environments or staging areas. It facilitates surface mapping, authentication setup, parallel testing, and reporting, while integrating with various MCP-capable hosts like Claude Code and Codex. Notable features include real network request capabilities, local artifact imports, and the ability to manage sensitive run data securely, all ensuring users adhere to permissions and authorization guidelines.

agentgg

2026-08-13 TypeScript ★ 196
`agentgg` is an agentic static application security testing (SAST) scanner designed for CI environments that leverages advanced reasoning capabilities over traditional pattern-matching methods. It intelligently navigates codebases by following imports and analyzing the call graph, allowing users to run scans on entire repositories or specific git diffs for pull request assessments. Key features include the ability to auto-download a catalog of agents, resume interrupted scans, and create reusable agents from past security reports, enhancing the overall efficiency and effectiveness of code security analysis.

LPE-Toolkit

2026-08-13 C ★ 13
The LPE Toolkit 2026 (xpl2026) is an advanced collection of 26 static binaries targeting local privilege escalation (LPE) vulnerabilities on Linux systems for penetration testing and security research. Notable features include universal compatibility across various Linux distributions and kernel versions, automatic detection and filtering of applicable exploits, and an interactive user interface for seamless operation. The toolkit is especially significant for its inclusion of newly researched exploits, enhancing its utility for security professionals.

pentestkit

2026-08-13 Python ★ 40
Pentestkit is a sophisticated, multi-agent penetration testing framework that utilizes the Claude Agent SDK to orchestrate a team of specialized agents. The tool excels in automating the penetration testing process by exploiting vulnerabilities, scoring them using CVSS v3.1, and generating comprehensive client-ready reports, all while accumulating knowledge in a shared database. Notable features include its ability to perform real exploitation of findings and a robust scoring system that achieved a perfect 104/104 on the XBOW benchmark suite.

HunterX

2026-08-13 Python ★ 13
HunterX is an AI-assisted offensive security engine designed for conducting authorized security assessments, integrating tools for reconnaissance, hypothesis-driven investigation, vulnerability validation, and professional reporting into a unified workflow. Unlike traditional vulnerability scanners, HunterX emphasizes thorough investigation and validation, ensuring that findings are evidence-based and report-ready. Notable features include AI-assisted reasoning, proof of concept engineering, and capabilities for reproducibility and impact assessment, enhancing the reliability of security assessments.

pullgoscript

2026-08-13 Go ★ 16
OBLITERATUS is an advanced red teaming framework designed for post-exploitation research and defensive evasion in Windows environments. It features a multi-layered stealth architecture for evasion, low-level syscall execution, and identity correlation through its Identity Nexus module, allowing for the bypassing of MFA and efficient credential management. Key capabilities include memory hardening, automatic UAC elevation, and a sophisticated operational interface that facilitates real-time process management and forensic analysis.

globalcve

2026-08-12 TypeScript ★ 62
GlobalCVE is an open-source vulnerability intelligence platform that aggregates Common Vulnerabilities and Exposures (CVEs) from various national and vendor sources, aiming for a clean and developer-friendly interface. Key features include multi-source aggregation with a unified view to avoid duplicates, a minimalist design with dark mode, and a serverless architecture for scalability. The platform emphasizes transparency and community-driven development, providing a free API and fostering collaboration among developers for continual improvement.

TerraSecure

2026-08-12 Python ★ 10
TerraSecure is an ML-powered Infrastructure as Code (IaC) security scanner designed to identify cloud misconfigurations in Terraform and HCL files at build time, effectively preventing potential breaches. It employs a pre-trained XGBoost model that delivers 92.45% accuracy with a significantly lower false positive rate of 10.71%, offering context and remediation guidance based on real-world breach data. Notable features include a hybrid detection approach that integrates a rules engine, machine learning, and AI analysis to provide actionable insights for developers.

ALPC-Enumerator

2026-08-12 C++ ★ 23
ALPC Enumerator is a Windows userland tool designed to enumerate and classify Advanced Local Procedure Call (ALPC) ports, including those associated with Protected Process Light (PPL) processes that evade standard enumeration techniques. It dynamically resolves ALPC Port types and employs `NtQueryInformationProcess` for classification, addressing blind spots in conventional tools, thereby benefiting threat hunters and vulnerability researchers by accurately mapping high-privilege targets and identifying potentially malicious activity. Notably, it has been validated against kernel debugger output for precision and reliability.

web-of-flaws

2026-08-12 Python ★ 18
Web of Flaws is a Markdown-based catalog that identifies vulnerable web patterns alongside safer alternatives, aimed at both developers and automated tools. Its primary use case is to educate users on exploitable vulnerabilities and provide concrete code examples for remediation, organized by security topics and vulnerability families. Notable features include detailed guides that explain risky patterns and their fix implementations.

CVE-2023-51467

2026-08-11 Python ★ 12
CVE-2023-51467 Scanner is a Python-based command-line tool designed to identify a specific vulnerability in the Apache OfBiz ERP system that allows unauthorized access due to an authentication bypass flaw. It enables users to scan individual URLs or lists of URLs for the vulnerability, supporting multiple concurrent threads for efficient scanning and providing output files for vulnerable targets. Notable features include customizable thread counts and flexible input options for URL scanning.

Threat-Patrol

2026-08-11 Python ★ 10
Threat-Patrol is a lightweight Python script designed for web application security testing, enabling users to scan websites for vulnerabilities such as SQL injection, XSS, CSRF, SSRF, LFI, and RCE. Its notable features include an easy-to-use command line interface, automatic scanning capabilities, and instant results, making it suitable for quick vulnerability detection.

Web_Vulnerability_Scanner-AI

2026-08-11 Python ★ 31
The Learning Grade AI Web Vulnerability Scanner is a non-destructive tool designed for identifying common web security issues such as unauthorized security headers, insecure cookie flags, and potential SQL injection vulnerabilities. It features a queue-based crawling mechanism for polite scanning, an AI-assisted report viewer for enhanced analysis, and requires explicit user confirmation for ethical scanning practices. This tool is particularly suited for educational purposes and authorized security assessments.

Reconner

2026-08-11 Go ★ 33
Reconner is a self-hosted reconnaissance tool designed for bug bounty hunters and security researchers, facilitating comprehensive web and network scanning from a single dashboard. It offers a full pipeline of discovery, vulnerability assessment, and continuous monitoring without relying on third-party services, ensuring that all data remains on the user's system. Notable features include real-time logging, native context-aware DAST for multiple vulnerabilities, and seamless integration with Nuclei for enhanced scanning capabilities.

NmapScanningTool-V1

2026-08-11 Python ★ 28
The Nmap Scanning Tool is an interactive wrapper for Nmap that simplifies the execution of common scans and enhances readability of results. It supports multiple scan profiles, including SYN, aggressive, and vulnerability scans, along with an optional output filter to highlight open ports. The tool requires Python and Nmap to be installed on the user's system and aids in providing helpful error messages regarding user permissions and installation checks.

CVE-2023-22515

2026-08-11 Python ★ 154
The CVE-2023-22515 exploit script is designed to target and exploit the critical Broken Access Control vulnerability in Confluence Server and Data Center instances, enabling unauthorized access. It offers two operational modes: Normal for single-target exploitation via a provided URL, and Mass for bulk processing using a list of target URLs from a file, with output detailing the success of the exploitation attempts. Notable features include real-time logging of the exploitation process and clear output indicating whether unauthorized access was achieved.

CVE-2025-55182

2026-08-11 Python ★ 68
The tool exploits the vulnerability CVE-2025-55182 to achieve remote code execution through prototype pollution in Next.js React Server Components. Its primary use cases include executing arbitrary commands or establishing a reverse shell on a target server, with features for specifying various listener and payload options. Additionally, a lab environment is provided for testing the exploit in a controlled Docker setup.

xsscan

2026-08-11 Python ★ 11
XSScan is a Playwright-based automated tool designed for bug bounty hunters and security researchers to detect executed cross-site scripting (XSS) vulnerabilities. Key features include real browser execution using Chromium, intelligent form submission, recursive crawling, and auto-generated reports of confirmed XSS findings, ensuring focus on vulnerabilities that are genuinely executed rather than merely reflected.

CVE-2026-21858

2026-08-11 Python ★ 260
The CVE-2026-21858 tool demonstrates a full exploitation chain involving unauthorized arbitrary file read (AFR) and remote code execution (RCE) in the n8n automation platform. By leveraging content-type confusion and expression injection vulnerabilities, it allows an attacker to forge admin tokens and execute commands with critical impact. Key features include automated exploitation via a Python script and specific exploit requirements, such as vulnerable configurations of n8n workflows.

Windfall

2026-08-11 Ruby ★ 18
Windfall is an exploitation framework that targets critical vulnerabilities in Windmill and Nextcloud Flow, specifically focusing on unauthenticated path traversal and authenticated SQL injection vulnerabilities. Its primary use case is to demonstrate how these vulnerabilities can lead to credential leaks and remote code execution, thereby enabling an attacker to exploit the affected systems. Notable features include a comprehensive assessment of the vulnerabilities' impact with high CVSS scores and detailed analysis of attack vectors, enhancing the tool's utility for security researchers and penetration testers.

OpenLPX

2026-08-11 Java ★ 13
OpenLPX is an anti-packet exploit tool designed for Minecraft servers, focusing on protecting against crash packet exploits, specifically NettyCrasher attacks, without requiring any external dependencies. Key features include a smooth packet limiter with a configurable violation system, advanced packet logging capabilities for analyzing potential exploits, and compatibility with Minecraft mods like Printer and Schematica, ensuring minimal disruption to player experiences. The tool provides detailed configuration options to tailor protection measures while allowing for real-time alerts and server management commands.

Root-My-Pixel

2026-08-11 Kotlin ★ 237
Root My Pixel is an Android application that automates the acquisition of temporary root access on Google Pixel devices using the NebuSec IonStack exploit (CVE-2026-43499) and integrates with ReSukiSU / KernelSU. It employs a sophisticated installation workflow for device detection and exploit execution while providing real-time log monitoring and management features like soft reboot and log exporting. This tool specifically targets a range of supported Pixel models and requires prerequisites such as the Shizuku service and ReSukiSU Manager for optimal functionality.

awesome-cybersecurity-books

2026-08-11 ★ 42
This repository offers a curated collection of over 70 free cybersecurity books organized by domain and difficulty, facilitating self-paced learning in various cybersecurity disciplines. Notable features include a structured learning roadmap progressing from beginner to advanced levels, an emphasis on community maintenance for up-to-date resources, and a direct link to an extensive Google Drive library containing the materials.

ai-red-teaming

2026-08-11 Python ★ 26
Red-Team AI is a white-box red teaming tool designed specifically for agentic AI applications, capable of reading source code to identify vulnerabilities that are unique to a particular technology stack. Its primary use case involves generating tailored attacks based on an application's specific implementation, rather than relying on generic adversarial prompts. Notable features include a modern React dashboard for scan management and compliance tracking, as well as integrations with popular agent frameworks, facilitating extensive security assessments and risk assessments for AI systems.

ASLRay

2026-08-10
ASLRay is a Linux-based tool designed for bypassing Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP/NX) in 32-bit and 64-bit ELF binaries through stack-spraying techniques. It leverages shell variables to efficiently exploit buffer overflow vulnerabilities, allowing successful execution of shellcode by circumventing ASLR randomness and exploiting predictable memory addresses. Notable features include cross-platform compatibility, a minimalistic design, and the ability to use return-to-libc techniques for DEP/NX mitigation on x32.

BugTraceAI-CLI

2026-08-10
BugTraceAI-CLI is an autonomous offensive security framework designed specifically for bug bounty hunting, effectively integrating LLM-driven analysis with real-world exploitation tools. Its key features include active exploitation of vulnerabilities using SQLMap, browser-based validation, and a focus on actionable outcomes, all while utilizing AI for hypothesis generation and traditional tools for verification. The framework emphasizes a robust methodology that allows users to think analytically, exploit dynamically, and validate thoroughly.

cloudgpt

2026-08-10
CloudGPT is an AWS vulnerability scanner that assesses customer-managed AWS policies for potential vulnerabilities using ChatGPT. It automatically redacts sensitive information such as account numbers to ensure privacy while querying OpenAI, and primarily focuses on parsing responses to identify vulnerabilities in policies. Users are advised to manually review the outputs for context, as the tool provides initial assessments based on a simplified response format.

hexstrike-ai

2026-08-10
HexStrike AI is an advanced, AI-powered penetration testing framework designed for cybersecurity automation, featuring over 150 integrated security tools and more than 12 autonomous AI agents. Its primary use case is to enhance vulnerability assessment and exploitation processes through intelligent decision-making and real-time dashboards, optimizing testing strategies based on target analysis. Notable features include support for multi-agent architecture, a modern visual engine, and capabilities such as attack chain discovery and parameter optimization.

hoppr-cop

2026-08-10
Hoppr-Cop is a CLI and Python library designed for generating comprehensive vulnerability reports from a CycloneDX Software Bill of Materials (SBOM) by aggregating data from multiple open-source vulnerability databases. It effectively combines information from various scanners to reduce duplicates and enhance accuracy, offering output in multiple formats such as CycloneDX VEX and HTML reports suitable for offline use. This tool provides a streamlined method for managing and communicating vulnerability information without the need to regenerate the SBOM frequently.

libformatstr

2026-08-10
libformatstr is a Python library designed to facilitate format string exploitation by generating payloads for various scenarios in binary exploitation. It allows users to easily manipulate memory addresses, write ROP chains, and guess argument numbers and padding. Notable features include support for both 32-bit and 64-bit architectures, customized order of writes, and the ability to handle string inputs when constructing payloads.

vuldash

2026-08-10
Vuldash is a comprehensive vulnerability management dashboard designed for ethical hacking projects, enabling collaboration between pentesters and clients. It supports custom plugins, facilitates incident tracking and reporting in both business and technical formats, and allows for online access to reported issues. The platform also features user management capabilities and the ability to import reports from various security tools such as Nmap and Zap Proxy.

petereport

2026-08-10
PeTeReport is an open-source application vulnerability reporting tool designed to streamline the report writing process for penetration testers and security researchers. Built using Django and Python 3, it facilitates the management of finding templates, detailed report generation in multiple formats (HTML, CSV, PDF, Jupyter, Markdown), and integration with tools like DefectDojo, while offering customizable outputs and a multilingual user interface. Notable features include a findings template database, customizable reports, and the capability to add appendices and attack flows to findings, enhancing the overall efficiency of the reporting phase in security assessments.

grype

2026-08-10
Grype is a vulnerability scanner designed for container images and filesystems, allowing users to detect known security issues across various OS package ecosystems and language-specific packages. Notable features include support for multiple image formats such as Docker and OCI, threat prioritization mechanisms like EPSS and KEV, and enhanced scanning capabilities through OpenVEX integration. It streamlines the vulnerability assessment process for developers and security teams by enabling quick scans of container images and SBOMs.

vcr

2026-08-10
The Vulnerability Compliance Report Tool converts Nessus scan files into formatted HTML reports, tailored for security professionals, auditors, and pentesters. It supports parsing Basic Network and CIS Benchmark scans for various Windows operating systems, enabling users to visually present vulnerability data in a structured and accessible manner. Notable features include a user-friendly dashboard, IP and vulnerability-focused navigation, and customizable templates for report generation.

go-dependency-scanner

2026-08-10 Go ★ 10
Educational dependency scanner built in pure Go—parse go.mod and go.sum, inspect direct and indirect modules, query OSV for vulnerabilities, and summarize licenses.

ai-smart-contract-auditor

2026-08-10 JavaScript ★ 75
AuditSentry is an AI-powered smart contract auditor designed for analyzing Solidity and Vyper contracts across EVM chains. It leverages 23 specialized AI agents to conduct in-depth security assessments, providing detection of critical vulnerabilities, working exploit proof-of-concepts, and gas profiling, all formatted into professional audit reports within minutes. Notable features include mainnet-fork simulations and on-chain certificates, enhancing both accuracy and trust in the audit process.

trivy-operator-dashboard

2026-08-09 C# ★ 101
The Trivy Operator Dashboard is a security management tool designed for Kubernetes environments, offering comprehensive insights into security posture through detailed reporting on vulnerabilities, policy validation, and compliance assessments. Notable features include user-friendly dashboards for various security reports, including vulnerability and cluster assessments, with capabilities for data export and inspection. The tool aims to streamline security monitoring and response, prioritizing simplicity in its core functionality while considering future enhancements based on community demand.

Auto-IDOR

2026-08-09 Python ★ 15
IDOR-Auto is an advanced testing tool designed specifically to identify Broken Object-Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR) vulnerabilities by employing differential access testing rather than relying on simple HTTP status codes. It distinguishes itself by utilizing multiple identity responses to determine if one user can access another user's data, while effectively minimizing false positives through robust response comparison, identifier analysis, and support for various input formats. Key features include canary detection, injection point flexibility, identification of encoded IDs, method tampering, and direct raw request importation, making it suitable for authorized security testing in penetration tests and bug bounties.

vulnapi

2026-08-08 Go ★ 279
VulnAPI is an open-source dynamic application security testing (DAST) tool tailored for scanning APIs to identify common security vulnerabilities. It features a command-line interface (CLI) that allows users to discover API details and execute scans using either a curl-like syntax or OpenAPI contracts, delivering comprehensive reports on detected vulnerabilities. Notable functionalities include detailed output reports, integration with OpenAPI specifications for scanning, and the ability to leverage the discover command for gaining insights into target APIs.

ARES-Spoofer-Byfron

2026-08-08 Rust ★ 55
ARES-RS is a Rust-based Roblox spoofer designed to protect user accounts from Byfron's detection and Roblox's ban system by modifying hardware identifiers (HWIDs). It features extensive configurability, automatic updates, and enhanced error handling, allowing users to execute spoofing operations either manually or automatically upon closing the Roblox application. Notable capabilities include spoofing BIOS, motherboard, and various hardware components, with recommendations for optimal use alongside a VPN.

Kryon

2026-08-08 Python ★ 29
Kryon is an autonomous, local-first cybersecurity agent designed for comprehensive offensive security tasks including compliance audits, penetration testing, vulnerability hunting, digital forensics, and incident response from a single command. It features a skill-based architecture that dynamically loads over 110 playbooks and employs deterministic pre-hooks for critical detections, ensuring that it provides both a thorough assessment and actionable outputs without reliance on external APIs. Additionally, it supports a wide range of compliance frameworks across multiple sectors, making it adaptable for various organizational needs.

conf-presentations

2026-08-07 ★ 319
The Quarkslab repository serves as a comprehensive archive of presentations delivered at various conferences and seminars, focusing on topics related to cybersecurity, reverse engineering, and hardware challenges. It features notable material such as workshop slides and papers on advanced techniques in Bluetooth hacking, binary instrumentation, and exploiting software vulnerabilities. This resource is primarily used for sharing knowledge and promoting discussions within the cybersecurity community through detailed lecture content and insights from industry experts.

Flow

2026-08-06 Java ★ 79
Mixeway Flow is a comprehensive DevSecOps tool that integrates security throughout the software development lifecycle (SDLC) by automating scans for security vulnerabilities across various aspects such as source code, dependencies, infrastructure as code (IaC), and potential secret leaks. Notable features include a unified dashboard for centralized threat management, seamless Git integration with automated scans triggered by webhooks, and an upcoming AI/LLM-powered verification engine to enhance vulnerability validation directly within the source code.

npm-shai-hulud-scanner

2026-08-06 Python ★ 15
The NPM Supply Chain Security Scanner is a robust tool designed to identify vulnerabilities in NPM and PyPI dependencies, specifically targeting known compromised packages associated with significant supply chain attacks from 2025 to 2026. Key features include comprehensive detection of transitive dependencies, integration with multiple programming ecosystems, and careful analysis of installation scripts and entangled dependencies for malicious patterns, alongside automated script options for continuous security monitoring and reporting.

ONUS

2026-08-06 Python ★ 11
ONUS is a locally-hosted vulnerability assessment and penetration testing tool designed for conducting comprehensive scans on authorized target domains. It features eight parallel scanning modules that assess various security aspects, employs deterministic CVSS v3.1 scoring for findings, and optionally utilizes AI for generating user-friendly remediation instructions, delivering results in both a PDF report and an interactive web dashboard. This air-gapped solution prioritizes simplicity and security, requiring no external dependencies or user accounts for self-hosted deployments.

cyberful

2026-08-06 TypeScript ★ 117
Cyberful is an AI-driven application-security workbench designed for authorized penetration testing, code auditing, and bug bounty research. It features robust workflows including pentest phases for evaluating live targets, supports isolated tooling for independent verification, and offers report-ready outputs while maintaining a local-first approach without emitting telemetry. Notably, Cyberful emphasizes trustworthiness in security findings by ensuring actions remain within defined authorization boundaries and by providing detailed evidence tied to each engagement.

CVE-2026-60004-POC

2026-08-06 Python ★ 17
The CVE-2026-60004-POC tool provides a proof-of-concept for exploiting a pre-authentication remote code execution vulnerability in Gitea versions 1.17 through 1.27.0, with a CVSS score of 9.8. This exploitation occurs via the `diffpatch` API endpoint, allowing attackers to inject malicious Git hooks that execute arbitrary commands by manipulating Git's patch processing. Notable features include two operational modes for automation and the ability to retrieve command output directly from the target server after exploitation.

Xpsd

2026-08-05 Go ★ 11
Xpsd is a vulnerability reachability analysis tool that leverages LLMs to determine if reported vulnerabilities are actually exploitable within a specified codebase. By ingesting CVE descriptions or vulnerability scan reports, it employs structural code navigation and other tools to generate structured verdicts and detailed markdown reports compatible with GitHub code scanning. Noteworthy features include GitHub CI integration, support for multiple vulnerability scanners, and flexible model switching for tailored analysis.

dheater

2026-08-05 Python ★ 217
D(HE)ater is a proof-of-concept tool that demonstrates the D(HE)at denial-of-service attack, which targets servers by saturating their CPU through enforced Diffie-Hellman ephemeral (DHE) or elliptic-curve Diffie-Hellman ephemeral (ECDHE) key exchanges over TLS and SSH. It allows users to specify protocols and various settings like key exchange type, socket timeout, and the number of threads for executing the attack, making it suitable for defensive security testing and research purposes. The tool is built on Python 3.9+ and relies on the CryptoLyzer library for traffic generation and DHE/ECDHE support validation.

JoySafeter

2026-08-05 Python ★ 304
JoySafeter is an AI-native platform designed to automate and orchestrate security agents at scale, facilitating rapid security operation deployments from concepts to production in minutes. With capabilities such as autonomous APK vulnerability detection and dynamic penetration testing through adaptable DeepAgents, it eliminates the need for extensive manual coordination and integrates seamlessly with over 200 security tools via the MCP Protocol. Its focus on multi-agent collaboration and cognitive memory redefines traditional security methodologies, enabling efficient analysis and reporting with minimal human intervention.

plecost

2026-08-05 Python ★ 381
Plecost is a professional security scanner specifically designed for WordPress installations, capable of detecting vulnerabilities in the core, plugins, and themes while referencing a daily-updated local CVE database. It offers various scanning modes, such as deep and fast scanning, along with features like asynchronous scanning, extensive configuration options, and compatibility with task queues like Celery, making it suitable for automated security assessments without any external API dependencies or data sharing.

secuditor-lite

2026-08-05 Python ★ 63
Secuditor Lite is a Python-based diagnostic security tool designed for Windows environments, facilitating endpoint security assessments through a user-friendly graphical interface. Its primary use case involves identifying vulnerabilities, suspicious activities, and misconfigurations across systems and networks, while providing features like SSL/TLS interception analysis, operational security evaluations, and the generation of structured audit reports. The tool supports comprehensive security checks covering system hardware, network configurations, shared folder permissions, and a variety of security controls.

pwn

2026-08-05 Ruby ★ 76
PWN is an open-source Ruby toolkit designed for offensive security automation, integrating various tools used in OSINT, network scanning, and vulnerability testing within a single workspace. Its primary use case is to streamline red teaming and pentesting efforts by providing a unified framework that supports automation through a tool-calling AI agent and a flexible plugin architecture. Notable features include 66 plugins, support for multiple LLM engines, and a feedback loop system that learns from previous mistakes, enhancing the efficiency of security assessments.

exploitbot

2026-08-05 Python ★ 10
ExploitBot is an AI-powered penetration testing toolkit designed for autonomous operation on Apple Silicon, enabling users to conduct comprehensive pentests without cloud dependency. Notable features include local LLM inference, three distinct interaction modes (Autopilot, Copilot, Manual), integration with major penetration testing tools, and automatic report generation in multiple formats. Additionally, it supports cross-engagement artifact sharing, a local CVE database, and multilingual interfaces, enhancing efficiency in vulnerability discovery and reporting.

Cybersecurity-Handbook

2026-08-05 JavaScript ★ 61
The Cybersecurity Handbook is an interactive, open-source knowledge base tailored for cybersecurity professionals, students, and enthusiasts. It offers over 400 comprehensive notes on diverse topics, enhanced by an interactive knowledge graph, full-text search capabilities, and a user-friendly interface that supports dark/light modes and is mobile-friendly. This community-driven resource keeps pace with the rapidly evolving cybersecurity landscape, providing practical insights into real-world threats and defense strategies without any paywalls.

osv-detector

2026-08-04 Go ★ 63
Osv-detector is an open-source auditing tool designed to identify vulnerabilities in software dependencies by leveraging advisory databases that comply with the OSV specification. Its primary use case is to analyze various package lockfiles across multiple ecosystems, including npm, Python, Ruby, and more, enabling developers to efficiently pinpoint security risks in their projects. Notable features include support for a wide range of lockfile formats and the ability to automatically determine the appropriate parser based on the filename.

awesome-reverse-engineering-and-malware-analysis

2026-08-04 Shell ★ 89
Awesome Reverse Engineering & Malware Analysis is a comprehensive resource that serves as a curated guide for reverse engineering and malware analysis tools, methodologies, and educational content. It categorizes entries across various disciplines such as static and dynamic analysis, exploit development, and digital forensics while providing quality assurance by checking all links and content for relevance. Notable features include structured learning tracks for different areas of focus, detailed tagging for easy navigation, and inclusion of community resources to enhance collaboration and knowledge sharing.

android-security

2026-08-04 ★ 10
Android Security is a comprehensive resource aimed at enhancing secure app development for Android through various methodologies such as reverse engineering, vulnerability testing, and data protection best practices. Notable features include a catalog of online analyzers and static analysis tools that facilitate multi-faceted security assessments, providing developers the means to identify and mitigate vulnerabilities within their applications effectively.

Mr.SIP

2026-08-04 Python ★ 431
Mr.SIP is a console-based SIP security framework designed for auditing and penetration testing of SIP-based systems. It includes three primary modules for network scanning, user enumeration, and Denial of Service (DoS) attack simulations, all leveraging high-performance multithreading and IP spoofing. The tool serves both as a research platform for SIP DDoS attacks and as a practical utility for assessing the security of VoIP infrastructures.

RobustPentestMacro

2026-08-03
RobustPentestMacro is a versatile Visual Basic macro designed for penetration testing, allowing testers to embed sophisticated post-exploitation techniques into Microsoft Office documents. Key features include platform detection for Windows and MacOS, sandbox evasion mechanisms, WMI persistence for automatic execution at startup, and social engineering tactics to obscure malicious behavior. The macro facilitates easy customization by enabling users to insert tailored payloads through defined functions for both operating systems.

findom-xss

2026-08-03
FinDOM-XSS is a specialized tool designed for detecting potential DOM-based XSS vulnerabilities in web applications rapidly. Its primary use case involves scanning specified URLs or lists of URLs to identify any security weaknesses, with the capability of outputting results to a designated file. Key features include its straightforward command-line interface and flexibility in handling multiple URLs through piping, complemented by dependency on LinkFinder for enhanced functionality.

GPTLens

2026-08-03
GPTLens is a vulnerability detection tool that leverages the capabilities of the GPT-4 API to analyze and identify vulnerabilities in smart contracts. It incorporates a multi-step auditing process through auditors, critics, and ranking systems, allowing for fine-tuned evaluation of smart contract safety. Notable features include customizable parameters for auditing and critic evaluations, along with support for running user-defined datasets.

magisk-frida

2026-08-03 Shell ★ 1437
MagiskFrida is a tool that enables the automatic execution of the Frida server on device boot across multiple root solutions, including Magisk, KernelSU, and APatch. It supports various architectures such as arm64, arm, x86, and x86_64, and provides instant updates by integrating with the official Frida build process. This tool is particularly beneficial for developers, reverse-engineers, and security researchers looking to leverage dynamic instrumentation in rooted Android environments.

mavs

2026-08-03
MAVS (Mobile Application Vulnerability Scanner) is a shell script designed for static analysis of Android APK files, focusing on identifying and demonstrating vulnerabilities. Its primary use case is to not only highlight potential security flaws but also provide actionable exploitation techniques, thereby enabling users to understand and mitigate risks effectively. Notable features include verbose output for detailed analysis and direct commands for exploiting vulnerabilities, enhancing the practical applicability of its findings.

aggroArgs

2026-08-03
aggroArgs is a command-line tool designed for probing and exploiting buffer overflows through aggressive argument testing. It features cyclic pattern overflows with automatic offset calculation, segfault monitoring, and the ability to generate proof-of-concept exploits. The tool supports various probing modes, extensive command-line option parsing, and is tailored for ELF files marked as executable, making it suitable for security researchers and penetration testers assessing software vulnerabilities.

Buffer-Overflow-Exploit-Development-Practice

2026-08-03
Buffer-Overflow-Exploit-Development-Practice is a tool designed for practicing exploit development against vulnerable software running in a virtual machine environment. It provides a structured approach to mastering buffer overflow exploitation techniques, including steps to find offsets, identify "bad characters," and generate shellcode using tools like msfvenom. Notable features include detailed guidance for verifying jump instructions and crafting exploit buffers, making it particularly useful for cybersecurity professionals preparing for certification exams such as OSCP.

SMBGhost_AutomateExploitation

2026-08-03
SMBGhost_AutomateExploitation is a Python tool designed to exploit the SMBGhost vulnerability (CVE-2020-0796) and assess the vulnerability of Windows target systems. It automates the process of executing a reverse shell or deploying custom shellcode, allowing users to interact with vulnerable machines directly while providing options for specifying various configurations, such as IP address, architecture, and payload loading. Notable features include retry logic for exploit attempts, a shellcode import function, and a built-in scanner to verify the susceptibility of target hosts.

Win7Blue

2026-08-03
Win7Blue is a penetration testing tool designed to scan and exploit vulnerabilities related to the EternalBlue exploit (CVE-2017-0143) specifically for Windows 7 systems. It features a vulnerability scanner that utilizes Nmap to detect susceptible targets and includes an architecture identification module to ascertain system architecture. The tool requires several dependencies including Python and Msfvenom for effective exploitation and is primarily tested on the Kali Linux platform.

WindowsExploits

2026-08-03
WindowsExploits is a collection of precompiled exploits for Windows operating systems, primarily focused on privilege escalation vulnerabilities. The repository consists mostly of forked content from another project, providing users with ready-to-use exploit code for security testing and penetration assessments. Notable features include its emphasis on ease of use and accessibility for penetration testers.

aktaion2

2026-08-03
Aktaion is an open-source machine learning tool designed for behavior-based detection of ransomware exploits, functioning independently of traditional static signatures. The prototype emphasizes the use of "Microbehaviors" to cohesively analyze multiple security signals and behaviors, supporting a more dynamic intrusion detection framework. The tool has transitioned from Java to Python3, enhancing its accessibility for educational purposes and integration into active defense strategies.

Callisto

2026-08-03
Callisto is an intelligent automated binary vulnerability analysis tool that leverages Ghidra's headless decompiler to extract and analyze pseudo code from binaries for potential security vulnerabilities. It utilizes Semgrep for initial analysis and validates findings with GPT-3.5-Turbo, enhancing accuracy and depth in vulnerability detection. The tool facilitates binary analysis and zero-day vulnerability discovery while providing a straightforward decompilation output for further manual review or integration with existing SAST tools.

PRET

2026-08-03
PRET (Printer Exploitation Toolkit) is a security testing tool designed for evaluating printer vulnerabilities by exploiting features of PostScript, PJL, and PCL printer languages. Its primary use case is to facilitate communications with a printer to perform various attacks, such as capturing and manipulating print jobs, while also offering functionalities for printer discovery and command execution in a user-friendly manner. Notable features include support for network and USB printers, detailed attack documentation, and command options for safety checks and logging.

cve-collector

2026-08-03
CVE-Collector is a Python tool designed to automate the collection of the latest CVE information, specifically targeting vulnerabilities with a severity score of 6 or higher from cvedetails.com. It features a simple delimiter-based file structure for storing collected data, eliminating the need for a traditional database management system, and allows for automated scheduling via cron jobs for continuous monitoring. The tool also provides detailed vulnerability information, including publish dates and associated CWE classifications.

paper_collection

2026-08-03
The repository serves as a curated collection of academic papers focusing on topics such as fuzzing, binary analysis, IoT security, and general exploitation techniques. It categorizes publications into read and unread sections, covering various specific implementations and methodologies, including AI advancements in fuzzing and static binary analysis approaches. Users can contribute by suggesting additional relevant papers through pull requests, enhancing the repository's comprehensiveness.

Pentest-Tools-Framework

2026-08-03
The Pentest Tools Framework is a versatile Python-based platform designed for penetration testing, featuring modules for exploits, scanners, and password management. Its notable capabilities include an intuitive command interface to manage various tools, execute modules, and update the framework easily. This comprehensive toolset is geared towards enhancing security assessments by providing a centralized solution for diverse pen-testing tasks.

porch-pirate

2026-08-03
Porch Pirate is an OSINT framework designed to conduct reconnaissance on publicly accessible Postman entities, enabling the extraction of sensitive information such as global secrets, unique headers, and endpoints. Its notable features include support for searching, dumping data from workspaces, and extracting URLs for further analysis, all while maintaining flexibility to adapt to varied search needs without being confined to predefined keywords. This tool enhances the efficacy of reviewing Postman assets by providing a simple command-line interface for extensive data enumeration.

SploitScan

2026-08-03
SploitScan is a comprehensive tool designed for cybersecurity professionals to efficiently identify exploits related to known vulnerabilities and assess their likelihood of exploitation. Key features include integration with the Exploit Prediction Scoring System (EPSS), a patching priority system based on vulnerability metrics, and the ability to import results from various vulnerability scanners. The tool also provides AI-powered risk assessments, supports multiple CVE handling with export options, and offers a user-friendly interface for streamlined operations.

ThunderCloud

2026-08-03
ThunderCloud is a cloud exploit framework designed for penetration testing of AWS and Azure environments. It features modules for enumerating roles, extracting credentials from vulnerable Cognito endpoints, attacking S3 buckets, and phishing AWS SSO credentials. This tool facilitates various attacks, making it valuable for security professionals assessing cloud infrastructure vulnerabilities.

peda

2026-08-03
PEDA (Python Exploit Development Assistance for GDB) is a GDB extension that enhances the debugging experience by colorizing disassembly and providing advanced commands to assist in exploit development. Notable features include utilities for checking binary security options, displaying function arguments, dumping ROP gadgets, and generating shellcode, all streamlined to facilitate the analysis and exploitation of binaries.

isf

2026-08-03
The Industrial Security Exploitation Framework (ISF) is an exploitation toolkit written in Python, derived from the NSA Equation Group's Fuzzbunch framework. It primarily facilitates research into industrial control systems by providing modules for controlling various PLCs, performing Modbus injections, and scanning for vulnerabilities. Notable features include support for multiple PLC brands, recovery of Telnet passwords, and a variety of loaded plugins to enhance its functionality.

routersploit

2026-08-03
RouterSploit is an open-source exploitation framework specifically designed for penetration testing of embedded devices. Its modular architecture includes various components such as exploits, credential testing modules, scanners, and payload generators, facilitating comprehensive vulnerability assessments. The framework also supports Bluetooth Low Energy, enhancing its capabilities for testing a broader range of devices.

BootStomp

2026-08-03
BootStomp is a boot-loader vulnerability analysis tool focused on identifying memory corruption and state storage vulnerabilities in ARM-compiled boot-loaders. Notable features include a taint analysis capability that tracks data flows and potential exploit paths, integration with tools like angr and IDA PRO, and the option to run analyses within a Docker container for convenience and environmental consistency.

pacu

2026-08-03
Pacu is an open-source AWS exploitation framework aimed at facilitating offensive security testing within cloud environments. Its primary use case is for penetration testers to identify and exploit configuration vulnerabilities in AWS accounts using various modules that allow for attacks like user privilege escalation and Lambda function exploitation. Notable features include session management for storing AWS keys, a modular architecture enabling easy extension of functionalities, and comprehensive command support for executing different exploitation techniques.

pegasus-neo

2026-08-03
PEGASUS-NEO is an advanced penetration testing framework that integrates a variety of security tools and custom modules aimed at aiding security professionals and ethical hackers in their assessments. Its primary use case includes reconnaissance, exploitation, and web hacking, supported by notable features such as automated exploitation, vulnerability scanning, and social engineering tools. The framework also provides functionalities for wireless attacks, code scanning, and forensic analysis, making it a comprehensive solution for penetration testing.

vuln-bot

2026-08-03
Vuln-Bot is a high-risk CVE intelligence platform designed to track and analyze critical and high-severity vulnerabilities with a probability of exploitation (EPSS) of 60% or higher. It automatically harvests and publishes vulnerability briefings every four hours, leveraging multiple authoritative data sources, including the CVEProject repository, and features advanced filtering, risk scoring, and interactive visualizations on an Alpine.js dashboard. Notable capabilities include mobile-first design, incremental harvesting for faster updates, and a robust CI/CD pipeline for security assurance.

CVE-2025-55182

2026-08-03
CVE-2025-55182 is a tool designed to exploit a critical prototype pollution vulnerability in React and Next.js Server Actions, allowing for Remote Code Execution (RCE). It features an automated scanning capability via a Nuclei template and a manual exploitation script in Python, enabling the execution of arbitrary commands on vulnerable servers while extracting output effectively from response headers. This tool aims to assist security professionals in assessing the impact of this vulnerability on affected versions of React and Next.js.

dl4sa

2026-08-03
The "Deep Learning for Code-centric Software Vulnerability Assessment" repository provides tools and data for assessing vulnerabilities in C/C++ code using deep learning models. Its primary use case is to facilitate automated vulnerability detection through various machine learning approaches, including both graph-based and non-graph models, with provisions for multitask learning. Notable features include a structured organization of data and model scripts, as well as detailed instructions for running each model.

Embedding-Poisoning

2026-08-03
Embedding Poisoning provides a data-free backdoor attack method for NLP models, allowing attackers to compromise the embedding layers by modifying a single word embedding vector without needing access to task-related datasets. The tool is particularly useful for sentiment analysis and sentence-pair classification tasks, facilitating experiments and demonstrating the vulnerabilities of embedding layers in common NLP tasks. Notable features include dataset preparation scripts, functionality for data-poisoning and testing, and compatibility with Hugging Face's Transformers library.

FIDL

2026-08-03
FIDL is a Python library designed to facilitate the use of the decompiler API within IDA Pro, focusing on vulnerability research and bug hunting in binaries. It provides a set of utilities that simplify the decompilation process for reverse engineering tasks, making it accessible for both specific security assessments and wider reverse engineering applications. Notable features include easy installation via pip, support for development mode with live editing, and comprehensive online documentation.

LLMgrep

2026-08-03
LLMGrep is an advanced security analysis tool that leverages the capabilities of Large Language Models and Semgrep for comprehensive vulnerability scanning and code analysis. It features a dual-engine mechanism for static analysis, AI-driven insights for vulnerability assessment, and the ability to generate custom security rules, enhancing the overall security posture of codebases. Additionally, users benefit from context-aware discussions and actionable suggestions to improve code quality and adhere to security best practices.

Oversight

2026-08-03
Oversight is a modular, web-based framework designed for the reverse engineering and red teaming of Large Language Models (LLMs). It features a plugin-based architecture allowing users to extend functionality, while providing tools for adversarial testing, prompt fuzzing, and layer analysis. The framework facilitates ease of use with an intuitive interface and the ability to generate detailed analysis reports, making it suitable for vulnerability research in LLM applications.

ReposVul

2026-08-03
ReposVul is a high-quality, repository-level vulnerability dataset designed to support vulnerability detection tasks within software projects. It features a comprehensive framework for data collection, including modules for vulnerability untangling, multi-granularity dependency extraction, and trace-based filtering, allowing for the analysis of 6,134 CVE entries across multiple programming languages. This dataset aids researchers and practitioners in identifying and mitigating vulnerabilities more effectively by providing detailed, organized information on code changes and their interrelations.

SoK-Code-Obfuscation-in-LLM-VD-arxiv

2026-08-03
This repository presents a systematic study on code obfuscation techniques aimed at thwarting vulnerabilities detected by LLM-based models. It includes components for managing obfuscated and unobfuscated code, auditing and evaluating LLM vulnerability detection results, and a suite of customizable scripts and tools for code obfuscation and analysis. Notable features include pre-existing datasets across various programming languages, integration with multiple LLM auditor models, and the capability to configure the environment for experimental setups.

cve-bench

2026-08-03
CVE-Bench is a benchmarking tool designed to evaluate AI agents' capacities to exploit real-world web application vulnerabilities, specifically utilizing critical-severity Common Vulnerability and Exposure (CVE) data. The tool enables automated assessments through tasks like denial of service, remote code execution, and unauthorized access, leveraging Docker for consistent environments and reproducible results. Notable features include a focused dataset of 40 CVEs, integration of automatic exploits, and support for various attack vectors, making it a pivotal resource for researchers in AI safety and security evaluation.

KitPloit_Arsenal

2026-08-03
KitPloit_Arsenal is an advanced security search engine that aggregates exploits and security vulnerability news to assist cybersecurity professionals and researchers. Its primary use case is to enhance penetration testing and threat assessment activities by providing a centralized resource for security tools and information. Notable features include a stable release built with Python 2.7 and a user-friendly interface that supports the open-source community.

mimikittenz

2026-08-03
`mimikittenz` is a post-exploitation PowerShell tool designed for extracting sensitive data, including plain-text passwords and various types of private information, from the memory of running processes using the Windows `ReadProcessMemory()` function. It supports a wide range of data extraction, including webmail credentials, financial application data, and more, employing customizable regular expressions for targeted information retrieval. Notable features include the ability to target specific processes and the flexibility for users to add custom regex patterns for further data extraction needs.

OWASP-Xenotix-XSS-Exploit-Framework

2026-08-03
OWASP Xenotix XSS Exploit Framework is a sophisticated tool designed for detecting and exploiting Cross Site Scripting (XSS) vulnerabilities. It boasts zero false positive scanning through its Triple Browser Engine and features over 1500 distinct XSS payloads, facilitating both vulnerability detection and WAF bypass. Additionally, it includes a comprehensive information gathering module and offensive XSS exploitation capabilities aimed at penetration testing and proof of concept development.

PwnXSS

2026-08-03
PwnXSS is a Python-based XSS scanner designed to identify cross-site scripting vulnerabilities in web applications. Its primary use case involves crawling websites to detect potential XSS weaknesses in both GET and POST forms through customizable settings and advanced error handling. Notable features include multiprocessing support, the ability to handle various HTTP methods, and the option to configure proxies and user agents for more thorough testing.

rex

2026-08-03
Rex is a tool designed for advanced crash triaging, exploration, and exploitation of vulnerabilities, particularly focusing on crash scenarios like buffer overflows. Its notable features include the ability to generate exploits that manipulate registers, leak memory, and export them in various formats (C, Python, binary) while supporting Linux ELF binaries. Rex also enables users to explore crashes to identify exploitation primitives and assess the reliability of generated exploits against specific defenses.

skills

2026-08-03
The Trail of Bits Skills Marketplace is a plugin repository designed to enhance AI-assisted security analysis, testing, and development workflows, compatible with the Claude Code platform. It provides a variety of plugins focused on smart contract security, code auditing, and other advanced security techniques, allowing users to efficiently integrate tools for vulnerability assessment and code review into their processes. Notable features include support for multiple blockchains, GitHub Actions auditing, and customizable static analysis workflows, enhancing the overall security posture of software projects.

ATSCAN

2026-08-03
ATSCAN is an advanced mass scanning tool designed for automated vulnerability assessment, allowing users to perform extensive searches for exploits and issues across multiple search engines, including Google, Bing, and Shodan. It boasts features like mass dork searching, exploitation capabilities, automated command execution, and the ability to detect various web vulnerabilities such as XSS, SQL injection, and file inclusion. The tool is written in Perl, supports proxy usage, and provides options for random user agents and engines to enhance anonymity during scans.

Awesome-Fuzzing

2026-08-03
Awesome Fuzzing is a curated repository that aggregates resources related to fuzzing and exploit development, offering a comprehensive selection of books, courses, videos, tools, and vulnerable applications for practitioners and learners. Notable features include categorized sections for various types of fuzzers, including cloud, file format, network protocol, and browser fuzzers, as well as resources for directed fuzzing and anti-fuzzing techniques. This repository serves as an essential learning platform for cybersecurity professionals seeking to enhance their skills in vulnerability detection and analysis.

awesome-nodejs-pentest

2026-08-03
The "Awesome Node.js for pentesters" repository provides a curated list of Node.js packages tailored for penetration testing, exploitation, reverse engineering, and cryptography. Its primary use case is to serve as a comprehensive toolkit for security professionals, featuring various modules for tasks such as OSINT, network scanning, brute-forcing, and post-exploitation techniques. Notable features include integration with the OWASP ZAP API, access to Shodan and Censys APIs, as well as utilities for geolocation and fingerprinting.

Priv2Admin

2026-08-03
Priv2Admin is a security analysis tool designed to interpret Windows OS privileges and their potential impacts on system security, specifically addressing threats to administrator access, integrity, confidentiality, and availability. It prioritizes using built-in commands, PowerShell scripts, and other methods to evaluate an environment's privilege landscape, allowing users to identify and mitigate risks associated with privilege escalation. The tool provides detailed descriptions of various Windows privileges, their implications, and potential exploitation methods via external tools.

diversevul

2026-08-03
DiverseVul is a specialized dataset designed for deep learning-based vulnerability detection in source code. It includes 7,512 vulnerable code snippets and provides comprehensive metadata, enabling researchers to evaluate and enhance vulnerability detection models effectively. Notable features include detailed commit and repository links, as well as resources for conducting label noise analysis, facilitating advanced research in the field of software security.

Exploit-Collector

2026-08-03
Exploit Collector is a repository that curates a selection of exploits, providing details for each exploit along with credit attribution. Its primary use case is to serve as a resource for researchers and cybersecurity professionals interested in various exploits for educational and testing purposes. Notably, it includes both well-known exploits and some original contributions from the repository's author.

beef

2026-08-03
BeEF, or The Browser Exploitation Framework, is a penetration testing tool specifically designed to assess web browser security by employing client-side attack vectors. Its primary use case involves hooking web browsers to serve as launch points for directed command modules and additional attacks, thereby exploiting the inherent vulnerabilities within the browser environment. Notable features include its focus on circumventing traditional network defenses and targeting web-borne threats in a systematic manner.

pown

2026-08-03
Pown.js is a modular security testing and exploitation toolkit developed in Node.js, emphasizing flexibility through standalone NPM modules rather than a monolithic framework. It provides users with a command-line interface to manage modules, execute scripts, and automate tasks, allowing for the easy integration of custom tools and features. Notably, Pown.js facilitates the installation and management of additional modules from the NPM registry, enhancing its functionality and adaptability in various security testing scenarios.

django-DefectDojo

2026-08-03
DefectDojo is a comprehensive DevSecOps and application security posture management tool that facilitates vulnerability management by orchestrating security testing, tracking vulnerabilities, and generating detailed reports. Its notable features include integration with various scanning tools, deduplication of findings, and provisions for both a Community Edition and a Pro Edition, allowing for flexible deployment options via Docker.

PPPwn-Luckfox

2026-08-03
PPPwn-Luckfox is a low-cost exploit tool designed for various PS4 firmware versions (up to 11.00) using compatible Luckfox Pico models. It features a web server interface for changing settings, executing exploits, and injecting payloads, while providing configuration options through a JSON file. Users are cautioned about known shutdown issues and can contribute to the project through pull requests for enhancements and bug fixes.

cod-exploits

2026-08-03
The COD Exploits repository catalogs various vulnerabilities in Call of Duty, providing proof-of-concept demonstrations for each identified exploit. It includes notable vulnerabilities such as Steam-Auth and Huffman, along with their associated CVE-IDs. The tool is intended strictly for academic research, emphasizing responsible usage to prevent misuse.

CVE-2020-0683

2026-08-03
CVE-2020-0683 is a proof-of-concept (PoC) exploit targeting a Windows Installer elevation of privilege vulnerability. The tool includes source code for Visual Studio C++ 2017 and provides a compiled executable to demonstrate the exploit. Key features include detailed documentation in a PDF for step-by-step reproduction of the exploit.

firebaseExploiter

2026-08-03
FirebaseExploiter is a CLI-based tool designed for the mass scanning and exploitation of insecure Firebase databases. Its key features include the ability to scan multiple hosts for vulnerabilities, upload custom JSON data via a specified URI path during exploitation, and generate results that verify the exploitation of identified vulnerabilities.

iblessing

2026-08-03
iblessing is an iOS security exploiting toolkit designed for application information gathering, static analysis, and dynamic analysis. Notable features include a cross-platform architecture, Mach-O parsing, a comprehensive scanner for dynamic analysis of arm64 assembly code, and tools for simulating Mach-O execution to uncover key information or attack surfaces. The toolkit integrates multiple engines such as Unicorn, Capstone, and Keystone to enhance its capabilities in handling Objective-C and Swift classes.

iris

2026-08-03
IRIS is a neurosymbolic framework that integrates large language models (LLMs) with static analysis for the detection of security vulnerabilities in software projects. It analyzes codebases by taking a project and a specified Common Weakness Enumeration (CWE) type as input, and produces potential vulnerability reports along with data on their related CVEs. Notable features include the CWE-Bench-Java dataset, which contains 213 CVEs across 49 CWEs, manual extraction of source and sink specifications, and Docker integration for streamlined deployment.

SafeLine

2026-08-03
SafeLine is a self-hosted Web Application Firewall (WAF) designed to secure web applications by filtering and monitoring HTTP traffic, thereby protecting against a wide range of attacks, including SQL injection, XSS, and code injections. Key features include proactive defense against bot abuse, HTML and JavaScript code encryption, IP-based rate limiting, and customizable web access control lists, ensuring comprehensive protection for web services.

Vulnerability-Disclosures

2026-08-03
The Mandiant Vulnerability Disclosures repository catalogs vulnerabilities identified by Mandiant, including those discovered through internal research and Red Team engagements. It serves as a resource for tracking these vulnerabilities, providing potential proof of concepts, and is governed by specific licensing for both CVE-related information and source code. Notably, Mandiant operates as a CVE Numbering Authority, focusing on both its own code and relevant third-party vulnerabilities.

exrs

2026-08-03
exrs is a collection of exercises focused on reverse engineering and exploitation, specifically using 64-bit ELF binaries. The tool primarily serves as a training platform, enabling users to solve challenges by reverse engineering binaries to achieve objectives such as executing code or spawning shells. Notably, the exercises enforce a clear separation from traditional cracking methods, emphasizing interaction via standard input/output as if engaging with a remote service while maintaining compatibility with NX and ASLR protections.

nysm

2026-08-03
nysm is an eBPF stealth container designed to facilitate the post-exploitation of systems by making offensive tools undetectable to system administration utilities. It achieves this by obscuring new eBPF programs, audit logs, PIDs, and sockets from tools like bpftool, ps, and auditd. Key features include the ability to run commands in a hidden context, with options for background execution and self-destruction after use.

OverRide

2026-08-03
OverRide is a cybersecurity training tool designed to explore disassembly, binary exploitation, and reverse-engineering through a series of ten progressively challenging levels. Each level includes a reverse-engineered binary, assembly disassembly notes, and a password required to advance, encouraging users to identify and exploit vulnerabilities using tools like GDB. Notable features include hands-on challenges such as Ret2Libc attacks, format string vulnerabilities, and stack overflows, making it an effective resource for enhancing penetration testing skills.

PaxOS-8

2026-08-03
PaxOS 8 is a lightweight operating system specifically designed for PaxoPhones, featuring a multi-platform emulator that allows users to run the system on various operating systems including Linux, Windows, and macOS. Its notable features include easy build instructions across multiple platforms, comprehensive setup guidance, and included dependencies for streamlined compilation. This tool is ideal for developers looking to emulate and experiment with the PaxOS environment on their local machines.

exploitgym

2026-08-03
ExploitGym is a comprehensive benchmarking platform designed to evaluate the capabilities of AI agents in exploiting a variety of real-world vulnerabilities present in userspace programs, Google's V8 engine, and the Linux kernel. It features a large-scale set of 869 instances and includes detailed setup and evaluation processes, as well as the ability to disable system defenses for more effective testing. This tool serves as an essential resource for researchers aiming to understand AI's effectiveness in security exploit development.

Meshtastic-Exploiteers-Hacker-Pager

2026-08-03
The Hacker Pager is a modified version of the Meshtastic project, designed specifically for the Hacker Pager hardware, enabling wireless messaging and LoRa communication functionality. Its primary use case includes long-range, low-power messaging and telemetry over a decentralized mesh network, suitable for outdoor and emergency scenarios. Notable features include support for multiple hardware platforms and the ability to share text messages and locations without relying on internet or cellular infrastructure.

semgrep-rules

2026-08-03
The semgrep-rules repository provides a curated set of Semgrep rules specifically designed for vulnerability research in C and C++ codebases. Its primary use case involves static analysis to detect various security vulnerabilities, such as the use of insecure API functions and potential buffer overflows, thereby enhancing code security. Notable features include easy integration with Semgrep for scanning, support for generating outputs in SARIF format for further analysis, and a focus on high-priority vulnerability detection.

local-root-exploits

2026-08-03 C ★ 38
The "local-root-exploits" repository provides a curated collection of local privilege escalation exploits for Linux systems. Its primary use case is to facilitate security research and testing by demonstrating vulnerabilities that can be exploited to gain root access on local Linux environments. Notable features include organized categories of exploits for different Linux kernel versions and configurations.

privesc-CVE-2010-0426

2026-08-03 Shell ★ 11
This tool demonstrates a local privilege escalation exploit for Sudo versions 1.6.x up to 1.6.9p21 and 1.7.x up to 1.7.2p4, specifically addressing the vulnerability in the sudoedit command that allows arbitrary command execution as the root user. The primary use case is to set up a vulnerable Docker environment for educational testing, enabling attackers to exploit the flaw and gain root access. Notable features include the provision of a simple Docker setup and a scripted exploit for demonstration purposes.

privesc-CVE-2015-5602

2026-08-03 Shell ★ 15
This repository provides a local privilege escalation exploit for the Sudo vulnerability identified as CVE-2015-5602. It utilizes a flaw in the sudoedit functionality that allows a malicious user to exploit symlink attacks, enabling them to gain root access by modifying sensitive files. The tool includes a Docker setup for mimicking a vulnerable environment, along with an exploit script for demonstration purposes.

rewolf-pcausa-exploit

2026-08-03 C++ ★ 39
The rewolf-pcausa-exploit is a Windows local privilege escalation tool targeting the PCAUSA Rawether vulnerability. Its primary use case is to enable users to gain elevated permissions within a Windows environment, exploiting specific weaknesses in the PCAUSA driver. Notable features include its focus on local escalation and detailed documentation linked for further information.

amd_eop_poc

2026-08-03 Batchfile ★ 27
The `amd_eop_poc` tool serves as a proof of concept for exploiting a privilege escalation vulnerability (CVE-2020-8950) within the AMD User Experience Program Launcher associated with Radeon Software. Its primary use case is to demonstrate the FileWrite escalation of privileges, enabling unauthorized access to system resources. Notable features include detailed documentation and references to external resources for further context on the vulnerability.

anyelevate

2026-08-03 C++ ★ 22
Anyelevate is a Windows x64 privilege escalation tool that leverages the anycall technique to elevate the privileges of a specified process by copying the system process token into the target process's context. The tool operates by manipulating physical memory to enable the execution of tasks with NT AUTHORITY\SYSTEM privileges, making it particularly useful for security researchers and penetration testers looking to demonstrate or exploit privilege escalation vulnerabilities. Notable features include its simplicity of use and the ability to specify a process ID for targeted elevation.

awesome-infosec

2026-08-03 ★ 108
Awesome Infosec is a curated collection of Information Security resources and tools designed to aid individuals in their studies and practices of cybersecurity. It encompasses various topics, including recon, web security, penetration testing, and exploit development, while also providing links to educational courses and labs. The continuously updated repository serves as a valuable resource for both beginners and experts in the field.

AymanSecNotes

2026-08-03 ★ 11
AymanSecNotes is a personal compilation of cybersecurity notes in PDF format, primarily serving as a self-study resource for various security domains including mobile, web, and networks. Notable features include plans for future enhancements such as a comprehensive cheatsheet, the transition from PDF to Markdown format, and the inclusion of methodologies and bug hunting tips, aimed at facilitating practical learning and knowledge sharing within the cybersecurity community.

byeintegrity-lite

2026-08-03 C++ ★ 15
ByeIntegrity Lite is a tool designed to exploit a shell protocol handler hijack to bypass Windows User Account Control (UAC) and achieve elevated privileges for executing programs at a higher integrity level. It specifically alters the handler for the `ms-settings` protocol to redirect it to `cmd.exe`, allowing execution of `fodhelper.exe`, which inherits elevated tokens. Notable features include its simplicity and compatibility with all versions of Windows 10; however, there are no precompiled binaries available to prevent misuse.

byeintegrity-uac

2026-08-03 C++ ★ 211
ByeIntegrity is a tool designed to bypass Windows User Account Control (UAC) in order to gain elevated Administrator privileges for executing programs at a high integrity level. Its notable features include the ability to hijack DLLs in the Native Image Cache (NIC) without relying on existing native images and the use of an auxiliary file generator (AUXGen) to facilitate the loading of shellcode without direct dependency on system resources. The latest update enhances its speed, reliability, and usability by streamlining the hijacking process and minimizing the initial configuration overhead.

byeintegrity2-uac

2026-08-03 C++ ★ 57
ByeIntegrity 2.0 is a tool designed for bypassing Windows User Account Control (UAC) to gain elevated administrator privileges by leveraging a specific elevated COM interface associated with the Internet Explorer Add-on Installer. It features a methodical approach utilizing the `COMAutoApprovalList` registry key to execute arbitrary programs via an elevated instance of `cmd.exe`, thereby circumventing UAC restrictions. This iteration builds on previous designs, sharing core functionality with the UACMe project while incorporating unique lolbin usage for execution.

byeintegrity3-uac

2026-08-03 C++ ★ 31
ByeIntegrity 3.0 is a tool designed to bypass Windows User Account Control (UAC) to achieve elevated privileges for executing arbitrary programs. It employs an elevated COM interface alongside a shell protocol handler hijack, allowing seamless execution of commands like `cmd.exe` with admin rights. Notable features include the use of the `IWscAdmin` interface and the ability to manipulate URL protocol associations to facilitate the UAC bypass in various Windows versions.

byeintegrity4-uac

2026-08-03 C++ ★ 18
ByeIntegrity 4.0 is a cybersecurity tool designed to exploit User Account Control (UAC) vulnerabilities in Windows for bypassing security mechanisms and achieving elevated privileges. It modifies the `windir` environment variable and utilizes a custom URL protocol to launch `cmd.exe` as an administrator, successfully circumventing UAC protections. Key features include the leveraging of COM interface methods and environment variable manipulation, making it an effective tool for demonstrating UAC bypass techniques in Windows environments.

byeintegrity5-uac

2026-08-03 C++ ★ 36
ByeIntegrity V is an advanced tool designed to bypass User Account Control (UAC) across all notification levels, granting elevated Administrator privileges to execute any program. Utilizing a combination of DLL hijacking, environment variable manipulation, and the Task Scheduler, it effectively circumvents UAC prompts by launching tasks with the "Run with highest privileges" setting enabled. This tool is particularly notable for its ability to operate without requiring administrator access initially or modifying critical system components, making it a stealthy approach for privilege escalation in Windows environments.

byeintegrity8-uac

2026-08-03 C ★ 288
ByeIntegrity 8.0 is a sophisticated Windows privilege escalation tool that exploits design and security flaws in the operating system, operational even with User Account Control (UAC) set to the highest level. It utilizes the Task Scheduler to trigger the WDI ResolutionHost task, manipulating environment variables to load a custom payload that executes with elevated privileges. Key features include controlled event triggering via ETW and direct communication with the Program Compatibility Assistant, enabling a bypass of potential policy restrictions.

CVE-2020-1034

2026-08-03 C++ ★ 125
This repository provides a proof-of-concept (PoC) for exploiting the CVE-2020-1034 vulnerability, which allows for privilege escalation on unpatched Windows 10 systems. It is primarily used for security research and understanding the exploitability of this specific vulnerability, with notable features including documentation links for deeper insight into exploitation techniques and the context of the vulnerability's discovery and remediation.

CVE-2020-28243

2026-08-03 Shell ★ 20
The CVE-2020-28243 tool exploits a command injection vulnerability within SaltStack's Salt, allowing for privilege escalation on affected minions when the master executes the `restartcheck` command. Notable features include a straightforward exploit script (`exploit.sh`) for executing arbitrary commands, and the capability to utilize pre-compiled static binaries if gcc is unavailable on the target system. This tool targets SaltStack versions from 2016.3.0rc2 to 3002.2, requiring specific access permissions to function effectively.

CVE-2021-27965

2026-08-03 C ★ 13
CVE-2021-27965 is a proof-of-concept (PoC) exploit targeting a local privilege escalation vulnerability in the MICSYS Windows driver, MsIo64.sys. This tool leverages stack-based buffer overflow in the driver's IOCTL dispatch routine, allowing arbitrary physical memory mapping, port access, and potential system crashes. Notable features include the ability to execute IOCTL requests that bypass Windows security mechanisms, facilitating unauthorized access to system-level operations.

cve-2022-21882-poc

2026-08-03 C++ ★ 49
The cve-2022-21882-poc repository provides a proof of concept (PoC) for the local privilege escalation vulnerability identified as CVE-2022-21882. Its primary use case is to demonstrate the exploitability of this vulnerability in a controlled environment, facilitating security research and testing. Notable features may include detailed instructions for replication of the exploit and potential impacts of the vulnerability.

cybersecurity-pam

2026-08-03 PHP ★ 28
The Privileged Access Management (PAM) repository is a curated collection of resources that encompasses software best practices, techniques, libraries, frameworks, and educational materials related to securing and managing privileged access to critical assets in cybersecurity. Notable features include categorized content for various platforms such as Linux and Windows, as well as practical guides on privilege escalation methods and access control strategies. This community-driven initiative aims to facilitate knowledge sharing and enhance best practices in the field of PAM.

delete2SYSTEM

2026-08-03 C ★ 126
Delete2SYSTEM is a tool designed to exploit arbitrary file and directory deletion vulnerabilities to achieve NT AUTHORITY\SYSTEM privileges on Windows systems. Utilizing methods derived from known techniques, it specifically targets deletion of critical folders related to Windows Error Reporting and Windows Media Player, leveraging vulnerabilities such as CVE-2020-1170 and CVE-2020-1571. Notable features include integration with the NtApiDotNet library and the ability to weaponize Windows services for privilege escalation.

dirty_sock

2026-08-03 Python ★ 681
Dirty Sock is a privilege escalation tool for Linux systems that exploits a vulnerability in the snapd API, allowing unauthorized user creation and root access. It provides two versions: the first requires an internet connection and SSH service to create a local user using Ubuntu SSO, while the second operates without these requirements, leveraging the installation of a "devmode" snap to execute arbitrary commands and bypass access controls. Notably, the tool can be used on both Ubuntu and other distributions with the snapd package installed, making it versatile in various environments.

docker-privesc

2026-08-03 Shell ★ 33
The Docker Privesc script is designed to exploit misconfigurations in Docker environments for privilege escalation purposes. Its primary use case is to gain elevated permissions by leveraging Docker's default configurations, especially in scenarios where a user has access to run Docker on a target system. Notable features include simple usage instructions, requirements for operational conditions, and illustrations of potential mitigation strategies to prevent such attacks.

exploit

2026-08-03 Python ★ 185
The "am0nsec/exploit" repository serves as a collection of exploit scripts and related resources, although the majority of the artifacts are not original contributions from the maintainer. Its primary use case is to provide a centralized resource for penetration testers and security researchers seeking various exploits. Notably, it includes links to the maintainer's social media and personal website for further engagement.

libinject

2026-08-03 C++ ★ 12
libinject is a static library designed for DLL injection into Windows x64 processes, featuring handle elevation capabilities to bypass certain protections. It enables users to obtain a process handle with higher privileges using elevated access, facilitating interaction with protected processes for debugging or analysis purposes. Notable features include process handle acquisition, memory allocation in target processes, and remote thread creation to execute the injected DLL.

Linux-Kernel-Exploitation

2026-08-03 C ★ 217
Linux Kernel Exploitation is a laboratory tool designed for practicing various exploitation techniques within the Linux kernel environment. It covers advanced exploitation methods such as ret2user, memory manipulation strategies, and kernel information leaks, while providing comprehensive guidelines for compiling and preparing kernel modules and necessary utilities. Notable features include detailed instructions for building kernel sources, configuring BusyBox, and setting up an initial filesystem for testing.

Love.exe

2026-08-03 ★ 15
Love.exe is a development tool designed for exploitation and penetration testing in Windows environments, specifically optimized for Windows 10 and 11 with default UAC settings. It offers functionalities to assist security professionals in identifying vulnerabilities within applications, and it encourages community engagement for enhancements and support. The repository is currently under active development, indicating ongoing updates and feature additions.

MIDA-Multitool

2026-08-03 Shell ★ 167
MIDA - Multitool is a comprehensive Bash script designed for system enumeration, vulnerability identification, and privilege escalation after system compromise. It integrates features from previous scripts like SysEnum and RootHelper, allowing users to gather detailed system information, check for useful utilities, download external tools, and search for potential cleartext credentials. Notably, it provides a robust framework for facilitating various tasks crucial for post-exploitation activities.

mobile-heavy-artillery

2026-08-03 Shell ★ 18
Mobile Heavy Artillery is a comprehensive toolkit designed for red teaming operations, facilitating reconnaissance, exploitation, and privilege escalation tasks. It includes a curated collection of open-source tools for network enumeration, web vulnerability assessment, secrets discovery, and OSINT activities, all easy to install and manage through a makefile. Notable features include a wide range of utilities for various cybersecurity processes, making it a versatile choice for penetration testers and security researchers.

PE-Linux

2026-08-03 Shell ★ 188
PE-Linux is a Linux privilege escalation tool designed to gather extensive system and environment information to identify potential vulnerabilities and misconfigurations. Its primary use case is to assist security professionals in auditing Linux systems for privilege escalation risks through features such as user enumeration, vulnerability checks, log analysis, and the collection of sensitive information like passwords and SSH keys. Notable features include kernel vulnerability checks, cron job enumeration, and detailed system information gathering to facilitate privileged access exploitation assessments.

polkadots

2026-08-03 Shell ★ 82
The polkadots tool is a local privilege escalation exploit targeting CVE-2021-3560, allowing the creation of a new privileged user to gain root access on affected Linux distributions such as RHEL 8, Fedora 21, Debian testing, and Ubuntu 20.04. It includes functionality to generate hashed passwords using OpenSSL, enabling users to customize account credentials during the exploit execution. Notable features include customizable account names and password hashes, along with default settings for easy deployment.

privilege_escalation

2026-08-03 ★ 16
The Privilege Escalation tool in this repository is designed for conducting structured labs on AWS IAM privilege escalation techniques. Its primary use case is to educate users on identifying vulnerabilities and exploiting permission misconfigurations within AWS environments, utilizing tools like Pacu and AWS-IAM-Permissions-Scanner. Notable features include step-by-step guides for creating low-privilege IAM users, testing permissions, and demonstrating privilege escalation methods through policy manipulation.

pwk-oscp

2026-08-03 ★ 36
The pwk-oscp repository serves as a comprehensive resource for aspiring penetration testers preparing for the OSCP certification, offering a curated collection of scripts, guides, and links to vulnerable machines and challenges. Notable features include categorized sections for enumeration, privilege escalation techniques, and certification resources, alongside curated lists of relevant literature and practical exercises from platforms like HackTheBox and VulnHub. This tool is particularly useful for individuals seeking structured guidance and useful materials throughout their penetration testing journey.

RootHelper

2026-08-03 Shell ★ 505
RootHelper is a Linux privilege escalation tool that facilitates the exploitation process on compromised systems through an array of eleven scripts designed for enumeration, exploit suggestion, and deployment. Notable features include support for command-line flags for quicker access and execution, as well as a collection of additional tools for enumeration and exploit deployment, such as Auto-Root-Exploit and Linux Smart Enumeration. This comprehensive suite aids penetration testers in efficiently performing privilege escalation tasks.

Rust-Privesc

2026-08-03 Rust ★ 20
Rust-Privesc is a collection of proof-of-concept (POC) tools designed to demonstrate User Account Control (UAC) bypass techniques implemented in Rust. It includes methods such as exploiting fake trusted directories and manipulating environment variables to execute command shell processes. Notable features include straightforward implementations of UAC bypass methods and the execution of `cmd.exe` as a default behavior.

suider

2026-08-03 Shell ★ 26
SUIDer is a Linux script designed to streamline the privilege escalation process by identifying exploitable binaries with the SUID bit set. It leverages GTFObins to provide relevant exploitation methods and generates links for reference. Notably, it emphasizes caution, as some SUID binaries may require custom methods not covered by the provided resources.

Suidsploit

2026-08-03 Shell ★ 12
Suidsploit is a penetration testing tool designed to exploit 137 files with the Suid bit set, enabling attackers to potentially gain elevated privileges on a target system. Its primary use case includes obtaining a root shell, accessing sensitive files such as /etc/shadow, and establishing reverse shells. Notable features include the ability to download the tool via a simple HTTP server and its focus on user-friendly execution on both the attacker's and victim's machines.

Active-Directory-Exploitation

2026-08-03 ★ 63
Active-Directory-Exploitation is a comprehensive PowerShell-based toolkit designed for conducting penetration testing and security assessments on Active Directory environments. Its primary use case is to enumerate domains, escalate privileges, enable lateral movement, and achieve persistence through various methodologies, including Kerberos ticket manipulation and exploitation of SQL Server trusts. Notable features include extensive modules for local and domain privilege escalation, detailed methods for lateral movement and persistence, and capabilities for cross-forest attacks.

chainreactor

2026-08-03 PDDL ★ 63
ChainReactor is an AI-driven tool designed to automate the discovery of privilege escalation chains on Unix systems. By analyzing system information and known vulnerabilities, it models the escalation process using Planning Domain Definition Language (PDDL) to generate potential exploitation chains. Notable features include its ability to rediscover existing exploits, identify new chains, and its successful evaluation on various platforms, including Amazon EC2 and Digital Ocean.

confluence-hack

2026-08-03 Java ★ 52
Confluence Hack is a tool designed to exploit CVE-2023-22515, enabling the creation of a new administrative user and compromising audit logs in Confluence servers. It features a web-based command shell plugin that allows for executing commands remotely, verified to work on Confluence Server 8.5.1. The repository is intended for educational purposes only and emphasizes ethical use.

CVE-2022-27502

2026-08-03 C++ ★ 27
CVE-2022-27502 is a DLL hijacking exploit targeting RealVNC Server versions up to 6.9.0, allowing for arbitrary command execution by leveraging a vulnerable installation process. The tool enables users to execute any command through a crafted DLL that captures the output in a specified output file. Notable features include the ability to modify the executed command by editing specific code lines and recompiling the DLL.

CVE-2023-27326

2026-08-03 C ★ 37
This repository provides an exploit for the Parallels Desktop vulnerability CVE-2023-27326, which allows local attackers to escalate privileges on affected installations. The exploit targets a flaw in the Toolgate component, enabling the execution of arbitrary code due to inadequate validation of user-supplied paths in file operations. It is notable for its specific applicability to version 18.0.0 of Parallels Desktop and the details of its exploitation, which are documented alongside a proof of concept.

CVE-2024-28085

2026-08-03 C ★ 56
Wall-Escape (CVE-2024-28085) is an exploit tool designed to leverage a vulnerability in the util-linux wall command that allows attackers to inject escape sequences into command line arguments, potentially leaking sensitive information such as user passwords. The tool sets up an environment to execute commands while monitoring for password input, effectively capturing credentials during user interactions—particularly in contexts like SSH login or sudo commands. Notable features include the ability to manipulate command outputs and create a fake prompt that misleads users into revealing their passwords.

CVE-2024-33352

2026-08-03 Kotlin ★ 21
CVE-2024-33352 identifies a critical vulnerability in BlueStacks for Windows, affecting versions prior to 10.40.1000.502. This flaw allows unprivileged users to access and modify configuration files stored in a world-writeable directory, enabling them to backdoor the virtual machine and gain code execution as a privileged user by manipulating shared folder settings. The README provides a detailed exploitation method and emphasizes the necessity of updating to a patched version to mitigate this security risk.

cybersec-notes

2026-08-03 ★ 14
Cybersec Notes is a comprehensive, expandable checklist aimed at individuals seeking to enhance their knowledge in various cybersecurity domains, including application, mobile, API, and network security. The tool features a structured outline of key topics and vulnerabilities, supplemented with resource links, while encouraging community contributions for continuous improvement and accuracy. Notable aspects include coverage of OWASP Top 10 vulnerabilities across multiple platforms and concepts related to DevSecOps.

DeadPotato

2026-08-03 C# ★ 480
DeadPotato is a privilege escalation tool designed to exploit the DCOM RPCSS vulnerability to gain NT AUTHORITY\SYSTEM level access on Windows systems. Its primary use case includes executing commands, creating new administrator accounts, establishing reverse shells, and dumping sensitive credentials using various modules like `-cmd`, `-newadmin`, and `-mimi`. Notable features include the ability to disable Windows Defender and collect domain data for BloodHound, making it versatile for penetration testing and security assessments.

EPScalate

2026-08-03 Python ★ 19
EPScalate is a proof-of-concept exploit that targets an elevation of privilege vulnerability (CVE-2023-31497) in QuickHeal's Seqrite Enterprise Endpoint Security solution. The tool leverages weak permissions on directory and file installations, enabling low-privilege users to escalate privileges to root by overwriting executable files or manipulating startup scripts. Notable features include the ability to perform privilege escalation via either daemon binary overwrites or injecting reverse shell commands into system initialization scripts.

HackTheBox

2026-08-03 CSS ★ 12
The HackTheBox repository contains write-ups detailing the author’s solutions to various HackTheBox machines, primarily aimed at preparing for the Offensive Security Certified Professional (OSCP) certification. Notable features include comprehensive problem-solving approaches and methodologies applicable to penetration testing scenarios.

Jr-Pentester-TryHackMe

2026-08-03 ★ 11
The Jr Penetration Tester repository provides solutions and an answer key for the Penetration Tester learning path on TryHackMe, aimed at equipping users with essential skills for a career in penetration testing. It covers various critical topics, including web hacking, Burp Suite, network security, vulnerability research, and exploitation techniques using Metasploit. Notable features include comprehensive sections that guide learners through foundational concepts and practical applications in cybersecurity.

Linux-Kernel-VR-Exploitation

2026-08-03 ★ 67
Linux-Kernel-VR-Exploitation is a toolset designed for vulnerability research and exploitation specifically targeting the Linux and Android kernel. It provides a comprehensive environment setup guide, along with resources for exploitation tutorials, practice playgrounds, and detailed academic research papers, facilitating both practical experimentation and theoretical understanding of kernel vulnerabilities. Notable features include curated links to extensive educational materials, CTF challenges for skill development, and insights into kernel tracing and various exploitation techniques.

Linux-Privilege-Escalation

2026-08-03 C ★ 61
The Linux-Privilege-Escalation tool provides a comprehensive set of techniques for escalating privileges on Linux systems. Its primary use case includes identifying vulnerabilities related to kernel exploits, file permissions, and sudo configurations, while notable features include detailed methods for exploiting kernel vulnerabilities, leveraging GTFOBINS for privilege escalation, and examining scheduled tasks and SUID binaries for potential exploitation paths.

MSAPer

2026-08-03 Shell ★ 16
MSAPer is an automated mass exploitation tool designed for identifying and exploiting the CVE-2023-3076 vulnerability in MStore API versions below 3.9.9, which enables unauthenticated privilege escalation through mass addition of admin accounts and PHP file uploads. The tool utilizes GNU Parallel for efficient execution and requires a list of target URLs as input. Notable features include the ability to run on both Linux and Windows platforms, along with installation instructions for necessary dependencies.

PayloadsAllTheThings

2026-08-03 Python ★ 11
Payloads All The Things is a comprehensive repository offering a curated list of payloads and techniques specifically designed for web application security testing. It includes detailed documentation on various vulnerabilities and how to exploit them, alongside resources for tools like Burp Intruder. Notable features include structured chapters with vulnerability descriptions, applicable payloads, and a collection of methodologies for diverse security scenarios, making it an essential toolkit for penetration testers and security professionals.

road-to-hacking

2026-08-03 ★ 75
Road To Hacking is a comprehensive guide designed for enthusiasts of Ethical Hacking, providing an extensive overview of widely used tools for penetration testing and auditing. Notable features include detailed instructions on tools such as Nmap for vulnerability detection, Metasploit for exploitation, and Aircrack-ng for cracking WPA/WPA2-PSK, among many others. This resource emphasizes practical usage, ensuring users have foundational knowledge in Linux and terminal commands to effectively utilize the tools presented.

system3

2026-08-03 ★ 194
#system3 is a tool designed to facilitate system shell access and the installation of system applications on Samsung devices, bypassing restrictions imposed by the One UI 5.1 SMT patch. It leverages the Factory Test Launcher to gain system UID privileges, enabling users to downgrade and install applications without encountering standard installation errors. Notable features include support for a wide range of Samsung devices and the ability to execute installations that are typically restricted, thereby restoring functionality for various system-level applications.

AKQ-PipeFS-ZeroDay-Exploit

2026-08-03 Shell ★ 13
AKQ_0D_PE is a playful tool designed to simulate a Zero-day local privilege escalation exploit targeting a vulnerability in the Linux PipeFS subsystem. It demonstrates memory corruption techniques, ROP injection, and namespace traversal, all while providing an interactive root shell, but it is ultimately a prank and does not exploit a real vulnerability. The tool serves as an educational illustration of exploitation methodologies and is intended for demonstration purposes only.

AIO-Pentesting

2026-08-03 PHP ★ 49
AIO-Pentesting is a comprehensive resource for penetration testers, encapsulating various methodologies, tools, and commands necessary for conducting thorough security assessments. It categorizes content into phases, covering pre-intrusion and intrusion techniques for both Linux and Windows environments, along with additional materials such as notes for certifications like OSCP and OSWE. Notable features include organized documentation on common pentesting stages, forensics, and various exploitation techniques, as well as links to essential vulnerability databases and binary libraries.

Archive

2026-08-03 Shell ★ 80
The Archive is a continually evolving repository that curates hacking methodologies, cheatsheets, and conceptual breakdowns, specifically designed to be a human-curated alternative to the increasing reliance on LLMs. Its primary use case is to provide easily accessible, spell-checked information along with referenced content derived solely from clear-net sources. Notable features include the inclusion of alternative resources with descriptions, page differentiation for talk notes, and plans for future enhancements such as a public REST API for querying the data.

awesome-windows-red-team

2026-08-03 ★ 607
The Awesome Windows Red Team repository is a comprehensive collection of resources tailored for Red Team professionals engaging in Windows environments. It encompasses a wide variety of materials including tools, books, courses, and techniques focused on topics such as Active Directory exploitation, lateral movement, privilege escalation, and defense evasion strategies. Notable features include structured categories for efficient navigation, making it suitable for users ranging from beginners to advanced practitioners.

chronomaly-webos

2026-08-03 C ★ 12
Chronomaly is a kernel exploit targeting CVE-2025-38352, facilitating persistent root access on LG webOS Smart TVs running kernel version 5.4.268 on ARM64 architectures. It features an automated exploit chain that leverages novel techniques, including a redesigned write primitive and non-destructive pipe reads, ensuring reliability on physical hardware through advanced race condition manipulations. The exploit has been validated across multiple TV models and firmware versions, and was disclosed responsibly to LG's Security Researcher Program.

copy-fail-CVE-2026-31431-IOC

2026-08-03 Python ★ 31
copyfail-detect is a detection toolkit designed to identify exploitation attempts of CVE-2026-31431, a local privilege escalation vulnerability in the Linux kernel that alters page-cache data without modifying the actual disk file. It features multiple detection layers, including real-time eBPF monitoring of suspicious activities, auditd rules for syscall tracking, and a page-cache comparison tool for post-exploitation analysis, enabling proactive defense and investigation against the vulnerability. The toolkit also provides mitigation scripts and documentation for responders to safely address incidents involving the Copy Fail exploit.

copyfail-rs

2026-08-03 Rust ★ 19
copyfail-rs is a cybersecurity tool that provides multi-vector proof-of-concept (PoC) exploitation and detection for CVE-2026-31431, specifically targeting vulnerabilities in PAM authentication systems. Its notable features include a unique PAM auth-bypass vector and a detection mechanism that identifies alterations in critical files that traditional file integrity monitoring solutions overlook, using a novel hashing approach that differentiates between actual disk state and memory cache mutations. This tool operates as a single static binary with no runtime dependencies, making it easily deployable across various Linux architectures.

copyfail-rs

2026-08-03 Rust ★ 14
copyfail-rs is a Rust implementation of the Copy Fail exploit (CVE-2026-31431), which demonstrates a local privilege escalation vulnerability on major Linux distributions by chaining the `AF_ALG` and `splice()` syscalls. This tool features a high-performance and memory-safe design, dynamic ELF payload construction, zero-copy exploitation for efficient interaction with the Linux kernel, and allows customization of commands to be executed with root privileges. It is intended strictly for educational and research purposes, focusing on understanding and mitigating similar vulnerabilities.

CVE-2024-32019-Netdata-ndsudo-PATH-Vulnerability-Privilege-Escalation

2026-08-03 Python ★ 14
This tool provides a Python-based exploit for the CVE-2024-32019 vulnerability in the Netdata Agent, specifically targeting the misconfigured `ndsudo` SUID binary that incorrectly handles the `PATH` environment variable. Its primary use case is for users with authorized access to demonstrate local privilege escalation (LPE) by executing a malicious binary with root privileges. Notable features include both manual and automated exploitation methods, aimed for educational purposes to assess potential risks in affected versions of the software.

CVE-2026-41089-Netlogon-RCE

2026-08-03 HTML ★ 29
CVE-2026-41089 is a critical cybersecurity tool designed to assess Windows Active Directory Domain Controllers for a severe unauthenticated remote code execution vulnerability caused by a stack-based buffer overflow in the Netlogon service. It allows users to execute crafted requests to identify susceptible systems without prior authentication, making it a crucial tool for detecting and mitigating potential exploits in enterprise environments. The tool features a Python-based script that facilitates various testing techniques, including baseline checks and aggressive payload testing, all while ensuring system stability.

Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201

2026-08-03 ★ 42
Glass Cage is a zero-click exploit chain targeting iOS 18.2.1, leveraging vulnerabilities in image processing and WebKit to achieve remote code execution, privilege escalation, and persistent control over compromised devices. The attack is initiated through a malicious PNG transmitted via iMessage, triggering an automatic parsing process that exploits multiple CVEs, ultimately allowing root access and the ability to manipulate device state without user interaction. Notable features include its stealthy operation, the capacity for device bricking, and comprehensive access to sensitive data through keychain exfiltration.

GoldenDMSA

2026-08-03 C# ★ 100
Golden dMSA is a cybersecurity tool that facilitates the exploitation of delegated Managed Service Accounts (dMSAs) through the "Golden DMSA" attack, allowing unauthorized password generation for dMSAs offline. Key features include the ability to extract KDS Root keys, enumerate dMSA accounts, guess ManagedPasswordIDs, and generate valid passwords, making it a potent tool for penetration testing and security assessments of systems with vulnerabilities in dMSA authentication. The tool is built for .NET Framework 4.7.2 and includes functionalities for password conversion, information gathering on dMSAs and KDS keys, as well as brute force password attacks.

Offensive-Security-Forensics-Portfolio

2026-08-03 ★ 23
The Offensive Security Forensics Portfolio is an educational repository showcasing practical skills in cybersecurity, particularly in forensic analysis, penetration testing, and vulnerability assessments. It features detailed documentation of various security techniques, including the implementation of Multi-Factor Authentication for SSH and memory forensics using the Volatility Framework, as well as threat hunting exercises with Splunk. This portfolio serves as a comprehensive example of applied offensive security methodologies within controlled environments.

PayloadsAllTheThings

2026-08-03 Python ★ 80526
Payloads All The Things is a comprehensive repository that provides a collection of useful payloads and techniques for web application security testing. It offers structured documentation on various vulnerabilities, including exploitation methods and payload examples, and is designed to assist penetration testers in identifying and utilizing attack vectors effectively. Notable features include templates for adding new vulnerabilities, integration with Burp Suite Intruder, and a community-driven approach to enhancing its content.

Pentesting-Methodology

2026-08-03 ★ 25
The Pentesting-Methodology repository provides a structured approach to penetration testing, encompassing networking fundamentals, reconnaissance, and analysis techniques. It includes tools for identifying web servers and technologies, brute-forcing subdomains, and performing directory enumeration, making it useful for security professionals looking to streamline their penetration testing workflows. Notable features include detailed networking information and integration with various reconnaissance tools such as Sublist3r and Amass.

PrivHunterAI-detects-access-vulnerabilities

2026-08-03 Go ★ 14
PrivHunterAI is a tool designed to identify unauthorized access vulnerabilities through passive proxying, utilizing various mainstream AI engines such as Kimi, DeepSeek, and GPT. The tool's notable features include support for HTTPS traffic detection, customizable request headers, and the ability to view scan results via both terminal and a web interface. It requires configuration of AI models and API keys, allowing for flexible integration and usage in vulnerability assessments.

rfxn-defense

2026-08-03 Shell ★ 14
rfxn-defense is a Linux defense tool that provides a responsive mitigation layer against local privilege escalation (LPE) vulnerabilities by deploying kernel-level protections as soon as new vulnerabilities are identified. It supports automatic updates every four hours and requires no system reboots to apply mitigations, currently covering seven LPE classes across two families, including various techniques such as `LD_PRELOAD` and `modprobe` interventions. This tool is designed for ease of installation and ongoing security management within environments running Enterprise Linux distributions.

SecOps-CLI-Guides

2026-08-03 Jupyter Notebook ★ 35
SecOps-CLI Guides is a curated repository providing PDF command-line cheat sheets and how-to guides tailored for security professionals, facilitating offline reference for key cybersecurity tools and techniques. Notable topics include Metasploit, Nmap, SQLMap, and Active Directory attacks, making it a valuable resource for penetration testing and security operations. The repository invites contributions to expand its collection, enhancing its utility for the security community.

Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462

2026-08-03 ★ 11
The tool addresses two high-severity privilege escalation vulnerabilities, CVE-2025-32463 and CVE-2025-32462, affecting the `sudo` utility in various Linux distributions, with a critical CVSS score of 9.3 for CVE-2025-32463. It emphasizes the risks associated with misconfigured `sudoers` rules, particularly those involving wildcard commands, and provides mitigation strategies such as immediate updates to the fixed version and careful audit of `sudoers` policies. Key features include vulnerability detection guidance and examples of secure configuration practices to prevent potential exploitation.

SUID3NUM

2026-08-03 Python ★ 678
SUID3NUM is a standalone Python script designed to identify and exploit SUID binaries on Linux systems, distinguishing between default and custom binaries. Its primary use case is in penetration testing, particularly for scenarios like Capture The Flag (CTF) challenges, where it automates the exploitation of non-default SUID binaries while providing a clear overview of potentially exploitable binaries from the GTFO Bins repository. Notable features include the ability to auto-exploit custom binaries without impacting the system, as well as color-coded output for improved readability.

Windows-Kernel-Exploitation

2026-08-03 Python ★ 20
Windows Kernel - Exploration is a repository that provides a collection of notes, tools, and code snippets for exploiting Windows kernel drivers, aimed at both research and offensive security applications. It covers both legacy driver vulnerabilities and modern exploitation techniques, including Bring Your Own Vulnerable Driver (BYOVD) methods, while offering resources for kernel debugging, PDB analysis, and understanding core primitives related to kernel exploits. Notable features include detailed discussions on essential exploit techniques, kernel mitigations, and various tools for PDB parsing and debugging.

WindowsPrivilegeEscalationVulnerabilityDisplayBox

2026-08-03 C++ ★ 20
WindowsPrivilegeEscalationVulnerabilityDisplayBox is a Windows executable designed for detecting and demonstrating privilege escalation vulnerabilities for security research and educational purposes. Key features include the ability to modify PowerShell execution policies, take ownership of files, elevate privileges to SYSTEM or TrustedInstaller, and display current permissions of the program. This tool is strictly for demonstration and is best utilized in controlled environments.

Writeups

2026-08-03 HTML ★ 157
The repository contains a collection of writeups detailing solutions and methodologies used in various Capture The Flag (CTF) competitions, including Hack The Box (HTB). Its primary use case is to provide insights and explanations for participants looking to learn from past challenges. Notable features include links to social media for support and engagement, as well as visual representation of stargazers over time.

AIX-for-Penetration-Testers

2026-08-03 ★ 34
AIX-for-Penetration-Testers is a comprehensive enumeration guide designed for penetration testers and red team operators focusing on AIX systems. Its primary use case is to facilitate the security assessment of AIX environments through detailed methodologies and tools for effective system enumeration. The repository serves as a collaborative platform for knowledge sharing, allowing users to contribute to the evolving guide.

Apollo

2026-08-03 Python ★ 16
Apollo is a lightweight Remote Access Tool (RAT) developed in Python, designed for post-exploitation tasks, enabling remote code execution and system information retrieval across multiple platforms including Windows, Linux, FreeBSD, and macOS. Key features include AES-256 encrypted communication, support for handling multiple clients simultaneously, basic port scanning capabilities, and functionality to eradicate traces of its presence on the client system.

Auto-PostXploit

2026-08-03 Python ★ 16
Auto-PostXploit is a Windows post-exploitation tool designed for Red Team operations, facilitating immediate system reconnaissance following an exploit. Its primary use case involves executing post-exploitation actions on compromised systems using Meterpreter, enabling security professionals to gather critical system information efficiently. Notable features include the ability to upload and execute scripts on target systems and automate information gathering, aiding in the assessment of security postures.

Credit-Card-Bruteforcer

2026-08-03 PowerShell ★ 89
Credit-Card-Bruteforcer is a security testing tool designed to exploit vulnerabilities in credit card systems by attempting to generate valid Primary Account Numbers (PAN) using partial hashes and a set of random PINs. The tool's primary use case is to assess the strength of credit card security measures, while its intentionally incomplete functionality indicates it is intended for educational or testing purposes rather than practical exploitation.

DNS-Persist

2026-08-03 C++ ★ 207
DNS-Persist is a post-exploitation agent utilizing DNS for command and control, primarily designed for persistence in compromised systems. It features multiple persistence mechanisms including LogonScript, RunKey, and Excel Addin persistence, as well as the ability to execute commands via a pseudo-interactive shell and inject 32-bit shellcode. The tool is built with a Python server-side and a C++ agent, with plans for future enhancements including additional persistence options and encryption capabilities.

ed

2026-08-03 Go ★ 27
Ed is a tool designed for identifying and exploiting accessible UNIX Domain Sockets, particularly useful for locating exposed Docker.sock instances that may not be mounted in their default locations. Notable features include the ability to hunt for various types of UNIX domain sockets, perform autopwn actions, and return output in JSON format, making it suitable for both security testing in DevOps processes and integration into CI/CD pipelines.

Efes

2026-08-03 C# ★ 11
Efes is a proof-of-concept tool that utilizes built-in speech recognition to detect and record specific keywords from spoken audio, saving the snippets for potential exfiltration. Its primary use case is in post-exploitation scenarios where capturing high-value data passively is critical. Notably, it records only short audio segments to minimize file size while focusing on relevant information.

go-implant

2026-08-03 Go ★ 17
A flexible cross-platform post-exploitation agent written in Go with basic functionalities

LDAP-credentials-collector-backdoor-generator

2026-08-03 PHP ★ 58
The LDAP-credentials-collector-backdoor-generator is a malicious tool designed to create backdoor scripts that log LDAP user credentials during HTTP basic authentication. Its primary use case involves injecting the generated backdoor into a target web application to capture sensitive username and password information from users who access the site. Notable features include customizable backdoor filename generation and the ability to store captured credentials in a file for easy retrieval by the attacker.

LinPwn

2026-08-03 C++ ★ 37
LinPwn is an interactive post-exploitation tool designed for enumerating information and facilitating privilege escalation on compromised Linux machines. Key features include executing shells, reading files, running scripts like LinEnum.sh for enumeration, downloading files, and extracting system password hashes and saved Wi-Fi credentials. This tool is essential for security professionals conducting penetration tests to assess vulnerabilities post-exploitation.

MacOS-WPA-PSK

2026-08-03 Python ★ 30
MacOS-WPA-PSK is a proof-of-concept script that demonstrates how macOS stores the wireless network key in plaintext within NVRAM, rendering it accessible without root privileges. This tool highlights the risks associated with the management of sensitive credentials in macOS, serving as a reminder that users should be aware of the non-secure treatment of such information. The script operates using Python and has been tested across specific versions of macOS.

msf-auxiliarys

2026-08-03 Ruby ★ 191
The msf-auxiliarys repository contains a collection of custom Metasploit auxiliary post-modules designed for post-exploitation tasks. Its primary use case is to enhance the capabilities of Metasploit by providing additional functionalities that facilitate common post-exploitation procedures. Notable features include ease of installation and integration with the Metasploit database, making it a valuable resource for security professionals.

poet

2026-08-03 Python ★ 181
Poet is a post-exploitation tool that facilitates remote control and management of compromised machines through a client-server architecture. It allows attackers to perform various operations on the target, such as reconnaissance, file exfiltration, remote execution, and self-destruction of the client. Notable features include a control shell for executing commands, automatic reconnection capabilities, and the ability to remove traces post-exploitation.

Post-Exploitation

2026-08-03 ★ 10
The Post-Exploitation tool facilitates advanced post-exploitation tasks within PowerShell environments, primarily aimed at improving threat actor capabilities during penetration testing and red teaming exercises. Notable features include modular payload execution, session management, and comprehensive system enumeration capabilities to leverage discovered information effectively.

postshell

2026-08-03 C ★ 81
PostShell is a post-exploitation tool designed to facilitate advanced shell access through both bind and backconnect methods, enabling attackers to maintain an interactive TTY session with job control while remaining stealthy. Notably, it features cloaked process names to minimize detection, a compact stub size of less than 14kb for easy deployment on Unix-like systems, and built-in anti-debugging mechanisms to enhance resilience against analysis. The tool's design allows for operation in environments with limited dependencies, improving post-exploitation flexibility.

PPF

2026-08-03 C ★ 13
A modular pentesting framework implemented in C

presentations

2026-08-03 ★ 29
The "presentations" repository contains a collection of PDF files showcasing various presentations. Its primary use case is to serve as a portfolio of educational content, presumably focused on cybersecurity topics. Notable features include accessibility as PDFs, allowing for easy distribution and review of the material.

punk.py

2026-08-03 Python ★ 143
punk.py is a post-exploitation tool designed for network pivoting from compromised Unix systems, facilitating the collection of usernames, SSH keys, and known hosts to establish SSH connections across discovered combinations. It supports both Python 2 and 3, features options for custom execution, password bypass, command execution with sudo, and the capability to crack hashed known hosts, making it versatile for penetration testing and exploitation scenarios.

RSPET

2026-08-03 Python ★ 263
RSPET (Reverse Shell and Post Exploitation Tool) is a Python-based framework designed for executing remote commands and facilitating post-exploitation activities in penetration testing scenarios. Notable features include TLS encryption for secure server-client communication, built-in file and binary transfer capabilities, support for managing multiple hosts, and a modular code design that allows for extensive customization and plug-in management through a RESTful API.

soapy

2026-08-03 Python ★ 15
Soapy is a post-exploitation tool designed to facilitate stealthy operations within a compromised system by creating a container that hosts a root terminal shell while monitoring and scrubbing log files. Its primary use case involves executing commands to extract sensitive information such as hashes and IP addresses, map the network, and perform other tasks without detection. Notable features include the ability to specify custom log file paths, delete files from specified directories post-session, and operate with minimal user prompts.

zombieant

2026-08-03 C ★ 227
Zombie Ant Farm is a toolset designed for offensive security practitioners to enhance evasion techniques against Linux Endpoint Detection and Response (EDR) systems. Its primary use case involves facilitating the development of custom offensive strategies through features such as distributed payload warehousing, in-memory payload delivery, and ASLR weakening shims, making it suitable for advanced penetration testing and research. The kit includes various components such as preloaders, evasion primitives, and a warehouse service, providing a modular approach to offensive operations.

AdbNet

2026-08-03 Python ★ 435
AdbNet is an exploitation tool designed for identifying and compromising vulnerable Android devices across the globe. Key features include post-exploitation modules, device scanning functionalities, IP address management, and integration with APIs from Censys and Shodan for discovering susceptible devices. Users can connect to these devices through common ports, execute commands, and utilize various exploits to gain control over the target systems.

AtlasC2

2026-08-03 C# ★ 212
AtlasC2 is a C# command and control (C2) framework designed for Stage 1 operations, primarily used for establishing footholds within Windows environments and executing C# payloads through HTTP-based implants. Notable features include the ability to manage listeners, connect to multiple implants, execute system commands via PowerShell or CMD, and dynamically load C# assemblies into memory, making it a potent tool for post-exploitation scenarios despite current OPSEC limitations.

autoMetasploit

2026-08-03 ★ 20
autoMetasploit is a Ruby script designed to streamline the processes of scanning, exploiting, and conducting post-exploitation activities with Metasploit. It automates key tasks by requiring configuration of plugins and supports report generation by integrating with external templates and email functionalities. Notable features include customizable brute force scripts, LDAP user enumeration capabilities, and the ability to send PDF reports via email.

awesome-malware

2026-08-03 ★ 278
Awesome Malware is a curated repository of various malware, botnets, and post-exploitation tools designed for research and educational purposes. It offers extensive categories such as analysis tools, banking trojans, C2 frameworks, credential stuffing checkers, and more, enabling users to explore and understand malicious software dynamics. Noteworthy features include a focus on free software projects and the inclusion of both historical and contemporary malware resources for comprehensive analysis.

AWS-Attack

2026-08-03 Python ★ 46
AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.

Bella

2026-08-03 Python ★ 205
Bella is a potent post-exploitation and remote administration tool designed specifically for macOS, leveraging Python for high-level automation and ease of use. Its primary use case involves establishing SSL/TLS encrypted reverse shells to facilitate comprehensive data extraction, including passwords, system information, and iCloud services, while offering features like multi-user support, reverse VNC connections, and extensive logging capabilities. Notably, Bella can gain root access to expand its functionalities and maintain persistent control over the target system, all while operating undetectably.

Bifrost

2026-08-03 Python ★ 50
Bifrost is an open-source command and control (C2) tool implemented as a Discord bot, allowing users to manage and communicate with compromised clients through the Discord API. It supports multiple platforms and provides features such as keylogging, antivirus enumeration, real-time encrypted communication, and file management capabilities. Designed for educational and authorized security testing purposes, Bifrost leverages the Discord infrastructure to maintain a stealthy connection with clients.

C2_Server

2026-08-03 Python ★ 58
The C2 Server is a Command and Control framework that enables attackers to manage compromised target machines through a reverse shell connection. It supports various commands for file management, directory navigation, and even malicious functions like keylogging and credential spoofing, enhancing the attacker's ability to interact with the victim's system. Written in Python, it provides a user-friendly interface for executing predefined commands and extracting sensitive information from infected devices.

Cobalt-Strike-Aggressor-Script-Collection

2026-08-03 PowerShell ★ 13
The Cobalt Strike Aggressor Script Collection provides a set of scripts designed to enhance post-exploitation capabilities within the Cobalt Strike framework. Key features include techniques for privilege escalation, persistence, and situational awareness, along with accessible notes that facilitate streamlined operations during engagements. This tool is primarily used by security professionals for advanced exploitation and operational efficiency in red team scenarios.

covermyass

2026-08-03 Go ★ 435
Covermyass is a post-exploitation tool designed for penetration testers to securely delete log files across multiple operating systems, including Linux, macOS, and Windows. It enables users to identify and overwrite log files with random data to obscure their activities before exiting a compromised server. Notable features include multiple overwrite iterations and the ability to handle file permissions, ensuring thorough data eradication.

Coyote

2026-08-03 C# ★ 22
Coyote is a C# post-exploitation implant designed for maintaining access to compromised Windows systems during red team operations. Its notable features include bypassing application whitelisting through InstallUtil.exe, utilizing a recursive DNS tunnel to retrieve encrypted commands, and maintaining a small footprint on both memory and network resources. The tool leverages a DLL that periodically polls a DNS TXT record for remote instructions, allowing operators to execute various payloads, such as spawning a reverse shell, while potentially evading detection.

Crowbar

2026-08-03 Python ★ 47
Crowbar is a comprehensive Windows post-exploitation tool designed to facilitate various tasks such as privilege escalation and system command execution via PowerShell. It includes an extensive range of scripts and utilities, notably the 'Hail Mary' feature for launching multiple scripts simultaneously, and checks for the presence of Windows Subsystem for Linux on the target machine. The tool is actively maintained, with regular updates that introduce new scripts and enhancements to improve functionality.

DeathNote

2026-08-03 Python ★ 36
DeathNote is a penetration testing cheat sheet tool that provides a collection of resources and techniques essential for conducting security assessments. Its primary use case is to streamline the penetration testing process by offering organized references for various attack vectors, including reverse shells, PowerShell exploits, Active Directory, brute-forcing, and persistence methods. Notable features include compatibility with both Python 2.7 and 3.7, straightforward installation, and customizable configurations.

DecryptRDCManager

2026-08-03 C# ★ 81
DecryptRDCManager is a .NET tool designed to decrypt credentials stored in Remote Desktop Manager (.rdg) files, leveraging the functionality of RDCMan.DLL. Its primary use case is to extract and read encrypted user credentials, particularly those contained within the more reliable `<credentialsProfile>` section, while also providing an option to automate file detection via user settings. Notable features include the ease of building the tool and its ability to handle paths for .rdg files seamlessly, along with a focus on credential profile extraction for enhanced reliability.

enumy

2026-08-03 C ★ 256
Enumy is a high-performance enumeration tool designed for penetration testing and Capture The Flag (CTF) challenges, facilitating the identification of common security vulnerabilities on target Linux machines. Its features include configurable scan options, the ability to output results in various formats, and support for multithreaded operations to optimize scan speed and efficiency. Suitable for both professional pentesters and hobbyists, Enumy assists users in uncovering security issues during post-exploitation phases.

Evasor

2026-08-03 C# ★ 326
Evasor is an automated security assessment tool designed for Windows that identifies executables with potential vulnerabilities for bypassing Application Control rules. It offers features such as locating processes vulnerable to DLL Injection and DLL Hijacking, as well as generating detailed assessment reports inclusive of descriptions, screenshots, and mitigation suggestions. This tool caters to both blue and red teams, enhancing efficiency during the post-exploitation assessment phase.

FudgeC2

2026-08-03 Python ★ 253
FudgeC2 is a PowerShell-based command and control (C2) platform that enhances collaborative red teaming by providing an organized structure for managing campaigns and implants. It features a web-based interface that allows operators to easily deploy and control various implants, execute commands, and gather system information, with support for custom modules and a range of built-in commands such as persistence and file manipulation. Designed for active development, FudgeC2 aims to improve understanding of adversarial techniques through detailed reporting and campaign timelines.

HackingComm

2026-08-03 Python ★ 78
HackingComm is a user-friendly penetration testing tool designed for individuals with limited terminal command knowledge. It simplifies common pentesting tasks on Kali Linux through a straightforward interface, allowing users to easily input required parameters while executing commands. Notable features include an installation script, guided prompts for user inputs, and reliance on Python for functionality, making it accessible for beginners in cybersecurity.

iPwn

2026-08-03 Python ★ 233
iPwn is a framework specifically designed for the exploitation of jailbroken iOS devices, enabling users to gain access and extract sensitive information. It incorporates a post-exploitation tool named 'iSteal', which offers various modules for information harvesting and management, including SSH brute-forcing capabilities using common credential wordlists. Notably, the framework is still under development, with ongoing enhancements for easier payload management and integration with existing iOS tweaks.

leprechaun

2026-08-03 Ruby ★ 245
Leprechaun is a penetration testing tool that facilitates the identification of valuable targets within an internal network by aggregating netstat results from multiple hosts. Its primary use case involves analyzing network traffic connections to uncover potential vulnerabilities and traffic patterns, and it features command-line options to specify output files, ports of interest, and IP address types. Notable features include the ability to output detailed connection statistics organized by server and traffic destination ports, enhancing visibility for security assessments.

mOrc

2026-08-03 Shell ★ 19
mOrc is a post-exploitation framework specifically designed for macOS, developed in Bash. Its primary use case is to facilitate post-exploitation activities by providing a shell environment that minimizes traceable artifacts, such as disabling the history file and preventing core dumps. Notable features include its integration as an ENV script and its capability to execute various post-exploitation commands securely.

mythic-crate

2026-08-03 Shell ★ 17
mythic-crate is a development environment for the Mythic Command and Control (C2) framework, designed to run on Ubuntu 18.04 using VirtualBox and Vagrant. It automates the setup of Mythic dependencies, facilitates port forwarding, and enables folder sharing between the host and guest systems. Notable features include SSH access, streamlined administration via host commands, and the ability to customize VM disk size.

NTLMX

2026-08-03 PowerShell ★ 19
NTLMX is a post-exploitation tool designed for extracting local NTLM user password hashes from the Windows registry, supporting both modern AES-128-CBC techniques introduced in Windows 10 and traditional MD5/RC4 methods for earlier versions. The tool requires SYSTEM privileges to operate and can be easily installed via PowerShell Gallery or from the GitHub repository. It has been validated on multiple Windows versions, ensuring compatibility across various PowerShell environments.

OffensiveAutoIt

2026-08-03 AutoIt ★ 452
OffensiveAutoIt is a collection of proof-of-concept scripts leveraging AutoIt v3 for offensive security purposes, focusing on UI automation and the execution of external code. The repository includes features for compiling scripts into standalone executables, decompiling AutoIt binaries, and obfuscating scripts, facilitating the development of malware and tradecraft research. Its notable use cases involve executing PowerShell and .NET assemblies while bypassing security mechanisms like AMSI and ETW.

OffensivePH

2026-08-03 C ★ 332
OffensivePH is a post-exploitation tool designed to bypass user-mode access controls using an outdated Process Hacker driver. Its primary use case is to execute shellcode or terminate processes, enabling actions such as process hijacking and API call redirection through DLL injection. Notable features include a standalone executable for process management, integration for shellcode injection, and automatic cleanup of its driver after execution.

Orc

2026-08-03 Shell ★ 401
Orc is a post-exploitation toolkit designed for Linux environments, implemented in Bash. It provides a variety of functions for privilege escalation, system enumeration, and network analysis, while ensuring output is concealed by using a temporary directory that is auto-deleted on exit. Notable features include functionalities to check Docker access, list D-Bus services, and exploit known vulnerabilities, making it a versatile component for offensive security operations.

peh

2026-08-03 PowerShell ★ 37
PEH (Post Exploitation Helper) is a script designed to facilitate the downloading of common post-exploitation tools onto a target machine with minimal commands. Its primary use case is to operate on machines lacking internet access, allowing users to specify tool files and network interfaces for resource acquisition. Key features include flexible file input, configurable network interface and port options, and straightforward usage through command-line commands.

PentaDrone

2026-08-03 PowerShell ★ 12
PentaDrone is an asynchronous PowerShell post-exploitation agent designed for red teaming and penetration testing, utilizing the Mitre Att&ck framework for automation through an autopilot mode. It allows security researchers to simulate HTTP loader-style botnets, facilitating malware research while providing extensive configurability for command-and-control server connections and agent behavior. Notable features include various persistence methods, USB spreading options, and customizable operational parameters.

Powerexploit

2026-08-03 PowerShell ★ 28
Powerexploit is a PowerShell-based exploitation framework designed to facilitate offensive post-exploitation tasks in Windows environments. It enables security professionals to automate the process of gaining and maintaining access to targets, quickly exfiltrating sensitive information, and leveraging vulnerabilities within the system. Notable features include a modular architecture for plugins, support for various attack vectors, and inherent obfuscation techniques to evade detection by security tools.

PXEnum

2026-08-03 Shell ★ 43
PXEnum is a shell script designed for automated post-exploitation enumeration on *NIX systems, facilitating the collection of essential system and network information to aid security assessments. It executes a comprehensive set of checks related to user, hardware, BIOS, network activity, and permissions, providing an organized output of findings, while ensuring compatibility across various Unix-like environments. Notable features include the ability to read directly from system files for improved reliability and the streamlined output format for enhanced readability.

rpc2socks

2026-08-03 Python ★ 194
rpc2socks is a client-server solution designed to establish a SOCKS5 proxy tunnel through a custom RPC and SMB connection for remote execution and communication between Unix or Windows hosts and Windows targets. The tool leverages a dedicated named pipe for communication, supports DNS resolution, and operates without authentication by default, making it suitable for establishing secure tunnels on networks where direct connectivity may be restricted. Notably, the client is a Python package while the server is a statically-linked C++ console application compatible with both 32-bit and 64-bit Windows environments.

SBD

2026-08-03 Shell ★ 27
SBD is a script designed to provide users with access to essential Linux utilities on compromised systems, including the ability to deploy BusyBox and download static binaries for various networking tools like Ncat, Socat, Nmap, and Ngrok. Its primary use case is to enhance functionality on a limited or compromised environment by offering a menu-driven interface for managing these utilities. Notable features include the ability to set output directories for downloads, clean up downloaded files, and a straightforward installation process using available commands like `wget` or `git`.

SharpLoginPrompt

2026-08-03 C# ★ 133
Sharp Login Prompt is a cybersecurity tool designed to create a phishing login interface that captures the username and password of the current user without interacting with lsass or requiring administrative credentials. Its primary use case is for red team assessments, allowing security professionals to simulate phishing attacks. Notable features include customizable headings and subheadings for the login interface, enhancing the deception in social engineering scenarios.

shennina

2026-08-03 Python ★ 557
Shennina is an automated host exploitation framework that leverages Artificial Intelligence for comprehensive scanning, vulnerability analysis, and exploitation of target systems. Integrated with Metasploit and Nmap, it features a self-learning AI engine for identifying exploits, supports post-exploitation capabilities, and automates data exfiltration while covering over 40 techniques from the MITRE ATT&CK framework. Notable features include heuristics mode for exploit recommendations, high concurrency performance, and cross-platform support for various operating systems.

sudo_sniff

2026-08-03 C ★ 44
sudo_sniff is a discreet tool designed for post-exploitation scenarios to capture user passwords when executing the sudo command by manipulating the user's `$PATH`. It functions by hijacking the sudo execution to record both successful and failed password entries, storing them in a specified temporary file. Notable features include the ability to adapt to different system configurations for sudo and potential enhancements for stealthier operation.

swap_digger

2026-08-03 Shell ★ 537
swap_digger is a Bash script designed for automating the analysis of Linux swap space for post-exploitation and forensic purposes. It extracts sensitive information such as user credentials, web form credentials, and WiFi keys from the swap area, and offers extensive options for customization, including extended searches and optional logging. The tool is especially useful in penetration testing scenarios and can operate on local or mounted swap devices.

TokenPlayer

2026-08-03 C++ ★ 300
TokenPlayer is a tool designed for manipulating and abusing Windows access tokens, focusing on the Win32 API. Its primary use case includes stealing and impersonating tokens, bypassing User Account Control (UAC) via token duplication, and creating new tokens for network authentication without elevated privileges. Notable features include the ability to execute applications under an impersonated context, spoof parent process IDs, and operate within non-interactive environments, making it suitable for various privilege escalation and security testing scenarios.

ghost

2026-08-03 Python ★ 162
Ghost Framework is an Android post-exploitation tool that leverages the Android Debug Bridge for remote device administration. It provides a user-friendly interface to execute various remote management tasks such as accessing the device shell, installing applications, capturing screenshots, and managing device settings. Notable features include password removal capabilities and comprehensive system information retrieval.

Agent-Loader

2026-08-03 C ★ 12
Agent Loader is a modular command-and-control (C2) tool designed to facilitate the deployment of in-memory payloads and covert operations through a DNS-over-HTTPS channel. Its notable features include dynamic function encryption, a reverse-shell module, and extensive file system management capabilities, alongside a customizable CLI builder for creating tailored implants via Python. The tool also offers a Node.js web panel for interactive management, showcasing a bot list and persistence mechanisms through OneDrive and Task Scheduler.

AlanFramework

2026-08-03 Assembly ★ 486
Alan Framework is a post-exploitation framework designed for red-team activities, enabling advanced functionality such as in-memory tool execution and encrypted communication. It supports multiple agent types including Powershell, DLL, and executable formats across different architectures and operating systems, with a powerful command shell and real-time agent configuration updates. Notable features include a fully compliant SOCKS5 proxy, JavaScript execution capabilities, and a lack of external dependencies, making it suitable for stealthy operational tasks.

Ant

2026-08-03 Python ★ 17
Ant is a post-exploitation tool designed to automate the deployment of tunnels and port forwarding over a specified network topology using configuration files. Key features include support for WMI, WinRM, and SMB protocols, along with four main commands—deploy, desinfect, redeploy, and probe—that facilitate topology management. The tool also includes validation for configuration file accuracy and allows comments for better user guidance.

AntiForensic.NET

2026-08-03 C# ★ 11
AntiForensic.NET is a lightweight library designed for Windows that facilitates the eradication of forensic trace logs from a computer system. Its primary use case involves implementing various anti-forensic techniques to ensure user privacy by removing artifacts such as application logs, event logs, and cached data. Notable features include the automatic deletion of numerous types of logs and cache files, including Recycle Bin contents, recent items, and compatibility logs, thereby aiding users in evading potential tracing.

awesome-cyber

2026-08-03 ★ 111
awesome-cyber is a curated repository that aggregates a diverse range of cybersecurity tools catering to red, blue, and purple team operations. This resource aims to provide an up-to-date collection of tools across various cybersecurity domains, including offensive and defensive techniques, forensics, and incident response. Notable features include organized categories for easy navigation and an open invitation for community contributions to keep the toolset relevant.

C-keystroke-monitoring-lab-poc

2026-08-03 C ★ 12
C_keylogger is a stealthy keylogging tool developed in C for Windows that utilizes a traditional approach to log keystrokes without relying on WinAPI hooks. It features persistence, remote activation, a stealth handler to hide the Command Prompt window, and efficient memory management through variable reuse. The tool is designed for educational purposes in a controlled lab environment, requiring specific amendments before compilation to ensure connectivity.

C2KepExec

2026-08-03 C ★ 13
C2KepExec is a Command and Control (C2) server designed to manage a BotNet of machines running a Remote Administration Trojan and is developed for educational purposes. Its notable features include remote keylogging, file management capabilities (uploading and downloading), integrated session control for multiple targets, and persistent infection techniques on Windows systems. The tool also allows for advanced monitoring functions such as screen captures and webcam access.

C2PE

2026-08-03 Go ★ 36
C2PE is a tool designed for Red Team operations, focusing on Command and Control (C2) capabilities and post-exploitation activities. It features experimental code implementations suitable for hacking scenarios, allowing users to deploy C2 infrastructures and manage compromised systems effectively. The tool is developed in Python and Go, ensuring cross-platform compatibility and adherence to PEP8 code standards.

Clipboard-Hijacker

2026-08-03 PowerShell ★ 38
Clipboard-Hijacker is a post-exploitation payload designed for penetration testing that monitors and captures clipboard data on a target machine. It automatically sends captured clipboard contents, which may include sensitive information, to a specified web server or webhook every 10 seconds, while also optionally logging data locally. Notable features include the ability to modify clipboard contents and error handling mechanisms for reliable data transmission.

csharp_reverse_shell

2026-08-03 C# ★ 26
The csharp_reverse_shell is a proof-of-concept tool for executing reverse shell operations in C# that supports SSL/TLS encryption and various evasion techniques. Its primary use case includes providing a stealthy command execution environment with features such as a no-visible-window mode, dual operation modes for interactive shell and shellcode execution, and advanced evasion strategies like AMSI and ETW bypassing. Notable functionalities include silent error handling and selective unhooking of system calls to avoid detection.

dfex

2026-08-03 Python ★ 45
DFEX is a tool designed for DNS-based data exfiltration, leveraging the DNS protocol to transmit files across networks while circumventing traditional firewalls. Its primary use case is in post-exploitation scenarios, employing unique tactics to outsmart advanced firewalls, including techniques that disguise data transfers in plain sight. Notable features include a dual-client and server architecture, and compatibility with Python environments to facilitate easy installation and setup.

DNS-Tunnel-Keylogger

2026-08-03 Python ★ 280
DNS Tunnel Keylogger is a post-exploitation tool designed to covertly exfiltrate keystrokes via DNS tunneling, allowing for lightweight and persistent data exfiltration while minimizing detection risks. The tool features separate components for Linux and Windows, employing bash scripts and a compiled executable respectively, along with a server setup that listens on UDP port 53 by default. Notably, it can send keystrokes silently and can be configured for automatic startup in interactive shells to maintain persistence.

ExtractBitlockerKeys

2026-08-03 Python ★ 403
ExtractBitlockerKeys is a post-exploitation script designed for system administrators to automate the extraction of BitLocker recovery keys from a domain. It features multithreaded LDAP connections to retrieve data from domain controllers, supports pagination for large domains, and allows for exporting results in various formats, including JSON, XLSX, and SQLite3. This tool is essential for managing BitLocker recovery information in a secure and efficient manner.

GOD-OF-RAT

2026-08-03 Python ★ 22
GOD-OF-RAT is an advanced Python Remote Access Trojan (RAT) framework designed for authorized penetration testing, offering extensive control over compromised systems. Its notable features include live screen controlling, credentials harvesting from various sources, an interactive agent builder with encryption capabilities, and advanced evasion techniques. The framework also supports remote shell access, file system management, and a suite of fun modules for additional functionalities.

gtfobins-cli

2026-08-03 Python ★ 145
GTFOBins CLI is a command-line tool designed for security professionals to quickly access and search for Unix binary exploitation techniques. It features capabilities such as fuzzy searching, filtering exploitation types, and an interactive mode for ease of navigation, all while providing an offline database for fast, local access. The tool supports cross-platform usage and enhances readability with syntax highlighting, allowing for efficient identification of security bypass methods.

Hacker-Road-Map

2026-08-03 ★ 30
The Hacker Road Map repository provides a comprehensive overview of resources and tools necessary for learning penetration testing and practicing ethical hacking. It features a categorized collection of UNIX-compatible, free, and open-source tools, along with guidance on essential concepts, basic steps of penetration testing, and additional educational materials to support newcomers in the field of information security. Notably, the project has been archived, indicating that the content may be outdated as a new initiative is anticipated to replace it.

HVNC-windows-remote-toolkit

2026-08-03 C++ ★ 50
HVNC is a remote administration toolkit designed for red-team operators, enabling covert access to an invisible Windows desktop without user awareness. Its primary use case is to facilitate stealthy remote operations by creating a hidden session that processes actions off-screen and communicates with the operator via VNC-like commands, supporting functionalities such as file transfers, keylogging, and launching applications. Notable features include simultaneous session handling in separate console windows and a clean-up script for system hygiene post-usage.

KitsuneC2

2026-08-03 Go ★ 13
KitsuneC2 is a pure-Go adversary emulation framework designed for security testing, providing both a web and CLI interface for user interaction with implants. Its notable features include dynamic implant generation, in-memory execution of shellcode, and malleable C2 traffic, making it a versatile tool for organizations aiming to evaluate their cybersecurity defenses. However, it is not intended for professional engagements as there are more mature frameworks available.

LOLSpoof

2026-08-03 Nim ★ 188
LOLSpoof is an interactive shell program designed to spoof command line arguments of spawned processes, specifically targeting 64-bit LOLBins. Its primary use case is to obscure such processes from detection by telemetry solutions used by antivirus, endpoint detection and response (EDR) systems, and security analysts. Notable features include the ability to craft a spoofed command line, the manipulation of process creation telemetry, and the handling of suspended processes to override command line parameters.

MagikIndex

2026-08-03 C++ ★ 35
MagikIndex is an advanced keylogger designed for stealthy data capture, boasting a low detection rate and various persistence mechanisms. It retrieves logged information via email, supports clipboard monitoring, and can capture screenshots with configurable modes while encrypting logs for security. Notable features include an auto-update capability, extensive system information logging, and a customizable architecture for tailored functionality.

merlin

2026-08-03 Go ★ 5600
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

Metasploit-Tutorial

2026-08-03 ★ 34
The Metasploit-Tutorial repository provides comprehensive guidance on utilizing the Metasploit framework, a robust open-source toolset designed for network enumeration, vulnerability identification, and exploit development. Users can learn key functionalities such as exploit execution, payload creation, and post-exploitation techniques through detailed sections covering various components and workflows of Metasploit. Notable features of the tutorial include practical exercises with modules, sessions, and Meterpreter commands, enabling hands-on experience with real-world cybersecurity tasks.

MsfMania

2026-08-03 Python ★ 516
MsfMania is a Python-based payload obfuscation framework primarily aimed at evading endpoint detection and antivirus systems on Windows platforms. It boasts notable features such as dynamic code generation, multi-layer encryption using RC4, local memory injection, and extensive metadata spoofing, making it suitable for authorized security testing and research activities.

pE

2026-08-03 ★ 16
pE is a comprehensive post-exploitation framework designed for offensive security operations, focusing on practical techniques and tool development across multiple programming languages including Bash, Python, C, and Go. It offers a structured roadmap for activities such as credential access, lateral movement, persistence techniques, and data exfiltration, alongside custom script creation and defense evasion strategies. Key features include detailed sections on host enumeration, Active Directory abuse, and environmental setup, aimed at enhancing the effectiveness and efficiency of post-exploitation efforts.

PivotSuite

2026-08-03 Python ★ 459
PivotSuite is a network pivoting toolkit designed for Red Teamers and penetration testers, enabling the movement within a compromised network using either forward or reverse connections. Notable features include support for TCP tunneling, SOCKS5 proxies, and various network enumeration functions, all without requiring administrative access on the compromised host. The tool operates independently of installation requirements, utilizing only Python's standard libraries, making it versatile across different platforms and environments.

powtel

2026-08-03 PowerShell ★ 15
Powtel is a remote system control tool designed for Windows environments, utilizing PowerShell and Telegram as its communication interface. Its primary use case is for authorized security testing and post-exploitation activities, providing features such as task scheduling, file upload/download capabilities, and screenshot functionality. The tool emphasizes ethical usage, aiming to aid cybersecurity professionals and researchers in controlled settings.

PyADRecon

2026-08-03 Python ★ 67
PyADRecon is a Python-based tool designed for gathering comprehensive information from Microsoft Active Directory environments, catering to the needs of penetration testers and blue teams. It supports NTLM and Kerberos authentication methods, can generate XLSX reports, and offers an HTML dashboard for visualizing collected data, making it a versatile resource for Active Directory reconnaissance. Additionally, it provides options for standalone report generation from CSV files, enhancing its usability in various assessment scenarios.

PyExfil

2026-08-03 Python ★ 809
PyExfil is a Python-based tool designed for stress testing the detection capabilities of security systems against various exfiltration and communication techniques employed by threat actors. It allows users to deploy multiple experimental and stable exfiltration methods, such as DNS queries, HTTP cookies, and ICMP packets, enabling organizations to evaluate their defenses. Notable features include a wide array of techniques for data exfiltration and communication, with the ability to configure and run tests across different operating systems.

PyIris

2026-08-03 Python ★ 326
PyIris is a modular remote access trojan (RAT) toolkit implemented in Python, designed for the dynamic creation, encoding, and encryption of RAT payloads to facilitate the remote control of compromised systems. Its notable features include cross-platform compatibility for both Windows and Linux, robust error handling, dynamic payload generation, and advanced functionalities such as keylogging, webcam access, and file manipulation, making it a versatile tool for malicious actors. The ongoing development aims to enhance its capabilities further with improved encryption methods and operational persistence techniques.

python-remote-session-lab-poc

2026-08-03 Python ★ 175
PythonRAT is a Command and Control (C2) server that orchestrates multiple machines infected with a Remote Administration Trojan (RAT), enabling the formation of a botnet cluster. Its primary use case is for educational purposes in cybersecurity training, allowing users to remotely control, monitor, and manipulate target sessions. Notable features include an integrated keylogger, screenshot and webcam capture, file transfer capabilities, privilege checking, and the ability to issue commands to all active sessions simultaneously.

reave

2026-08-03 Python ★ 50
Reave is a post-exploitation framework developed for hypervisor endpoints, designed to facilitate automated penetration testing in heavily virtualized environments. This Python-based tool operates on a listener/agent model, offering features such as real-time interactive terminal sessions, automatic hypervisor enumeration, and modular payloads for tasks including exfiltration and persistence. Notably, Reave supports versatile configurations for agents, enabling comprehensive control over operations and network interactions.

redpill

2026-08-03 PowerShell ★ 219
Redpill is a post-exploitation tool designed to facilitate various tasks following initial access via reverse TCP shells, particularly for red team engagements. It comprises a collection of PowerShell scripts, with the main script, redpill.ps1, serving as a central hub to download, configure, and execute these scripts, offering functionalities similar to the meterpreter environment. Notable features include system enumeration, remote process management, web server deployment, and a keystroke logger, all intended to enhance the capabilities of shell access in compromised systems.

RedVision

2026-08-03 HTML ★ 13
RedVision is a collection of custom-designed HTML user interfaces specifically intended for Command & Control (C2) systems. Its primary use case is to enhance the operational efficiency of security professionals by providing a visually appealing and functional interface for managing C2 capabilities. Notable features include an array of templates, each visually distinct, allowing for flexible customization to suit various C2 deployment scenarios.

ReHTTP

2026-08-03 PHP ★ 78
ReHTTP is a PowerShell-based HTTP shell that features a web user interface, designed primarily for remote management and control of clients on a Windows platform. Key functionalities include executing PowerShell commands, managing client connections, and creating custom modules and variables, along with sophisticated event handling capabilities for connection management. This tool also supports scheduled tasks and offers a history feature for command execution, enhancing its usability in system administration and penetration testing contexts.

rogue

2026-08-03 Shell ★ 14
Rogue is a bash script that automates penetration testing workflows by integrating tools such as Nmap, Metasploit, and John the Ripper. It streamlines the scanning, exploiting, and reporting phases of pentesting, providing a modular and customizable experience for security professionals. Notable features include automated scans, exploitation configuration, credential harvesting, and structured report generation, all initiated with a simple input of a target IP address.

RUSTVERSARY

2026-08-03 Rust ★ 29
RustVersary is a comprehensive toolkit designed for malware development and penetration testing using the Rust programming language. It includes a variety of tools and scripts that facilitate tasks such as enumeration, exploitation, and post-exploitation, each thoroughly documented to aid both personal use and community contributions. Notable features include advanced techniques for process injection, persistence mechanisms, and a structured catalog of utilities tailored for security assessment challenges.

searchbins

2026-08-03 Shell ★ 52
Searchbins is an offline command-line tool designed to search for GTFOBins binaries that allow users to bypass local security restrictions in misconfigured systems. Its notable features include the ability to enumerate specific binary functions, display commands to exploit those functions, maintain an up-to-date GTFOBins database, and allow for file-based binary searches. This tool serves as a valuable resource for security professionals to identify and utilize potential vulnerabilities in binary applications.

SeaShell

2026-08-03 Python ★ 721
The SeaShell Framework is a post-exploitation tool designed for iOS and macOS that facilitates remote access to devices, allowing for control and extraction of sensitive data. Its notable features include a powerful payload named Pwny which supports custom post-exploitation modules, encrypted communication via TLS 1.3, and a basic set of modules for exfiltrating user data such as SMS, voicemail, and browsing history. Actively updated, it supports a wide array of iOS versions susceptible to specific vulnerabilities, enhancing its utility in security assessments and penetration testing.

Sh3ller

2026-08-03 PowerShell ★ 33
Sh3ller is a lightweight command-and-control (C2) framework designed for managing incoming reverse shells via PowerShell. Its primary use case is to maintain persistent access to compromised systems, allowing users to manage multiple shell sessions simultaneously with minimal dependencies. Notable features include an always-on listening mode, support for various reverse shell payloads, and intuitive session management commands.

silkwire

2026-08-03 Go ★ 10
Silkwire is a gRPC-based Command and Control (C2) framework designed for authorized penetration testing and red team operations. It supports multiple platforms (Windows, Linux, macOS) and offers advanced features including dynamic implant generation, post-exploitation modules, keylogging, and enhanced evasion techniques against detection mechanisms. The tool emphasizes encryption for communications and session management, making it a robust option for security professionals in performing comprehensive security assessments.

SoundShell

2026-08-03 Go ★ 11
SoundShell is a Command-and-Control (C2) tool developed in Go that utilizes the Spotify Web API to execute encoded commands and generate corresponding playlists. Its primary use case is to dynamically create playlists based on user-inputted commands, with notable features including custom command execution, command encoding for playlist generation, and random track selection from a predefined song pool.

sshimpanzee

2026-08-03 Python ★ 294
Sshimpanzee is a tool for creating a static reverse SSH server that initiates connections from the victim machine to an attacker's IP, bypassing the need for incoming connection requests. It provides all standard SSH functionalities, including port forwarding and dynamic SOCKS proxies, while also offering advanced tunneling methods like DNS Tunneling, ICMP Tunneling, and HTTP encapsulation to facilitate communication in restrictive network environments. Notable features include customizable build configurations, support for multiple tunneling mechanisms, and the ability to generate new SSH keys upon build.

TTPs

2026-08-03 ★ 28
The FreeZeroDays/TTPs repository serves as a curated collection of offensive security notes, focusing on Tactics, Techniques, and Procedures (TTPs). It provides a repository of validated commands and resources targeted towards researchers and practitioners in offensive security. Notably, the documentation emphasizes accuracy and reliability, and it draws inspiration from other established collections in the field.

Unicorn

2026-08-03 C ★ 10
Unicorn is a Command and Control (C2) framework designed for post-exploitation and remote control operations. Built using Python and Flask, it features a client-server architecture that supports multiple listeners, dynamic command execution, and client chat synchronization, while still being in development with planned enhancements such as a proxy server and GUI integration. This tool is aimed at cybersecurity professionals for managing agents and executing commands in compromised environments.

venus

2026-08-03 Python ★ 76
Venus is a VS Code extension designed to serve as an agent for the Mythic C2 framework, enabling operators to create and deliver payloads to target systems. This tool automates the packaging of VS Code extensions and supports various commands for interacting with the system environment, although it currently lacks support for encrypted payloads. Notably, Venus is cross-platform compatible and requires manual installation on target machines after preparation.

WebcamBOF

2026-08-03 C ★ 166
WebcamBOF is a Beacon Object File (BOF) for Cobalt Strike that enables webcam capture functionality. Its primary use case is to facilitate remote image acquisition by allowing users to save webcam images either to disk or download them directly over the Cobalt Strike beacon. Notable features include multiple save methods, including capturing images as screenshots, and the ability to enumerate connected webcam devices.

WindowSpy

2026-08-03 C ★ 287
WindowSpy is a Cobalt Strike Beacon Object File designed for targeted user surveillance, facilitating stealthy detection of significant user activities such as entering credentials or accessing confidential documents. It operates by comparing active window titles against a customizable list to trigger specific actions, like screenshots, only when relevant activities are detected, thus minimizing unnecessary data collection. Key features include easy integration with Cobalt Strike, a configurable keyword list for triggering surveillance, and the ability to customize the actions performed upon detection.

XENA

2026-08-03 Go ★ 395
XENA is a cross-platform cybersecurity automation framework designed for adversary simulations and red team operations, featuring a built-in post-exploitation agent and a command-and-control (C2) server. Notable features include an elegant dark-themed user interface that supports desktop, web, and mobile formats, along with high-level automation capabilities for orchestrating C2 clusters. This community edition serves as an integrated tool for penetration testing, facilitating a comprehensive approach to security assessment.

ZeroPulse

2026-08-03 JavaScript ★ 141
ZeroPulse is a modern Command & Control (C2) platform designed for secure remote management and monitoring of systems, utilizing Cloudflare Tunnel technology for encrypted connections. Key features include built-in authentication, support for WinRM and SSH interactions, a responsive React interface with real-time terminal integration, and comprehensive DNS management. The tool is currently in active development and is intended primarily for testing and evaluation purposes.

byob

2026-08-03 Python ★ 9499
BYOB is an open-source post-exploitation framework designed for educational purposes that facilitates command and control operations following a system compromise. It features a comprehensive web GUI for managing post-exploitation tasks, customizable payload generation for multiple platforms, and the ability to dynamically load third-party packages without leaving traces on the disk. The framework is optimized for ease of use, allowing students, researchers, and developers to extend its capabilities with minimal effort.

linux-priv-esc-audit

2026-08-03 Shell ★ 13
linux-priv-esc-audit is a Linux system auditing script designed to identify privilege escalation vulnerabilities and enhance security. It offers dual-mode operation for both root and low-privilege users, generates comprehensive audit reports with vulnerability insights, and provides user-friendly guidance throughout the audit process. Regular updates ensure the tool remains effective against new security threats and techniques.

ShellCode-Elevator-Uac-Bypass-Inject-Any-X64-fud

2026-08-03 C++ ★ 10
ShellCode Elevator is a sophisticated tool for bypassing User Account Control (UAC) and injecting shellcode into processes on x64 systems while maintaining stealth and undetectability. Its primary features include fully undetectable operation, privilege escalation, memory-only execution, and anti-debugging mechanisms to prevent detection by security tools. This makes it a potent option for executing malicious payloads without alerts on target systems.

ShellOrd

2026-08-03 Python ★ 17
ShellOrd is a cross-platform Command & Control (C2) framework designed for authorized penetration testing and educational purposes, implemented in Rust and Java. It supports Windows, MacOS, and Linux, and features a modular architecture with extensions, secure memory handling, and encrypted data transmission over TCP or UDP. The framework enables users to build and automate workflows, serving as an alternative to Trickest, while emphasizing speed and security.

cryptolyzer

2026-08-03 Python ★ 48
CryptoLyzer is a comprehensive security auditing tool that analyzes various cryptographic protocols, including TLS, SSL, SSH, IKE, and DNSSEC. It uniquely identifies over 400 cipher suites and cryptographic algorithms using a custom implementation that operates independently of OpenSSL, enabling the detection of vulnerabilities often missed by traditional tools. With both command-line and API interfaces, CryptoLyzer offers versatile output formats and a unified approach, making it an essential solution for security assessments across multiple cryptographic attack surfaces.

pysentry

2026-08-03 Rust ★ 249
PySentry is a robust vulnerability scanning tool for Python dependencies, designed to audit projects against known security issues by analyzing lock files or manifests and resolving the full dependency tree. Its notable features include support for various dependency formats, integration with multiple vulnerability databases for comprehensive reporting, and capabilities for continuous integration (CI) environments, allowing detailed output formats and customizable failure thresholds. The tool is optimized for speed, utilizing a Rust core for efficient processing and local caching.

TrivySummary

2026-08-03 Java ★ 11
TrivySummary is a reporting tool designed to interpret and summarize JSON outputs from Trivy vulnerability scans, facilitating visual and comparative reports for package vulnerabilities. It consolidates vulnerabilities by CVE and provides functionality for generating PDF or JSON reports, comparing scan results over time, and integrating with CI/CD pipelines to enforce security thresholds. Notable features include customizable report generation, integration of EPSS scores for exploitability assessment, and whitelisting capabilities for specific CVEs.

argus

2026-08-03 Python ★ 28
Argus is a comprehensive security scanning tool that integrates Static Application Security Testing (SAST), container security, Infrastructure as Code (IaC) scanning, and dynamic application security testing (DAST) into a single command-line interface (CLI) or GitHub Actions workflow. It supports various scanners such as Bandit, Gitleaks, and Trivy, enabling users to detect vulnerabilities, secrets, and security weaknesses across code, containers, and cloud configurations. Notable features include an interactive terminal UI for triaging scan findings, customizable integration with CI pipelines, and export options for results.

tmas-scan-action

2026-08-03 Shell ★ 16
The TMAS Scan Action is a GitHub Action that integrates the TMAS (TrendAI™ Artifact Scanner) CLI tool to scan artifacts in the GitHub workspace for open-source vulnerabilities, malware, or sensitive secrets. Notable features include detailed scan results displayed in action logs, summary reports in job summaries, and automated comments on related pull requests, enhancing CI/CD pipelines with security assessments for files, directories, and container images.

AutoCVE

2026-08-03 Python ★ 1386
AutoCVE is an automated tool designed for end-to-end CVE discovery, encompassing project screening, source code auditing, vulnerability verification, and report generation. Its notable features include a multi-agent collaborative auditing system and flexible auditing modes tailored for different objectives, enabling efficient management of vulnerability assessment through structured automated workflows. The tool simplifies the CVE reporting process, allowing users to easily submit their findings after a comprehensive auditing experience.

h1domains

2026-08-03 Python ★ 529
h1domains is a Python tool that retrieves and lists domains approved for bug bounty programs on HackerOne, focusing specifically on those marked as "in-scope." Its primary use case is to assist security researchers in identifying valid targets for vulnerability testing while providing a regularly updated repository of domains. Notable features include an automated script to fetch the latest data and a comprehensive list of domains across various companies and services.

mercator

2026-08-03 PHP ★ 548
Mercator is an open source web application designed for dynamic mapping of information systems, providing IT professionals with a comprehensive overview of their digital environments. It enables users to visualize dependencies, track compliance, generate architectural reports, and facilitate risk management through features like graphical representations, compliance monitoring, and integration with security tools. Notably, Mercator supports multi-user collaboration and offers a REST API for seamless system integration, making it a valuable asset for organizations aiming to enhance information system governance.

PermCheck

2026-08-03 PHP ★ 11
PermCheck is a lightweight tool designed for verifying proper executable permissions on files within a PHP project. By utilizing a customizable XML configuration file, it allows users to specify which directories and files should be executable, thus enhancing project consistency and security. Notable features include support for various PHP versions, minimal dependencies, and integration with the Symfony Console Component for ease of use.

bearer

2026-08-03 Go ★ 2739
Bearer is a static application security testing (SAST) tool that scans source code for security and privacy risks by analyzing data flows. It supports a wide range of programming languages and offers features like detection of vulnerabilities in line with OWASP Top 10 and CWE Top 25, as well as identifying sensitive data flows for privacy compliance reporting. Bearer is available in both an open-source CLI version and a comprehensive commercial version, providing advanced analysis capabilities.

bugsy

2026-08-03 TypeScript ★ 68
Bugsy is a command-line tool designed for automatic security vulnerability remediation in code, functioning as both a scanner and analyzer for SAST (Static Application Security Testing) reports from various vendors like Checkmarx and Snyk. Its notable features include two operational modes—Scan, which runs SAST scans and identifies vulnerabilities directly, and Analyze, which processes pre-generated SAST reports to provide automated code fixes, effectively streamlining the remediation process for developers. Additional functionality allows Bugsy to be utilized as an MCP server for enhanced integration with AI tools in vulnerability scanning and fixing.

cynative

2026-08-03 Go ★ 194
Cynative is a read-only cybersecurity tool designed for deep infrastructure research, allowing users to query various systems such as GitHub, GitLab, AWS, GCP, Azure, and Kubernetes in a unified manner. It executes code in an ephemeral sandbox to provide verified insights while maintaining strict access controls, thereby ensuring that users can confidently audit their cloud environments without compromising security. Notable features include its ability to reason through code-to-runtime environments, a robust action-gate mechanism for authorization, and evidence-backed findings that trace back to their origins.

rearm

2026-08-03 Java ★ 126
ReARM is a Release Governance Platform that facilitates the management of software releases by providing insights into their composition, security posture, and compliance through the storage and organization of Software Bill of Materials (SBOMs), security artifacts, and vulnerability data. Notable features include support for OCI-compatible storage, adherence to regulatory frameworks, and the introduction of a Product-Component relationship model for enhanced release metadata organization. This tool is particularly useful for organizations aiming to streamline their release processes while ensuring compliance with various security standards.

references

2026-08-03 ★ 14
The "references" repository serves as a compiled collection of reusable references, providing access to a variety of resources related to contemporary issues such as the Russo-Ukrainian War and political events. Notable features include links to remote documents, calendars, and an emphasis on critical themes like agnotology, which explores the social fabric of ignorance. The repository aims to facilitate informed discussions and act as a resource for understanding the implications of various socio-political phenomena.

rust-in-peace

2026-08-03 Python ★ 17
Rust-in-Peace is an autonomous security review tool specifically designed for Rust programming, facilitating the detection and remediation of vulnerabilities related to memory safety and panic handling in unsafe contexts. It integrates various detectors such as Miri and AddressSanitizer into a comprehensive pipeline that automates the process of finding, grading, and reporting vulnerabilities while also enabling targeted fuzzing. This tool emphasizes a structured approach by utilizing a machine-readable threat model and supports a recall-first strategy to improve detection accuracy through multiple scanning runs.

SecObserve

2026-08-03 Python ★ 295
SecObserve is an open source vulnerability and license management tool designed for software development teams and cloud environments, enabling efficient assessment and reporting of vulnerabilities across multiple scanning tools. It features a centralized dashboard for viewing and filtering scan results, as well as easy integration into CI/CD pipelines through pre-defined GitLab CI templates and GitHub Actions for streamlined vulnerability scanning. This tool aims to simplify the vulnerability management process, allowing teams to focus on addressing significant security issues.

syzkaller

2026-08-03 Go ★ 6313
Syzkaller is an unsupervised coverage-guided kernel fuzzer designed to discover security vulnerabilities in various operating system kernels, including Linux, FreeBSD, and Windows. Its notable features include support for multiple OS environments, a focus on automated bug detection, and an extensive documentation set for setup and usage. Initially developed for Linux, Syzkaller has broadened its capabilities to include several other operating systems, enhancing its utility in kernel security research.

trivy

2026-08-03 Go ★ 37715
Trivy is a versatile security scanner designed for identifying vulnerabilities and misconfigurations across various targets, including container images, filesystems, Git repositories, virtual machine images, and Kubernetes environments. It can detect OS packages, known vulnerabilities, infrastructure as code (IaC) issues, sensitive data, and software licenses. Trivy is easily integrable with popular tools and platforms, supporting a wide range of programming languages and systems, making it a comprehensive choice for security assessments.

vulnerablecode

2026-08-03 Python ★ 699
VulnerableCode is an open-source database designed to catalog software package vulnerabilities, accessible through a Web UI and a comprehensive API. Its primary use case is to provide detailed information on vulnerabilities affecting software packages, including upstream and downstream impact analysis, thereby facilitating better vulnerability management. Notable features include its focus on Package URLs (PURLs) for easy identification of packages, along with the ability to build custom instances of the database.

wildbox

2026-08-03 Python ★ 132
Wildbox is a self-hosted, open-source security operations platform designed for comprehensive threat monitoring, analysis, and automated responses, allowing users to maintain full control over their data. It features aggregated threat intelligence from over 50 sources, cloud security posture management for major providers, and utilizes YAML-based playbooks for incident automation, alongside advanced LLM capabilities for enhanced threat analysis and reporting. The architecture is built on microservices, providing flexibility and scalability through a robust API gateway, identity management, and integrated data management tools.

suspicious_IPs

2026-08-03 ★ 17
The 'suspicious_IPs' repository provides a compiled list of potentially malicious or harmful IP addresses. Its primary use case is for cybersecurity professionals to enhance threat detection and mitigation measures by identifying and blocking traffic from these suspicious IPs. Notable features include a straightforward format that allows for easy integration into firewall rules and intrusion detection systems.

ai-reverse-engineering

2026-08-03 Python ★ 154
Rev·Deck is a localized static-analysis workstation that integrates Ghidra with an AI-driven web interface for reverse engineering binaries. It allows users to browse deterministic evidence from analyzed binaries without executing them, while an AI assistant provides fact-based responses citing specific evidence. This tool supports various LLM backends and enables secure, efficient analysis with a user-friendly interface.

Reversecore_MCP

2026-08-03 Python ★ 194
Reversecore MCP is an AI-powered server designed to facilitate reverse engineering and security analysis by integrating 120 analysis tools into a unified interface. It utilizes natural language processing to allow AI assistants to perform tasks like malware analysis, vulnerability research, and source code auditing, significantly simplifying the interaction with complex command-line tools. Notable features include structured tool results that AI can reason about and chain into follow-up queries, making it highly efficient for rapid security assessments and investigations.

augur

2026-08-03 Rust ★ 120
Augur is an advanced IDA headless plugin designed for efficient analysis of binary files by extracting strings and associated pseudocode. Its primary use case is to streamline vulnerability research by organizing and storing the pseudocode of functions that reference specific strings in an intuitive directory structure, leveraging the Hex-Rays decompiler's capabilities. Notable features include rapid processing, support for various architectures, and a robust decompilation process using the `decompile_to_file` API from the Haruspex library.

DeepZero

2026-08-03 Python ★ 626
DeepZero is an automated vulnerability research pipeline engine that allows users to define and orchestrate data processing workflows using YAML configuration files. Notable features include support for parallel execution, resumable runs, integration with language model providers, and extensibility for custom processing components, making it ideal for analyzing and assessing vulnerabilities in a target corpus of files. The tool is built to enhance efficiency in vulnerability research while ensuring fault tolerance and state management during execution.

ghidra-scripts

2026-08-03 Java ★ 302
The `ghidra-scripts` repository comprises a collection of scripts designed for Ghidra to enhance reverse engineering and vulnerability research. It features tools that locate insecure function calls, extract pseudocode, and resolve iOS and MIPS syscalls, thereby streamlining the analysis process for security researchers. Compatibility is maintained with Ghidra version 12.0.2.

haruspex

2026-08-03 Rust ★ 134
Haruspex is an advanced headless plugin for IDA Pro that efficiently extracts pseudocode from binaries, formatted for integration with IDEs or further parsing by static analysis tools like Semgrep. Notable features include its high-speed performance, compatibility with various architectures supported by IDA's Hex-Rays decompiler, and structured output where each function's pseudocode is saved separately for easy analysis.

oneiromancer

2026-08-03 Rust ★ 145
Oneiromancer is a reverse engineering assistant designed to enhance code analysis by utilizing a locally running large language model (LLM) that has been fine-tuned for Hex-Rays pseudocode interpretation. Its primary use case is to analyze code snippets, providing high-level descriptions, suggested function names, and variable renaming recommendations, while also saving improved pseudocode for further inspection. Notable features include cross-platform compatibility, integration with the pseudocode extractor 'haruspex', and the ability to invoke analysis through external crates, facilitating a seamless development experience.

open-reverselab

2026-08-03 Python ★ 1094
ReverseLab is an open-source reverse engineering lab designed for capturing and analyzing various attack scenarios across multiple domains, including CTF pentesting, APK reverse engineering, and PE binary analysis. Its notable features include a comprehensive knowledge base organized into specialized categories, over 100 automation tools for rapid execution, and a modular architecture that supports various signal types and attack chains. Users can easily set up the tool on multiple platforms with provided scripts, ensuring a streamlined onboarding experience.

rhabdomancer

2026-08-03 Rust ★ 133
Rhabdomancer is a high-performance headless plugin for IDA that identifies calls to potentially insecure API functions within binary files. It aids security auditors by backtracking from these functions to find vulnerabilities related to untrusted input, complete with a prioritization system that categorizes known bad API calls. Notable features include support for various C/C++ binary targets and the ability to customize the list of bad API functions according to user-defined criteria.

rizin

2026-08-03 C ★ 3826
Rizin is a comprehensive reverse engineering framework designed for analyzing binaries, disassembling code, and debugging programs, offering enhanced usability and features compared to its predecessor, radare2. It supports a wide array of operating systems and architectures, includes multiple utilities for scripting and binary manipulation, and facilitates interaction with popular programming languages through rzpipe. Notable features include a command-line assembler, tools for binary comparison and pattern searching, as well as extensive file format compatibility.

cascade-protocol-dissector

2026-08-03 HTML ★ 151
Torii Gateway is a middleware solution designed to provide researchers with persistent, authenticated access to advanced inference pathways of large language models (LLMs) while bypassing tiered consumption limits imposed by commercial APIs. Its notable features include protocol reflection to mimic enterprise-tier traffic, token frame rebalancing to adjust apparent consumption rates, and session entropy injection for neutralizing identifiable session fingerprints, facilitating a seamless connection to multiple inference providers without altering client-side code. This tool serves as a crucial resource for overcoming restrictions that hinder research and experimentation with frontier LLM capabilities.

TryHackMeWriteups

2026-08-03 Python ★ 17
TryHackMeWriteups is a comprehensive repository that curates free TryHackMe rooms, providing organized resources for cybersecurity enthusiasts to learn and practice various skills. Notable features include categorized rooms across diverse topics, detailed notes and summaries, step-by-step writeups for Capture The Flag challenges, and continuous updates, making it an ideal starting point for beginners in cybersecurity and ethical hacking.

bento

2026-08-03 Dockerfile ★ 76
Bento is a lightweight Docker container designed for penetration testers and Capture The Flag (CTF) players, providing a minimalistic environment with essential tools for web and infrastructure security testing. It supports GUI applications via X forwarding, allowing users to seamlessly run tools like Burp Suite, and includes collaborative features through an embedded code-sharing pad (CodiMD). Notable features include minimal bloat, portability, and customizable deployment options via Docker Compose.

Cannon

2026-08-03 Python ★ 19
Cannon is a post-exploitation framework developed in Python, designed primarily for Unix-based systems to facilitate post-access tasks on compromised machines. Its functionalities include uploading and downloading files, executing pre-defined modules, and harvesting reverse shells, making it a powerful tool for security professionals and penetration testers. The framework also offers some compatibility with Windows systems, expanding its utility across different platforms.

cgPwn

2026-08-03 Shell ★ 356
cgPwn is a specialized Ubuntu virtual machine designed for hardware hacking, reverse engineering (RE), and wargaming, equipped with an extensive suite of tools such as Pwndbg, Pwntools, and Radare2. Its primary use case is to provide a comprehensive environment for cybersecurity practitioners to develop, test, and exploit vulnerabilities. Notable features include easy setup using Vagrant, a sophisticated collection of debugging and exploitation tools, and customizable configurations through personal dotfiles.

firstblood

2026-08-03 Python ★ 37
FirstBlood is a Python 3 library designed to extend built-in objects and enhance utility functions, primarily for rapid development in Capture The Flag (CTF) scenarios. Notable features include method chaining for easier function calls, advanced manipulation of strings and bytes, and integrated cryptographic functions such as XOR and various hashing algorithms. However, users should exercise caution, as the library may alter standard Python behavior and is not intended for production environments.

flagWarehouse

2026-08-03 Python ★ 13
FlagWarehouse is a Flask-based flag submission system designed for Attack/Defense Capture The Flag (CTF) competitions, utilizing SQLite for data management. It allows teams to submit flags to a verification server while providing a user-friendly web interface to display statistics and manage flag submissions efficiently. Key features include customizable configurations for flag formats and submission intervals, automatic flag extraction from exploits, and real-time feedback on submissions.

jwtXploiter

2026-08-03 Python ★ 291
jwtXploiter is a security testing tool designed to assess the vulnerabilities of JSON Web Tokens (JWTs). It enables penetration testers and developers to exploit known CVEs, manipulate token payloads, verify JWTs, and perform key confusion attacks by retrieving public keys from SSL connections. Notable features include support for all JWT algorithms, automated generation of JSON Web Keys (JWK), and the ability to tamper with vulnerable header claims like kid, jku, and x5u.

karkinos

2026-08-03 Python ★ 197
Karkinos is a comprehensive library database tool designed for binary exploitation on Linux, facilitating the identification of unknown libraries and their associated symbols. It provides capabilities to locate library packages, dump useful symbols and gadgets for return-oriented programming (ROP), and supports various architectures, including x86, ARM, and more, by indexing a wide range of libraries like glibc and libstdc++. Key features include commands to find libraries by offsets, dump detailed library information, and update the internal database autonomously.

Scuffed_Low_Level_Stash

2026-08-03 ★ 107
Scuffed Low Level Stash is a curated resource repository focused on binary exploitation and reverse engineering, providing a wealth of educational materials including tutorials, courses, and reference links related to assembly language and low-level programming. Its notable features include a comprehensive list of recommended resources, practical tutorials, and useful references for both beginner and advanced practitioners in the field. The tool serves as a centralized platform for learners and professionals looking to enhance their skills in binary exploitation tactics.

YAPS

2026-08-03 PHP ★ 84
YAPS is a lightweight PHP reverse shell that operates as a single file, allowing users to execute commands on remote systems through a TCP listener. It features customizable password protection, enumeration capabilities for gathering system information, and the ability to manage concurrent connections and execute PHP code remotely. Notably, it can auto-download enumeration tools, exploit known vulnerabilities like CVE-2021-4034, and send shellcode to the target host while supporting operations on both Linux and Windows in future updates.

bug-bounty-tips

2026-08-03 Python ★ 37
The bug-bounty-tips repository provides a comprehensive collection of resources and tools tailored for bug bounty hunters. It includes a curated list of required scripts and tools like Amass, SQLMap, and Fuff, facilitating efficient reconnaissance and vulnerability assessment. The repository emphasizes community engagement through platforms like Telegram and Twitter, aiming to enhance knowledge sharing among cybersecurity professionals.

CTF-Checklist

2026-08-03 ★ 62
CTF-Checklist is a comprehensive resource aimed at cybersecurity enthusiasts participating in Capture The Flag (CTF) challenges, providing a curated list of vulnerabilities and associated tools for exploitation across various domains including forensics, web, and binary exploitation. Noteworthy features include a variety of tools such as packet analyzers, password crackers, SQL injection frameworks, and binary exploitation utilities, assisting users in effectively evaluating and leveraging security weaknesses. It serves as a vital reference for those looking to enhance their skills in ethical hacking and vulnerability assessment.

hash-length-extension

2026-08-03 Python ★ 39
The length-extension-tool is a Python library that implements hash length extension attacks and supports multiple hashing algorithms, including MD5, SHA1, and SHA256. Its primary use case is to exploit vulnerabilities in hashing algorithms that utilize the Merkle-Damgård construction, allowing an attacker to append data to a hashed message without knowing the original input. Notable features include a straightforward API for computing hashes and performing extension attacks, as well as built-in tests to validate the implementation against standard Python hashing libraries.

pwndra

2026-08-03 Python ★ 708
Pwndra is a collection of utilities designed to enhance the Ghidra reverse engineering environment, specifically for pwn and Capture the Flag (CTF) challenges. Key features include the ability to replace constants with human-readable counterparts, annotate system calls and their arguments, conveniently convert character representations, and quickly navigate to the main function of binaries. This toolset streamlines the analysis workflow, improving usability for cybersecurity practitioners working with various CPU architectures.

TryHackMe-Zero-To-Hero

2026-08-03 JavaScript ★ 54
The TryHackMe - Hackers Learning Path repository provides a structured framework for beginners in cybersecurity to learn and practice through a series of rooms and hands-on exercises. Key features include an automated environment setup script, instructional content covering foundational topics like Linux, networking, and various security tools (e.g., Nmap, Burp Suite, Metasploit), and practical penetration testing exercises to simulate real-world attacks. This resource is designed to guide users incrementally from introductory levels to more advanced cybersecurity skills.

avala

2026-08-03 Python ★ 10
Avala is a tool designed for the rapid development, execution, and monitoring of exploits in attack-defense capture the flag (CTF) competitions. It simplifies the process for teams by allowing them to focus on exploiting vulnerabilities and implementing patches without being bogged down by technical complexities. Notably, Avala is informed by the practical experiences of the Serbian National ECSC Team and provides functionality for integrating with various services to facilitate quick exploit deployment.

CTF-Resources

2026-08-03 ★ 10
The CTF Resources repository is a comprehensive collection of cybersecurity tools and practice platforms specifically designed for Capture the Flag (CTF) competitions. It includes an extensive array of tools categorized into areas such as Open Source Intelligence (OSINT), steganography, and anonymous communication, offering functionalities from data gathering and analysis to secure and anonymous internet browsing. Notable features include links to various open-source tools, detailed descriptions, and categorization for ease of use, supporting users in enhancing their digital security skills.

liveexploit

2026-08-03 Python ★ 12
Live Exploit is a comprehensive Python-based tool tailored for Capture The Flag (CTF) challenges, exploit development, and vulnerability research. It offers a rich feature set including buffer overflow payload generation, ROP chain creation, fuzzing, and interactive command execution, all presented through an intuitive command-line interface. This all-in-one toolkit is designed for both novice and advanced users, streamlining numerous exploit-related tasks while being cross-platform compatible.

reversingBits

2026-08-03 HTML ★ 646
The Reversing Bits Cheatsheets repository serves as a comprehensive resource for assembly programming, reverse engineering, and binary analysis tools. It includes in-depth guides on installation, usage examples, and advanced tips for a variety of tools, such as assemblers, debuggers, disassemblers, and binary analysis frameworks, catering to different operating systems and user needs in the field of cybersecurity. Notably, it features prominent tools like Ghidra, IDA Pro, and GDB, making it a valuable reference for professionals involved in security and malware analysis.

TryHackMe

2026-08-03 Shell ★ 392
TryHackMe is a free cybersecurity learning path designed to advance users from novice to expert through a range of practical exercises, introductory Capture The Flag (CTF) challenges, and educational modules covering topics like OpenVPN, Linux fundamentals, web scanning, and Metasploit. This resource is suitable for both newcomers to the field and those looking to enhance their skills, and it culminates in a comprehensive foundation in cybersecurity, preparing users to address more complex challenges. Notable features include diverse content formats, hands-on labs, and accessible learning materials to foster practical experience in cybersecurity practices.

vheap

2026-08-03 JavaScript ★ 75
vHeap is an extendable visualization and exploitation tool designed for glibc heap memory analysis during debugging sessions, primarily targeting security researchers and CTF players. It allows users to visualize heap memory in real-time within a web browser leveraging GDB's pwndbg integration, with features like automatic heap state updates and customizable extensions for other debuggers. Notably, vHeap facilitates easier exploitation of heap memory by transforming complex memory structures into interactive visual representations.

ataka

2026-08-03 Python ★ 126
Ataka is a command-line tool designed for running exploits in competitive Capture The Flag (CTF) hacking environments, allowing players to create, manage, and test their exploits efficiently. Notable features include the ability to set up exploits with specified target IPs, hot-reload configurations, and a templating system for easy exploit creation. The tool operates within a Docker container, providing a flexible and isolated environment for users to conduct their attacks and tests.

CTF_tools

2026-08-03 ★ 390
CTF Tools is a curated repository that aggregates a variety of resources, websites, and tools specifically designed to assist in solving Capture The Flag (CTF) challenges. It organizes tools by category, providing practical links ranging from ASCII tables to cryptographic calculators, thus serving as a quick reference resource for CTF participants and teams during competitions. Notable features include a wide assortment of utility tools for cryptography, data conversion, and training resources, as well as guidelines for collaborative contributions to the repository.

ctf-helper

2026-08-03 Python ★ 35
CTF Helper is a multifunctional tool designed for Capture The Flag (CTF) competitions and various cybersecurity tasks. It features capabilities for decoding data formats such as Base64 and hex, JWT decoding and brute-forcing, web exploit utilities, and OSINT tools for geolocation and Shodan lookups, all built with modularity and extensibility in mind. This tool serves as a comprehensive resource for security professionals engaging in threat analysis and live security challenges.

ctf-party

2026-08-03 Ruby ★ 90
ctf-party is a command-line interface (CLI) tool and library designed for Capture The Flag (CTF) participants and security professionals, streamlining the process of scripting and exploit writing. It enhances Ruby's String class with concise methods for common coding tasks, like encoding and decoding, thus minimizing the need for extensive code and dependencies. Notable features include a range of easy-to-use commands that perform various encoding and transformation operations, making it particularly useful for rapid development in CTF contexts.

exploitfarm

2026-08-03 Python ★ 59
ExploitFarm is a distributed attack platform designed for security competitions, enabling users to easily share and execute exploits in a coordinated manner. The tool facilitates the replication of attacks, flag submissions, and data collection for analysis, all while providing a user-friendly TUI and centralized server management. Key features include client-server architecture, customizable configurations for competition settings, and detailed tracking of attack performance.

ftp-scan

2026-08-03 Python ★ 21
FTP Scanner is a lightweight tool designed for penetration testing and Capture The Flag (CTF) challenges, capable of detecting anonymous logins, listing files, and performing banner grabbing. It features heuristic software and version extraction, alongside a local exploit database lookup for identifying potential vulnerabilities based on the FTP server's banner. This portable tool operates as a single Python script, requiring minimal dependencies and offering customizable usage options, including the ability to specify custom ports and vulnerability database paths.

MyCTFLib

2026-08-03 Python ★ 13
MyCTFLib is a collection of templates for Capture The Flag (CTF) competitions, designed to assist with various challenge types, including exploitation, cryptography, and web vulnerabilities. It features scripts to easily copy relevant libraries for pwn, crypto, and web challenges, streamlining the setup process for participants. The library includes specific tools and functionalities such as exploited scripts, cryptographic algorithms, and web exploitation techniques.

ronin-payloads

2026-08-03 Ruby ★ 23
ronin-payloads is a Ruby micro-framework designed for constructing and executing exploit payloads as plain Ruby classes, providing a modular and user-friendly alternative to tools like msfvenom. It supports a variety of languages and payload types, facilitates cross-compilation, and includes built-in common payloads for reverse and bind shells across multiple operating systems. Noteworthy features include a simple command-line interface, extensive documentation and test coverage, and the flexibility to host additional payloads in separate repositories, promoting decentralized usage.

seg

2026-08-03 Rust ★ 21
`seg` is a command-line utility designed for analyzing and exploiting ELF binaries, offering comprehensive binary intelligence with a single command. Its primary use case targets CTF players and penetration testers, providing features such as dangerous function detection, libc resolution, and automatic exploit strategy suggestions. Notably, `seg` supports dual output formats for both human readability and automation pipelines, streamlining the reconnaissance process by integrating multiple tool functionalities into a cohesive reporting system.

sentinel-reverse

2026-08-03 Python ★ 78
sentinel-reverse is an AI-powered autonomous binary reverse engineering tool designed to enhance the efficiency of analyzing complex binaries by automating traditional manual processes. It features capabilities such as AI-driven function decompilation, LLM-based semantic inference for variable naming, and context-aware vulnerability detection, enabling analysis of 50-200 functions per hour with complete data privacy and zero API costs. This tool leverages GPU acceleration and incorporates a multi-round confidence-driven analysis to optimize the reverse engineering workflow.

winpwn

2026-08-03 Python ★ 196
Winpwn is a Windows-centric debugging and exploitation toolset designed for both user and kernel modes, built upon Python's capabilities. It supports various debugging environments, including Windbg and GDB, and offers features like process memory manipulation, remote connections, and assembly/disassembly functionalities, making it ideal for security researchers and developers focused on Windows exploitation. The tool is compatible with both Python 2 and 3 and facilitates an extensive configuration for customized debugging sessions.

0-click-RCE-Exploit-for-CVE-2024-10924

2026-08-03 PHP ★ 14
This repository provides a proof-of-concept exploit for CVE-2024-10924, allowing an attacker to bypass authentication and two-factor authentication in the Really Simple Security WordPress plugin to achieve remote command execution (RCE). The script automates the process of impersonating an administrator, uploading a malicious plugin, verifying interaction with the payload, and establishing an interactive remote shell. Notably, it operates pre-authentication, requiring only the target URL and a malicious plugin as input.

Bug-Bounty-Beginner-Roadmap

2026-08-03 ★ 81
The Bug Bounty Beginner Roadmap serves as a comprehensive guide for newcomers interested in bug bounty hunting, providing essential knowledge on security vulnerabilities and effective learning paths. It emphasizes the importance of foundational skills in computer systems, networking, and operating systems, while also highlighting the potential rewards of participating in bug bounty programs. Notable features include curated resources and links to courses tailored for building the necessary expertise in this evolving field.

coli

2026-08-03 JavaScript ★ 35
COLI (Command Orchestration & Logic Interface) is a command line tool designed to streamline workflow management by enabling users to visually create and connect tasks through a drag-and-drop interface. It offers features such as real-time scan monitoring, an interactive web terminal, and a built-in file explorer, making it ideal for those seeking a more efficient way to manage command line operations and enhance visualization. Additionally, COLI supports mobile access, allowing users to operate workflows from anywhere.

cryptocat-gitbook

2026-08-03 ★ 18
CryptoCat is a secure messaging tool designed for private communication via end-to-end encryption. Its primary use case is to enable users to chat in real-time while ensuring that messages remain confidential. Notable features include anonymous chat rooms and the ability to communicate securely without data logging.

CTF-to-Pentest-Translating-CTF-Patterns-into-Real-World-Exploits

2026-08-03 ★ 11
CTF-to-Pentest is a guide that emphasizes the transition from a Capture the Flag (CTF) mindset to a penetration testing (pentest) approach, highlighting how common vulnerabilities like SQL injection and remote code execution must be handled with precision and discipline in real-world scenarios. It provides insights on translating CTF techniques into practical, low-impact strategies that prioritize thorough reporting over noise generation. Noteworthy features include personalized methods for vulnerability probing, safe proof-of-concept recommendations, and real-world case studies showcasing vulnerabilities found in high-value companies.

hacker101-CTF-Solutions

2026-08-03 ★ 22
Hacker101 CTF Solutions is a comprehensive repository that provides detailed walkthroughs and solutions for challenges encountered in the Hacker101 Capture The Flag (CTF) platform, focusing on web application security vulnerabilities. Key features include a structured organization with solution documentation and supporting screenshots for each challenge, as well as coverage of various attack vectors such as XSS, SQL injection, and permission issues. This educational tool is aimed at both novices and experienced individuals seeking to improve their penetration testing skills through practical, hands-on experience.

IP-Vortex

2026-08-03 Shell ★ 10
IP-Vortex is an advanced IP rotation tool designed for security professionals, enabling anonymous security testing by frequently changing public IP addresses. Its primary use case is to facilitate fuzzing and vulnerability scanning while avoiding IP-based rate limiting, featuring automatic IP rotation, timed intervals, multi-interface support, and optional MAC address randomization. Notable features include comprehensive logging, network status monitoring, and seamless integration with security testing workflows.

JWT-Authentication-Bypass-Exploiting-Unverified-Signature-for-Bug-Bounty

2026-08-03 ★ 13
The JWT Authentication Bypass tool demonstrates the exploitation of a vulnerability where the server fails to verify the signature of JSON Web Tokens (JWTs), allowing attackers to forge tokens and impersonate users, including administrators. Its primary use case is for bug bounty hunters and web security professionals to illustrate how improper JWT implementation can lead to unauthorized access to sensitive application areas, such as admin panels. Notable features include detailed step-by-step instructions for executing the exploit using tools like Burp Suite and JWT Inspector.

mongobleed-scanner

2026-08-03 Python ★ 35
MongoBleed is a high-performance proof-of-concept scanner designed to identify vulnerable MongoDB instances affected by CVE-2025-14847, a pre-authentication heap memory disclosure vulnerability. Utilizing asynchronous I/O with Python's asyncio, the tool efficiently scans large network ranges, ensuring precise detection and minimal false positives by validating response lengths against the requested leak size, while automatically logging vulnerable targets. Additionally, it requires no external dependencies, making it straightforward to deploy in authorized security testing environments.

nuclei-MonaCodeScanner

2026-08-03 ★ 84
The Nuclei-MonaCodeScanner repository provides a set of custom Nuclei templates focused on source code security analysis, targeting vulnerabilities such as hardcoded secrets, configuration leaks, debug routes, and exposure of sensitive files. Designed for use in Static Application Security Testing (SAST) and CI/CD pipelines, these templates facilitate the identification of OWASP Top 10 vulnerability patterns within source code, enhancing security assessments and red team activities.

Pinakastra

2026-08-03 Go ★ 63
Pinakastra is an AI-powered penetration testing framework designed for automated reconnaissance and exploitation, specifically tailored for penetration testers and bug bounty hunters. It features extensive capabilities for subdomain discovery, live host probing, URL analysis, and active exploitation of vulnerabilities like XSS and SQL injection, enhanced by AI-driven vulnerability detection and smart payload generation to minimize false positives. The tool also generates customizable reports in various formats, thereby streamlining the assessment process and improving efficiency in security testing.

RedTiger

2026-08-03 Python ★ 16
RedTiger is an automated XSS (Cross-Site Scripting) vulnerability testing tool that streamlines security assessments by performing subdomain enumeration, link filtering, endpoint extraction, and XSS scanning. Notable features include intelligent filtering of endpoints, a rich terminal UI with detailed reporting, and dependency checking to ensure all required tools are available. The tool is designed to enhance testing efficiency by focusing on parameters in URLs, improving the accuracy of vulnerability assessments.

vasuki

2026-08-03 Shell ★ 20
Vasuki is an automation tool designed for security professionals that streamlines the process of subdomain enumeration and vulnerability scanning. It aggregates multiple reconnaissance tools to identify subdomains, check for subdomain takeover potential, and detect various injection parameters including XSS and SSRF. Notable features include integration with tools like Nuclei for vulnerability scanning, notification capabilities for scan results, and an organized output of findings in text files.

Web-Scraper

2026-08-03 Python ★ 35
Web Scraper is a Python-based tool designed for web hacking and assessment, featuring a suite of 20 widely-used functionalities for executing various attacks and reconnaissance tasks with a single command. Its notable features include ASN lookups, HTTP header analysis, subdomain discovery, vulnerability scanning, and more, providing users with a comprehensive toolkit for bug bounty and data extraction efforts. It operates on Python 3.7 or higher and is optimized for Linux environments.

JWTLens

2026-08-03 Java ★ 55
JWTLens is a comprehensive security scanner for JSON Web Tokens (JWTs) integrated with Burp Suite, designed to automatically detect and test for vulnerabilities across a wide array of JWT attack vectors. It incorporates 56 security checks, enabling both passive analysis and active exploitation tactics, including signature bypasses and algorithm confusion. Key features include a JWT Forge tab for live token editing, a built-in secret extractor to identify hardcoded secrets, and efficient request/response scanning capabilities for thorough JWT vulnerability assessments.

Admin-Panel-Finder-Of-Any-Website

2026-08-03 Perl ★ 18
The Admin Control Panel Finder is a Perl-based tool designed to identify potential admin login paths on websites, catering primarily to developers and security professionals for authorized testing. It automatically checks common admin panel URLs across various web technologies, such as PHP and ASP, and employs keyword detection for typical login fields, making it a lightweight and beginner-friendly tool for ethical hacking and cybersecurity education.

BugBoard

2026-08-03 HTML ★ 49
BugBoard is an open-source web application that acts as a centralized dashboard for cybersecurity tools, enabling users to efficiently identify and report vulnerabilities such as SQL Injection, XSS, and CSRF. Its modular design allows users to focus on specific vulnerabilities while providing a user-friendly interface that caters to both novices and experienced professionals in the bug bounty process. Notable features include comprehensive vulnerability assessments and an intuitive layout for streamlined navigation.

claude-security-research-skill

2026-08-03 Shell ★ 22
Claude Security Research Skill enhances the Claude AI with structured security assessment workflows, enabling it to effectively manage and execute security research across multiple phases, including reconnaissance, vulnerability scanning, and reporting. Notable features include tool chaining, automated phase management based on target types, and the capability for Claude to interpret tool outputs, suggest subsequent actions, and compile professional assessment reports. This skill integrates seamlessly into Claude's environment, facilitating detailed and methodical security assessments without generating payloads or exploit code.

HuntTheBug

2026-08-03 Shell ★ 60
HuntTheBug is an advanced reconnaissance framework tailored for bug bounty hunters, combining over 30 security tools into a streamlined workflow to facilitate automated vulnerability discovery. Notable features include parallel execution for enhanced speed, live domain verification, real-time Telegram notifications for immediate alerts, and comprehensive scanning capabilities for subdomains, URLs, and directories. This toolkit is specifically optimized for use on Kali Linux, ensuring efficient and effective reconnaissance processes.

ios-26-activation-research

2026-08-03 C ★ 31
The iOS 26 Activation Lock repository documents 31 firmware-level vulnerabilities found in iOS 26.3, specifically targeting the activation lock subsystem. It serves primarily as a resource for the security research community, featuring self-contained writeups for each vulnerability, ranking from critical to less severe, along with proof-of-concept implementations and exploitation scripts. Notable features include detailed descriptions, reproduction steps, and evidence for each finding, aiding researchers in understanding and possibly mitigating the identified security issues.

OnlyVulns

2026-08-03 Python ★ 12
OnlyVulns is a nonprofit, open-source platform designed for security researchers to publish vulnerability disclosures in a controlled and safe environment. It enables researchers to document their findings, including proof-of-concept submissions and technical write-ups, while allowing them to manage vendor communications and disclosure timelines autonomously. Key features include a non-corporate framework, an embargo process for pre-publication coordination, and options for community support and tipping, fostering a researcher-first approach to vulnerability disclosure.

pentest-agents

2026-08-03 Python ★ 813
The Pentest Agent Suite is an autonomous bug-bounty framework designed for use with Claude Code and six other AI coding tools, featuring a collection of 50 agents, 26 commands, and 19 CLI tools. It provides a comprehensive methodology for vulnerability hunting, including automated exploit chaining, endpoint tracking, semantic writeup searches, and installation compatibility across multiple development environments. Its core functionalities enable users to efficiently conduct security assessments and manage bounties via integration with live platforms and cost tracking mechanisms.

solana-security-standard

2026-08-03 JavaScript ★ 37
The Solana Security Standard (SOL-0XX) is a tool that integrates security rules into development environments to detect Solana-specific vulnerabilities in real time, based on insights from $514M worth of exploits. It features a comprehensive set of 52 rules covering various bug classes, with support for multiple IDEs and CI tools, and allows for easy installation through plugins for different platforms. This tool emphasizes immediate feedback on potential security issues as developers write code for Solana programs.

argo

2026-08-03 Python ★ 54
Argo is an LLM-native static vulnerability detection tool that analyzes source code to identify security vulnerabilities by simulating a human auditor's review process. It offers tailored auditing via archetype-driven prompts, adversarial validation, and multi-backend support while focusing on both general code audits and specialized bug-bounty triage modes. Notable features include threat-informed auditing, cross-checks against project documentation, opt-in remediation proposals, and a commitment to detection-only operations without executing the analyzed code.

bug-bounty

2026-08-03 PHP ★ 132
Bug Bounty is a comprehensive knowledge base designed for security researchers, penetration testers, and bug bounty hunters, featuring methodologies, cheatsheets, automation tools, wordlists, and real-world write-ups. Its primary use case involves equipping users with the necessary resources for web penetration testing, API security, cloud exploitation, and modern vulnerability assessment techniques. Notable features include battle-tested methodologies and a focus on ethical hacking practices, underscoring the importance of authorized testing only.

dioterms

2026-08-03 ★ 70
dioterms is a CC0-licensed framework designed to serve as the canonical language for vulnerability disclosure, facilitating open modifications through community contributions. Its primary use case involves standardizing disclosure policies across various platforms while ensuring accountability and consistency via a single-source architecture. Notable features include multiple term templates for different disclosure scenarios, support for translations, and integration with tools like policymaker for generating and verifying policies.

flounder

2026-08-03 TypeScript ★ 330
Flounder is an autonomous white-hat security auditing tool designed to automate the process of preparing, auditing, exploiting, and verifying security vulnerabilities in software systems. Its primary use case involves leveraging coding agents to analyze public-source or authorized targets, enabling an end-to-end audit workflow that includes mapping attack surfaces, constructing exploit paths, and generating reports based on execution-backed findings. Notable features include framework-agnostic reasoning, an autonomous audit loop for streamlined processes, and execution-grounded findings that validate vulnerabilities through real-world testing.

gerobug

2026-08-03 HTML ★ 104
Gerobug is an open-source, self-managed bug bounty platform designed for organizations to easily deploy their own bug bounty programs without incurring significant costs associated with third-party services. Key features include a streamlined installation process with a single command setup, robust security measures like email parsing and network segregation, and automated HTTPS configuration using NGINX and Let’s Encrypt. This solution facilitates efficient vulnerability reporting through an email parser and provides a dedicated dashboard for managing submissions.

HackerOne-Disclosed-Reports

2026-08-03 ★ 40
HackerOne Disclosed Reports is a comprehensive, auto-updated database that aggregates publicly disclosed vulnerability reports from HackerOne, featuring nearly 10,000 entries categorized by severity, weakness, and bug bounty programs. Its notable features include statistical insights on bounties and vulnerabilities, structured metadata for individual reports, and various browsing options for easy access to specific data through categories and leaderboards. This tool serves as a valuable resource for security researchers and professionals seeking to analyze disclosure trends and vulnerabilities in the bug bounty landscape.

kali-dockerized

2026-08-03 Dockerfile ★ 24
The "kali-dockerized" repository provides Docker images for Kali Linux and Ubuntu 26.04, tailored for bug bounty programs, penetration testing, security research, computer forensics, and reverse engineering. Key features include the use of the official Kali Linux Docker image with systemd support, compatibility with Docker's host network driver for enhanced performance, and tools for local deployment on Kubernetes clusters. The setup also includes installation instructions for utilities such as Dive for image exploration and Trivy for vulnerability scanning.

open-kritt

2026-08-03 JavaScript ★ 2034
open·kritt is an open-source security research platform designed to orchestrate AI agents for the identification and validation of vulnerabilities in code repositories. It enables users to create custom workflows for security research, run scans on local or remote codebases, and prioritize findings with configurable severity rankings and automatic de-duplication. Notably, it supports integration with various AI model providers, allowing for flexible model access and requiring minimal setup for operation.

orgs-data

2026-08-03 Shell ★ 88
The orgs-data repository is designed to assist bug bounty hunters in identifying leaked secrets, vulnerabilities in GitHub Actions workflows, and conducting reconnaissance by gathering information from organizations' repositories. Notable features include scripts for listing GitHub organization names and tracking programs for potential vulnerabilities, along with a collaborative approach to maintain an up-to-date database of organizations and bug bounty programs.

policymaker

2026-08-03 TypeScript ★ 16
Policymaker is an open-source tool that facilitates the rapid creation of vulnerability-disclosure policies, safe harbor clauses, and security.txt files without the need for legal assistance. It streamlines the process through a user-friendly wizard, producing defensible documents based on standardized, lawyer-reviewed language sourced from the dioterms framework. Key features include support for DNS Security TXT records and complete public domain output, ensuring compliance with current vulnerability disclosure standards.

actions-all-in-one

2026-08-03 ★ 21
SecureStack provides an all-in-one GitHub Action designed to enhance security across GitHub project workflows by integrating several security analyses into a single step. It performs sensitive data detection, software composition analysis for vulnerable dependencies, scans for cloud misconfigurations and web vulnerabilities, and generates a Software Bill of Materials (SBOM) for comprehensive security coverage. Notable features include customizable severity settings for different analyses and a user-friendly setup utilizing GitHub Secrets for API key management.

advisor

2026-08-03 Makefile ★ 40
Alcide Kubernetes Advisor is an agentless tool designed for auditing and ensuring compliance of Kubernetes clusters, focusing on enhancing DevSecOps workflows by providing early security scans. Its notable features include vulnerability scanning of Kubernetes infrastructure, detection of misplaced secrets and excessive access permissions, workload hardening, and application of security best practices for Istio and Ingress Controllers. The tool seamlessly integrates into CI/CD pipelines and offers a baseline profiling capability to streamline issue detection pertinent to a specific cluster.

aqua-microscanner-plugin

2026-08-03 Java ★ 35
The Aqua Jenkins MicroScanner Plugin facilitates the scanning of Docker builds within Jenkins for OS package vulnerabilities, ensuring the security of containerized applications. It integrates seamlessly into both Freestyle and Pipeline jobs, allowing users to configure vulnerability scans as part of their build process. Notable features include customizable actions for handling high-severity vulnerabilities, detailed scanning output in both console and HTML formats, and ease of setup requiring only Docker installation and token configuration.

avain

2026-08-03 Python ★ 67
AVAIN is an automated vulnerability analysis framework designed for IP-based networks, leveraging a modular architecture to conduct comprehensive assessments of both networks and individual hosts. It features collaborative modules that facilitate reconnaissance, vulnerability correlation, and active detection of security issues, culminating in a vulnerability score to gauge overall security. Noteworthy capabilities include simple result sharing, extensive module configurability, and the ability to integrate various tools, making it a robust platform for penetration testing and security evaluation.

awesome-software-supply-chain-security

2026-08-03 ★ 54
The "Awesome Software Supply Chain Security" repository provides a curated list of tools and resources aimed at enhancing security throughout the software supply chain lifecycle. It covers various aspects, including Software Bill of Materials (SBOM), Software Composition Analysis (SCA), Static Application Security Testing (SAST), and tools for secret detection and malware analysis. Notable features include extensive categorizations of tools for CI/CD practices, Kubernetes security, and risk management, offering a comprehensive landscape for professionals seeking to bolster supply chain integrity.

badmoodle

2026-08-03 Python ★ 63
badmoodle is a community-driven vulnerability scanner designed specifically for Moodle platform instances, aimed at penetration testers and security researchers. It identifies both official and community-discovered vulnerabilities, allowing users to operate in check mode for detection or exploit mode to validate and leverage identified vulnerabilities. Notable features include its modular architecture for easy integration of community vulnerability modules, multiple testing levels, customizable output options, and capability to scrape the latest vulnerabilities from Moodle's security resources.

burp-bounty

2026-08-03 BlitzBasic ★ 80
Burp Bounty is an extension for Burp Suite designed to enhance the capabilities of its scanning features by providing additional profiles for both active and passive scanning. Its primary use case is to facilitate vulnerability assessment by identifying misconfigurations and sensitive information exposure in various environments, particularly in Linux configurations. Notable features include predefined profile sets for scanning multiple common configurations and vulnerabilities, such as Apache2, MySQL, and JWT tokens.

clj-nvd

2026-08-03 Clojure ★ 15
clj-nvd is a Clojure tool designed to check dependencies specified in `deps.edn` against known security vulnerabilities from the National Vulnerability Database. It offers commands such as `check`, `update`, and `purge`, and generates detailed reports on vulnerabilities, with configuration options available through a dedicated `clj-nvd.edn` file. This tool acts as a wrapper around the existing lein-nvd, utilizing its functionality while adapting it for the Clojure tools.deps ecosystem.

collector

2026-08-03 Python ★ 156
Collector is an automated tool designed for identifying XSS vulnerable parameters across entire domains by leveraging the Wayback Machine. Key features include comprehensive crawling of websites and JavaScript files, advanced error handling, and the capability to collect GET parameters. This tool facilitates a systematic approach to vulnerability assessment in web applications.

container-auto-scan

2026-08-03 Python ★ 23
Lacework Auto Scanner is a tool designed to automate vulnerability assessments for active containers in a Lacework account, streamlining the scanning process via its API or inline scanner capabilities. It efficiently utilizes a local cache to skip rescans of recently assessed containers, with flexible configuration options for scan frequency and targeted registries. Notably, it supports Inline Scanning for containers lacking registry integration, enhancing its versatility and effectiveness in diverse environments.

CORS-Scanner

2026-08-03 Go ★ 30
CORS-Scanner is a Go-based tool designed to identify CORS misconfiguration vulnerabilities in web applications. It allows users to specify origin headers and cookies for testing and processes line-delimited domains to check for vulnerabilities such as reflected origins with credentials and wildcard configurations. Notable features include customizable options for origin headers and cookie handling, as well as the capability to input multiple domains efficiently for scanning.

cybersecurity-dynamic-analysis

2026-08-03 ★ 14
The "cybersecurity-dynamic-analysis" repository is a curated collection of dynamic application security testing (DAST) tools, libraries, and frameworks aimed at enhancing vulnerability scanning processes. It primarily assists developers and security professionals in identifying and debugging vulnerabilities that static analysis may overlook, by evaluating applications during runtime. Notable features include support for multiple programming languages and links to various tools like Microsoft IntelliTest, KLEE, and Valgrind for dynamic analysis tasks.

dorkScanner

2026-08-03 Python ★ 286
DorkScanner is a search engine dorking tool that allows users to scrape search engines for vulnerable URLs based on user-defined queries. It is primarily used by security auditors and researchers to uncover hidden information on public websites. Notable features include support for multiple search engines (Google and Bing), customizable query parameters, and the ability to specify the number of pages and processes for enhanced searching efficiency.

erebus

2026-08-03 Go ★ 134
Erebus is a configurable parameter-based vulnerability scanner that utilizes YAML templates to identify vulnerabilities across multiple targets efficiently, ensuring zero false positives. Its notable features include an intercepting proxy that allows users to dynamically test parameters as they browse web applications, along with built-in support for updating and downloading community-contributed vulnerability templates. This tool is designed for rapid scanning of large networks, making it ideal for penetration testers and cybersecurity researchers.

FazScan

2026-08-03 Perl ★ 88
FazScan is a versatile vulnerability scanning and penetration testing tool implemented in Perl, designed to assess various web vulnerabilities, including SQL injection and CMS-specific weaknesses. With 18 distinct options, it enables users to perform automated scans for common vulnerabilities, detect content management systems, bypass WAF protection, and even conduct denial of service attacks. Its cross-platform compatibility allows for deployment on Linux, Windows, and Android systems.

FireStorePwn

2026-08-03 Shell ★ 65
FireStorePwn (fsp) is a vulnerability scanner designed to analyze APK files for weaknesses in Firestore database security configurations, assessing both authenticated and unauthenticated access. Its primary use case is to identify insecure rules that could allow unauthorized data manipulation or access, potentially resulting in data theft and increased billing. Notable features include the ability to scan APKs with or without authentication using both user credentials and tokens.

Frey-Ruck-Attack

2026-08-03 HTML ★ 13
The Frey-Rück Attack implementation allows for the extraction of the ECDSA secret key ("K") from vulnerable Bitcoin transactions. This tool is particularly useful for cryptocurrency analysts and researchers studying signature vulnerabilities in blockchain protocols, enabling them to restore Bitcoin wallets by solving the discrete logarithm problem through compromised signatures. Notable features include practical examples of vulnerable Bitcoin addresses and methodologies for conducting cryptanalysis efficiently.

Gopo

2026-08-03 Go ★ 12
Gopo is a proof-of-concept (PoC) framework designed for generating and executing multiple exploitation scripts compatible with XRAY V2's PoC functionality. It facilitates vulnerability scanning by allowing users to load and execute predefined or custom PoCs against specified targets, with options for proxy settings, threat management, and debugging features. Notable capabilities include the ability to handle rules with logical expressions, multi-threaded scanning, and customizable execution parameters to optimize performance and accuracy.

HexraysToolbox

2026-08-03 Python ★ 485
HexRays Toolbox (hxtb) is a versatile set of IDAPython scripts designed for identifying and analyzing code patterns in binaries across various processor architectures. Its primary use cases include vulnerability scanning, malware analysis, and proving code similarities, thus making it valuable for security analysts and reverse engineers. Notable features include a user-friendly GUI via hxtb_shell for query formulation, custom scripting capabilities, and batch processing scripts for enhanced automation.

htk-lite

2026-08-03 Python ★ 130
htk-lite is a streamlined version of the hackers-tool-kit, maintaining essential hacking capabilities while being lightweight. Its primary use case is to facilitate various penetration testing tasks. Notable features include easy installation with a simple Git clone, user-friendly command execution, and an update script for keeping the tool current.

jaeles-signatures

2026-08-03 ★ 329
The Jaeles Signatures repository provides a collection of default signatures for the Jaeles project, a framework designed for security scanning and vulnerability detection. Its primary use case is to enhance the scanning capabilities of Jaeles by allowing users to implement custom and predefined signatures targeting specific vulnerabilities, misconfigurations, and sensitive information. Notable features include easy integration with Jaeles, the ability to configure and reload signatures, as well as support for active and passive detection methodologies.

laravel-security-checker

2026-08-03 PHP ★ 51
The Enlightn Security Checker for Laravel is a tool designed to identify dependencies with known security vulnerabilities within Laravel applications. Utilizing an Artisan command, it allows developers to scan their composer.lock file for issues, with options to customize output format, exclude development dependencies, and manage caching directories for advisory databases. Notable features include flexibility in command parameters and integration with Composer for effective vulnerability management.

log4j-detector

2026-08-03 Java ★ 640
Log4J Detector is a scanning tool designed to identify vulnerable versions of the Log4J library, specifically addressing critical CVEs such as CVE-2021-44228 and related vulnerabilities. It meticulously analyzes the entire file system, including nested applications, to locate Log4J instances, even those obscured within complex structures like uber jars. Supporting multiple operating systems, this tool provides detailed reporting on the safety status of detected Log4J versions, facilitating comprehensive vulnerability assessments.

midas

2026-08-03 Python ★ 14
MiDas is a transformer-based tool designed for detecting vulnerability-fixing commits in software projects by utilizing a multi-granularity approach that examines commits at various levels (commit, file, hunk, line). Notable features include seven distinct feature extractors that leverage CodeBERT for contextual representation, enabling effective identification and extraction of relevant commit features. This tool facilitates improved vulnerability management and can be replicated using specific training processes and dataset requirements.

MyBBscan

2026-08-03 Python ★ 23
MyBBscan is a Python-based tool that scans the `/inc/plugins/` directory of MyBB 1.8 forums for known vulnerabilities in plugins. Its primary use case is to identify outdated or vulnerable plugins that could pose security risks, facilitating proactive remediation efforts. Notable features include simple command-line execution and clear user prompts for scanning specific forum URLs.

nessusbeat

2026-08-03 Go ★ 31
Nessusbeat is a Beat designed to monitor a local Nessus vulnerability scanner's reports directory, facilitating the export, parsing, and output of scan results to various supported Beat outputs. Its primary use case is to enhance vulnerability management workflows by automating the reporting process. Notable features include configurable report paths and potential future enhancements to support remote polling and API-based authentication.

OrgASM

2026-08-03 Python ★ 38
OrgASM is a modular attack surface mapping tool designed for discovering and enumerating potential vulnerabilities within a target's ecosystem, such as subdomains, IPs, and services. It integrates seamlessly with other tools like nuclei for scanning and wappalyzer for service detection, offering features such as a customizable configuration file, pivoting to related FQDNs, and the ability to automate scans using community APIs. Users can extend its functionality by adding custom APIs and tools, making it highly adaptable for various cybersecurity needs.

OWASP_ZAP_API_scripts

2026-08-03 Python ★ 11
The OWASP ZAP API scripts facilitate automated security testing for web applications by integrating with the OWASP ZAP penetration testing tool. Key features include scripts for API authentication and context management, allowing for streamlined attack simulations on platforms like Hackazon. These scripts are designed to be placed in specific directories within the ZAP framework for optimized functionality.

packj-github-action

2026-08-03 ★ 10
Packj is a GitHub Action that audits pull requests for malicious or risky open-source dependencies across NPM, PyPI, and RubyGems ecosystems. It employs static, metadata, and dynamic analysis to identify security vulnerabilities, flagging packages based on over 40 risky attributes derived from extensive research on supply chain attacks. Notable features include the ability to integrate seamlessly into GitHub workflows and provide feedback via comments on pull requests when risky dependencies are detected.

pathgro

2026-08-03 Scheme ★ 12
PathGro is a tool that enhances security testing by taking a brief list of path strings and generating extensive mappings through combinatorial growth, facilitating comprehensive path enumeration. It is primarily designed for dirbusting and forced browsing techniques to maximize attack surface coverage for software components handling pathnames. Notably, PathGro is implemented as a set of GNU Guile modules, providing command-line interface capabilities that allow for various combination generation methods.

r3con

2026-08-03 Shell ★ 34
R3CON is a multifunctional web reconnaissance and vulnerability scanning tool designed for rapid crawling and detailed vulnerability detection across various attack vectors, including XSS, SQL injection, and open redirections. It offers multi-threaded crawling capabilities and extensive reconnaissance features, such as DNS lookups, subdomain enumeration, and identification of vulnerable libraries. The tool allows users to perform both active and passive scans, providing a comprehensive solution for web application security assessments.

repo-lookout

2026-08-03 ★ 32
Repo Lookout is a large-scale security scanner designed to identify publicly exposed source code repositories that may contain sensitive information, which could lead to security incidents like data leakage and ransomware attacks. Its primary use case is to automatically detect such vulnerabilities and report them to the relevant domain's technical contact. Notable features include its focus on combating repository exposure and providing resources for mitigations related to various server software.

scanvus

2026-08-03 Python ★ 44
Scanvus is a credentialed authenticated vulnerability scanner designed for Linux hosts and Docker images, utilizing external vulnerability detection APIs such as Vulners and Vulns.io for comprehensive assessments. It supports various assessment types including localhost scans, remote SSH connections with key or password authentication, and scanning of Docker images. Notable features include detailed vulnerability reporting, interoperability with external APIs, and the ability to inventory target hosts.

security-checker

2026-08-03 PHP ★ 339
Enlightn Security Checker is a command-line tool designed to identify dependencies in your application with known security vulnerabilities by leveraging the Security Advisories Database. Its primary use case is to enhance application security during development, allowing for checks against defined vulnerabilities through commands that can display results in various formats and exclude development dependencies. Key features include customizable output formats, the ability to exclude certain vulnerabilities, and an API for integration into other codebases.

sqli-hunter

2026-08-03 Ruby ★ 433
SQLi-Hunter is an HTTP/HTTPS proxy server that serves as a wrapper for the SQLMAP API, designed to simplify the process of detecting SQL injection vulnerabilities. Its primary use case is to facilitate web application testing by providing tools for sending requests through a proxy, while also offering configurability for SQLMAP injection techniques, threading, and user-agent customization. Notable features include Docker support for easy deployment, the ability to persist output files, and various options to target specific hosts and adjust testing parameters.

sqlmap

2026-08-03 Python ★ 19
sqlmap is an open-source penetration testing tool designed to automate the detection and exploitation of SQL injection vulnerabilities in web applications. Its robust detection engine supports extensive capabilities such as database fingerprinting, data retrieval, and command execution on the underlying operating system, making it an essential tool for security professionals. Key features include a variety of switches for advanced testing, support for multiple databases, and the ability to access the file system via out-of-band connections.

subdover

2026-08-03 Python ★ 111
SubDover is a multi-threaded subdomain takeover vulnerability scanner written in Python 3, featuring over 88 fingerprints of potentially vulnerable services. It incorporates a built-in subdomain enumeration method and utilizes CNAME records for verification, allowing for quick scanning of both individual targets and lists of subdomains. Notable features include configurable threading for performance optimization, result saving capabilities, and a clean output format, making it a versatile tool for security professionals.

topscan

2026-08-03 Shell ★ 13
TopScan is an automated web vulnerability scanner designed to quickly identify security weaknesses in web applications. Its primary use case includes subdomain enumeration, active subdomain verification, and vulnerability checks for XSS, information disclosure, and subdomain takeover, among other features. Notable functionalities include gathering WHOIS information, extracting URLs from sitemaps, and detecting hidden servers and admin panels.

Vulmap-Windows

2026-08-03 PowerShell ★ 33
Vulmap-Windows is a network vulnerability mapping tool designed for Windows environments that identifies potential security vulnerabilities across various network services. Its primary use case is to assist security professionals in assessing network risks by providing comprehensive views of exploitable vulnerabilities. Notable features include automated scanning, integration with various vulnerability databases, and customizable reporting options.

vuln-scanner-flask

2026-08-03 Python ★ 28
vuln-scanner-flask is a web application designed for scanning vulnerabilities within websites and performing network exploitation and reconnaissance. Its notable features include an intuitive user interface, fast scanning capabilities, and functionalities for scheduling assessments and generating reports. The tool aims to facilitate security assessments while ensuring user-friendliness and security.

vulnscan-parser

2026-08-03 Python ★ 24
vulnscan-parser is a Python tool designed to parse and normalize results from various security scanning tools such as Nessus, Nmap, and Metasploit into a consistent object-oriented structure. It supports multiple file formats, allowing for efficient parsing of large files without memory issues while accommodating various output formats and structures. Key features include the ability to handle overlapping files, retain unique host objects, and extract relevant security findings for further analysis.

vulscanpro

2026-08-03 Python ★ 47
VulScanPro is an automated web vulnerability scanner designed to identify security weaknesses in domains through over 100 attack vectors, including SQL injection and Cross-Site Scripting. It not only detects vulnerabilities but also provides detailed descriptions and potential solutions for each issue. The tool features command-line options for customizable scanning, including the ability to skip certain tools for faster results.

Web-Fuzzer

2026-08-03 Python ★ 10
Web-Fuzzer is a robust web application fuzzing tool designed to automate the identification of vulnerabilities such as XSS, SQL injection, and command injection. Utilizing technologies like Selenium and BeautifulSoup, it crawls web applications to collect internal URLs, detects forms and input parameters for fuzzing, injects payloads, and analyzes responses for potential security flaws. Notably, it supports various injection types and can be used in testing environments like DVWA, with further enhancements planned for threading support and proxy usage.

WordPress_AutoExploiter

2026-08-03 Shell ★ 29
WordPress_AutoExploiter is a cybersecurity tool designed for exploiting vulnerabilities in various versions of WordPress, including Stored XSS, XML-RPC DDoS, and SQL Injection. Its primary use case is for penetration testing and security assessments to identify weaknesses in WordPress installations. Notable features include targeting specific vulnerable versions and facilitating exploitation techniques through a user-friendly interface.

www-project-zap

2026-08-03 HTML ★ 117
The OWASP ZAP project is a leading open-source web application security scanner designed to identify vulnerabilities in web applications during development and deployment. Its primary use case involves automated security testing, providing tools for both developers and security professionals to facilitate vulnerability detection and remediation. Notable features include a user-friendly interface, extensive API support, and a variety of plugins to enhance its scanning capabilities.

XAttacker

2026-08-03 Perl ★ 59
XAttacker is a web vulnerability scanner designed to automate the detection of security weaknesses in web applications. Its primary use case is to identify vulnerabilities such as SQL injection and cross-site scripting (XSS) through a user-friendly interface and customizable attack payloads. Notable features include multi-threaded scanning, a comprehensive report generator, and support for various web technologies.

xforwardy

2026-08-03 Python ★ 50
XForwardy is a Host Header Injection scanning tool designed to identify potential misconfigurations that may allow for Host Header Injections, as well as checking for CORS misconfigurations in specified URLs. It is a lightweight tool requiring minimal dependencies and is straightforward to install and execute.

BeeXSS

2026-08-03 Python ★ 38
BeeXSS is an automated tool that identifies Blind XSS (Cross-Site Scripting) vulnerabilities in web applications by scanning URL parameters and injecting payloads. Its notable features include the use of customizable Blind XSS-specific payloads, headless browsing via Selenium WebDriver for efficient scanning, and detailed reporting of potential vulnerabilities. The tool is intended for educational and ethical penetration testing purposes, ensuring users have permission to test the targeted applications.

bsqli

2026-08-03 Python ★ 21
Bsqli is a customizable vulnerability scanner designed to identify SQL injection vulnerabilities using a targeted payload list, ensuring high accuracy with minimal false positives. It is optimized for rapid scanning across multiple hosts and supports multithreading for enhanced performance. Notable features include support for both single URL and file-based target inputs, as well as options for output management and SSL verification settings.

firmware-analysis-toolkit

2026-08-03 Python ★ 1583
The Firmware Analysis Toolkit (FAT) is designed to assist security researchers in analyzing and identifying vulnerabilities within IoT and embedded device firmware by providing automated firmware emulation capabilities based on Firmadyne. Key features include the ability to run firmware images in a controlled environment without the need for a PostgreSQL database, as well as streamlined setup and interaction via Python scripts, enabling real-time testing and network interface configuration.

harbor-scanner-aqua

2026-08-03 Go ★ 36
The Harbor Scanner Adapter for Aqua Enterprise serves as a bridge between the Harbor scanning API and Aqua Enterprise's scanning capabilities, enabling vulnerability scanning of container images stored in the Harbor registry. Notable features include its implementation of the Pluggable Scanners API, which allows for ad hoc scanning and the generation of vulnerability reports, while also requiring specific version dependencies and configurations to function properly. The adapter does not provide visibility or enforcement for Aqua's image assurance policies, which must be managed via the Aqua Management Console.

LMAP

2026-08-03 ★ 31
LMAP (Large Language Model Mapper) is an out-of-the-box evaluation tool for large language models (LLMs), aimed at aiding developers and compliance teams in assessing security and safety risks associated with LLM deployments. It includes features such as universal HTTP access for various LLMs, a user-friendly GUI for ease of use, multi-objective testing capabilities, automated and manual redteaming modules, and customizable datasets for specific applications. Additionally, LMAP streamlines the evaluation process by generating formatted reports compatible with CI/CD pipelines, ensuring comprehensive vulnerability assessment pre- and post-deployment.

nessus

2026-08-03 ★ 73
The Cracked Nessus in Docker repository provides a Dockerized version of the Nessus vulnerability scanner, facilitating easy setup and deployment. Its primary use case is to enable security professionals to run Nessus scans in a contained environment, allowing for quick administration and updates via simple Docker commands. Notable features include automated installation through Docker, a straightforward user interface accessed via a web browser, and commands for migrating data between container versions.

network-vulnerability-scanner

2026-08-03 Go ★ 10
The network-vulnerability-scanner is a tool designed to identify vulnerabilities within networked systems by analyzing hosts and services for known security flaws. Its primary use case is to enable network administrators and security professionals to assess the security posture of their network infrastructure. Notable features include support for various network protocols, customizable scanning options, and detailed reporting on discovered vulnerabilities and recommended mitigations.

neural-network-hacking

2026-08-03 Python ★ 131
This repository provides a structured introduction to offensive techniques that exploit neural networks, focusing on areas such as bug hunting, malware injection, and information extraction. Each technique is accompanied by practical exercises to facilitate hands-on learning. Notable features include detailed instructions for setting up a Python environment and using various ML tools, as well as a diverse range of attack scenarios aimed at enhancing understanding of security vulnerabilities in neural networks.

NextSploit

2026-08-03 Python ★ 93
NextSploit is a command-line utility for detecting and exploiting the Next.js vulnerability identified as CVE-2025-29927. It automates the process of identifying vulnerable Next.js versions and attempts to exploit the flaw by bypassing middleware protections, potentially allowing unauthorized access to restricted content. Notable features include automated version detection using Wappalyzer, mass URL scanning capability, and an integrated Chrome browser launch for exploitation tests.

RevOK

2026-08-03 Python ★ 27
RevOK is a cybersecurity tool designed to simulate malicious targets for testing security scanners and software that processes attacker-controlled data. Its core feature, the "stub" component, allows users to listen for incoming requests and serve crafted attack responses based on customizable templates and substitution lists. Notably, RevOK has been utilized to identify critical vulnerabilities, including XSS to RCE bugs in Metasploit Pro, highlighting its effectiveness in researching and weaponizing security scanner vulnerabilities.

StealthNewSQL

2026-08-03 Shell ★ 10
StealthNewSQL is an advanced command-line tool designed for detecting, exploiting, and securing NewSQL database vulnerabilities. It features capabilities such as DNS-based data exfiltration, advanced WAF evasion techniques, automated exploitation, and seamless integration with CI/CD pipelines, making it suitable for penetration testers, security researchers, and developers focused on database security. Notable functionalities include real-time monitoring, comprehensive reporting, and a modular plugin system for extending its capabilities.

Vulnerability-Scanner

2026-08-03 Python ★ 17
The Vulnerability Scanner is a user-friendly tool designed for beginners in cybersecurity, capable of scanning systems for vulnerabilities and gathering information on potential targets. It includes features like DNS enumeration, OS detection, service/version detection, and integration with the OWASP ZAP for comprehensive security assessments. The tool is specifically built for Kali and Parrot Linux environments and requires minimal prior knowledge, making it an ideal starting point for aspiring security professionals.

wacat

2026-08-03 TypeScript ★ 114
wacat is an automated web application testing tool that simulates chaotic input by navigating through a web application's links and forms in a random manner, providing comprehensive testing coverage. It offers advanced features like AI-driven error detection and content generation, supports various configurations for authentication, and can run in headless mode suitable for Continuous Integration (CI) pipelines. Built on Playwright, wacat is designed for user-defined behaviors and can detect a range of issues, making it ideal for thorough application assessments in a controlled environment.

xray-automation

2026-08-03 Shell ★ 20
The Xray automation script is a Bash utility designed for scanning websites for vulnerabilities using the Xray tool. It provides functionalities to scan multiple URLs from a text file or a single URL, with the added capability to download and install Xray if it is not already present. Notable features include comprehensive help documentation and the ability to output scan results both to a file and the terminal.

A.S.E

2026-08-03 PHP ★ 15
A.S.E (Automated Security Evaluator) is a vulnerability management tool designed to automate the process of evaluating software security by integrating with OWASP Dependency-Track. Its primary use case is to assess vulnerabilities based on real-world exploitability and notify relevant teams via Slack, leveraging CVE scoring models such as CISA KEV and EPSS. Notable features include the automation of CycloneDX SBOM generation, tiered alerting for critical vulnerabilities, and configurable thresholds for alerts sent to teams.

ALNUR

2026-08-03 Python ★ 12
ALNUR is an open-source end-to-end vulnerability scanner that evaluates application projects for security weaknesses, including CVEs in dependencies and potential risks in architecture, secret leaks, and agentic AI applications. Notable features include a comprehensive CVE scanner, in-depth architecture and standards compliance analysis, and support for various programming languages and frameworks, with customizable reporting options. The tool also offers optional LLM-enhanced analysis for generating executive summaries and remediation guidance.

ASST

2026-08-03 JavaScript ★ 190
OWASP ASST (Automated Software Security Toolkit) is an open-source, command-line web vulnerability scanner primarily focused on detecting security flaws in PHP and MySQL applications, while also capable of being extended to support additional programming languages. It provides detailed reports that not only identify vulnerabilities but also offer explanations and remediation strategies, thus educating developers on securing their code. ASST uniquely aligns its scanning approach with the OWASP Top 10 Web Application Security Risks, enhancing its effectiveness in comprehensive vulnerability assessment.

aur_checker

2026-08-03 Python ★ 11
aur_checker is a command-line security analysis tool designed for inspecting Arch Linux AUR PKGBUILD files to detect potential vulnerabilities. It employs a context-aware static analysis methodology, optionally enhanced with AI inspection, resulting in detailed risk assessments that include trust signals and explainable scoring. Key features include a user-friendly output format, JSON integration for CI purposes, and the ability to analyze multiple packages or files simultaneously.

brs-xss

2026-08-03 Python ★ 34
BRS-XSS is an advanced XSS vulnerability scanner designed for modern web applications, providing deterministic and auditable detection capabilities. It features context-aware scanning, WAF evasion techniques, and a comprehensive knowledge base for payload management, along with a user-friendly web interface that supports real-time monitoring, detailed reporting, and customizable scanning options. Notably, it includes a Pentesting Task Tree strategy engine for adaptive testing, A/B testing for strategy comparison, and multiple report formats for enhanced analysis.

BurpAPISecuritySuite

2026-08-03 Python ★ 335
BurpAPISecuritySuite is a professional-grade extension for Burp Suite that consolidates multiple functionalities for API reconnaissance, intelligent fuzzing, and AI-enhanced security testing into a single interface. It is designed to improve performance and usability by sharing resources across various tabs, thereby minimizing memory usage and CPU overhead while maintaining a stable and efficient testing environment. Notable features include support for REST, GraphQL, and SOAP APIs, as well as tools for passive discovery, fuzzing, and advanced security assessments based on the OWASP API Top 10 guidelines.

cache-commander

2026-08-03 Rust ★ 68
Cache Commander (ccmd) is a terminal UI tool designed for exploring, auditing, and managing developer cache directories on macOS and Linux. Its primary use case is to help developers identify and clean up accumulated cache data, scan for known CVEs, and manage outdated dependencies, all through an intuitive two-pane interface that supports multiple cache providers. Notable features include vulnerability scanning, reclaiming disk space from various cache types, and integration with AI for enhanced capabilities.

cd

2026-08-03 Shell ★ 50
CloudDefense.AI is an automated web application security testing tool designed to identify vulnerabilities such as SQL injection and cross-site scripting, enhancing overall application security. It supports various security assessments including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API scanning, facilitating a DevSecOps approach by integrating security assessments seamlessly into the development lifecycle. Notable features include its comprehensive application stack risk assessments and compatibility with multiple programming languages and integration points.

cent-nuclei-templates

2026-08-03 Python ★ 14
The cent-nuclei-templates repository provides a curated collection of 9,284 high-quality nuclei templates, generated and filtered through the cent tool for use with the Nuclei scanner. Its primary use case is to enhance vulnerability scanning by offering templates that are free from duplicates, noise, and outdated syntax, thereby improving accuracy and effectiveness in detecting vulnerabilities. Notable features include extensive deduplication processes, community-sourced additions, and ongoing maintenance scripts to ensure template quality and relevance.

chaca-scanner

2026-08-03 Rust ★ 41
Chaca is a native desktop web security scanner designed specifically for developers, providing fast and opinionated security audits of web applications through a user-friendly interface without requiring terminal use. It features both passive and active scanning capabilities, support for numerous content management systems and APIs, and generates detailed reports with filtering and export options. Additional highlights include a real-time progress dashboard, persistent scan history, and customizable scan presets, all built on a tech stack utilizing Rust, React, and Tauri.

claude-cybersecurity

2026-08-03 Shell ★ 215
Claude Cybersecurity is an AI-powered code security audit tool designed to enhance vulnerability detection and compliance verification through the integration of 8 parallel specialist agents. It stands out by addressing issues often overlooked by static analysis tools, such as business logic flaws and contextual authorization checks, while supporting a broader range of programming languages and providing in-depth threat intelligence. Notable features include seamless integration with Claude Code, zero configuration requirements, and extensive coverage of vulnerabilities including IaC and container security.

claude-pentest-skills

2026-08-03 Python ★ 33
Claude Pentest Skills is a structured penetration testing skill pack designed for Claude Code that employs an OWASP-based methodology to streamline web application security assessments. It features a 6-gate validation process to filter out false positives, a series of interactive slash commands for efficient testing, and automated report generation in both markdown and PDF formats, ensuring compliance with verification and documentation standards. The tool improves the efficiency and reliability of pentesting workflows by maintaining consistent coverage tracking and enforcing scope before testing.

clawsecure-openclaw-security

2026-08-03 HTML ★ 38
ClawSecure is an independent security scanning and auditing platform designed for the OpenClaw ecosystem, which focuses on ensuring the integrity and safety of AI agent skills and workflows. It features a proprietary 3-Layer Audit Protocol that has examined over 3,000 skills against all OWASP ASI Top 10 security vulnerabilities, revealing that 41% of audited skills contain security flaws. It also offers free developer tools to enhance functionality and user experience within the OpenClaw framework.

CloudVault

2026-08-03 Python ★ 11
CloudVault is an enterprise-grade security scanner designed for multi-cloud storage environments, specifically targeting AWS S3, Google Cloud Storage, and Azure Blob. It offers advanced attack chain analysis, automated permission checking, and comprehensive risk scoring, facilitating real-time discovery of exposed cloud resources through certificate transparency monitoring. Notable features include interactive text user interface (TUI), alerts integration with communication platforms, compliance mapping, and various export formats for reporting and remediation.

CorsOne

2026-08-03 Python ★ 29
CorsOne is a specialized security testing tool for detecting Cross-Origin Resource Sharing (CORS) misconfigurations in web applications. It efficiently tests over 40 CORS bypass techniques, providing accurate results with low false positives and supporting advanced features such as customizable origin testing, proxy configurations, and multiple output formats for comprehensive reporting. The tool employs asynchronous operations for high performance and includes options for easy integration and flexible request handling.

Critikal

2026-08-03 Python ★ 14
Critikal is an autonomous security research agent specifically designed for smart contracts, capable of identifying exploitable vulnerabilities in blockchain protocols through a comprehensive analysis process. It ingests repository data, performs reconnaissance, maps the attack surface, and validates its findings, generating proof-of-concept tests using Foundry along with detailed audit reports in HTML and Markdown formats. Notable features include multi-model support for AI analysis, an integrated knowledge graph, and a user-friendly TUI demo for easy interaction.

CVE-2025-58434-AND-59528-POC

2026-08-03 Python ★ 19
The Flowise Dual CVE PoC is a proof-of-concept tool for exploiting two critical vulnerabilities (CVE-2025-58434 and CVE-2025-59528) in the Flowise platform, enabling an attacker to achieve unauthenticated account takeover followed by remote code execution in an automated manner. It leverages a flawed password reset mechanism and unsanitized user input in JavaScript execution to facilitate these exploits, making it particularly dangerous for both cloud and self-hosted deployments. The tool includes modular functionality for conducting attacks and is intended solely for authorized security research purposes.

discoursemap

2026-08-03 Python ★ 22
DiscourseMap is an advanced security scanner designed specifically for Discourse forum platforms, offering over 25 specialized security modules for comprehensive assessments. It features capabilities such as CVE detection, plugin analysis, and API testing, all optimized for quick performance and reliability, delivering detailed reports in multiple formats. The tool is well-suited for vulnerability detection and compliance verification, making it essential for securing Discourse environments.

docker-registry-ui

2026-08-03 JavaScript ★ 16
Docker Registry UI provides a modern web interface for managing Docker registries with enhanced features such as vulnerability scanning through Trivy, bulk operations, and multi-registry support. It facilitates repository and tag management while offering storage analytics and a responsive design. The tool is designed for both local and production setups, allowing users to quickly deploy and manage registries efficiently.

EthicalHackingTools

2026-08-03 Python ★ 15
The HackerAI Framework (Project Sirra) is a modular security testing environment tailored for ethical hackers and security researchers, emphasizing cross-platform compatibility including mobile devices. It features a universal orchestrator for module management, built-in security scanning capabilities, advanced web scanning with asynchronous support, and the ability to export results in multiple formats like HTML and JSON.

FastCVE

2026-08-03 Python ★ 61
FastCVE is a command-line tool designed for rapid and efficient querying of the Common Vulnerabilities and Exposures (CVE) database, enabling users to retrieve detailed information about security vulnerabilities, including descriptions, CVSS scores, and references to advisories. Notable features include its Docker containerization, automatic database management with PostgreSQL, and the ability to populate and incrementally update the local vulnerability database from multiple external sources, making it an effective solution for security professionals and developers aiming to monitor and assess vulnerabilities in their systems and applications.

Fathometer

2026-08-03 Python ★ 36
Fathometer is a self-hosted CVE intelligence tool designed for administrators of plain root servers and VPSes, providing context-specific assessments of vulnerabilities. The tool leverages Trivy for scanning local hosts while utilizing a language model to evaluate the relevance of CVEs, ensuring that only pertinent findings are highlighted. Its streamlined interface features a fleet dashboard and triage workspaces tailored for individual operators, focusing on actionable insights without the complexity of extensive features common in enterprise solutions.

GVM-Docker

2026-08-03 XSLT ★ 16
GVM-Docker is a containerized deployment of the Greenbone Vulnerability Manager and OpenVAS, designed for vulnerability scanning and management. It supports both AMD 64-bit and ARM 64-bit architectures, facilitating easy installation and upgrades through Docker on Linux systems and Windows with WSL 2. Notable features include compatibility with various systems, an upgrade-safe architecture, and guidance on maintaining PostgreSQL, ensuring a seamless user experience for security assessments.

hackbrowser-mcp

2026-08-03 TypeScript ★ 21
hackbrowser-mcp is a specialized browser-based security testing tool that empowers AI agents to identify vulnerabilities within web applications. Unlike typical browser MCPs focused on automation tasks, hackbrowser-mcp utilizes the Model Context Protocol to facilitate in-depth security assessments, including injection testing and access control evaluations across multiple isolated user sessions. It features 39 integrated security tools, full traffic capture, and advanced reporting capabilities, enabling detailed vulnerability discovery through natural language instructions.

honeyscanner

2026-08-03 Python ★ 66
Honeyscanner is a vulnerability analyzer designed for honeypots, capable of automatically simulating various cyber attacks to assess the security posture of the honeypot. It employs a range of tactics, including exploitation of software vulnerabilities, denial of service, and fuzzing techniques, delivering comprehensive evaluation reports that provide security enhancement recommendations. Targeted at security enthusiasts and organizations, Honeyscanner serves as an essential tool for validating the robustness of honeypot implementations.

ICS-Ninja-Scanner

2026-08-03 Python ★ 10
ICS Ninja Scanner is a specialized security assessment tool for industrial control systems (ICS) that supports comprehensive device discovery and testing across 11 protocols, including Modbus and S7. It features built-in CVE correlation, compliance mapping to frameworks like IEC 62443 and NIST 800-82, and offers functionalities such as scan diffing and industry-specific scan profiles, ensuring a thorough and tailored assessment for operational technology environments.

JitterBug

2026-08-03 Shell ★ 13
JitterBug is a reconnaissance tool designed to conduct passive information gathering by querying third-party databases for basic data, open ports, and potential CVEs associated with target IPs, all without direct interaction with the targets. Its stealthy operation ensures minimal detection risk, making it suitable for pre-attack reconnaissance and security assessments. Notable features include the ability to operate without direct engagement with targets and seamless integration within the DiaLog Project.

Libellux-Up-and-Running

2026-08-03 ★ 69
Libellux: Up & Running is a comprehensive guide for installing open-source security software from source, focusing on implementing a Zero Trust Network to bolster existing application security. The tool provides detailed documentation for notable security solutions including WireGuard for VPN, OSSEC for intrusion detection, Greenbone for vulnerability management, and ClamAV for antivirus. This resource is geared towards enhancing threat detection and prevention capabilities within various IT environments.

nextgenmap

2026-08-03 Python ★ 12
NextgeNmap is a security-focused automation GUI for Nmap designed for security operations and systems teams, enabling repeatable and efficient scans while minimizing noise in reporting. Key features include curated scan profiles, automated scheduling, integration with community scripts (like SearchSploit), and the generation of HTML reports for stakeholder presentation, all provided in a user-friendly cross-platform desktop application.

nuclei-plugin

2026-08-03 Java ★ 16
Nuclei is a fast tool for configurable targeted vulnerability scanning based on templates offering massive extensibility and ease of use.

octofleet

2026-08-03 TypeScript ★ 19
Octofleet is an open-source endpoint management platform designed to facilitate the monitoring and management of a fleet of devices from a unified dashboard. Its primary use case involves deploying software, tracking vulnerabilities, managing patches, and controlling devices securely and efficiently. Notable features include a lightweight agent footprint, real-time hardware and software inventory, remote job execution capabilities, a comprehensive security center with vulnerability scanning, and extensive patch management tools.

omnisci3nt

2026-08-03 Python ★ 369
Omnisci3nt is a unified web reconnaissance toolkit designed for cybersecurity professionals, ethical hackers, and security researchers, enabling automated analysis of critical domain-related data such as subdomains, SSL/TLS certificates, and exposed services. Its notable features include IP and WHOIS lookups, DNS enumeration, port scanning, and web crawling, all aimed at enhancing visibility into a domain's attack surface for security assessments and threat modeling. The tool is intended for authorized testing and provides a streamlined workflow for comprehensively analyzing the external exposure of web assets.

pentester-mcp

2026-08-03 Python ★ 52
Pentester-MCP is an open-source penetration testing toolkit that integrates over 200 popular cybersecurity tools via the Model Context Protocol (MCP), enabling AI assistants to autonomously conduct penetration tests. Notable features include intelligent tool execution generated from cheat sheets, AI-optimized documentation for argument handling, and secure operation through Docker sandboxing, isolating tools from the host system to prevent dependency clutter. The toolkit covers various categories including reconnaissance, web exploitation, and network security, making it a comprehensive solution for automated penetration testing.

pentesting-cyber-mcp

2026-08-03 JavaScript ★ 27
Pentesting Cyber MCP is a framework that provides standardized server implementations for 50 popular security tools via the Model Context Protocol (MCP), facilitating automation in pentesting and bug bounty tasks. Each MCP server encapsulates a security tool with a uniform interface, making it interoperable with any MCP-compatible client and allowing seamless integration into security assessments. Notable features include a wide range of tools covering reconnaissance, vulnerability scanning, and exploitation, all accessible through standard MCP interfaces.

perseus

2026-08-03 Shell ★ 67
Perseus is an interactive security assessment tool that enhances Claude Code's capabilities by facilitating autonomous penetration testing of your codebase. It supports multiple programming languages and frameworks, automatically detecting the project's environment and vulnerabilities across various dimensions, including API security and infrastructure. Notable features include smart auto-detection, engagement modes for different environments, and a structured four-phase assessment methodology to ensure comprehensive evaluation and reporting of security issues.

public-skills-builder

2026-08-03 Python ★ 223
Public Skills Builder is a tool designed to generate Claude Code bug bounty skills by analyzing and extracting valuable data from over 500 public HackerOne reports and GitHub writeups. It produces 18 structured skill files, each targeting a different vulnerability class, complete with real-world techniques, payloads, and methodologies essential for enhancing bug hunting skills. Notable features include the ability to work exclusively with publicly available data and the generation of targeted skill files ready for integration with Claude Code.

pwned-deps

2026-08-03 Python ★ 164
`pwned-deps` is a multi-ecosystem CLI tool designed for quickly identifying compromised package versions in developer lockfiles, such as those used in npm, PyPI, Maven, Cargo, Go, and RubyGems. It provides rapid assessments—flagging risks like supply-chain malware and hijacked packages—by leveraging data from public APIs and curated feeds, with output options including terminal reports, JSON, and SARIF for integration into code scanning platforms. Key features include support for various lockfile formats, one-shot scans, and continuous monitoring modes.

qryon

2026-08-03 Rust ★ 11
Qryon is a security vulnerability scanning tool designed to rapidly identify issues within codebases, boasting scan times significantly faster than competing tools, capable of analyzing up to 1 million lines of code in under a minute. It supports 28 programming languages with a rich set of over 647 security rules covering various vulnerabilities, including SQL injection and hardcoded secrets, while offering features like interactive TUI for browsing findings, AI-powered triage, and integration with CI/CD pipelines via SARIF output. The tool leverages native Rust matchers for optimal performance and provides flexible installation options across various platforms.

rag-security-scanner

2026-08-03 Python ★ 73
RAG/LLM Security Scanner is a professional security testing tool designed to identify critical vulnerabilities in Retrieval-Augmented Generation (RAG) systems and large language model (LLM) applications, such as chatbots and knowledge retrieval systems. Notable features include advanced prompt injection detection, data leakage assessments, function abuse testing, and comprehensive reporting capabilities, making it suitable for both demo and production environments. The tool supports easy integration with popular AI systems and provides detailed JSON/HTML reports with actionable insights.

react2shell-ultimate

2026-08-03 Python ★ 152
React2Shell Ultimate is a professional vulnerability scanner specifically designed for detecting the CVE-2025-66478 Remote Code Execution (RCE) vulnerability in Next.js applications utilizing React Server Components. Notable features include advanced exploitation capabilities, sophisticated techniques for WAF bypass, multiple scanning modes, and a full-featured web interface for interactive use and API access, making it suitable for authorized security testing and research.

RedTiger-Tools

2026-08-03 Python ★ 686
RedTiger-Tools is a versatile automation tool designed for penetration testing (pentesting) and open-source intelligence (OSINT) that aims to consolidate multiple operations into a single, configurable platform. It features a plugin system for extending functionality, centralized configurations using JSON files, and dual operation modes (CLI and interactive interface), ensuring compatibility with both Windows and Linux environments while adhering strictly to legal and ethical standards for usage.

safelog4j

2026-08-03 Java ★ 43
Safelog4j is an instrumentation-based security tool designed to help teams identify, verify, and mitigate the log4shell vulnerability (CVE-2021-45046) without the need for scanning or upgrading log4j. The tool utilizes interactive application security testing (IAST) to confirm exploitability and runtime application self-protection (RASP) to prevent exploitation by disabling the vulnerable JNDI lookup code dynamically. Unlike traditional scanning methods, Safelog4j provides greater accuracy and speed by operating from within the running application context.

SCOUT

2026-08-03 Python ★ 10
SCOUT is an advanced firmware analysis platform designed for product security and internal red-team operations, transforming raw firmware blobs into evidence-backed exploitability chains and lab-bounded proof-of-vulnerability modules. It features a hybrid analysis engine capable of auditing both ELF binaries and shell scripts, emphasizing controlled weaponization and audit-ready reporting while reducing false positives. Notably, SCOUT prioritizes detailed evidence lineage and supports a structured approach to exploit development, favoring higher fidelity over traditional bulk scanning techniques.

secgate

2026-08-03 Python ★ 12
SecGate is a lightweight, integrated security tool for Linux servers that combines gateway authentication, attack monitoring, vulnerability scanning, and AI assistance into a single package with minimal resource requirements. It offers one-command deployment, operates with around 120MB of memory, and includes unique features such as customizable TCP port authentication, multi-node management via SSH, and comprehensive security dashboards. Ideal for individual developers and multi-service deployments, SecGate provides a zero-configuration solution for rapid security enhancements.

Secrover

2026-08-03 Python ★ 253
Secrover is an open-source security auditing tool that generates comprehensive, human-readable security reports, focusing on vulnerabilities in dependencies, code, and domains. Its notable features include easy setup via YAML configuration, automation capabilities with scheduled scans and GitHub Actions, cross-platform compatibility, and flexible report exports to various remote destinations. The tool aims to provide actionable insights for users, making it accessible for both technical and non-technical audiences.

ShubhamWebScript-Website-vulnerability-Checker

2026-08-03 Python ★ 40
ShubhamWebScript is a Python-based website vulnerability checker designed for educational and ethical hacking purposes, allowing users to assess the security of web applications through automated scanning of parameter-based URLs. It detects common vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), and Remote Code Execution indicators, while also performing server header fingerprinting. The tool features both single and bulk URL scanning capabilities, making it beginner-friendly and suitable for learning basic web security practices.

SmartCode-Guard

2026-08-03 Java ★ 20
SmartCode-Guard is an AI-powered static code analysis tool specifically designed to identify security vulnerabilities in Java source code. It integrates a modular architecture that includes a parser for extracting code structure, a rule engine for detecting common security anti-patterns, and an AI engine for deep semantic analysis, making it highly effective for enforcing secure coding practices and allowing for customization through extensible security rules. Notable features include static rule enforcement and intelligent analysis for preparing code snippets for LLM-based audits.

vigil

2026-08-03 JavaScript ★ 19
Vigil is an open-source, AI-powered security operations platform designed for comprehensive vulnerability management, incident response, and compliance tracking within a unified Express.js framework. Key features include six built-in scanners (Nmap, Nuclei, Trivy, Nikto, OpenSSL, DNS), 20 autonomous agents for parallel operations, and support for custom AI integrations, all while maintaining a lightweight architecture without external dependencies. The platform also offers advanced functionalities like role-based access control, two-factor authentication, and an encrypted credential vault for enhanced security.

VISTA

2026-08-03 Java ★ 21
VISTA (Vulnerability Insight & Strategic Test Assistant) is an AI-driven extension for Burp Suite that enhances security testing through real-time traffic analysis and intelligent vulnerability detection. It offers notable features such as an interactive AI advisor for context-aware testing suggestions, customizable analysis templates, and a comprehensive payload library, enabling pentesters to conduct faster and more systematic assessments. Additionally, VISTA supports multiple AI providers, including OpenAI and Azure, to tailor its guidance to user needs.

vuln-scout

2026-08-03 Python ★ 24
VulnScout is a security analysis tool designed for whitebox security reviews, offering offline quick scans and evidence-backed verification for identifying vulnerabilities within codebases. It provides features such as shared findings documentation, various output formats for reports, and support for multiple deep analyzers, making it suitable for integration into continuous integration workflows. Notably, it operates without requiring a remote service and includes capabilities for auditing, verifying findings, and generating structured reports.

vulnhawk

2026-08-03 Python ★ 82
VulnHawk is an AI-powered code security scanner designed to identify vulnerabilities that conventional SAST tools like Semgrep and CodeQL may overlook, particularly those related to business logic flaws where the absence of expected patterns is key. It employs contextual code analysis by comparing similar components across a codebase, facilitating the detection of security issues without the need for extensive configuration or custom rules. Notably, it supports various AI backends, integrates easily into CI/CD pipelines, and operates entirely locally or privately using options like Ollama.

ward

2026-08-03 Go ★ 334
Ward is a specialized security scanner for Laravel applications that performs targeted security checks by understanding the application's structure, including routes, models, and configuration files. Notable features include live vulnerability lookups against the Packagist advisory database, comprehensive checks for common misconfigurations, and the ability to generate detailed reports on security findings, making it a valuable tool for both development environments and CI/CD pipelines.

wordfence-cli

2026-08-03 Python ★ 158
Wordfence CLI is a high-performance security scanner designed for detecting PHP malware and vulnerabilities in WordPress installations. Written in Python, it operates in a multi-process environment, allowing for parallel scans, scheduling, and integration with other commands via input and output piping. Notable features include the ability to scan directories for malware and vulnerabilities efficiently, as well as comprehensive installation and configuration documentation.

Worm-GPT-LLM-2026

2026-08-03 C++ ★ 29
Worm GPT Core is an advanced adversarial prompt delivery framework designed for AI researchers and cybersecurity professionals to evaluate and exploit vulnerabilities in large language models (LLMs). It automates the delivery of jailbreak prompts and features innovative mechanisms for alignment evasion, multi-threaded prompt execution, and seamless integration with both commercial and local LLMs. The tool aims to enhance penetration testing capabilities within AI systems while ensuring zero telemetry and optimized performance.

wp-taint-scan

2026-08-03 Go ★ 21
wp-taint-scan is a specialized static analysis tool designed to detect genuine vulnerabilities in WordPress plugins using a native Go-based taint analysis engine. It enables users to scan multiple versions of plugins in parallel and offers features such as detailed source-to-sink dataflows, version diffs to track changes in vulnerabilities, and a thorough understanding of the WordPress security model, significantly reducing false positives. Notable vulnerability classes include SQL injections, XSS, path traversal, and missing authorization issues, making it an essential tool for enhancing WordPress security.

wprecon

2026-08-03 Go ★ 20
WPRecon is an advanced WordPress reconnaissance and vulnerability scanning tool designed for security engineers to identify vulnerabilities, misconfigurations, and information disclosure in WordPress installations. It utilizes a YAML-driven template architecture that facilitates easy extensibility, rapid deployment as a single binary, and features such as high-performance parallel scanning, a diverse library of over 150 templates, and multi-format output options. Notable capabilities include automatic retries for failed requests, comprehensive HTTP operations, and a variety of matchers and extractors for efficient data retrieval and analysis.

XSSniper

2026-08-03 Python ★ 11
XSSniper is an advanced open-source XSS vulnerability scanner designed for professional security testing. It features asynchronous scanning for enhanced performance, a comprehensive payload library tailored to the latest CVEs, and sophisticated WAF bypass techniques. Notable capabilities include intelligent context-aware detection, smart parameter discovery, and detailed vulnerability reporting for effective analysis of web applications.

z0scan

2026-08-03 Python ★ 367
A lightweight active and passive scanner that combines the advantages of local and distributed models, supports dynamic external plugin import, and is dedicated to exploring web black-box vulnerabilities.

ZENVORA-VULNSCAN

2026-08-03 Python ★ 10
ZENVORA VulnScan v2.0 is a comprehensive vulnerability scanner designed for web applications, focusing on detecting various security issues such as SQL injection, cross-site scripting (XSS), and command injection. It includes features like anonymity levels through Tor and ProxyChains, automated report generation in TXT and JSON formats, and an extensive list of tests for common vulnerabilities. This tool is intended for authorized use only, highlighting the importance of ethical scanning practices.

aem-dispatcher-security-scan

2026-08-03 Python ★ 19
AEM Dispatcher Security Scan is a command-line tool designed to perform security assessments on Adobe Experience Manager (AEM) Dispatcher configurations. It consolidates known security-sensitive URLs for AEM Dispatcher, allowing users to specify target websites and customize scan parameters while leveraging Docker for deployment. Notable features include configurable HTTP request timeouts, support for custom test paths, and an easy-to-use interface via command-line options.

agent-audit

2026-08-03 Python ★ 225
Agent Audit is a security tool designed to identify vulnerabilities in AI agent code prior to production deployment. Its primary use case involves scanning for risks associated with unsafe inputs, command execution, and configuration errors, utilizing a framework of 72 rules aligned with the OWASP Agentic Top 10. Notable features include tool-boundary taint tracking, configuration auditing, and the ability to enforce security measures within continuous integration workflows.

agent-security-scanner-mcp

2026-08-03 JavaScript ★ 121
The agent-security-scanner-mcp is a comprehensive security scanning tool designed for AI coding agents, providing functionalities to audit code, servers, prompts, and AI-generated packages for vulnerabilities. Key features include the ability to grade agent security, identify risks like SQL injection and package hallucinations, generate Software Bill of Materials (SBOMs), and facilitate semantic reviews using project context. The tool supports various AI platforms, ensuring robust integration and security checks before code execution.

airom

2026-08-03 Go ★ 14
AIROM is a tool designed for scanning filesystems, git repositories, container images, and Kubernetes workloads to identify and document AI components in software. It generates an AI Bill of Materials that includes models, datasets, and frameworks used in the code, providing line-by-line evidence for each entry. Notable features include support for various scan targets, output formats like CycloneDX and SPDX, and the ability to gate builds based on identified risks.

api

2026-08-03 Python ★ 371
The Vulners Python SDK is a comprehensive client for accessing Vulners' vast vulnerability intelligence database, facilitating queries on CVEs, exploits, and advisories enriched with risk metrics like CVSS and EPSS. It enables users to assess vulnerabilities across various software and systems, stream data for integration into custom pipelines, and set alerts for new matching vulnerabilities, all while supporting asynchronous operations for enhanced performance. Notably, it incorporates features for tracking active exploits and provides an AI-ready infrastructure for real-time data processing.

ApiHunter

2026-08-03 Rust ★ 24
ApiHunter is an asynchronous, modular API security scanner designed for baseline testing and regression detection in APIs. It facilitates both offensive and defensive use cases, enabling red-team activities like pentesting and exploit validation, as well as providing CI/CD regression gating and early misconfiguration detection. Notable features include adaptive concurrency, support for a variety of API security checks (such as CORS, CSP, GraphQL), and the ability to scan large numbers of targets rapidly with integrated threat intelligence capabilities.

apiscanner

2026-08-03 Python ★ 15
APISCAN is an advanced API vulnerability scanner that systematically evaluates APIs against the OWASP API Security Top 10 (2023) by utilizing OpenAPI/Swagger specifications. Notable features include automatic form login detection, deep scan modes for comprehensive testing, real-world attack pattern detection, and a user-friendly cross-platform GUI for enhanced usability. The tool is designed to proactively identify and model security vulnerabilities, providing actionable insights with detailed evidence.

artifact-keeper

2026-08-03 Rust ★ 986
Artifact Keeper is an enterprise-grade open-source artifact registry designed to support over 45 package formats, including Maven, NPM, Docker, and more. It features a WASM plugin system for custom format handling, automated security scanning for vulnerabilities, and a robust architecture with multi-auth support, full-text search capabilities, and artifact signing functionalities. Built in Rust, it emphasizes security with hardened container images and advanced replication features for scalable deployment.

auditor-skill

2026-08-03 Rust ★ 51
auditor-skill is an open-source AI-driven security audit tool designed for auditing Solana programs and applications. It leverages AI agents to evaluate codebases against 1,346 verification items across 20 security domains and 131 known attack vectors, producing detailed reports that include executable proofs of vulnerabilities and suggested fixes. Notable features include a comprehensive audit lifecycle, token efficiency through pre-scanning, and deep coverage of Solana-specific methodologies.

awesome-security-pipeline

2026-08-03 Python ★ 14
Awesome Security Pipeline is a comprehensive guide designed for selecting and implementing open-source security tools within CI/CD pipelines. It features a pre-configured baseline that integrates multiple tools such as Gitleaks, Semgrep, and Trivy, enabling continuous security validation and machine-readable evidence generation. The repository is actively maintained, with weekly status checks and regular updates to ensure the effectiveness of the security controls and methodologies provided.

bitrixprobe

2026-08-03 Python ★ 20
BitrixProbe is a Python-based vulnerability assessment tool specifically designed for CMS 1C-Bitrix/Bitrix24 installations. It offers dual modes of operation: `pentest` for external HTTP/HTTPS scans and `audit` for authenticated SSH scans, enabling comprehensive evaluation of both public exposure and server configurations. Notable features include integration with vulnerability databases, enumeration modules, and the ability to generate standardized reports, thus facilitating effective security assessments and audits.

cataam

2026-08-03 Python ★ 12
Cataam is an open-source security toolset that provides a variety of scripts and templates aimed at enhancing security and compliance practices for organizations. It features practical functionalities such as hardening scripts, CVE detection tools, and compliance documentation, making it suitable for security teams, DevOps, and compliance engineers. Notable offerings include a local-first prompt hygiene tool, CVE detection scripts updated promptly after disclosures, and a comprehensive collection of CIS Benchmark guides and compliance templates.

cert-x-gen

2026-08-03 Python ★ 21
CERT-X-GEN is a polyglot execution engine designed for vulnerability detection, allowing users to write security checks in multiple programming languages including Python, Go, Rust, C, and Shell. It provides a unified execution layer that enables complex detection logic, such as multi-step protocol conversations and performance-critical operations, and is tailored for integration in CI/CD environments. Notable features include language-agnostic templates, sandboxing capabilities, and the ability to mix various programming languages within a single scan.

ChYing

2026-08-03 Go ★ 721
ChYing is an open-source penetration testing tool designed to provide an interactive platform for security professionals, facilitating the capture, modification, and replay of HTTP/HTTPS traffic. Its notable features include a lightweight UI, built-in scanning capabilities from the Jie tool, automated attack testing with multiple payload types, and an intuitive workflow for JWT parsing, which makes it an alternative to heavier tools like Burp Suite. The tool aims to offer a modern and customizable solution for active and passive web vulnerability assessments.

cloud-audit

2026-08-03 Python ★ 69
cloud-audit is an open-source AWS security scanning tool designed to identify attack paths, IAM escalation routes, and prioritize necessary fixes based on their impact on security. It operates in a read-only mode, ensuring no modifications are made to the user's AWS infrastructure while providing detailed reports on correlations between vulnerabilities and suggested remediation steps, including AWS CLI and Terraform fixes per finding. Key features include the identification of attack chains using MITRE ATT&CK methodology, root-cause analysis for prioritized fixes, and a simulation function to evaluate the potential impact of proposed changes.

cscan

2026-08-03 Go ★ 420
CSCAN is an enterprise-level distributed network asset scanning platform designed for comprehensive asset management and vulnerability detection. Its notable features include a distributed architecture for flexible scalability, automated scanning pipelines, customizable password dictionaries, periodic task scheduling, and real-time notification subscriptions, supporting extensive data isolation across multiple workspaces. This tool is ideal for organizations seeking to efficiently monitor and secure their network infrastructure.

cve-lite-cli

2026-08-03 TypeScript ★ 681
CVE Lite CLI is a terminal-based vulnerability scanning tool designed to analyze project lockfiles and provide actionable remediation commands. It focuses on delivering validated fix commands alongside parent-aware guidance for transitive dependencies, emphasizing a remediation-first approach while ensuring that no sensitive data leaves the user's machine. As an officially recognized OWASP Lab Project, it integrates seamlessly into CI workflows, promoting secure coding practices.

cwe_checker

2026-08-03 Rust ★ 1353
cwe_checker is a static analysis tool designed to identify common software vulnerabilities, specifically by detecting classes of bugs known as Common Weakness Enumerations (CWEs) in ELF binaries across multiple CPU architectures. It leverages Ghidra for disassembly and utilizes a plugin-based, extensible architecture that supports customizable analyses, making it a useful resource for firmware analysis on Linux and Unix systems. Notable features include easy setup via Docker, support for various architectures, and the ability to integrate with the FACT framework for enhanced analysis capabilities.

cyber-neo

2026-08-03 Python ★ 254
Cyber Neo is an open-source cybersecurity analysis agent designed to run within Claude Code, enabling developers to conduct comprehensive security audits on their projects effortlessly. The tool scans for vulnerabilities across 11 categories, including code security, authentication, cryptography, and dependency vulnerabilities, providing prioritized reports with concise remediation guidance. Notable features include no installation requirements, real-time operation, and the ability to run five parallel subagents for rapid assessments.

DeepSec

2026-08-03 Python ★ 323
DeepSec is an AI-driven security platform that integrates code security auditing and authorized penetration testing into a unified CLI and terminal workbench. It features a three-layer detection architecture for real-time vulnerability scanning, leveraging regex, AST analysis, and LLM semantic evaluation, along with IDE plugins for seamless development integration. The platform is designed to enhance security efficiency by augmenting traditional methods with advanced AI capabilities.

dianxing

2026-08-03 ★ 877
DianXing (点星) is an AI-driven end-to-end code security auditing system that autonomously identifies and verifies vulnerabilities in source code without human intervention, offering a structured output of detected issues. Unlike traditional SAST tools, it employs semantic understanding to uncover deep vulnerabilities, such as authentication bypass and privilege escalation, which are often missed by conventional scanners. The system has demonstrated the ability to autonomously exploit zero-privilege remote code execution vulnerabilities, reinforcing the need for responsible disclosure of its capabilities.

DLL-Hijacking-Vulnerability-Scanner

2026-08-03 C++ ★ 11
DLL Hijacking Vulnerability Scanner is a specialized tool for identifying DLL hijacking vulnerabilities within signed Windows executable files. It features automated scanning, DLL dependency analysis, and comprehensive filtering options, enabling security professionals to test executables for hijacking susceptibility and analyze their DLL loading behaviors, as well as generating detailed vulnerability reports.

DockSec

2026-08-03 Python ★ 476
DockSec is an AI-powered Docker security scanner designed to translate complex security vulnerabilities into actionable insights for developers. It leverages popular security scanners like Trivy and Hadolint to provide prioritized vulnerability assessments and plain English explanations, while also suggesting specific fixes for Dockerfiles and generating interactive security reports. The tool ensures privacy by conducting scans locally, with options for local AI processing, minimizing external data exposure.

drogonsec

2026-08-03 Go ★ 175
Drogonsec is an open-source security scanner designed to perform comprehensive security assessments through Static Application Security Testing (SAST), Software Composition Analysis (SCA), and secret detection, aligning with the OWASP Top 10:2025 framework. It supports over 20 programming languages and various deployment strategies, including local or cloud-based AI remediation for findings. Key features include the ability to scan for vulnerabilities, identify misconfigurations in Infrastructure as Code (IaC), and integrate with CI/CD pipelines for automated security reporting.

eraser

2026-08-03 Go ★ 618
Eraser is a tool designed for Kubernetes administrators that facilitates the removal of non-running images from all nodes within a cluster. Its primary use case is to help optimize storage and resources by cleaning up unused images, thereby improving cluster efficiency. Notable features include easy integration with Kubernetes environments and a user-friendly quick start guide for rapid deployment.

fleet-cve-scanner

2026-08-03 PowerShell ★ 12
The fleet-cve-scanner is an open-source, PowerShell 7-based CVE scanner designed for managing vulnerabilities in software across RMM-managed fleets, without the need for agents or appliances. It cross-references the software inventory of managed endpoints against multiple authoritative security feeds to determine if installed software versions are vulnerable and assess their urgency. Key features include the ability to generate per-device CSV reports, a SQLite history database for change tracking, and an HTML dashboard, making vulnerability assessment and management streamlined and efficient.

foxguard

2026-08-03 Rust ★ 289
Foxguard is a comprehensive security scanning tool designed for local environments, offering fast analysis of code, secrets, dependencies, and post-quantum cryptographic risks. It boasts over 200 built-in rules across 12 programming languages, supports taint tracking, provides efficient CI integrations, and features output formats compatible with various tools such as SARIF and Semgrep. Key capabilities include secrets scanning, OSV-backed dependency checks, and the ability to pinpoint changes in code branches through diff mode scanning.

getobserver

2026-08-03 Go ★ 13
Observer is a command-line tool designed to analyze codebases and generate a comprehensive production health report, all from a single, offline binary with no dependencies or account requirements. It combines various analysis methods—such as static analysis, dependency checks, and runtime error detection—into a unified report that includes a security rating and suggested fixes for identified issues. The tool is aimed at developers seeking to efficiently identify and remediate production problems without navigating complex code and server logs.

grummage

2026-08-03 Python ★ 47
Grummage is an interactive terminal frontend for the Grype vulnerability scanner, designed to simplify the analysis of Software Bill of Materials (SBOMs) by providing a user-friendly interface for navigating and viewing vulnerability details. Its notable features include real-time utilization of the Grype vulnerability database, customizable views by package name, vulnerability ID, package type, and severity, along with intuitive navigation controls. Grummage aims to streamline the process of vulnerability management for developers without the need to delve into complex query syntax.

harbor-scanner-adapter

2026-08-03 Go ★ 40
The Harbor Scanner Adapter for Anchore Engine/Enterprise facilitates the integration of Harbor's scanning capabilities with the Anchore API, enabling vulnerability assessments on Docker images stored within Harbor. It offers TLS/HTTPS protection for API communications, supports authentication through Bearer tokens and Basic authentication, and can be configured via environment variables or configuration files. This tool is essential for users seeking to leverage Anchore's scanning features directly from Harbor, enhancing their image security posture.

honey

2026-08-03 Shell ★ 40
honey is an automated supply-chain security tool that orchestrates multiple security scanners to assess vulnerabilities across a developer's machine. It integrates the findings from various scanners, such as bumblebee for compromised packages and osv-scanner for known CVEs, providing a unified verdict and optional daily reports through a messaging system. Key features include scheduling scans, customizable reporting policies, and the ability to suppress previously acknowledged findings.

isitsecure

2026-08-03 Python ★ 39
isitsecure is an AI-powered security scanner designed for modern web applications, integrating Static Analysis (SAST), Dynamic Analysis (DAST), and AI-driven code review into a single scanning process. Its notable features include automatic generation of DAST tests based on SAST findings, AI-generated code patches for vulnerabilities, and support for multiple programming languages and frameworks. This tool targets developers aiming to improve code security without requiring deep security expertise, offering a comprehensive report along with actionable fixes for identified issues.

it-depends

2026-08-03 Python ★ 411
It-Depends is a tool designed for automatically generating dependency graphs and Software Bill of Materials (SBOM) for various programming packages and source code repositories, supporting languages such as Go, JavaScript, Rust, Python, and C/C++. Key features include complete dependency version resolution, C/C++ support without the need to build projects, automated mapping of native library dependencies through dynamic analysis, and integration with vulnerability scanning from the OSV database.

L0p4Map

2026-08-03 Python ★ 608
L0p4Map is a robust network monitoring and visualization tool that enhances the capabilities of Nmap, providing security researchers and network administrators with detailed insights into their network infrastructure through an intuitive interface. Key features include continuous monitoring of network traffic, real-time alerting for unauthorized devices, extensive device fingerprinting, and the ability to generate a real-time graphical representation of network topology. The tool supports multiple platforms (Linux, Windows, macOS) and integrates seamlessly with existing Nmap functionalities to deliver a comprehensive view of network security.

medusa

2026-08-03 Python ★ 971
MEDUSA is an AI-first security scanner designed to detect vulnerabilities in AI/ML applications, offering over 40,000 detection patterns and built-in rules for identifying threats such as API key leaks and AI supply chain attacks. Notable features include no setup required for usage, the ability to scan GitHub repositories for potential repo poisoning, and interactive tools for purging leaked information. The tool supports parallel processing for speed, integrates with various IDEs, and provides multiple reporting formats for versatility in usage.

nsauditor-ai

2026-08-03 JavaScript ★ 20
NSAuditor AI is a modular, AI-assisted network security audit platform designed to assess and prioritize vulnerabilities without data exposure, operating entirely within your infrastructure. It utilizes 27 specialized scanning plugins to generate AI-powered vulnerability reports while ensuring zero data exfiltration, as all processes including analysis and monitoring are conducted offline and any external API calls are opt-in. This tool emphasizes privacy and security by ensuring that sensitive scan data never leaves the user's environment.

nuclei

2026-08-03 Go ★ 30950
Nuclei is a high-performance vulnerability scanner that utilizes YAML-based templates for customizable vulnerability detection, aiming to reduce false positives by mimicking real-world attack scenarios. Its notable features include ultra-fast parallel scan processing, support for multiple protocols such as HTTP and DNS, and seamless integration into CI/CD pipelines as well as various issue tracking and logging systems. The tool is designed for security professionals to stay ahead of trending vulnerabilities while conducting thorough regression testing.

nyx

2026-08-03 Rust ★ 38
Nyx is a local-first security scanner designed for cross-language taint analysis of code repositories, providing a sandboxed dynamic verification environment. Its notable features include a user-friendly React-based UI for real-time results, a detailed flow visualizer for tracking data paths, and the ability to persist triage states alongside code commits, ensuring collaboration within teams. Additionally, Nyx can be seamlessly integrated into CI pipelines, generating SARIF reports for GitHub Code Scanning.

OmniStrike

2026-08-03 Java ★ 14
OmniStrike is a state-aware security scanning tool for Burp Suite that enables precise and customizable security testing by allowing users to target individual parameters within requests. It features 14 active scanning engines, 10 technology-aware scanners, and session automation capabilities, alongside optional AI analysis for focused vulnerability testing. This tool is designed to facilitate detailed assessments of modern web technologies while maintaining user control over scanning processes and findings management.

opena2a

2026-08-03 TypeScript ★ 20
OpenA2A CLI is a unified command-line interface designed for the OpenA2A security toolchain, enabling users to identify and rectify security vulnerabilities such as credential leaks, shadow AI, and unsigned configurations with a single command. Notable features include automated security reviews and remediation capabilities, Apache 2.0 licensing, and integration with various security-focused sister packages.

PenHunter

2026-08-03 Go ★ 30
PenHunter is a modular web vulnerability scanner designed for penetration testers, bug bounty hunters, and security researchers, focused on identifying a wide range of web vulnerabilities, including XSS, SQL Injection, and RCE. It features advanced detection methods, such as boolean and time-based techniques, as well as built-in WAF evasion capabilities, and can integrate with external tools like sqlmap and dalfox. The tool supports concurrent scanning, interactive CLI usage, and provides organized output in multiple formats, enhancing workflow efficiency in security assessments.

pentest_skill

2026-08-03 Python ★ 27
Pentest Skill is a comprehensive black-box web penetration testing toolkit designed to streamline the bug bounty workflow through a structured five-phase approach: Intake, Recon, Enum, Hunt, and Report. Notable features include a workflow controller with checkpoints for phase progression, a collection of 48 Python scripts for various testing phases, and an extensive library of attack playbooks and payloads, facilitating targeted vulnerability assessment and reporting.

perimeter-hardening-suite

2026-08-03 HTML ★ 51
BitDefender Total Security Ultimate Protection is a comprehensive cybersecurity suite that functions as a modular framework for fortifying network defenses against a wide array of cyber threats. Its primary use case revolves around system hardening, employing features such as vulnerability scanning, real-time threat correlation, and sandbox-based execution to protect various environments from evolving threats. Notable capabilities include automated policy enforcement, advanced heuristic analysis, and deep kernel inspection for rootkit remediation, all integrated within a responsive interface supporting multilingual operations and continuous 24/7 support.

pi-codex-security

2026-08-03 TypeScript ★ 12
pi-codex-security is a tool that integrates OpenAI Codex Security functionality into pi agent sessions, enabling users to scan repositories for vulnerabilities, review findings by severity, and automatically fix issues. Notable features include customizable scanning options, detailed artifact generation in various formats (e.g., SARIF and JSON), and a user-friendly command interface for initiating scans and managing authentication. This tool is particularly useful for developers who want to enhance their code security seamlessly within their development environment.

plankton

2026-08-03 Python ★ 22
Plankton is a command-line web vulnerability scanner designed to conduct checks against the OWASP Top 10 (2021) vulnerabilities on specified URLs. It generates colorful terminal outputs and supports multiple report formats, including a styled HTML report, JSON, and plain text, enabling users to customize scan parameters with ease. Key features include 12 specific vulnerability checks, configurable options such as timeout and user-agent, and an accessible single-file script for quick deployment.

presidio-hardened-vuln-scanner

2026-08-03 Python ★ 49
The presidio-hardened-vuln-scanner is a web application vulnerability scanner designed to analyze both a deliberately vulnerable Flask application and its hardened version. It facilitates a comprehensive security assessment through static analysis, dynamic scanning, and manual exploitation, highlighting various vulnerabilities such as SQL injection and XSS, with a structured approach to measure and verify fixes. Notable features include integration with tools like Bandit and pip-audit for static analysis, as well as a custom scanner to dynamically check for vulnerabilities.

quodeq

2026-08-03 Python ★ 23
Quodeq is an open-source AI-powered tool designed for scanning codebases to detect security vulnerabilities and design flaws, aligning with the ISO 25010 quality dimensions. It provides detailed findings such as grades, violations with line numbers, and fix plans, with every issue mapped to a corresponding CWE identifier. Notably, it operates locally without telemetry, runs on various platforms, and offers both cloud and local model configurations for flexibility and privacy.

refuse

2026-08-03 TypeScript ★ 10
Refuse is a self-hostable HTTP service that supports the refuse-cli tool, designed to block the installation of vulnerable packages by querying a local SQLite database populated with public vulnerability feeds. It features a REST API for package checks, a built-in admin UI, and frequent updates from various sources, allowing users to verify package safety and enforce security policies during package management operations.

repomind

2026-08-03 TypeScript ★ 278
RepoMind is an AI-powered tool designed to facilitate the understanding of public GitHub repositories and developer profiles through advanced code reasoning and architecture visualization. It offers zero-setup access for public repositories, context-aware analysis to provide relevant files, security scanning with verification reporting, and real-time feedback during the analysis process. Notable features include automated architecture mapping, a streamlined user interface for discovering trending repositories, and a robust cleaning mechanism through its Agentic Context-Augmented Generation architecture for reliable query responses.

RouteVulScan-2.0

2026-08-03 Java ★ 42
RouteVulScan is a passive recursive path probing extension for Burp Suite that leverages the Montoya API to perform low-noise vulnerability detection during web security testing. It automatically scans traffic for hidden endpoints and sensitive files using customizable YAML-based detection rules, allowing users to quickly identify high-value vulnerabilities without the need for manual dictionary management. Key features include automatic path recursion, support for active scanning of individual requests, and a comprehensive rules engine for effective vulnerability assessment.

scanner

2026-08-03 Python ★ 10
Bawbel Scanner is an open-source tool designed to assess MCP servers and skill files for vulnerabilities, specifically providing OWASP AIVSS scores without executing any code. Its primary use case includes detecting AVE vulnerabilities and ensuring compliance with the MCP specification, while notable features encompass a variety of focused scans, conformance grading, and vulnerability management functionalities. The tool supports formats for reporting, a public vulnerability database, and provides guidance for remediation, making it a comprehensive solution for security assessments of MCP environments.

sec-af

2026-08-03 Go ★ 197
SEC-AF is an AI-native security auditing tool that confirms exploitability of vulnerabilities in codebases by providing a detailed data flow trace and verifiable evidence for each finding. It allows users to initiate audits via a single API call or command line interface, returning comprehensive reports that include severity, exact location, and a verdict on each vulnerability. Notably, SEC-AF offers a cost-effective solution for thorough security assessments, typically costing about $1.40 per full audit.

Shai-Hulud-2.0-Detector

2026-08-03 TypeScript ★ 146
The Shai-Hulud 2.0 Detector is a cybersecurity tool designed to protect projects from the Shai-Hulud 2.0 npm supply chain attack, a significant threat that compromised numerous packages in the npm ecosystem. Its primary use case involves detecting vulnerable packages and facilitating community reporting of compromised software, enhancing the security posture of development environments. Notable features include automated daily updates of an affected packages database, advanced configuration options for tailored scanning, and support for various integration methods including GitHub Actions and local CLI usage.

Shield-Eye-Core

2026-08-03 Python ★ 11
ShieldEye Core is a desktop network security scanner designed for Linux, primarily aimed at security researchers, pentesters, and system administrators. It utilizes Nmap for comprehensive port and service discovery, identifies vulnerabilities in common CMS platforms by cross-referencing with the CIRCL CVE database, and evaluates HTTP security headers, all presented through a GTK 4 GUI with intuitive reporting features. Key functionalities include customizable scanning profiles, a detailed analysis of web security, and robust safety measures against unauthorized access and disruption.

ShieldEye_ComplianceScan

2026-08-03 Python ★ 33
ShieldEye ComplianceScan is a web compliance and vulnerability scanner that assesses web targets against key security standards including GDPR, PCI-DSS, and ISO 27001. It features a GTK4 desktop interface, a CLI for automated scanning, and a REST API for integration, while providing detailed reports that include CVSS v3.1 scoring and export options in various formats. The tool evaluates critical aspects like TLS configuration, security headers, and cookie settings, making it suitable for regular compliance checks and configuration sanity evaluations.

Sighthound

2026-08-03 Rust ★ 277
Sighthound is a Tree-sitter based static vulnerability scanner designed for identifying security vulnerabilities in source code through AST-aware rules and taint-flow analysis. It supports multiple programming languages, executes scans in parallel, and offers output in various formats including JSON, CSV, and SARIF for integration with GitHub Code Scanning. Notably, Sighthound allows for custom rule packs and provides both pattern and taint mode analysis, catering to complex multi-file projects.

SILENTCHAIN

2026-08-03 Java ★ 450
SILENTCHAIN AI™ - Community Edition is a Burp Suite extension designed for AI-powered passive vulnerability analysis, providing intelligent detection of OWASP Top 10 vulnerabilities and security misconfigurations in real-time HTTP traffic. Notable features include context-aware detection using various AI models, detailed reporting with CWE and OWASP mapping, and robust data privacy measures through automatic sensitive data redaction. The tool enhances traditional security scanning by focusing on real vulnerabilities with zero false positives, making it a significant addition to web application security testing.

still_active

2026-08-03 Ruby ★ 18
`still_active` is a dependency auditing tool that evaluates the maintenance status of packages across multiple ecosystems, including Ruby, npm, PyPI, Cargo, and more, by identifying archived repositories, lack of recent releases, and vulnerabilities that remain unpatched. Its notable features include last-commit activity checks, OpenSSF scorecard evaluations, and detection of “poison-pill” dependencies that may hinder security updates. This tool serves as a complementary addition to existing package management solutions by proactively highlighting risks associated with outdated or abandoned dependencies.

symfony-security-auditor

2026-08-03 PHP ★ 87
Symfony Security Auditor is an AI-driven security auditing tool designed for Symfony applications, focusing on identifying application-level flaws that traditional static analysis tools may overlook. It features an adversarial Attacker and Reviewer loop to validate vulnerabilities and produces reports in multiple formats, including JSON and HTML. The auditor can operate in two modes: as a standalone CLI tool or integrated into Symfony applications, providing flexibility for different auditing needs.

synapse-ce

2026-08-03 Go ★ 36
Synapse is a governed control plane designed for comprehensive software composition analysis, vulnerability detection, and reporting, facilitating security assessments in a controlled environment. Its primary use case revolves around automating security workflows, ensuring tamper-evident evidence collection, and allowing for deterministic scanning across various ecosystems with multiple built-in scanners. Notable features include a robust SBOM generation, risk-based prioritization of findings, and strict adherence to authorization and scope constraints before tool execution.

terraview

2026-08-03 Go ★ 11
Terraview is an open-source security analysis tool designed for Terraform plans that integrates static scanners like Checkov, Trivy, and Terrascan with AI contextual analysis, executing these processes in parallel. It inspects infrastructure provisioned with Terraform to identify security misconfigurations and compliance issues while enriching results through multi-provider contextual insights. Notable features include built-in security scanner capabilities, seamless configuration management, and native policy-as-code support, all without external dependencies.

trawld

2026-08-03 JavaScript ★ 11
trawld is a package vulnerability monitoring tool designed for developer fleets, enabling continuous oversight of project dependencies across enrolled machines. It features a real-time dashboard for vulnerability tracking using a Cloud Brain and a global npm agent that automates project discovery, scheduled rescans, and maintains live status updates. With seamless onboarding and no code modifications required, trawld enhances security management for development environments.

vigolium

2026-08-03 Go ★ 1055
Vigolium is a high-fidelity vulnerability scanner that offers two distinct scanning modes: Native Scan for fast and flexible multi-phase assessments, and Agentic Scan for autonomous, AI-driven code auditing. It features 317 scanner modules covering a wide array of vulnerabilities, including OWASP Top 10, and employs out-of-band testing to enhance accuracy. The tool is designed for both manual and automated security assessments, enabling comprehensive coverage of web applications and codebases.

vuls

2026-08-03 Go ★ 12248
Vuls is an agent-less vulnerability scanner designed for Linux, FreeBSD, and macOS systems, written in Go, that automates the detection of vulnerabilities by continuously monitoring installed software against a variety of vulnerability databases. It generates regular reports that inform users about affected systems and related vulnerabilities, mitigating the risks of human oversight in the management of software updates. Notable features include high-quality scanning capabilities across major operating systems and integration with multiple security advisories and vulnerability databases.

webscan

2026-08-03 Python ★ 25
WebScan is an automated web security auditing tool designed to crawl, discover, and audit web applications. It features a robust plugin architecture with 41 plugins, offers multiple report formats, and is tailored for both site owners and bug hunters, providing user-friendly options like safe mode and detailed explanations of findings, as well as advanced stealth capabilities for more experienced users. Notable capabilities include request rate limiting, user-agent rotation, and proxy support to maintain the user's anonymity.

wscan

2026-08-03 Go ★ 712
wscan is a comprehensive web security scanner designed for active, passive, and AI-driven penetration testing, addressing a wide range of vulnerabilities from the OWASP web vulnerability landscape. Key features include a browser-based WebUI for scan management, support for multiple scanning modes, an extensive library of built-in detection plugins, and integration with external POC engines like Nuclei, Xray, and Goby. Additionally, it offers an AI agent mode for automated testing and a reverse-connect platform for exploiting blind vulnerabilities.

wshawk

2026-08-03 Python ★ 13
WSHawk is an open-source toolkit designed for WebSocket security testing and web application penetration testing, integrating a CLI scanner, web dashboard, and desktop application. Notable features include stateful WebSocket testing, context-aware payload evolution, browser-assisted evidence collection using Playwright, and a comprehensive suite of web pentesting tools such as fuzzers and interceptors, all under the AGPL-3.0 license. The toolkit also supports project-backed workflows and offers various integrations and reporting formats for efficient security assessment.

xalgorix

2026-08-03 Go ★ 944
Xalgorix is an open-source AI-driven penetration testing platform that autonomously conducts comprehensive pentesting methodologies and verifies each finding through an independent verification process, ensuring the delivery of proven vulnerabilities rather than uncertain results. It is designed for self-hosting and supports a "bring-your-own-LLM" model, allowing integration with user-defined language models, while catering to both Linux environments and containerized implementations through Docker. Notable features include its autonomous execution, independent verification of findings, and the ability to run in a secured Docker container.

Awesome-Hacking-Learning-Path

2026-08-03 ★ 31
Awesome Hacking & Cybersecurity Learning Path is a comprehensive resource designed to guide individuals from beginner to advanced levels in ethical hacking, penetration testing, and cybersecurity. It features curated materials on bug bounty hunting, OSINT tools, CTF challenges, and practical exercises for real-world scenarios, alongside essential concepts in networking and web application security. Notable features include detailed roadmaps for penetration testing, hands-on labs from platforms like TryHackMe and HackTheBox, and extensive coverage of privilege escalation techniques across multiple operating systems.

security-suite

2026-08-03 Python ★ 98
Security Suite is an open-source toolkit designed for comprehensive OSINT reconnaissance, web security testing, API security assessments, and compliance checks, all enhanced with AI-powered analysis capabilities. It features 11 OSINT modules, six web scanners, and four API security tools, along with integration for SIEM systems, scheduled scans, and a REST API for programmatic access. The tool simplifies setup across multiple operating systems and allows for customization of AI models and tool options during installation.

AI-OSINT-Security-Analyzer

2026-08-03 Python ★ 14
The AI OSINT Security Analyzer is a Streamlit-based web application that leverages AI technology, specifically Cohere's Command A model, to conduct comprehensive threat assessments for websites, IP addresses, and software vulnerabilities. It integrates multiple data sources such as Shodan, VirusTotal, AbuseIPDB, and CVE databases, providing users with actionable insights into security risks. The tool features a user-friendly interface and is open source, inviting community contributions to enhance its capabilities.

BannerGrapV2

2026-08-03 Go ★ 11
BannerGrapV2 is an advanced network reconnaissance and vulnerability discovery tool designed for both offensive and defensive security operations, making it suitable for Red and Blue Teams, bug bounty hunters, and security auditors. Notable features include multi-threaded banner grabbing, extensive service fingerprinting, a robust vulnerability detection engine, and flexible reporting options in multiple formats, all powered by a performance-focused architecture enabling concurrent scans of up to 10,000 hosts.

LeakIXClient-Python

2026-08-03 Python ★ 28
The LeakIX Python client provides a programmatic interface for interacting with the LeakIX platform, primarily utilized for retrieving and handling data related to internet leaks, subdomains, and other events in a structured manner. It supports both synchronous and asynchronous API calls, with responses encoded in a defined format, allowing users to leverage built-in methods for response handling and data transformation. This client is compatible with Python versions 3.11 through 3.14 and facilitates easy integration into Python applications through its straightforward installation and documentation.

va-pt

2026-08-03 Python ★ 40
The VAPT Toolkit provides a comprehensive environment for vulnerability assessment and penetration testing, integrating over 50 third-party security tools and custom automation frameworks on an Ubuntu 22 platform. Notable features include a deterministic network exploitation orchestrator that automates host discovery and vulnerability verification using nmap and Metasploit, as well as a MITM browser autopwn orchestrator combining tools like bettercap and Responder for streamlined exploitation. The toolkit supports extensive automation in reporting, deliverable generation, and a wireless attack framework for versatile testing capabilities.

contrastapi

2026-08-03 Python ★ 33
ContrastAPI is a comprehensive security intelligence tool designed for AI agents, providing grounded answers regarding vulnerabilities, threats, and attack surfaces by aggregating data from authoritative sources like the NVD and CISA KEV. It features a robust REST API with over 60 endpoints for CVE/KEV/CWE lookups, exploit probability scoring, domain and IP investigations, IOC enrichment, and code-security checks, while also facilitating seamless integration through SDKs for Python and Node.js. Notably, it is free to use without requiring API keys or signups, offering 55 tools and 7 resources for effective security analysis.

DogeRat-Premium

2026-08-03 ★ 105
DogeRat is a premium Android RAT (Remote Access Trojan) designed for comprehensive control over target devices, specifically within an educational context. Key features include real-time screen capture, advanced keylogging, and the ability to manage files and applications remotely, alongside a powerful admin dashboard that supports simultaneous control of multiple devices. The tool also offers undetectability by antivirus software and persistent functionality, ensuring uninterrupted access even after device restarts.

pinkcord

2026-08-03 Python ★ 17
Pinkcord is a Python-based remote administration tool that uses Discord bots for command and control (C2) communication, allowing users to manage remote systems in a manner analogous to traditional RATs. Notable features include executing remote shell commands, file transfers, screen capture, and system interaction capabilities, while leveraging Discord's infrastructure for seamless communication. It is important to note that Pinkcord is designed strictly for educational purposes and its misuse can lead to legal repercussions.

VulnScan

2026-08-03 Python ★ 70
VulnScan is a vulnerability scanning tool designed to assist website owners in identifying and addressing security threats by leveraging the OpenAI ChatGPT AI model to analyze JavaScript code for vulnerabilities. Although no longer actively maintained, it offers features aimed at detecting and fixing security flaws, with potential future enhancements planned, including support for various vulnerability types and improved user interface options. The tool is intended for educational use, emphasizing the importance of compliance with legal standards.

awacs-scanner

2026-08-03 Python ★ 18
awacs-scanner is an automated vulnerability scanning tool designed to gather extensive information about systems and identify potential exploits using multiple sources, including Vulners API and SearchSploit. Its primary use case involves scanning for vulnerabilities across multiple targets specified in files, streamlining the reconnaissance process without the need for manual searches. Notable features include various scan modes such as stealth_flight, vuln_scan, and battering_ram, as well as capabilities for S3 bucket discovery.

google-hacking-assistant

2026-08-03 TypeScript ★ 150
Google Hacking Assistant is a Chrome extension designed to enhance security research by automating the injection of predefined and customizable hacking syntax into search engine results from platforms such as Google, Baidu, and Bing. It features an intelligent sidebar that facilitates advanced searches with over 11 built-in query types, custom syntax management, and bulk URL extraction capabilities, while ensuring user privacy through local data storage and no tracking. This tool aims to streamline the process of conducting legitimate security assessments and penetration testing.

Quze

2026-08-03 Python ★ 13
Quze is an advanced penetration testing framework that employs quantum-inspired techniques, such as probabilistic optimization and adaptive payload mutation, to evade high-level security defenses without utilizing actual quantum computing. Its notable features include AI-driven payload mutation for dynamic attack vector generation, autonomous reconnaissance for vulnerability identification, and advanced obfuscation methods to disguise malicious traffic and execute commands stealthily. Designed for authorized penetration testing, it focuses on maximizing exploitation success while maintaining stealth against signature and behavior-based detection systems.

uCVE

2026-08-03 Go ★ 37
uCVE is a cybersecurity tool developed in Go that facilitates the extraction of Common Vulnerabilities and Exposures (CVE) associated with specific software and version numbers. It generates reports in HTML format and supports exporting data in various formats, including text, JSON, and CSV, offering customizable search parameters such as risk levels and vendor inclusion/exclusion. The tool is designed for penetration testing and vulnerability management, streamlining the process of identifying security risks in software dependencies.

Windows-Post-Exploitation

2026-08-03 ★ 544
The Windows Post-Exploitation repository provides a comprehensive resource for post-exploitation techniques specifically tailored for Windows systems. It includes an extensive catalog of commands, tools, and guides for executing post-exploitation tasks, especially in scenarios where traditional frameworks like Meterpreter are unavailable. Notable features include curated lists of PowerShell scripts, privilege escalation tools, and various post-exploitation techniques, making it an invaluable tool for penetration testers and security professionals.

AndroidHack_BackDoor

2026-08-03 Smali ★ 150
AndroidHack_BackDoor is a Python and shell script designed to facilitate the integration of a backdoor into Android APK files while leveraging the Android Debug Bridge (ADB) for remote device access. It is primarily intended for educational use and requires a solid understanding of various technical tools such as Metasploit, Apktool, and the Android SDK. Notable features include a simplified process for backdoor insertion and remote accessibility of Android devices.

dorkGen

2026-08-03 Python ★ 18
DorkGen is a script designed to generate keyword combinations for web page URLs, serving primarily for web scraping, testing, and security-related applications. It enables rapid creation of dork lists based on user-defined variables and features persistent configurations through external config files for enhanced usability. Additionally, recent updates have expanded the range of available dorks, improving the tool's functionality.

exploit

2026-08-03 Python ★ 133
Exploit is an offensive hacking tool designed to assist cybersecurity professionals and ethical hackers in executing exploits and conducting penetration testing. Its primary use case is to facilitate hacking activities, enabling users to automate various exploitation tasks. Notable features include ease of installation on any Linux distribution and comprehensive support for dependency management through a requirements file.

reveng_rtkit

2026-08-03 C ★ 275
reveng_rtkit is a Linux Loadable Kernel Module (LKM) rootkit specifically designed for the 5.11.0-49-generic Linux kernel, primarily used for post-exploitation stealth techniques. Its key features include syscall table address retrieval, function hooking, and the capability to hide itself and other processes from system monitoring tools, making it difficult to detect. Additionally, it implements an IOCTL for interactive control and can bypass known rootkit detection tools like rkhunter.

worm-ai

2026-08-03 Python ★ 327
Worm-AI CLI is a command-line interface that provides access to Grok models via an unofficial reverse-engineered API wrapper. It is designed for flexible interaction with large language models, featuring a built-in jailbreak system for unrestricted responses and a fully customizable terminal UI. Its modular architecture allows for easy modifications and enhancements, making it suitable for research and educational purposes.

Brutus

2026-08-03 Python ★ 48
Brutus is a Python-based tool designed for learning and experimentation in cybersecurity environments. It offers a sandbox feature for testing functionality in isolated, no-network containers, making it suitable for safe experimentation. Notable features include a development setup with linting and formatting tools, as well as a defined structure for module organization.

NetRaze

2026-08-03 Rust ★ 11
NetRaze is an offensive network-execution toolkit developed in Rust, providing a memory-safe, single-binary alternative to traditional Python-based tools like NetExec and CrackMapExec. It maintains a similar workflow for network post-exploitation but enhances performance with async I/O and offers a desktop GUI for visual workflow composition. Currently in alpha, it focuses on core functionality with a goal of expanding its protocol coverage across various operating systems.

PHP-Web-Security

2026-08-03 ★ 11
PHP-Web-Security is a tool designed to enhance the security of PHP web applications by implementing best practices for preventing common vulnerabilities such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF). It provides features for secure password hashing, session management, and includes a compilation of tools for web framework hardening, static code analysis, and security advisories. Notable components include security modules, static analysis tools, and resources aimed at both developers and educational content for improving overall web security.

s1c0n

2026-08-03 Python ★ 75
s1c0n is a reconnaissance tool designed to simplify the vulnerability assessment process for web servers. Its primary use case includes automated scanning for WAFs, ports, subdomains, web directories, and content management systems, with the capability to customize user-agent strings and scan through proxies. Notable features include comprehensive auto-detection of server technologies, WordPress plugin enumeration, and an easy installation process, catering to various Linux distributions.

emp3r0r

2026-08-03 Go ★ 1741
emp3r0r is an advanced, zero-trust post-exploitation framework and command & control (C2) system designed for secure operations on both Linux and Windows environments. Its notable features include autonomous gossip mesh networking, fileless memory execution of Starlark-scripted agents, and robust cryptographic identity pinning, ensuring high levels of stealth, operational control, and security against impersonation attacks. The framework facilitates seamless integration and execution without relying on host-based interpreters, making it highly suitable for high-security scenarios.

linemadpeas

2026-08-03 Shell ★ 11
Linemadpeas is a comprehensive Linux privilege escalation enumeration tool implemented in Bash, designed to thoroughly scan Linux systems for potential privilege escalation vulnerabilities. It offers a user-friendly interface, automatic detection of over 25 vulnerability categories, and detailed exploit methods with executable examples while generating two separate output files for enumeration reports and exploit strategies. This tool is particularly valuable for penetration testing, security auditing, and educational purposes in understanding escalation techniques.

Nucleimonst3r

2026-08-03 Shell ★ 264
Nucleimonst3r is a high-speed vulnerability scanner tailored for Red Teams and Bug Bounty Hunters, enabling rapid identification of potential attack targets by fetching and filtering URLs from a specified domain. It leverages the httpx tool for scanning and provides dynamic template generation, real-time scan statistics, and comprehensive report generation, allowing users to customize scans effectively and integrate with other security tools for enhanced testing capabilities.

Preview-DarkStar

2026-08-03 Python ★ 27
DARKSTAR v2.1 is a command-line penetration testing framework designed for security professionals, featuring 57 modular tools across various categories. Its key features include a plug-and-play plugin system, automatic plugin discovery, a matrix-inspired color-coded terminal UI, and support for threading and async operations, making it highly customizable and efficient for diverse security assessments. The toolkit is compatible with multiple platforms, including Kali Linux, Termux, Windows (WSL), and macOS, and requires only standard Python dependencies.

Web-Security

2026-08-03 ★ 11
Web-Security is a comprehensive resource designed to educate users on web security practices, particularly focusing on the OWASP Top 10 vulnerabilities including XSS, SQL injection, and CSRF. It provides a collection of materials, tools, and hands-on labs, aimed at enhancing secure coding practices for developers. Notable features include detailed explanations of various vulnerability classes, their exploitation techniques, and links to relevant communities and learning resources.

CyberElite

2026-08-03 ★ 18
Awesome-Hacking is a comprehensive resource hub designed for hacking, pentesting, and security research, providing a curated collection of tools and materials beneficial for System and Network Administrators, DevOps professionals, and security researchers. Notable features include its repository of daily use tools, practical navigation through a simple Table of Contents, and an open-source nature that encourages contributions from users. The repository serves as a valuable reference point for anyone interested in cybersecurity.

INtrack

2026-08-03 HTML ★ 60
INtrack is a multi-threaded internet crawler and security scanner focused on network reconnaissance and vulnerability detection. It supports various scanning types, including the detection of web applications, IoT devices, and exposures, while offering flexible target selection, customizable settings, and real-time progress visualization. Notable features include support for multiple scanner types based on CVEs, the ability to scan either specific IPs or subnets, and a customizable thread count for efficient scanning.

ShinobiShell

2026-08-03 Python ★ 15
ShinobiShell is a specialized penetration testing tool designed for file exfiltration and exploit injection, facilitating remote shell interactions between the attacking and victim machines. Its notable features include encrypted tunnel creation, a command for seamless reverse shell connections, and capabilities for managing machine information and various payload delivery methods through a user-friendly shell interface. The tool is particularly geared toward enhancing operational efficiency during pentesting activities.

VivisectION

2026-08-03 Python ★ 22
VivisectION is an emulation-driven toolset designed as a plugin for the Vivisect reverse engineering framework, enhancing GUI capabilities with functions for function emulation and reconnaissance. It enables users to emplace an emulator for specific functions easily, offering features such as an interactive console for dynamic analysis, and streamlined integration with other Vivisect tools. Noteworthy functionalities include function emulation via context menu operations and an interactive Python shell for advanced analyses, fostering a comprehensive environment for vulnerability research and reverse engineering.

asm-payloads-loaders

2026-08-03 Assembly ★ 10
The asm-payloads-loaders tool provides a series of assembly-written payload loaders for x86-64 Linux, utilizing only native syscalls without external dependencies. It features various loading mechanisms, including file-based, HTTP, and DNS payload loading, with options for dynamic memory allocation and checksum verification for integrity checks. This tool is designed to facilitate the development and understanding of payload loading techniques through detailed examples and documentation.

Atomic-Red-Team-C2

2026-08-03 Python ★ 178
ARTC2 is an advanced execution framework designed to help security teams efficiently execute attack scenarios across multiple breach points, primarily focusing on Windows OS environments. Its notable features include rapid deployment, modern command and control capabilities utilizing encrypted communications, and dynamic attack formations that enable execution without recompilation. The tool supports extensive logging for evidence collection and analysis, facilitating rapid evaluation of endpoint detection and response (EDR) solutions against MITRE ATT&CK frameworks.

blexploit

2026-08-03 Python ★ 23
Blexploit is a comprehensive offensive Bluetooth Low Energy (BLE) security framework designed for red teams and security researchers, facilitating passive scanning, exploitation, and replay attacks with advanced anomaly detection. Its modular architecture includes features such as GATT enumeration, customizable attack simulations, and offline sandbox environments, while automatically generating risk assessments and attack module suggestions based on detected device UUIDs. Key functionalities, including real packet injection and an Isolation Forest-based detection mechanism, make it versatile for both testing and education in Bluetooth security contexts.

claude-code-pentest

2026-08-03 Python ★ 24
claude-code-pentest automates the penetration testing lifecycle using six specialized skills that range from reconnaissance to exploit chaining and report generation. Its notable features include subdomain enumeration, vulnerability discovery across web applications and APIs, cloud infrastructure analysis, and the capability to compose findings into comprehensive bug bounty reports—all implemented via 43 standalone Python scripts that require no external dependencies. The tool is designed for authorized security testing only and is integrated with Claude Code for user-friendly command execution.

CS-EDR-Enumeration

2026-08-03 C ★ 94
CS-EDR-Enumeration is a Cobalt Strike Aggressor Script designed to enumerate antivirus (AV), endpoint protection platform (EPP), endpoint detection and response (EDR), and telemetry/SIEM products on Windows hosts post-compromise. It features six commands with varying noise levels to suit different operational risk tolerances, and includes a comprehensive signature database for major security vendors, enabling silent enumeration techniques that minimize detection. Notable capabilities include kernel driver enumeration, automatic threat level assessment, and color-coded output for quick identification of security products.

drakben

2026-08-03 Python ★ 21
DRAKBEN is an AI-powered autonomous penetration testing framework that utilizes natural language processing to perform comprehensive security assessments, allowing users to issue commands in plain language. Its notable features include a self-evolving engine for dynamic tool synthesis, a multi-language interface supporting Turkish and English, and advanced memory systems for context-aware decision-making and persistent learning. This framework streamlines the penetration testing process from reconnaissance to reporting with minimal user intervention.

empirectf

2026-08-03 C++ ★ 135
EmpireCTF is a comprehensive repository of Capture The Flag (CTF) write-ups that chronologically documents solutions and methodologies applied in various CTF competitions from 2018 to 2025. The primary use case of this tool is to serve as a reference for cybersecurity enthusiasts and professionals seeking to enhance their skills in solving CTF challenges. Notable features include categorized write-ups by year and challenge type, facilitating easy navigation and study of different techniques and tools utilized in the CTF landscape.

find-cve-agent

2026-08-03 JavaScript ★ 45
find-cve-agent is an open-source tool designed for discovering real CVEs in open-source packages using a structured multi-agent approach. It features a comprehensive workflow encompassing target discovery, vulnerability validation, and responsible disclosure, equipped with a six-gate verification process to minimize false positives. This tool is particularly aimed at enhancing the effectiveness of security researchers by leveraging a coordinated team of agents specializing in different aspects of the vulnerability hunting process.

ghostpack-binaries

2026-08-03 PowerShell ★ 20
GhostPack Binaries is a repository offering precompiled binaries and scripts for various security and red team tools compatible with Windows, Linux, and macOS. Its primary use case is to facilitate authorized security testing and educational purposes, providing streamlined access to essential utilities while emphasizing the importance of ethical usage. Notable features include cross-platform support and a focus on prebuilt security tools, enabling users to conduct red teaming activities efficiently.

httpworker

2026-08-03 C++ ★ 90
HTTPWorker is a Flask-based command and control (C2) framework designed for security competitions, utilizing custom Windows implants written in C++. Its primary use case involves coordinating and managing remote Windows clients with capabilities such as command execution, file management, system information retrieval, and user interface access through an authentication-protected web app. Notable features include Docker support for deployment, integration with Pwnboard for beacon tracking, and customizable implant configurations to evade detection.

MCPScan

2026-08-03 TypeScript ★ 25
MCPScan is an offensive security auditing tool specifically designed for MCP servers to identify vulnerabilities and misconfigurations. It conducts comprehensive checks across eight categories, including tool poisoning, credential leakage, remote code execution, and supply chain issues, allowing developers to mitigate security risks in AI-connected environments effectively. Notable features include detailed vulnerability reporting, CVE references for known issues, and the ability to detect common attack vectors and exposed sensitive data.

nightmare-exploit-roadmap

2026-08-03 Python ★ 96
The Nightmare Exploitation Roadmap is a structured educational resource designed to advance users' binary exploitation skills through a layered curriculum that emphasizes theoretical understanding and practical application. It focuses on building capabilities to analyze unknown binaries, identify exploit primitives, and develop automated exploitation techniques while navigating real-world security mitigations. Notable features include a non-linear approach to learning, preservation of module names for clarity, and a comprehensive progression from foundational knowledge to advanced exploitation strategies.

pentest-toolkit

2026-08-03 Python ★ 37
Pentest Toolkit is an advanced penetration testing framework designed for rapid and efficient security assessments, integrating over 100 industry-standard tools into both a Python suite for automation and a Bash interface for hands-on operations. Its primary use case includes comprehensive testing phases, from reconnaissance and web security to SSL/TLS analysis and network assessment, all culminating in professional report generation. Notable features encompass automated reporting in multiple formats, robust web application vulnerability testing, and streamlined reconnaissance processes.

periodic-table-offensive-security

2026-08-03 HTML ★ 139
The Periodic Table of Offensive Security serves as a visual reference for 118 essential tools, frameworks, and standards utilized in offensive security and red teaming. Its primary use case includes aiding penetration testing, red team training, and providing a comprehensive overview of tools for OSINT, exploitation, and post-exploitation phases. Notable features include downloadable print-friendly PDFs and an interactive clickable version that links directly to resources for each tool represented.

Proxy_Bypass

2026-08-03 PowerShell ★ 13
Proxy_Bypass is a post-exploitation tool designed to identify user agents capable of circumventing proxy restrictions. It offers batch processing, the ability to test various user agents against specific domains, and includes a predefined library of user agents for immediate use. Notable features include verbose output, support for custom user agents, and future enhancements such as multi-threading and additional language support.

reai-r2

2026-08-03 C ★ 16
RevEng.AI Radare2 Plugin enhances the Radare2 framework with AI-driven reverse engineering functionalities, including decompilation, function analysis, and binary similarity detection. It seamlessly integrates with existing Radare2 workflows, providing automated setup scripts across multiple platforms and the capability to utilize an external API for advanced analysis tasks. Noteworthy features include a straightforward installation process, automatic library path configuration, and the generation of necessary configuration files directly through Radare2 commands.

reait

2026-08-03 Python ★ 33
Reait is a toolkit designed for the analysis of compiled executable binaries utilizing the RevEng.AI API, primarily aimed at identifying similar components, vulnerabilities, and generating advanced YARA++ REAI signatures for binary files. Notable features include the ability to extract symbol embeddings, conduct similarity searches among executable programs, and support for stripped ELF and PE binaries in both GNU/Linux and Windows environments. The tool facilitates in-depth binary analysis through commands that submit executables, retrieve analysis results, and query a database for similar symbols.

ropfilter

2026-08-03 Python ★ 13
`ropfilter` is an advanced tool designed for filtering, ranking, and chaining ROP gadgets derived from `rp++` dumps, specifically for 32-bit x86 architectures. Its notable features include smart gadget filtering based on register transfers and memory operations, automated multi-gadget chain synthesis, and a constraint solver that utilizes YAML/JSON specifications, enhancing the robustness and efficiency of ROP chain construction.

SecuSploitX

2026-08-03 HTML ★ 38
SecuSploitX is an advanced, modular, open-source penetration testing and cybersecurity toolkit designed for offensive security operations. It features a comprehensive suite of tools including web and network security modules, AI-driven automation for tasks like phishing simulations, and both GUI and CLI interfaces for user flexibility across multiple platforms. Notable capabilities include automated vulnerability scanning, advanced brute force tactics, and extensive documentation, making it suitable for both educational and professional use.

The-Potato-Garden

2026-08-03 ★ 27
The Potato Garden repository compiles various Windows privilege escalation tools, referred to as "Potatoes," each sourced from different open-source projects. Its primary use case is to provide security professionals with readily accessible binaries for testing and exploiting vulnerabilities within Windows environments. Notable features include the aggregation of multiple tools into a single collection, enabling streamlined access and use for penetration testing and security assessments.

TibaneC2

2026-08-03 C ★ 68
TibaneC2 is a modular Command & Control (C2) framework designed for offensive security research and red teaming, featuring a C/C++ core server, a PHP-based web panel, and a CLI console. Its notable characteristics include cross-platform implants, multi-language stagers, and scripting tools for enhanced automation and emulation, facilitating extensive customization without altering core functionality. The framework is intended strictly for educational and authorized testing purposes.

Vigilo

2026-08-03 TypeScript ★ 63
Vigilo is an autonomous smart contract security auditing tool designed to identify vulnerabilities within Web3 applications. Utilizing specialized agents within a structured pipeline, it facilitates an automated auditing process by handling tasks such as reconnaissance, deep analysis, and report generation across multiple programming languages including Solidity and Rust. Notably, Vigilo features a modular architecture with dedicated auditors for various vulnerability types and integrates seamlessly with existing development workflows like Foundry.

w4af

2026-08-03 Python ★ 48
w4af is an open-source web application security scanner designed for developers and penetration testers to identify and exploit over 200 vulnerabilities, such as Cross-Site Scripting and SQL Injection. Built on Python 3.11 and currently in an alpha development phase, it features integrations for unit and integration testing alongside comprehensive documentation for user guidance.

White-Papers

2026-08-03 ★ 13
The MottaSec White Papers repository is a centralized collection of technical and cybersecurity white papers published by MottaSec, providing insights into various topics such as military drone security and IoT device boot integrity. Notable features include a clear organizational structure for easy navigation, self-contained papers with supporting materials, and multiple access formats including GitHub markdown and professionally formatted PDFs. This repository serves as a vital knowledge base reflecting the expertise and research of MottaSec in the cybersecurity domain.

bughunter-ai

2026-08-03 TypeScript ★ 65
BugHunter AI is an autonomous bug bounty hunting framework that leverages Claude Code and the Personal AI Infrastructure (PAI) to conduct vulnerability assessments without human intervention. Its notable features include 28 specialized AI agents and 51 skills that operate in parallel through hypothesis-driven attacks, real-time reporting, and automatic generation of professional bug bounty reports. This tool significantly accelerates the reconnaissance and exploitation phases of security testing, offering enhanced capabilities such as cross-session learning and encrypted credential management.

EVA

2026-08-03 Python ★ 524
EVA is an AI-driven penetration testing tool designed to aid users throughout the pentesting lifecycle with intelligent analysis, automated enumeration, and real-time vulnerability assessment. It features support for multiple AI backends, session management for persistent interactions, and an interactive interface for executing commands and analyzing results, thereby enhancing the efficiency of penetration testing efforts. This tool aims to assist, rather than replace, cybersecurity professionals by providing strategic guidance and quicker outcomes during engagements.

GadgetExplorer

2026-08-03 C# ★ 16
GadgetExplorer is a command-line tool designed for discovering potential deserialization gadget chains within .NET applications. It analyzes one or more assemblies, constructing reachability graphs to identify when a deserialization entrypoint can lead to various vulnerabilities, including file writes and command execution. The tool comes pre-configured with a comprehensive set of sinks across different vulnerability categories, making it valuable for researchers and exploit developers in the .NET community.

ligolo-mp

2026-08-03 Go ★ 532
Ligolo-MP is a sophisticated pentesting tool that facilitates collaborative pivoting through a client-server architecture, allowing multiple concurrent tunnels with automated TUN management. Its notable features include SOCKS and HTTP proxy support, cross-platform compatibility, and dynamic mTLS-enabled agent generation, all while providing a user-friendly terminal-based GUI for efficient monitoring and management.

LogHound

2026-08-03 Python ★ 11
LogHound is a post-exploitation tool designed for analyzing Windows Security Event Logs (.evtx) to facilitate BloodHound mapping, aiding Red Teams in tracking lateral movement targets and deciphering active user sessions. Notable features include a chunk-based streaming parser that minimizes memory usage, support for Pass-The-Hash and Kerberos authentication methods, and the ability to generate detailed reports in various formats, ensuring effective operational security during network penetration testing.

Machine_Learning_CTF_Challenges

2026-08-03 Python ★ 263
Machine Learning CTF Challenges provides a collection of capture-the-flag (CTF) challenges focused on exploiting vulnerabilities in AI agents, machine learning pipelines, and large language models. Users can engage in practical scenarios such as manipulating training data, prompting model injections, and breaching autonomous systems to capture flags. The repository includes nine challenges that vary in difficulty and are aligned with OWASP and MITRE attack vectors, thus addressing contemporary security concerns in AI applications.

malware-apk

2026-08-03 Java ★ 152
Malware APK is a testing and exploitation tool designed for security engineers and bug hunters to create malicious Proof of Concept (PoC) applications for vulnerability testing in Android environments. Notable features include a variety of testing modules for intent injection, task hijacking, and accessibility monitoring, without requiring device rooting. It also supports advanced options like caching intercepted intents and compiling native code for arbitrary code execution, making it a comprehensive utility for penetration testing.

mcp-security-hub

2026-08-03 Python ★ 772
MCP Security Hub provides a collection of production-ready, Dockerized Model Context Protocol (MCP) servers tailored for offensive security applications, enabling AI-assisted security assessments and vulnerability scanning. With 38 MCP servers covering various domains like reconnaissance, web security, and binary analysis, it integrates over 300 security tools accessible through natural language commands via AI clients like Claude. Noteworthy features include a CI/CD-ready setup with GitHub Actions, minimal Docker images, and orchestration capabilities with Docker Compose for streamlined multi-tool workflows.

Microsoft-SQL-TDS-Downgrade-Attack

2026-08-03 Python ★ 10
The Microsoft SQL TDS Downgrade Attack tool performs a Man-in-the-Middle attack by intercepting Tabular Data Stream (TDS) packets between a client and MSSQL server, enabling the downgrading of encryption for TDS login packets. Its primary use case is to extract sensitive login credentials (username and password) by manipulating traffic through ARP spoofing and modifying intercepted packets. Notable features include automatic cleanup of the ARP spoofing and iptables rules upon stopping the script, and requirements for running include a Linux host with root privileges and necessary dependencies like arpspoof and iptables.

offensive-claude

2026-08-03 Python ★ 352
Offensive Claude is a spec-driven offensive security framework designed for Claude Code that implements structured engagement workflows following the Cyber Kill Chain methodology. It features a comprehensive set of 31 kill-chain skills, collaborative agents, and a shared vulnerability library, facilitating automated penetration testing, reconnaissance, exploit development, and reporting through a series of orchestrated commands. This tool is particularly useful for security researchers and practitioners to streamline their offensive security operations while maintaining high quality and traceability throughout the engagement process.

rustsploit

2026-08-03 Rust ★ 59
Rustsploit is a modular offensive security tool written in Rust, designed for targeting embedded systems such as routers and cameras. It features a unified interface that provides an interactive shell, command-line execution, and a post-quantum encrypted REST/WebSocket API, along with built-in fingerprinting using Recog and JARM/JA3 methods. Notable aspects include self-registering modules, a credential management system, and extensive support for various network protocols and services, making it a versatile tool for penetration testing and vulnerability assessment.

SUASS

2026-08-03 JavaScript ★ 185
SUASS is a comprehensive repository designed to provide cybersecurity professionals and learners with a wide array of study materials, covering essential topics such as penetration testing, cloud security, mobile application security, network security, and more. This resource serves as a centralized hub for enhancing knowledge and skills in cybersecurity, offering practical learning pathways through Capture the Flag (CTF) challenges and recommendations for certifications. Notable features include categorized content for various security domains and links to external learning platforms and communities.

The-LLM-Red-Teamer-s-Playbook

2026-08-03 ★ 41
The LLM Red Teamer's Playbook provides a systematic methodology for assessing and bypassing various defense layers in Large Language Models (LLMs), such as input filters and alignment mechanisms. It emphasizes a diagnostic approach to identify and understand the specific defenses in place before selecting appropriate attack techniques, mapped to the Adversarial AI Threat Modeling Framework (AATMF) v3. This guide is intended for AI red teamers, security engineers, and researchers, enabling them to conduct unauthorized testing responsibly while improving the security of AI systems.

webstrike-framework

2026-08-03 Python ★ 25
WebStrike is an automated web penetration testing framework designed to orchestrate various Kali tools through a structured phase-based pipeline, enhancing the workflow of web pentesting. It links tools together, utilizing outputs from one as inputs for the next while providing deduplication and comprehensive reporting. The framework allows for both manual and automated modes of operation, enabling users to manage the level of intrusion and control over testing processes efficiently.

frameseven

2026-08-03 Go ★ 14
frameseven is a CLI-oriented offensive web security scanner designed for authorized security testing, capable of mapping a target's attack surface while executing active checks for prevalent web vulnerabilities and misconfigurations. Key features include extensive reconnaissance capabilities, support for authenticated scans, and structured reporting options, along with a dedicated MCP server for AI agents to utilize the same framework tooling. The tool emphasizes a standard-library-centric Go codebase, enhancing readability and extendability.

khaos-c2

2026-08-03 C ★ 218
KHAØS C2 is a sophisticated post-exploitation command and control framework designed for stealth and evasion against endpoint detection systems. It features five covert communication channels, including Microsoft Teams and GitHub Gist, ensuring that the traffic blends with normal operations. The framework includes extensive post-exploitation capabilities, such as token theft, process injection, and lateral movement, along with a user-friendly React-based UI for real-time monitoring and payload management.

local-vuln-research-pipeline

2026-08-03 Python ★ 168
LVRP (Local Vuln Research Pipeline) is an exhaustive LLM-driven vulnerability research tool designed to identify vulnerabilities across various source code files in up to 16 programming languages. It constructs a complete call graph of the codebase, enumerates all source-to-sink paths, and validates these paths for exploitability using a hybrid approach that combines static analysis and LLM insights. The tool is capable of analyzing extensive projects such as the Linux Kernel and VSCode, while ensuring deterministic path enumeration and comprehensive coverage, including blind spot reviews.

opentaint

2026-08-03 Kotlin ★ 149
OpenTaint is an open-source taint analysis engine designed for application security, effectively identifying vulnerabilities that abstract syntax tree (AST) pattern matchers may overlook. Its primary use case involves enhancing security measures for applications, particularly those built with technologies like Java, Kotlin, and Spring, by allowing large language model (LLM) agents to execute vulnerability rules while offering scalable performance. Notable features include formal taint analysis capabilities and extensive integration support for various programming languages and platforms.

Pentest-Swarm-AI

2026-08-03 Go ★ 2403
Pentest Swarm AI is an open-source penetration testing tool that leverages a swarm architecture for coordinated multi-agent operations, enabling efficient vulnerability assessment. Its primary use case is facilitating authorized security testing through live integration with popular offensive tools like nmap, sqlmap, and Metasploit, while incorporating AI models for advanced analysis. Notable features include a stigmergic blackboard for agent coordination, automated evidence capture, and the ability to generate submission-ready reports.

vulnify

2026-08-03 Python ★ 30
Vulnify is a CVE ingestion and enrichment pipeline that consolidates vulnerability data from various sources into a normalized SQLite database, facilitating easier access and exploration of this information. Its notable features include a comprehensive CVE repository, integration with various vulnerability databases, and a Streamlit-based explorer that provides approximately 70 pre-built views for data analysis. The tool also supports resume-safe pipeline states, enabling seamless data ingestion even after interruptions.

WindowsShell-Injector-Shellcode-Loader

2026-08-03 C++ ★ 15
WindowsShell-Injector is a shellcode execution framework designed for security research and penetration testing on Windows systems. It features encrypted payloads, anti-debugging mechanisms, and an intuitive Qt-based GUI, allowing for seamless loading and execution of shellcode. Notable capabilities include asynchronous execution via separate threads, dynamic memory protection, and runtime API resolution to enhance evasion of static analysis tools.

x64dbg

2026-08-03 C++ ★ 49362
x64dbg is an open-source binary debugger designed specifically for Windows, facilitating malware analysis and reverse engineering of executables without source code access. Key features include a comprehensive plugin system for extensibility, support for both 32-bit and 64-bit debugging, and a user-friendly interface that offers various tools such as memory mapping and graph visualization to enhance the debugging process.

yublueflower

2026-08-03 Shell ★ 22
yublueflower is a security workflow designed to identify real-world threats by integrating multiple open-source tools, such as urlfinder, katana, and nuclei, to analyze web assets and vulnerabilities. It supports functionalities like session management, web archiving, and extended workflows for optimizing bug bounty results, while mapping findings to known vulnerabilities (CWE/CVE). This tool specifically operates within a Kali Linux environment and is ideal for penetration testers and security professionals looking to enhance their threat discovery processes.

adminexploit

2026-08-03 Batchfile ★ 93
WAE (Windows Admin Exploit) is a tool designed to gain administrative rights on outdated Windows systems by utilizing a bootable USB drive to execute a batch script. The primary use case is for unauthorized access in environments like schools or workplaces, but it is only effective on very old Windows builds as modern security measures have rendered it obsolete. Notable features include a straightforward installation process and the ability to manipulate user accounts through command line inputs, though the repository is maintained purely for historical and educational reference.

ADMMutate

2026-08-03 C ★ 94
ADMmutate is a polymorphic shellcode mutation engine designed to evade Network Intrusion Detection Systems (NIDS) by generating unique but functionally equivalent code fragments that resist signature-based detection. Its notable features include XOR-based polymorphic encoding, sliding key mechanisms, and multiple code paths, enhancing its ability to obfuscate shellcode in various architectures such as IA32, SPARC, and MIPS. The tool specifically targets signature analysis weaknesses in NIDS, employing advanced techniques to adapt and randomize its output dynamically.

AmongUsMenu

2026-08-03 C++ ★ 16
AmongUsMenu is a cheat menu designed for the game Among Us, intended for educational purposes to demonstrate how cheating software operates. It offers two versions, a normal DLL for injection and a proxy version that integrates directly with the game, featuring a set of hotkeys for various functionalities such as showing a menu, radar, or console. The project has been archived and is no longer actively maintained.

Antivirus-Engines

2026-08-03 Python ★ 45
Antivirus Engines is a comprehensive exploration of antivirus engine technologies, focusing on their development to combat the evolving cyber threat landscape. It provides in-depth technical insights into various detection methodologies, including signature-based, heuristic, and behavioral approaches, complemented by algorithmic implementations of notable techniques such as the Aho-Corasick algorithm and Bloom filters. The resource serves as both a reference for advanced malware analysis and a practical guide for implementing cutting-edge antivirus technologies.

awesome-uefi-security

2026-08-03 ★ 225
The "Awesome UEFI Security" repository compiles an extensive array of resources related to UEFI and BIOS security, serving as a centralized reference for researchers and developers in the field. It features categorized materials including CTF challenges, documentation, tools, notable vulnerabilities, and training resources, making it an invaluable asset for anyone looking to enhance their understanding of UEFI security threats and defenses. Noteworthy sections include links to various bootkits and development projects, further enriching the repository's utility for comprehensive UEFI security exploration.

Bl0ck

2026-08-03 Python ★ 12
Bl0ck is a specialized attack tool designed to exploit vulnerabilities in Wi-Fi 5 (802.11ac) and Wi-Fi 6 (802.11ax) networks by utilizing Block Ack (BA) frame attacks. Its primary use case is to disrupt the transmission of Quality of Service (QoS) Data traffic, effectively cutting off internet access for connected devices without disconnecting them from the access point. Notable features include its capability to execute three distinct attack scenarios that can halt data transmission from the AP to the target device and facilitate further attacks, such as Deauthentication and Evil Twin assaults.

BlackOut

2026-08-03 Java ★ 15
BlackOut is an addon for the Meteor client that enhances gameplay by introducing advanced features such as an upgraded CrystalAura, BedAura, and PacketFly, among others. Its primary use case is to improve user performance and competitiveness in Meteor client-based environments. Notable features include enhanced functionality and ease of installation when integrated with Fabric and Meteor, along with community support via Discord.

bluekit

2026-08-03 Python ★ 17
Bluekit is an extensible engine and command-line interface (CLI) tool designed to enhance the functionality of the BlueToolkit. Its primary use case is to provide an adaptable framework for developers aiming to integrate and extend tools within the BlueToolkit ecosystem. Notable features include its extensibility and robust CLI capabilities for efficient tool management.

bluetoothexploits

2026-08-03 Python ★ 24
BluetoothExploits is a directory containing various Bluetooth exploits intended for use with the BlueToolkit framework. Its primary use case is to provide security professionals and researchers with a set of tools to assess and exploit vulnerabilities in Bluetooth implementations. Notable features include a curated collection of exploits specifically designed to enhance Bluetooth security testing capabilities.

brash

2026-08-03 JavaScript ★ 181
Brash is a tool designed to exploit a critical vulnerability in the Blink rendering engine of Chromium-based browsers, allowing for a denial of service (DoS) attack through rapid updates of the `document.title` property. By circumventing rate limiting, it can generate millions of DOM mutations per second, causing browsers like Chrome and Edge to crash within seconds and significantly degrade system performance. The tool showcases an impactful attack vector that affects over 3 billion users, highlighting the need for vigilance against architectural flaws in web rendering engines.

CloakQuest3r

2026-08-03 Python ★ 2254
CloakQuest3r is a Python-based security research tool designed to assess potential origin IP exposure of websites utilizing Cloudflare and similar reverse proxy or CDN services. Its primary use case involves subdomain enumeration and passive analysis techniques to identify misconfigurations that could lead to the disclosure of sensitive server infrastructure. Notable features include its capability for real IP detection, making it essential for security professionals, penetration testers, and web administrators focusing on authorized security testing and infrastructure hardening.

CORS-vulnerability-with-basic-origin-reflection

2026-08-03 HTML ★ 13
This repository presents a proof-of-concept for exploiting a CORS (Cross-Origin Resource Sharing) vulnerability characterized by a misconfigured policy that allows arbitrary `Origin` headers and sets `Access-Control-Allow-Credentials: true`. The primary use case involves demonstrating how such vulnerabilities can be detected and exploited to exfiltrate sensitive data, such as an API key, from a victim's browser. Notable features include detailed steps for testing the vulnerability using tools like Burp Suite and a lab walkthrough that guides users through the detection and exploitation processes.

CORS-vulnerability-with-trusted-null-origin

2026-08-03 HTML ★ 12
The CORS vulnerability tool demonstrates the exploitation of a null origin CORS misconfiguration in a web application, enabling attackers to exfiltrate sensitive API keys. This GitHub repository provides a comprehensive walkthrough of a proof-of-concept (PoC) attack on a sample lab site, detailing the steps and methods used to identify and exploit the vulnerability, along with suggested mitigation techniques to enhance security. Notable features include a structured guide with practical examples and screenshots to aid in understanding the exploit and its implications.

cs2-realtime-demo-radar

2026-08-03 HTML ★ 44
The CS2 Real-time Demo Radar Visualizer is a tool designed to visualize player activities and game dynamics in real-time for Counter-Strike 2 demos. Notable features include automatic game path detection, detailed player statistics, real-time updates every 50ms, customizable display settings, and a mini radar interface for secondary monitors. This tool is intended for educational and personal use, and it requires specific commands to function properly in a game environment.

CVE-2025-10585-The-Chrome-V8-Zero-Day

2026-08-03 ★ 13
This repository addresses the critical CVE-2025-10585 type-confusion vulnerability in the Chrome V8 JavaScript engine, emphasizing the urgent need for patching due to confirmed active exploits in the wild. It provides an overview of the vulnerability’s mechanics, highlighting how it allows attackers to leverage arbitrary read and write primitives for executing code and bypassing security measures. Notably, it also discusses the exploit chain necessary for achieving full system compromise through crafted web content.

CVE-2025-24054_CVE-2025-24071-PoC

2026-08-03 Python ★ 22
The tool showcases a proof-of-concept (PoC) for exploiting the NTLM hash leak vulnerability identified as CVE-2025-24054 through malicious `.library-ms` files. Its primary use case is for educational and research purposes, allowing security professionals to demonstrate how NTLMv2 hashes can be extracted by triggering SMB authentication requests on unpatched Windows systems. Notable features include a script for generating the malicious file, instructions for setting up a fake SMB server using Responder, and a sample file configured to facilitate the attack.

CVE-2025-31702

2026-08-03 Python ★ 10
The CVE-2025-31702 repository provides a collection of tools, exploits, and research artifacts aimed at analyzing and addressing vulnerabilities associated with CVE-2025-31702, particularly in relation to P2P/Easy4IP exposure and auto-update inconsistencies. Its primary use case is to equip defenders with auditable utilities for validating deployments, while also offering detection strategies and mitigation guidance for SOC and IR teams. Notable features include lab scripts, parsers, and comprehensive documentation of research and proof-of-concept efforts for enhanced operational transparency.

CVE-2025-32463

2026-08-03 Shell ★ 48
CVE-2025-32463 is a privilege escalation exploit targeting vulnerable versions of sudo (1.9.14 to 1.9.17) that allows attackers to gain root access without requiring gcc to be installed on the target system. The tool includes pre-compiled payloads for various architectures, directly executing an exploit via scripts, making it notably convenient for users who may lack compilation tools. This exploit is intended solely for educational and authorized testing purposes.

CVE-2025-32463_chwoot

2026-08-03 Shell ★ 530
The CVE-2025-32463_chwoot repository provides a proof-of-concept implementation to demonstrate the privilege-escalation vulnerability in the chroot feature of vulnerable versions of `sudo`. It includes a Docker environment to build and run an exploit that showcases how to gain root access in affected systems. Notable features include a Dockerfile for setting up the environment and a script that facilitates the execution of the exploit inside a container.

CVE-2025-40634

2026-08-03 Python ★ 31
The CVE-2025-40634 tool serves to exploit a stack-based buffer overflow vulnerability in the TP-Link Archer AX50 router, specifically in its firmware version 1.0.14 Build 20240108 rel.42655(4555). The primary use case is to enable remote code execution capabilities both from the local network (LAN) and the wider internet (WAN) by manipulating DNS response packets. Notably, the tool revisits a vulnerability with a similar root cause to CVE-2020-10881, requiring a custom exploit due to differing exploitation processes.

CVE-2025-54253-Inside-the-Adobe-AEM-Forms-Zero-Day

2026-08-03 ★ 10
CVE-2025-54253 is a critical vulnerability affecting Adobe Experience Manager (AEM) Forms on JEE versions ≤ 6.5.23.0, enabling unauthenticated remote code execution through misconfigured Struts/OGNL endpoints. This tool primarily assists penetration testers and defenders in identifying and mitigating risks associated with this vulnerability, emphasizing proactive patching, threat hunting, and implementing hardened configurations. Notable features include a structured testing checklist for AEM environments, methods for validating configurations, and logging techniques for identifying exploitation attempts.

CVE-2025-55182

2026-08-03 Python ★ 15
The CVE-2025-55182 Scanner & Exploiter tool is designed to detect and exploit a critical remote code execution vulnerability in specific versions of React Server Components. It features detection capabilities for scanning single or multiple targets, as well as an exploitation mode that provides an interactive shell and options for reverse shell execution. The tool supports proxy usage and allows for multi-threaded scanning to enhance performance.

CVE-2025-59287

2026-08-03 Python ★ 16
The CVE-2025-59287 tool is an automated exploit designed to target a critical unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS). Its primary use case is to facilitate the exploitation of this vulnerability with minimal user intervention, offering features such as payload generation, built-in reverse shell capabilities, cross-platform compatibility, and AES encryption. The tool also includes dependencies auto-management and can be run across multiple operating systems, ensuring ease of use for penetration testers and security researchers.

CVE-2025-59287-PoC

2026-08-03 Python ★ 15
The CVE-2025-59287-PoC tool serves as a proof-of-concept for exploiting vulnerabilities in Windows Server Update Services (WSUS), specifically targeting CVE-2025-59287 and CVE-2023-35317. Its primary use case is academic research and defense technique development, allowing users to initiate Remote Code Execution (RCE) by sending crafted SOAP requests to vulnerable WSUS servers. Notable features include customizable payloads, the ability to generate random client DNS names, and verbose debug logging for detailed operation insights.

CVE-2025-59287-When-your-patch-server-becomes-the-attack-vector

2026-08-03 SQL ★ 10
CVE-2025-59287 refers to a critical unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS) that can be exploited through unsafe deserialization of attacker-controlled data. The tool illustrates how attackers can leverage this vulnerability via crafted `AuthorizationCookie` payloads to gain SYSTEM-level access on the server, enabling them to deploy malicious updates and pivot within corporate networks. Immediate patching is emphasized, along with recommendations for temporary isolation and detection measures against exploitation attempts.

CVE-2025-66516-Writeup-POC

2026-08-03 Python ★ 11
The CVE-2025-66516-Writeup-POC repository provides a detailed analysis and proof of concept for a critical XML External Entity (XXE) injection vulnerability in Apache Tika, with a CVSS score of 10.0. This vulnerability enables remote attackers to exploit specially crafted PDF documents to read arbitrary files and exfiltrate sensitive information. Notable features include specific details on affected versions, the technical breakdown of the vulnerability, and instructions for testing in a controlled environment.

CVE-2025-68613-POC

2026-08-03 Python ★ 28
CVE-2025-68613-POC is a Python-based proof-of-concept tool designed to demonstrate a critical Remote Code Execution (RCE) vulnerability in the n8n workflow automation platform. It includes a scanner for non-destructive detection of vulnerable instances and a Nuclei template for automated testing of expression injection capabilities, both facilitating the assessment of affected versions and helping security professionals identify potential exploits safely. Notably, it emphasizes the ability to interact with Node.js global contexts to validate vulnerability exploitation scenarios.

CVE-2025-8088-BUILDER-Winrar-Tool

2026-08-03 Python ★ 28
The CVE-2025-8088 WinRAR path traversal tool is a Python script designed to exploit a path traversal vulnerability found in WinRAR, facilitating the creation of malicious archives that deploy payloads to the Windows startup folder. Notable features include the ability to create customizable decoy files, employ alternate data streams (ADS) for payload concealment, and modify archive structures to ensure reliable execution. This tool serves primarily as an educational resource for cybersecurity testing within controlled environments.

cve-pocs

2026-08-03 Python ★ 57
The pwnfuzz/cve-pocs repository provides a collection of proof-of-concept (PoC) exploits for various CVEs, intended for educational and security testing purposes. Each exploit is organized by vulnerability, featuring specific scripts or research artifacts aimed at demonstrating the security flaws. Notably, the repository includes detailed links to individual exploits for different vulnerabilities, offering structured access for security professionals.

DDOS-archive

2026-08-03 C ★ 45
The illusionsec Archive is a comprehensive collection of Distributed Denial of Service (DDoS) tools, scanners, and botnet resources tailored for cybersecurity professionals and researchers. It features multiple versions of notable botnets, such as Mirai and QBot, alongside vulnerability exploits, various attack methods (Layer 4, Layer 7, UDP, TCP), and additional utilities for bot compilation and command/control management. This archive serves as an extensive toolkit for testing and analyzing DDoS attack methodologies and their defensive countermeasures.

DEDSEC_CLICKFIX2

2026-08-03 ★ 16
DEDSEC_CLICKFIX2 is a Linux-based social engineering tool that employs the ClickFix attack to deploy malware through a deceptive software activation interface. It features customizable malicious payload links, a realistic URL masking system, and integrated tunneling for remote access, while also attempting to disable security measures to ensure stealthy execution of its payload. The tool is designed for penetration testing and educational purposes, leveraging user trust to facilitate the delivery of malicious software effectively.

DefconArsenalTools

2026-08-03 ★ 49
Defcon Arsenal Tools (DArT) is a curated repository designed to provide security professionals with a comprehensive collection of tools, scripts, and resources for various cybersecurity tasks, including network scanning, vulnerability assessment, and exploit development. Notable features include organized categories for tools based on specific functions, such as credential scanning, network attacks, and malware research, facilitating quick access to relevant resources for users within the DEFCON community. The project emphasizes educational use and knowledge sharing, promoting responsible application in security practices.

Domaineer

2026-08-03 Python ★ 12
Domaineer is a semi-automated bot designed to extract data from domains, facilitating domain analysis and intelligence gathering. It supports multiple platforms, including Linux, Windows, and Android, and can be easily installed via Python dependencies. The tool is currently under maintenance for enhancements, with plans to transition to a desktop application using PyQT and Golang.

Eneio64-Driver-Exploits

2026-08-03 C++ ★ 132
This tool is an exploit for the vulnerable Windows kernel driver eneio64.sys, enabling the mapping of physical memory read/write operations to virtual memory read/write. It demonstrates how to leverage this vulnerability for privilege escalation via token theft, targeting Windows 11 versions, specifically builds 22H2, 23H2, and 24H2. The exploit also outlines the necessary offsets for different Windows versions and serves as an educational resource.

exploit-CVE-2022-25765

2026-08-03 Python ★ 31
The tool exploits a command injection vulnerability in the pdfkit Ruby gem, specifically in versions prior to 0.8.7.2, allowing attackers to execute arbitrary commands through specially crafted URLs. Key features include custom command generation and reverse shell capabilities, providing flexibility for targeting vulnerable web applications. The exploit serves solely for educational and authorized security research purposes.

ExploitAddr

2026-08-03 Python ★ 58
ExploitAddr is a reconnaissance tool primarily designed to uncover the real IP addresses of websites obscured by Cloudflare, as well as identifying any associated domains and server details. Key features include multi-IP detection, sorting by software vendor, fast searching with threading, and status code checks for domains. Users must provide a Censys API key for functionality.

googlephotos-filestorage

2026-08-03 Java ★ 24
The googlephotos-filestorage tool is a Java application that enables the steganographic encoding of files into image data for upload to Google Photos. Its primary use case is to allow users to exploit Google Photos' former unlimited storage policy by converting files into images, thus facilitating file storage and retrieval. Notable features include encoding file data into the RGB channels of pixels, with the ability to expand storage capacity by utilizing the alpha channel.

grafanaExp

2026-08-03 Go ★ 270
grafanaExp is a tool designed to exploit the CVE-2021-43798 vulnerability in Grafana, enabling automated detection of vulnerable instances, extraction of keys, and decryption of server database files. Its primary use case is to assist in the security assessment of Grafana installations by providing the capability to reveal sensitive configuration data and datasource information. Notable features include an 'exp' command for vulnerability detection and information retrieval, and a 'decode' command for local decryption of large database files.

HackingAllTheThings

2026-08-03 Python ★ 149
HackingAllTheThings is a curated repository of cybersecurity tools and notes, aimed at supporting the archiving and study of various IT security certifications. It includes both original tools developed by the author and additional resources collected from diverse sources, thereby providing a structured approach to cybersecurity learning and practice.

iOS-Shortcuts-Exploits

2026-08-03 ★ 128
iOS Shortcuts Exploits is a repository that catalogs a variety of exploits and unusual behaviors associated with iOS shortcuts, emphasizing vulnerabilities that can be used for memory overloading and crashing applications. Key features include detailed explanations and proofs of concept for various exploits, such as the wallpaper switching action that can overload memory, alongside methods to trigger system-level issues and manipulate functionality like dark/light mode transitions. It serves as a unique resource for understanding and leveraging specific weaknesses within the iOS shortcuts framework.

KSMBD-CVE-2025-37947

2026-08-03 C ★ 20
The KSMBD-CVE-2025-37947 repository provides a proof-of-concept exploit targeting the out-of-bounds write vulnerability identified as CVE-2025-37947 in the ksmbd kernel server. Its primary use case is to demonstrate the exploitation of the vulnerability through various provided scripts and configuration files, including a BPF tracer and a minimal trigger. Notable features include a ready-to-use build system and a script to launch a testing environment using QEMU.

Laravel-RCE-Exploitation-Toolkit

2026-08-03 Python ★ 56
The Laravel RCE Exploitation Toolkit is a set of Python scripts designed for identifying and exploiting Remote Code Execution (RCE) vulnerabilities in Laravel applications via exposed .env files and compromised APP_KEYs. The first script, rce.py, generates a malicious payload to execute arbitrary code on the target server by writing a backdoor, while the second script, envtobase64.py, scans for .env files to extract APP_KEYs for reconnaissance purposes. Notable features include automated backdoor creation, result logging, and easy integration with target lists.

litefuzz

2026-08-03 Python ★ 69
Litefuzz is a multi-platform fuzzer designed to identify security-related bugs in userland binaries, clients, and servers across Linux, Mac, and Windows operating systems. Notable features include easy setup, support for both CLI and GUI applications, and capabilities for handling network communication, making it suitable for a wide range of testing scenarios. It emphasizes simplicity in discovering vulnerabilities rather than high performance or academic accolades.

Mirage

2026-08-03 Kotlin ★ 11
Mirage is an Android application designed to facilitate the auto-injection of shared objects into target processes using the hxo framework. Its primary use case is to enhance the functionality of applications, specifically within the context of Android environments, while supporting versions from Android 9 onwards. Key features include easy installation via an APK, developer support for customization, and a community-driven approach for real-time assistance and feedback.

Misanthro.py

2026-08-03 Python ★ 13
Misanthro.py is a multi-threaded injection framework designed for aggressive testing of HTTP headers, cookies, and GET/POST parameters, specifically targeting blind injection vulnerabilities such as blind XSS. It features high-throughput payload delivery, authenticated session support, and customizable attack vectors, while not interpreting application responses. The tool is optimized for speed and scalability, allowing users to perform extensive injection testing with minimal configuration.

Multi-Client-Reverse-Shell

2026-08-03 Python ★ 19
Multi-Client Reverse Shell is a tool designed for establishing multiple concurrent reverse shell connections from target machines to a listener, allowing for remote access and control. Notable features include an automatic persistence mechanism on Windows that disguises the backdoor as a regular file, as well as capabilities for file upload and download between the target and the hacker's listening server. The tool supports usage on both Linux and Windows platforms and is specifically designed to provide notifications for incoming connection requests from the targets.

n8n-CVE-2025-68613-exploit

2026-08-03 ★ 106
The n8n-CVE-2025-68613-exploit tool demonstrates a critical Arbitrary Code Execution vulnerability in n8n's workflow expression evaluation system for versions prior to v1.122.0. This exploit allows authenticated users to execute arbitrary commands by manipulating user-defined expressions in workflows, exposing the underlying runtime to system-level access. Notable features include injectible payloads for executing commands and a step-by-step reproduction process for testing the vulnerability.

padre

2026-08-03 Go ★ 280
Padre is an advanced tool designed for conducting Padding Oracle attacks against CBC mode encryption, enabling the decryption of tokens and encryption of arbitrary data. It features automatic fingerprinting of padding oracles, detection of cipher block lengths, and provides hints for overcoming failures during operations, all while supporting various encoding rules for enhanced flexibility. Particularly useful for security researchers and penetration testers, Padre can effectively exploit vulnerabilities to disclose encrypted session information or bypass authentication mechanisms.

PoCs-and-Exploits

2026-08-03 C ★ 13
The PoCs-and-Exploits repository offers a collection of exploits authored by the creator, categorized into three main directories: personal CVEs, their own exploits for external vulnerabilities, and third-party exploits for quick reference. The tool is primarily used for sharing research findings in cybersecurity, with an emphasis on privacy and documentation quality. Notable features include the organization of exploits by authorship and a commitment to including comprehensive README files for each exploit to elucidate their mechanics and root causes.

PoE

2026-08-03 F# ★ 12
PoE (Proof-of-Exploit) is a domain-specific language tailored for exploit development, offering an intuitive syntax that facilitates the writing of exploits. It features static typing, inline assembly integration, and the ability to manipulate bit-vectors, while supporting local, remote, and SSH modes for interacting with target systems. The tool is built on a .NET interpreter and includes automated patching functionalities, enhancing usability for cybersecurity practitioners.

pwnpasi

2026-08-03 Python ★ 394
PwnPasi is a professional automated binary exploitation framework tailored for CTF competitions and security research, streamlining the complex process of binary exploitation. It features smart vulnerability detection, advanced exploitation techniques like ROP chain construction and syscall exploitation, and supports multiple architectures with options for local and remote exploitation. Additionally, it offers flexible deployment modes and integrates various technical tools for thorough binary analysis.

pyFUD

2026-08-03 Python ★ 117
pyFUD is a cross-platform, fully undetectable (FUD) remote access tool (RAT) designed for multi-client handling, allowing persistent shell access and additional functionality such as file upload and download capabilities. The tool supports both Windows and Linux, with features including auto-reconnect and client executable conversion using PyInstaller, aimed primarily at educational use. Users are cautioned against uploading payloads to VirusTotal to maintain its effectiveness.

R2SAE

2026-08-03 Python ★ 63
R2SAE is a command-line tool designed to exploit prototype pollution vulnerabilities in React Server Actions, facilitating remote command execution on affected servers. Key features include command execution on single or multiple hosts, an interactive shell for streamlined command input, and a vulnerability scanning capability with both passive and active methods. This tool is intended solely for authorized security testing and educational purposes.

React2Shell

2026-08-03 Python ★ 53
React2Shell is an advanced exploitation toolkit specifically designed to target the React2Shell vulnerability (CVE-2025-55182) in Next.js applications. It offers an interactive shell experience with features such as command history, automated privilege escalation through pipe injection, and secure file transfer capabilities using base64 encoding. The tool consolidates its exploit logic into a single executable file, making it portable and easy to deploy for ethical penetration testing and security research.

react2shell-exploit

2026-08-03 Python ★ 19
React2Shell is an exploit tool designed to leverage a critical remote code execution (RCE) vulnerability in React Server Components (CVE-2025-55182), featuring multiple techniques to bypass Web Application Firewalls (WAFs). Its primary use case includes executing arbitrary JavaScript commands via HTTP requests while providing options for non-destructive vulnerability detection and sophisticated WAF evasion strategies, such as charset manipulation and junk data padding. The tool supports a variety of customization flags to enhance exploitation efficacy and evade detection mechanisms effectively.

Red-Team-Rising

2026-08-03 Python ★ 67
Red Team Rising is a comprehensive resource repository designed for red and purple team professionals, encompassing topics like Penetration Testing, Digital Forensics, Exploit Development, and Malware Analysis. It provides curated study materials, reference links to training platforms and notable YouTube channels, as well as practical commands and tools for various OS distributions suited for cybersecurity tasks. Notable features include a wide array of recommended resources for self-study and a focus on both offensive and defensive security strategies.

ronin-exploits

2026-08-03 Ruby ★ 80
ronin-exploits is a Ruby micro-framework designed for the creation and execution of exploit code, allowing exploits to be implemented as Ruby classes. Its primary use case is to simplify the process of writing exploits while providing a modular structure similar to Metasploit, featuring support for various exploit types such as stack overflows, command injections, and cross-site scripting. Notable features include a succinct API, the ability to load exploits from Ruby files or external git repositories, and a minimal memory footprint, making it efficient for security research and development.

Scripting

2026-08-03 PowerShell ★ 56
PDB2JSON is an Azure Functions-based application designed for secure authentication of running memory in Windows systems through its extensive SHA256 hash database. The tool provides a JSON-based interface for remote interactions with a Code+PDB analysis server, enabling functionalities like symbol resolution and hash verification without uploading binary data. Its notable features include a just-in-time hashing methodology for integrity protection and automation support for memory dump analysis through various scripting examples.

SettingContent-MS-File-Execution

2026-08-03 ★ 24
SettingContent-MS-File-Execution is a proof-of-concept tool that exploits the SettingContent-MS file execution vulnerability in Windows 10. It facilitates the automatic launch of Internet Explorer to load a specified website, which can be utilized to exploit existing vulnerabilities within the browser or to execute online payloads. Notable features include the ability to maximize the browser window and target specific online resources.

tcb-lpe

2026-08-03 Go ★ 18
SeTcbPrivilege Local Privilege Escalation (LPE) is a tool implemented in Go that leverages the SeTcbPrivilege privilege escalation technique to allow users to execute arbitrary commands with elevated permissions on Windows systems. Its primary use case is for gaining administrative access by manipulating service configurations, and it features automatic service deletion post-execution, with a manual clean-up option available. This tool provides a streamlined method for executing commands that would normally require higher privileges.

testbuild_exploit

2026-08-03 Shell ★ 11
testbuild_exploit is a tool designed to achieve elevated privileges (UID 1000) on vulnerable Android devices running test-signed ROMs by patching system apps to inject a backdoor. This allows users to execute commands with nearly root-level access, although functionality may be limited by SELinux configurations. Key features include the ability to modify any app, not just system ones, and integration with ADB for command execution.

TI-MultiView-data-recovery

2026-08-03 ★ 12
TI-MultiView-data-recovery is a tool designed to recover entries from the TI-30XS MultiView™ and TI-30XB MultiView™ scientific calculators after they have been reset. The procedure allows users to restore inputs and answers displayed on the home screen, leveraging specific key sequences, while noting that it does not recover settings or statistical data. The tool highlights the persistence of memory even after a reset, providing a workaround for users to retrieve valuable calculations.

TokenElevation

2026-08-03 C++ ★ 26
TokenElevation is a Windows utility that facilitates privilege escalation by enabling the SeImpersonatePrivilege, allowing the user to impersonate a logged-on user and duplicate the token of a specified target process. This tool is primarily used in administrative and debugging scenarios, enabling users with local Administrator access to execute new processes under the context of a target process to perform elevated tasks. Notable features include process token manipulation and the capability to spawn a new command prompt with the privileges of the target process specified by its PID.

Tor-0day-JavaScript-Exploit

2026-08-03 HTML ★ 10
The tool "Tor-0day-JavaScript-Exploit" serves as a comprehensive educational resource and demonstration of the CVE-2024-9680 vulnerability, a critical use-after-free exploit in the Tor Browser's animation handling. It includes both the original exploit code used in the wild and a modified version with detailed analyses, showcasing the exploitation process through various stages such as initialization, DOM crafting, and trigger mechanisms. This repository is intended primarily for security education, defensive research, and authorized vulnerability assessments, emphasizing ethical and legal usage.

udbg

2026-08-03 Rust ★ 19
udbg is a cross-platform Rust library designed for binary debugging and memory manipulation, providing uniform interfaces across various operating systems. Its primary use case is to facilitate the inspection and control of multiple debug targets without invasive attachment, supporting comprehensive target information retrieval and debugging functionalities. Notable features include support for multiple architectures, non-invasive operation modes, and capabilities for breakpoint and watchpoint management.

valthrun-cs2

2026-08-03 Rust ★ 24
Valthrun an open source external CS2 read only kernel gameplay enhancer.

vulnerability

2026-08-03 HTML ★ 25
The 'vulnerability' tool catalogs known vulnerabilities for various software, with a current focus on Microsoft Internet Explorer and Apple OSX, listing specific Common Vulnerabilities and Exposures (CVEs) associated with each platform. The primary use case is to provide a reference for security professionals looking to understand and track reported vulnerabilities. Notable features include the organization of vulnerabilities by vendor and product, enabling easier identification of security concerns.

WaSonar

2026-08-03 JavaScript ★ 53
WaSonar is a command-line interface tool designed for educational research and security assessments focused on the WhatsApp protocol. It facilitates real-time device tracking, device discovery, and profile extraction from linked devices, while also offering a resource exhaustion feature that can stress test the target by sending oversized payloads. Notably, WaSonar employs silent probes to determine online status without alerting the user and allows users to initiate rapid, high-frequency message deliveries to gauge system resilience.

wpctf2025

2026-08-03 CSS ★ 15
The WP CTF 2025 repository offers a collection of cybersecurity challenges created for the WP Capture the Flag event, aimed at enhancing skills among young cybersecurity enthusiasts. It features a diverse range of challenges across multiple categories such as Crypto, OSINT, PWN, and Reversing, with varying difficulty levels, and includes source code, solutions, and walkthroughs for each challenge. Notable features include the ability to exploit vulnerabilities, reverse engineer to understand systems, and perform forensic analysis, making it a comprehensive resource for hands-on learning in cybersecurity.

WSUS-CVE-2025-59287-RCE

2026-08-03 C# ★ 11
WSUS-CVE-2025-59287-RCE is a proof-of-concept exploitation tool for a critical remote code execution vulnerability (CVE-2025-59287) in Microsoft Windows Server Update Services. The tool automates the generation and transmission of a malicious payload that exploits insecure deserialization in the WSUS GetCookie() endpoint, enabling unauthorized execution of arbitrary code with system privileges. Key features include payload generation, AES encryption, and SOAP request construction, facilitating a straightforward reverse shell setup through user input for target and listener configurations.

XWormRCE

2026-08-03 C# ★ 15
XWorm RCE is a proof of concept tool that demonstrates a zero-click vulnerability within the XWorm plugin for RDP connections. It exploits a flaw where the server fails to validate client responses, allowing an attacker to execute commands on the victim's machine without user interaction. Notable features include the ability to exploit the vulnerability without initiating a connection command, showcasing its potential for remote code execution.

0xKern3lCrush

2026-08-03 C ★ 52
0xKern3lCrush is an educational repository designed to understand Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques and document key artifacts related to recent vulnerabilities like CVE-2026-0828. It provides safe user-mode reconnaissance code for process enumeration, alongside static analysis on identified vulnerable drivers, aimed at assisting security professionals in recognizing patterns in malicious behavior and improving detection capabilities. Notable features include an emphasis on ethical usage, detailed research notes, and a lack of any exploitative code to prevent misuse.

botnet-exploits

2026-08-03 Python ★ 20
The botnet-exploits repository is a collection of network vulnerability scanners designed to identify security weaknesses across various devices for educational and authorized testing purposes. It includes tools specifically for testing DVRs, ZHONE routers, Fiber routers, and performing telnet brute force attacks, featuring capabilities like multi-threaded scanning, real-time status updates, and automated credential testing. Users are required to configure payload URLs for legitimate testing environments, reinforcing the ethical use of these tools.

CVE-2023-23752-EXPLOIT

2026-08-03 Python ★ 18
CVE-2023-23752-EXPLOIT is a proof of concept tool designed to demonstrate an improper access check vulnerability in Joomla versions 4.0.0 to 4.2.7, allowing unauthorized access to sensitive web service endpoints. Its primary use case is for educational and ethical security research, emphasizing responsible usage and compliance with legal standards. The repository includes a PoC to illustrate the exploit, highlighting the potential severity of the vulnerability.

CVE-2025-27237

2026-08-03 Python ★ 20
CVE-2025-27237 is a local privilege escalation vulnerability affecting the Zabbix Agent for Windows, which arises from OpenSSL configuration file hijacking due to hardcoded paths accessible to low-privileged users. This tool provides scripts and proof-of-concept (PoC) implementations to analyze affected Zabbix binaries, compile malicious DLLs, and facilitate exploitation in vulnerable systems, while also offering methods for detection and remediation. Key features include binary analysis tools and detailed documentation for ensuring system security against this identified vulnerability.

DEDSEC_BKIF

2026-08-03 ★ 31
DEDSEC_BKIF is a keystroke injection tool that exploits CVE-2023-45866, enabling attackers to manipulate Bluetooth-enabled devices across Android, Linux, and iOS platforms. Its primary use case is remote keystroke injection and unauthorized command execution through a zero-click Bluetooth vulnerability, allowing devices to be compromised without user interaction. Notable features include support for rubber ducky payloads and the capability to bypass authentication, making it a versatile threat in the realm of Bluetooth security.

Ethical_Hacking_and_Penetration_Testing

2026-08-03 Python ★ 94
This repository serves as a comprehensive resource for ethical hacking and penetration testing, offering a collection of articles, scripts, tutorials, and multimedia content focused on various platforms including Linux, Windows, and cloud services. It aims to share the author's expertise and provide guidance on security practices while emphasizing the importance of legal compliance. Regular updates are planned to enhance the repository's educational value for the cybersecurity community.

ForceAdmin

2026-08-03 AutoIt ★ 120
ForceAdmin is a malicious tool designed to create an infinite loop of User Account Control (UAC) prompts, compelling users to grant administrative privileges by overwhelming them with requests. It provides various script templates in formats such as batch, PowerShell, AutoHotkey, AutoIt, HTA, and VBScript, facilitating execution via PowerShell and bypassing antivirus protections. Notable features include no dependencies, dual architecture support for x86 and x64 systems, and a fileless execution method.

PoC-Research-Papers

2026-08-03 JavaScript ★ 115
The "Proof-of-Concept (PoC) Research Papers" repository aggregates recent academic papers focused on exploit generation, empirical analysis, and applications of Proof-of-Concept methodologies in cybersecurity. Its primary use case is to serve as a comprehensive resource for researchers and practitioners to access and contribute to the latest findings and developments in PoC research. Notable features include a well-organized categorization of papers by year and topic, making it easier to navigate the content and identify relevant studies.

RE_Mal_Exploit_Tutorials

2026-08-03 ★ 16
RE_Mal_Exploit_Tutorials serves as a comprehensive resource hub focused on reverse engineering, malware analysis, and exploit development. It aggregates various tutorials, guides, and tools, facilitating knowledge acquisition for security professionals and enthusiasts interested in understanding and mitigating software vulnerabilities. Noteworthy features include curated links to both beginner and advanced learning materials across multiple platforms, encompassing both theoretical and practical aspects of cybersecurity topics.

tx2hax

2026-08-03 Rust ★ 81
tx2hax is a repository that provides exploit implementations for vulnerabilities in the Tegra X2 and Magic Leap One devices, primarily focusing on achieving code execution in the BootROM of the Tegra X2 through USB Recovery Mode. Notable features include specific exploits such as `rcmhax`, `sparsehax`, and `dtbhax`, along with detailed writeups that document the exploitation techniques and methodologies employed.

0-to-Hero

2026-08-03 C ★ 10
This repository provides a proof-of-concept for a Windows local privilege escalation exploit that combines a User Account Control (UAC) bypass with token duplication to elevate a process to SYSTEM-level privileges. It serves primarily for educational purposes, demonstrating key concepts of Windows security, such as token mechanics and process elevation, while employing techniques like registry manipulation and access token duplication to illustrate vulnerabilities in privilege management. Notably, the tool employs specific Windows APIs for process creation and token handling, highlighting potential attack vectors in a controlled environment.

AiGPT-WordPress-Exploitation-Framework

2026-08-03 Python ★ 133
AiGPT is an automated exploitation framework designed for rapidly discovering and compromising vulnerable WordPress sites, leveraging a multi-vector engine to exploit thirteen unauthenticated CVEs. Key features include intelligent plugin fingerprinting, the ability to create unauthorized WordPress admin accounts, direct access through SQL injection, and a multi-threaded scanning capability for efficiency across networks. This tool is intended for authorized penetration testing and security research purposes.

AKILT

2026-08-03 Go ★ 116
AKILT is an open-source botnet framework designed for security enthusiasts and malware analysts to facilitate the study of botnet operations. Written in Go, it supports both client and server functionalities with advanced features such as screen capture, remote command execution, DDOS attacks, and a keylogger, while aiming to remain undetectable. The tool provides a valuable resource for understanding the implementation and behavior of botnets in a controlled environment.

AntiDarkSword

2026-08-03 Objective-C ★ 104
AntiDarkSword is an iOS jailbreak tweak and a TrollStore dylib designed to enhance the security of vulnerable iOS devices against WebKit RCE and iMessage zero-click exploits. Its notable features include the ability to selectively disable Just-In-Time (JIT) compilation, spoof user agents, block risky attachments, and isolate system daemons, effectively mitigating various types of attacks. Additionally, the tool can deploy a Corellium honeypot to disrupt advanced payloads.

Atomic-Mirai

2026-08-03 C ★ 17
Atomic-Mirai is an educational tool modeled after the Condi-Mirai botnet family, aimed at facilitating research on IoT security vulnerabilities and DDoS attack methodologies. It features a flexible compilation process for various architectures and includes a command and control (C&C) server setup, allowing users to simulate and analyze attack vectors in a controlled environment. Notably, this tool is strictly intended for educational and research purposes, with a clear disclaimer against illegal usage.

attackmate

2026-08-03 Python ★ 51
AttackMate is an automation tool designed to execute cyber attack scenarios across all phases of the Cyber Kill Chain, integrating seamlessly with penetration testing frameworks like Metasploit and Sliver Framework. It allows users to script commands, generate payloads, schedule and chain attack steps using configuration files, and perform background operations, including file transfers and HTTP interactions. Noteworthy features include automation of shell or SSH commands, comprehensive support for Metasploit and Sliver commands, and a user-friendly interface for managing complex attack scenarios.

Autorun-ng

2026-08-03 Rust ★ 52
Autorun-ng is a versatile tool designed for launching applications with a streamlined user interface, supporting both Linux and Windows environments. Its notable features include a sandboxed filesystem leveraging cap-std for enhanced security, ergonomic Lua API bindings for seamless integration, and a zero-dependency library for accessing source engine interfaces. This tool eliminates the need for menu plugins or manual injections, making application execution efficient and user-friendly.

awesome-mcp-security

2026-08-03 ★ 733
Awesome MCP Security is a comprehensive resource focusing on the security aspects of the Model Context Protocol (MCP), providing guidance on best practices, potential vulnerabilities, and mitigation strategies. It includes a variety of materials such as academic papers, articles, tools, and security considerations aimed at enhancing the security of applications utilizing MCP. Notable features include detailed security guidelines for both clients and servers, highlighting the importance of human oversight and proper input validation.

awesome-vm-escape

2026-08-03 ★ 607
The "awesome-vm-escape" repository is a comprehensive collection of write-ups, exploits, and resources focused on virtual machine escape and container breakout vulnerabilities. It includes categorized information on various platforms such as VMware, VirtualBox, QEMU, and Docker, providing valuable insights for security researchers and practitioners looking to understand and exploit VM-related security flaws. Notable features of the repository include curated lists of exploits and case studies relevant to each virtualization technology, which facilitate knowledge sharing and advancement in the field of cybersecurity.

bluebox

2026-08-03 Go ★ 264
Bluebox is a collection of exploits tailored for various VoIP products, primarily designed for penetration testing and the exploitation phase of VoIP environments. It utilizes the Go Exploit Framework and features a Docker Compose file that includes an Asterisk server for testing purposes, facilitating a streamlined approach for security professionals to assess vulnerabilities in VoIP systems.

BlueToolkit

2026-08-03 Jupyter Notebook ★ 729
BlueToolkit is an extensible, black-box framework designed for testing Bluetooth vulnerabilities in both Bluetooth Classic (BR/EDR) and Bluetooth Low Energy (BLE) systems. Its primary use case includes semi-automated testing through its three main modules: Recon for capability gathering, Exploit for executing a range of 43 public exploits, and Report for generating comprehensive JSON reports. Additionally, the framework has been evaluated against multiple automotive brands, revealing significant security vulnerabilities in their Bluetooth implementations.

Bolt-Unblocker

2026-08-03 TypeScript ★ 61
Bolt Unblocker is a Node.js-based proxy tool designed to bypass content restrictions, offering support for various popular platforms, including GeForce NOW and Discord. Its notable features include a user-friendly OS GUI, two high-speed proxy options, flexible cloaking capabilities, and robust site support, leveraging the latest Ultraviolet V3 proxy service for improved performance compared to outdated alternatives. Users can deploy Bolt on multiple platforms but must avoid certain static hosting services to ensure full functionality.

C-hacks

2026-08-03 Python ★ 295
C-hacks is a social media gathering tool designed for educational purposes, featuring WhatsApp, Facebook, and Instagram hacking capabilities, along with information gathering functionalities. Notable features include IP location tracking and phishing scripts, as well as modified WhatsApp for enhanced functionality. Installation is straightforward, requiring basic Linux commands to set up and execute the tool.

CentralizedPotatoes

2026-08-03 ★ 26
CentralizedPotatoes is a repository that aggregates various privilege escalation exploits in the Windows operating system, known as "potato" exploits, which leverage impersonation privileges to elevate access from service accounts to system level. The tool categorizes and documents these exploits, ranging from Hot Potato to God Potato, thereby providing a comprehensive reference for cybersecurity professionals and penetration testers. Notable features include a chronological list of exploits with links to their respective implementations and guidance on prioritizing their use based on effectiveness.

clickfix-builder

2026-08-03 Python ★ 23
ClickFix Builder is a dual-mode social engineering toolkit designed for red teamers, pentesters, and security researchers, enabling the generation of realistic fake captcha techniques for executing malware commands on Windows targets. Its notable features include the generation of portable files such as HTML and JS stubs, as well as a VPS deployment mode that provides real-time logging, IP blocking, and bot detection. The tool also offers a dark-mode GUI for enhanced usability and customizable payloads, making it versatile for various security testing scenarios.

clpzcode

2026-08-03 TypeScript ★ 16
clpzcode is an automated penetration testing tool that orchestrates a full pipeline of security assessments, including subdomain enumeration, vulnerability detection, exploitation, and privilege escalation. Notably, it employs an AI agent that intelligently adapts its actions based on tool responses, supports multi-agent parallelism for concurrent tasks, and features 29 built-in escalation chains for efficient threat exploitation. The tool’s command-driven interface allows users to initiate complex assessments with minimal input, streamlining the penetration testing process.

Conocimiento

2026-08-03 ★ 109
The "Vault de Conocimiento" is a personal repository designed for self-directed learning and documentation across various fields, including Cybersecurity, Computer Science, and Programming. It primarily serves as an organized collection of notes for ethical hacking, pentesting, cryptography, and more, structured for optimal use with the Obsidian note-taking app, which facilitates idea connections and navigation. Notable features include internal linking, graphical visualization, and a comprehensive index that covers foundational to advanced topics in multiple domains.

copy-fail-CVE-2026-31431

2026-08-03 Python ★ 4056
Copy Fail is a cybersecurity tool designed to exploit CVE-2026-31431, a vulnerability affecting specific Linux distributions. Its primary use case is for security researchers and penetration testers to demonstrate and assess the impact of this flaw across various operating systems, including Ubuntu, Amazon Linux, RHEL, and SUSE. Notable features include compatibility with multiple Linux kernel versions and a comprehensive technical writeup for understanding the vulnerability's implications.

Copy-Fail-CVE-2026-31431-Kubernetes-PoC

2026-08-03 C ★ 187
Copy Fail is a proof-of-concept tool designed to demonstrate a method for fully unprivileged containers to achieve node-level code execution on Kubernetes by exploiting the CVE-2026-31431 Linux kernel vulnerability. It leverages the shared image layers in container runtimes, allowing an unprivileged pod to corrupt binaries in a shared layer that are later executed by privileged DaemonSets, thereby achieving container escape. Notable features include validation on multiple cloud platforms (Alibaba Cloud, Amazon EKS, and Google GKE) and a comprehensive breakdown of the attack chain, which includes page-cache corruption, cross-container propagation, and privileged execution.

copyfail-exploit

2026-08-03 Python ★ 25
CopyFail is a Python-based exploit tool targeting the CVE-2026-31431 vulnerability, which allows local privilege escalation on vulnerable Linux kernels (4.11 to <6.18). It utilizes the AF_ALG socket interface bug to enable unprivileged users to overwrite setuid binaries, bypassing race conditions and kernel-specific offsets, making it applicable across various distributions. Key features include the ability to check system vulnerability status, a simple execution process, and container escape capabilities, all while being an educational tool intended for authorized testing only.

copyFail30

2026-08-03 Python ★ 44
CopyFail is a Python library designed to perform the splice system call between file descriptors for Python versions earlier than 3.10, utilizing ctypes for syscall implementation. Its primary use case is to facilitate efficient data copying between file descriptors in environments where the splice() function is not natively available. Notable features include compatibility with both legacy and current Python versions, enhancing its versatility in various applications.

Cracking-OSCP-Your-Roadmap-to-Ethical-Hacking-Success

2026-08-03 Python ★ 10
The "Cracking OSCP" repository offers a comprehensive roadmap for aspiring ethical hackers pursuing the OSCP certification. It features a structured playlist of video tutorials and supplementary notes across various topics, including computer networks fundamentals and practical examples, aimed at providing a solid foundation for ethical hacking methodologies. Notable aspects include detailed guidance on note-taking, network concepts, and the OSI model, making it a valuable resource for both beginners and those preparing for the OSCP exam.

CVE-2020-10558

2026-08-03 HTML ★ 15
CVE-2020-10558 is a tool that documents a critical Denial of Service vulnerability in Tesla Model S, 3, and X vehicles prior to software version 2020.4.10, which allows remote attackers to crash the vehicle's Infotainment system by exploiting improper web instruction handling. The tool provides insights into the attack vector, impact on vehicle functionality, and remediation details following responsible disclosure protocols. Notably, the findings led to a fleet-wide OTA update from Tesla to mitigate the vulnerability, highlighting its significance in automotive cybersecurity.

CVE-2021-41773_CVE-2021-42013

2026-08-03 Shell ★ 20
This tool serves as a proof of concept (PoC) exploit for the Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013, which allow for path traversal and remote code execution (RCE) in versions 2.4.49 and 2.4.50. Its primary use case is to demonstrate these exploits against specified targets, facilitating security assessments and vulnerability testing. Notable features include the ability to read sensitive files and execute arbitrary commands on the server via customizable input parameters.

CVE-2022-0847-Container-Escape

2026-08-03 C ★ 37
The CVE-2022-0847 tool exploits a vulnerability known as "Dirty Pipe" to achieve container escape, allowing an attacker to overwrite read-only files on the host system from within a container. Its primary use case is for demonstrating the potential risks associated with granting the `CAP_DAC_READ_SEARCH` capability to containers. Notable features include the ability to bypass file permission checks and use the `splice()` system call to overwrite files directly on the host filesystem.

CVE-2023-43208-EXPLOIT

2026-08-03 Python ★ 29
CVE-2023-43208-EXPLOIT is a Proof-of-Concept (PoC) tool designed to exploit a remote code execution vulnerability in Mirth Connect versions prior to 4.4.1. The tool utilizes specially crafted HTTP requests to execute arbitrary OS commands on vulnerable systems, offering features such as single and batch target exploitation, customizable listening options for reverse connections, and multi-threaded scanning capabilities.

CVE-2024-6387_Check

2026-08-03 Python ★ 527
CVE-2024-6387_Check is a specialized tool for detecting servers vulnerable to the newly identified `regreSSHion` vulnerability in OpenSSH (CVE-2024-6387). It supports rapid scanning of IP addresses, domain names, and CIDR ranges, incorporates features such as multi-threading for efficiency, SSH banner retrieval, and options for assessing LoginGraceTime settings, all while providing detailed and easily interpretable output. Notably, the tool also includes IPv6 support and recognizes patched OpenSSH versions to enhance the accuracy of vulnerability assessments.

CVE-2025-14558

2026-08-03 Python ★ 13
CVE-2025-14558 is an exploit tool designed to demonstrate a command injection vulnerability in the `rtsold` service on FreeBSD systems, which allows remote code execution due to improper validation of DNSSL domain names. It requires Layer 2 adjacency to the target and enables attackers to execute arbitrary commands with root privileges by leveraging shell metacharacters. The tool is intended for defensive security research and authorized testing only.

CVE-2025-25198-PoC

2026-08-03 Python ★ 20
The CVE-2025-25198-PoC tool serves as a proof-of-concept exploit targeting a host header poisoning vulnerability in Mailcow's password reset mechanism. It automatically sets up a local HTTPS listener, retrieves a CSRF token, and initiates a password reset request with a manipulated Host header to capture valid reset links from the target system's responses or callbacks. Notable features include automatic CSRF token handling, customizable attack parameters, and the ability to retry until a reset link is successfully captured.

CVE-2025-60787

2026-08-03 Python ★ 10
CVE-2025-60787 is a proof-of-concept tool that exploits an authenticated remote code execution vulnerability in motionEye versions up to 0.43.1b4. It features two main commands: `revshell` for establishing a reverse shell connection and `command` for executing arbitrary commands on the target system, facilitating exploitation of the vulnerability. Users must provide the target's URL and authentication credentials to utilize the tool effectively.

CVE-2026-0073-Android-ADBD-bypass-POC

2026-08-03 Python ★ 22
The CVE-2026-0073 tool exploits a critical authentication bypass vulnerability in the Android ADB daemon (`adbd`), enabling an attacker on the same local network to gain unauthorized shell access to the target device. It leverages a type confusion issue in the TLS client certificate validation process, allowing for full control without user consent. Notable features include the capability to execute single commands, use different key types, and support for verbose output to trace the exploitation process.

CVE-2026-23918-Apache-H2-PoC

2026-08-03 Python ★ 23
This tool is a proof-of-concept exploit for the double-free vulnerability (CVE-2026-23918) in Apache's `mod_http2`, capable of inducing a denial-of-service (DoS) by repeatedly crashing server workers through a race condition in stream cleanup. It allows users to demonstrate this vulnerability's impact via various modes, including aggressive DoS and passive vulnerability detection, by manipulating how Apache handles early stream resets. While remote code execution (RCE) is theoretically possible, it requires multiple specific conditions, making reliable exploitation complex and unlikely for most attackers.

CVE-2026-27771

2026-08-03 Python ★ 19
CVE-2026-27771 is a proof-of-concept tool that exploits an authentication bypass vulnerability in Gitea's OCI container registry, allowing unauthorized remote attackers to retrieve private container images from affected instances. Designed primarily for educational and authorized security research, it can scan for vulnerable Gitea setups and facilitate the pulling of container images without authentication. Notable features include scanning for instances, pulling all images or specific repositories, and the ability to operate with a personal access token when sign-in is required.

CVE-2026-31431-CopyFail-Universal-LPE

2026-08-03 Python ★ 57
CVE-2026-31431-CopyFail is a local privilege escalation exploit targeting a vulnerability in the Linux kernel's AF_ALG crypto subsystem, allowing an unprivileged user to perform a 4-byte arbitrary write in the kernel's page cache. The tool offers multiple exploitation methods, including dynamic ELF entry point overwrites and full binary replacements, with compatibility for both Python 2 and 3. Notable features include determinism without race conditions, operation within default Docker containers, and independence from kernel version, making it applicable across all kernels since 2017.

CVE-2026-31431-Linux-Copy-Fail

2026-08-03 Rust ★ 56
The CVE-2026-31431-Linux-Copy-Fail tool is a Rust-based local privilege escalation exploit that leverages an arbitrary page cache write vulnerability in Linux systems. It facilitates the execution of customizable shellcode, including a Meterpreter payload, and offers functions for testing vulnerability and executing exploits. Notable features include support for direct payload substitution and detailed usage instructions for compiling and executing the tool on affected Linux distributions.

CVE-2026-41089

2026-08-03 Python ★ 212
CVE-2026-41089 is a proof-of-concept (PoC) tool that exploits a stack-based buffer overflow vulnerability in Windows Domain Controllers' LSASS service via crafted UDP packets to port 389, potentially causing a denial of service (DoS) by crashing and rebooting the Domain Controller with no authentication required. It features a straightforward three-phase operation, confirming the target's liveness, executing the overflow, and checking if the DC is still operational, while being designed to work with Python 3.8 and later without external dependencies. Notably, it highlights the inherent risk of stack corruption leading to remote code execution (RCE) possibilities.

CVE-2026-41940-Exploit-PoC

2026-08-03 Python ★ 13
The CVE-2026-41940 Exploit PoC tool is designed to exploit a vulnerability for bypassing authentication in specific web applications. Its primary use case involves running an exploit script that captures session tokens, which can then be manipulated in Burp Suite to gain unauthorized access. Notable features include straightforward exploitation commands and session hijacking techniques for effective testing of web application security.

CVE-2026-48908-PoC

2026-08-03 Python ★ 16
CVE-2026-48908-PoC is a proof-of-concept exploit for a critical unauthenticated remote code execution vulnerability in the SP Page Builder component for Joomla. This tool leverages the improper access control in the asset.uploadCustomIcon task to upload malicious files to a publicly accessible directory, ultimately enabling an attacker to execute arbitrary code on the target server. Notable features include an adaptive payload mechanism that tests various file extensions and .htaccess file injections to bypass server restrictions, as well as cleanup functionality to remove uploaded artifacts after exploitation.

CVE-Mapper

2026-08-03 Python ★ 12
CVE Mapper is a tool designed to correlate Nmap scan results with relevant CVEs specific to the discovered product versions, minimizing false positives. It utilizes the Vulners API to provide version-accurate vulnerability mappings while re-validating the affected version ranges and generating confidence levels for each finding. The tool supports multiple output formats including JSON, CSV, and HTML, making it versatile for reporting and further analysis.

cve-scores

2026-08-03 ★ 258
CVE Scores is a tool designed to aggregate and analyze vulnerability scores from various sources, specifically the Exploit Prediction Scoring System (EPSS) and the Vulnerability & Exploit Data Aggregation System (VEDAS). Its primary use case is to predict future exploitation of vulnerabilities and estimate the prevalence and exploit maturity of identified vulnerabilities. Notable features include real-time data updates, integration of proprietary and open source intelligence, and the ability to assess vulnerabilities across multiple identifiers.

Dirty-Frag-Kubernetes-PoC

2026-08-03 C ★ 18
Dirty Frag is a proof-of-concept tool that demonstrates how an unprivileged Kubernetes Pod can exploit the Dirty Frag vulnerability (CVE-2026-43284) to achieve node-level code execution on Amazon EKS by corrupting in-memory cached pages of shared container image layers. Its primary use case is to illustrate the risks associated with privileged DaemonSets in Kubernetes clusters that share image layers, as it allows for direct execution of compromised binaries by these privileged workloads. Notable features include the ability to target any privileged DaemonSet, leveraging kernel page-cache corruption alongside the sharing of image layers, thereby exposing a significant security vulnerability in Kubernetes environments.

dirtyfrag-arm64

2026-08-03 C ★ 29
dirtyfrag-arm64 is an ARM64/AARCH64 exploit tool adapted from the original x86_64 dirtyfrag PoC, targeting vulnerabilities CVE-2026-43284 and CVE-2026-43500. Its primary use case is for privilege escalation by corrupting system binaries, specifically employing an ESP path for exploitation due to limitations on the ARM64 architecture. Notable features include detailed analysis of AppArmor bypass methods and architecture-specific payload adaptations, allowing it to interact with existing user and network namespaces on vulnerable systems.

End-To-End-SOC-Home-Lab

2026-08-03 C++ ★ 11
End-To-End-SOC-Home-Lab is a comprehensive project designed to construct a Security Operations Center (SOC) lab on a personal computer, utilizing Splunk for monitoring and detection of cybersecurity threats. It enables users to simulate various attack scenarios, analyze the resultant logs and telemetry, and develop effective detection mechanisms, thereby fostering skills pertinent to both red team attack simulations and blue team defensive strategies. Notable features include detailed guidance on setting up infrastructure, practical use cases for threat detection, and a focus on hands-on learning through real-world attack techniques.

ESP32-Sour-Apple

2026-08-03 Python ★ 618
SourApple is a ported exploit targeting iOS 17 devices that uses BLE pairing requests to induce crashes on vulnerable iPhones. It specifically operates on ESP32 and Raspberry Pi platforms, allowing users to evaluate the security of their devices under controlled conditions. Notable features include a focus on educational use, testing on multiple iOS models, and the provision of troubleshooting guidance for common compilation errors.

exploitation-grimoire

2026-08-03 Python ★ 64
PwnLand is an open-source resource designed for security researchers and CTF participants, focusing on binary exploitation techniques. It provides an extensive collection of practical examples, tutorials, and research materials on various vulnerabilities, including buffer overflows, format string vulnerabilities, heap exploitation, and kernel exploits. Notable features include structured directories for different exploitation methods, debugging guides, and challenges for hands-on practice.

express-honeypot

2026-08-03 JavaScript ★ 21
Express Honeypot is a honeypot tool designed to detect and log remote file inclusion (RFI) and local file inclusion (LFI) attacks against web applications. It functions by serving fake URLs generated from a list of known vulnerable paths, dynamically logging any malicious requests, and downloading the attempted remote files for analysis. Key features include a lightweight log viewer and the ability to customize monitored URLs, making it an effective solution for catching and studying automated scanning bots.

ext-remover

2026-08-03 JavaScript ★ 562
EXT-REMOVER is a curated collection of exploits designed specifically for ChromeOS, facilitating various forms of system modifications and enhancements, such as unenrollment from management systems and disabling or freezing browser extensions. It includes notable capabilities like bypassing security measures, tampering with policies, and modifying system configurations, though users are cautioned against misuse that can cause significant damage. The repository serves as a resource for those seeking to explore the security aspects of ChromeOS within legal boundaries.

external-process

2026-08-03 C++ ★ 12
The external-process framework provides mechanisms for interacting with external Win32 processes, enabling operations such as reading and writing process memory, allocating memory, calling functions with various calling conventions, and performing code injection. It is primarily used for creating trainers or utilities that modify the behavior of running applications. Notable features include the ability to search for byte sequences in memory and a built-in external process simulator for testing purposes.

gef

2026-08-03 Python ★ 8329
GEF (GDB Enhanced Features) is a powerful tool designed to enhance the functionality of GDB (GNU Debugger) for exploit development and reverse engineering across multiple architectures such as x86/64, ARM, and MIPS. Notable features include architecture agnosticism, a single installation script, full Python 3 support, and a variety of commands that optimize the debugging experience while facilitating dynamic analysis. The tool is designed to reduce cognitive load on developers by offering a more intuitive interface and extensive community contributions.

HatSploit

2026-08-03 Python ★ 329
HatSploit is a modular penetration testing framework designed for writing, testing, and executing exploit code. Its primary use case is to facilitate security assessments and vulnerability exploitation in a structured manner. Notable features include its extensibility through modules and a user-friendly interface for deploying exploits.

isoalloc

2026-08-03 C ★ 389
Isolation Alloc (IsoAlloc) is a secure, C11-based memory allocator designed as a drop-in replacement for `malloc` on 64-bit Linux and MacOS systems, emphasizing memory allocation isolation to enhance security by spatially separating objects of various sizes and types. Key features include the management of memory through distinct zones for specific sizes, comprehensive debugging support for memory leaks and usage, and built-in compatibility with Address Sanitizer and similar tools. IsoAlloc is particularly suitable for applications where security and performance of memory management are crucial.

k8gege.github.io

2026-08-03 HTML ★ 42
The k8gege.org repository hosts a website that serves as a centralized platform for Kubernetes-related resources and tools. Its primary use case is to provide educational content, documentation, and best practices for Kubernetes users and developers. Notable features include curated links to tutorials, articles, and other valuable resources in the Kubernetes ecosystem.

Linux-Exploitation

2026-08-03 C ★ 18
The Linux-Exploitation repository provides a comprehensive set of tools and techniques for performing privilege escalation on Linux systems. Its primary use case is to assist security professionals in identifying vulnerabilities that can be exploited to gain higher access levels, featuring sections on manual enumeration, automated tools, password mining, misconfiguration exploitation, and maintaining access through SSH key uploads. Notable features include detailed guides on various escalation methods, scripts for automated enumeration, and an exhaustive list of potential exploits tailored for Linux environments.

Lost-NDS-TV

2026-08-03 ★ 485
Lost-NDS-TV is a project aimed at restoring the hidden television composite video output feature of the Nintendo DS Lite's SoC through custom hardware designs and software solutions. Its primary use case is to enable video output from the DS Lite for enhanced viewing experiences, supported by comprehensive schematics, production files, and installation tutorials. Notable features include detailed documentation and video tutorials for installation, making it accessible for users interested in retro gaming modifications.

Magento-Polyshell-RCE

2026-08-03 PHP ★ 29
Magento PolyShell is an advanced exploitation toolkit designed for unauthenticated remote code execution (RCE) on Magento 2.x through polyglot file uploads via the REST API. It tests over 45 PHP extension variants while utilizing multi-header support, server fingerprinting, and advanced WAF bypass techniques to maximize exploitation success across a wide range of environments. Key features include interactive and CLI modes, categorization of results by target, and extensive post-exploitation capabilities for system information retrieval.

Malware

2026-08-03 PowerShell ★ 50
The "Malware" repository offers a collection of malware samples and resources for cybersecurity professionals. Its primary use case is to facilitate testing and analysis of malware, including the ability to download various samples using proxy tools like proxychains. Notable features include the inclusion of the EICAR test file for antivirus testing and the ability to aggregate IP addresses from logs for streamlined malware acquisition.

Mephisto

2026-08-03 Python ★ 77
Mephisto is a WordPress vulnerability scanner and exploitation framework designed for authorized penetration testing, enabling security professionals to assess multiple WordPress installations for security weaknesses. Key features include multi-CVE support, mass scanning capabilities, automatic detection of vulnerable plugins and themes, and the ability to upload web shells for post-exploitation access, all while ensuring anonymity through proxy support and anti-detection measures.

MS-RPC-Fuzzer

2026-08-03 C# ★ 349
MS-RPC Fuzzer is a PowerShell module designed for automated vulnerability research in Microsoft Remote Procedure Call (MS-RPC) implementations. Its primary use case involves dynamically building RPC clients to fuzz various RPC procedures using random inputs, aiming to identify potential vulnerabilities in RPC services efficiently. Notable features include a structured three-phase process for inventorying RPC interfaces, performing fuzzing based on gathered data, and analyzing results with options for visualization in a Neo4j database.

neospring

2026-08-03 Swift ★ 13
Neospring is a tool designed to facilitate the respring process in LiveContainer environments, addressing limitations found in existing solutions like InstaSpring and respringapp. By leveraging a method originally developed by neon and ported to Swift by skadz, it offers a streamlined and effective approach for developers and users working with iOS customization. Notable features include enhanced compatibility with LiveContainer, enabling efficient system refresh without typical constraints.

NmiCallbackBlocker

2026-08-03 C++ ★ 195
The NmiCallbackBlocker is a driver concept that modifies kernel memory to prevent Non-Maskable Interrupts (NMIs) from executing by altering processor affinity masks. Its primary use case is to aid in bypassing anti-cheat mechanisms within gaming environments, leveraging techniques like signature scanning and structure manipulation for stealth operations. Notable features include the ability to evade detection through spoofing techniques and encrypted signatures, though it is important to note that the project includes no built-in anti-cheat protections.

NTRGhidra

2026-08-03 Java ★ 222
NTRGhidra is a plugin for Ghidra that serves as a Nintendo DS loader, enabling users to analyze and debug DS software within the Ghidra environment. It supports Ghidra version 12.0.4 and allows for dynamic loading and unloading of overlays, enhancing the tool's functionality for developers working with Nintendo DS applications. Notable features include extension installation for Ghidra and comprehensive build instructions for developers interested in modifying the loader.

octoscan

2026-08-03 Go ★ 274
Octoscan is a static vulnerability scanner designed for GitHub action workflows, enabling users to identify potential security issues within their CI/CD pipelines. Its primary use case is analyzing workflows for various vulnerabilities, including dangerous actions, credentials exposure, and expression injection. Notable features include the ability to download workflows from remote repositories, customizable rule sets for scanning, and support for multiple output formats, ensuring flexibility in vulnerability reporting.

OnlyShell

2026-08-03 Go ★ 68
OnlyShell is a Go-based reverse shell handler designed for penetration testers and security researchers, enabling the management of multiple reverse shell connections concurrently. Key features include automatic shell type detection, background shell management, command broadcasting across active shells, and the option for encrypted communications with TLS support. The tool offers an intuitive command-line interface and allows for real-time interaction and status monitoring of all connected sessions.

padoracle

2026-08-03 JavaScript ★ 10
Padoracle is a Node.js tool designed to perform Padding Oracle Attacks, allowing users to crack plaintext from encrypted data using a known initialization vector (IV) and ciphertext. Its notable features include a user-friendly command-line interface (CLI), robust API support, the ability to generate IV and ciphertext with modified plaintext, and an ultra-fast cracking capability with unlimited concurrency. This tool is particularly useful for security researchers and professionals looking to exploit vulnerabilities in web applications utilizing padding oracle patterns.

Pentagram-exploit-tester

2026-08-03 C ★ 19
Pentagram-exploit-tester is a utility designed to assess whether a device running iOS 15.0 to 15.1.1 and 15.2 BETA 1 is vulnerable to CVE-2021-30955, facilitating compatibility with jailbreak exploits. The tool informs users of their device's status regarding this vulnerability, advising against updates if the device is vulnerable. Notably, the tool allows for multiple testing attempts in case of transient errors during execution.

poc-cve-2025-55182

2026-08-03 TypeScript ★ 15
This repository provides a proof-of-concept for CVE-2025-55182, a critical pre-authentication remote code execution vulnerability found in specific versions of React Server Components. The vulnerability enables unauthenticated attackers to execute arbitrary JavaScript code on the server by exploiting unsafe deserialization through prototype chain traversal in the Flight protocol. Notably, the tool facilitates demonstration of the exploit process, requiring a vulnerable React setup and tools like Burp Suite for payload delivery and testing.

postexploitation-toolbox-android

2026-08-03 Kotlin ★ 20
The postexploitation-toolbox-android is a specialized toolkit for executing post-exploitation techniques on Android devices, particularly designed for Android 14 on the Samsung S21 Ultra. It leverages CVE-2024-34740 to allow code injection into system processes, enabling features such as temporary app debuggability, system-wide permission bypassing, and dynamic resource editing, while providing a user-friendly interface for manipulating system service internals through Java reflection.

prober

2026-08-03 Go ★ 12
Prober is a pentesting framework designed to simplify the management of GitHub repositories by eliminating the complexities of git submodules. Its primary use case is to allow penetration testers to easily download and clone necessary tools with straightforward commands, enhancing usability in security assessments. Notable features include a clean execution script and a focus on user-friendly setup processes.

pub

2026-08-03 Python ★ 265
The `pub` repository contains a collection of proof-of-concept (PoC) exploits and tools designed to demonstrate vulnerabilities disclosed by the author, tintinweb. Its primary use case is to aid security researchers and developers in understanding and testing these vulnerabilities. Notable features include a structured directory of PoCs and integrated GPG public key for secure communications.

pwnkit

2026-08-03 Python ★ 32
pwnkit is an exploitation toolkit designed for pwn CTFs and Linux binary exploitation research. It provides a suite of features including exploit templates, I/O helpers, ROP gadget mappers, and various utilities for crafting and executing exploits, making it ideal for both novice and experienced exploit developers. Notable features include customizable templates, integration with gdb helper scripts, and the ability to operate as a CLI tool or Python API.

ropcatalog

2026-08-03 Python ★ 36
ropcatalog is a Python tool designed for parsing, classifying, and browsing ROP (Return-Oriented Programming) gadgets from rp++ output files, primarily aiding in Windows exploit development. It features an interactive REPL with extensive search options, ASLR support for dynamic address adjustments, bad character filtering to enhance exploit reliability, and multiple output formats for easy integration into exploit code. The tool is tailored for users engaged in ROP chain construction and binary exploitation tasks.

samsung-s25-research

2026-08-03 Python ★ 16
The Samsung S25 Vulnerability Research repository provides tools and scripts for exploiting vulnerabilities in the Samsung Galaxy S25, specifically focusing on a one-click remote code execution (RCE) exploit and a method for arbitrary APK installation. Notable features include the `1click-rce` tool for RCE exploitation and the `local-apk-install` script for generating APK signatures, accompanied by detailed instructions for each. This resource is primarily aimed at cybersecurity researchers and enthusiasts investigating mobile device security.

scap-rs

2026-08-03 Rust ★ 25
scap-rs is a Rust library designed for interacting with the National Vulnerability Database, encompassing various modules such as CVSS, CVE, CPE, and CWE, which facilitate vulnerability scoring, disclosure, platform enumeration, and weakness classification. Its primary use case provides developers with tools to access and manipulate vulnerability data, enabling better security posture management. Notable features include support for multiple vulnerability-related standards and well-documented APIs for ease of integration.

SNEK_Blue-War-Hammer

2026-08-03 C ★ 218
The SNEK Blue War Hammer is a research tool that facilitates the exploration of Windows Defender's update mechanisms and potential vulnerabilities through sophisticated Windows API interactions. It is primarily aimed at security researchers and system administrators for educational purposes, implementing advanced features such as RPC communication, COM interfaces, VSS manipulation, and kernel-level file system operations. Notably, it allows for the extraction and analysis of Defender update packages directly from Microsoft, highlighting attack vectors associated with file access controls during the update process.

Sni5Gect-5GNR-sniffing-and-exploitation

2026-08-03 C++ ★ 312
Sni5Gect is a comprehensive framework designed for sniffing unencrypted 5G NR messages and injecting custom packets during over-the-air communication between base stations and User Equipment (UE). It is primarily used for security research to conduct various attacks, such as crashing UE modems, downgrading network technologies, and implementing device fingerprinting and authentication bypass tactics. Notable features include the ability to capture MAC-NR messages and send arbitrary messages to target devices during specific communication states, enabling detailed exploitation of 5G networks.

sqlmap-skynet

2026-08-03 Python ★ 98
SQLMap Skynet is an AI-assisted tool that enhances the SQLMap functionality by providing a structured, autonomous workflow for SQL injection testing, complemented by a real-time dashboard and MCP tool server for agent automation. Notable features include operational phases for detecting, bypassing, enumerating, and dumping vulnerabilities, as well as autonomous AI tuning and a memory system that learns from past successes to improve future scans. This tool is optimized for both Windows and Linux servers, operating in a headless mode without a GUI, making it suitable for automated security testing environments.

Sub-Ringan-Framework

2026-08-03 Shell ★ 59
Sub-Ringan Framework is an automated bug hunting tool tailored for identifying vulnerabilities in web applications, primarily aimed at bug bounty hunters and cybersecurity professionals. Its notable features include comprehensive subdomain discovery, live URL scanning, detection of XSS, SSRF, SQL injection, and LFI vulnerabilities, along with the ability to efficiently organize target files for enhanced workflow.

sysnc

2026-08-03 Shell ★ 10
sysnc is a bash wrapper around netcat designed for simplified remote command execution and interactive shell access, particularly on Android devices running Termux. Notably, it can exploit zygote injection (CVE-2024-31317) to establish a system-level shell, allowing for configurable command execution and interaction with a remote server. Key features include an interactive mode with a colored prompt, support for streaming scripts via stdin, and configurable options for host, port, and UID through command-line flags or environment variables.

The-Wagon-Site

2026-08-03 HTML ★ 13
The Wagon Site is a versatile web application that aggregates a variety of tools, including exploits, bookmarklets, games, and proxies. It serves as a centralized platform for users seeking easy access to these resources, emphasizing functionality through a bookmarklet for streamlined launching. Notable features include a diverse array of tools and a community-driven approach with a dedicated Discord channel for user engagement.

tower-of-flaws

2026-08-03 C++ ★ 20
TowerOfFlaws is a proof-of-concept tool that demonstrates vulnerabilities in the anti-cheat driver (`GameDriverX64.sys`) of the game Tower of Fantasy, specifically related to arbitrary process protection and termination. The tool allows users to bypass protections and terminate processes like `notepad.exe`, showcasing the vulnerabilities in a controlled environment. It requires a C++20 compiler and CMake for building, and emphasizes responsible usage in authorized contexts.

VulnParse-Pin

2026-08-03 Python ★ 12
VulnParse-Pin is a post-scan intelligence and decision support engine designed to transform vulnerability scan findings into a prioritized and explainable remediation plan, focusing on real-world exploitability rather than just severity scores. It reduces vulnerability noise by up to 94% by incorporating factors such as Known-Exploited Risk (CISA KEV), real-world exploitation probability (EPSS), and exploit availability from public databases, thereby enabling more effective risk management. Notable features include normalization of data, enriched scoring models, and customizable prioritization based on actual threat signals.

vulristics

2026-08-03 Python ★ 129
Vulristics is an extensible framework designed to analyze publicly available information on vulnerabilities, enabling classification and prioritization of CVEs using data sources such as Vulners.com, Microsoft, NVD, and AttackerKB. Initially developed for Microsoft Patch Tuesday reporting, it allows users to generate comprehensive reports for arbitrary CVE lists, custom profiles, and specific Microsoft Patch Tuesday events. Notable features include customizable report generation and integration of multiple vulnerability databases to facilitate a structured analysis process.

wordpress-malware

2026-08-03 PHP ★ 71
WordPress Malware is a collection of malware samples sourced from compromised WordPress websites, organized by the date they were discovered. The repository includes custom PHP functions commonly used for malicious actions, such as file modification and execution of PHP code. This tool serves as a resource for developing malware detection solutions and is utilized by associated cPanel plugins for scanning and mitigating malware threats.

WPAxFuzz

2026-08-03 Python ★ 210
WPAxFuzz is a comprehensive Wi-Fi fuzzing tool designed to test vulnerabilities in the 802.11 protocol's management, control, and data frames, as well as the SAE exchange for WPA3 networks. It features different operating modes for frame size manipulation, the ability to execute fuzz tests against any access point supporting WPA2 or WPA3, and includes a Denial of Service (DoS) attack module that leverages the results of fuzzing. The tool can be executed via a simple command line and requires pre-installed dependencies like Scapy and aircrack-ng for optimal functionality.

wphunter

2026-08-03 Python ★ 13
wphunter is a Python CLI tool designed for scanning WordPress plugins, themes, and core files for known CVE vulnerabilities, as well as detecting gambling spam injections (judol) and looking up public exploits. It operates both offline, using exported lists, and remotely via a URL, providing AI-powered analysis through Claude, including intelligent threat assessments and actionable remediation steps. Notable features include support for multiple vulnerability sources, comprehensive judol detection mechanisms, and version-aware matching to report relevant vulnerabilities based on the installed versions.

xnuimagefuzzer

2026-08-03 Objective-C ★ 42
XNU Image Fuzzer is a tool designed for fuzz testing Apple image decoding and re-encoding processes within CoreGraphics and ImageIO. It leverages multiple input modes to generate and parse images through various consumers, providing features such as bitmap-context permutations, ICC profile manipulation, and detailed metrics logging. The framework supports both native execution and deployment within Xcode for comprehensive testing and analysis of image handling on macOS and iOS platforms.

Zenith-Basic-RAT

2026-08-03 Python ★ 13
Zenith-Basic-RAT is a remote access tool (RAT) that operates through Discord, facilitating a range of post-exploitation actions with over 20 modules including system information retrieval, file management, and user monitoring. It is designed for educational purposes and features customizable executable names and session management to enhance stealth and functionality. Notable capabilities include password extraction, screen blocking, and the ability to execute commands remotely on the victim's machine.

Bash

2026-08-03 Shell ★ 39
Bash is a collection of Bash scripts designed primarily for use by Red Teamers to facilitate offensive security tasks and simplify common operations in a Linux environment. Key features include various exploit scripts targeting vulnerabilities such as CVE-2014-6271 (ShellShock) and CVE-2006-3392 for remote file disclosure, as well as utility scripts for obtaining system information and performing network reconnaissance. The toolset is easily installable via standard Linux practices, promoting accessibility and efficiency for cybersecurity professionals.

bluesploit

2026-08-03 Python ★ 90
BlueSploit is a comprehensive Bluetooth framework targeting both Classic BR/EDR and BLE communication, featuring 160 modules for various purposes including exploits, denial of service, and reconnaissance. Its notable capabilities include persistent state storage, advanced scanning for Bluetooth devices and key exchange mechanisms, as well as support for AES-128 cryptography and mesh networking protocols. The tool is designed for authorized testing and enables users to engage interactively through a REPL interface, managing attacks and reconnaissance tasks efficiently.

BrowserSnatch

2026-08-03 C ★ 331
BrowserSnatch is an offensive-security tool designed for authorized penetration testing that extracts and decrypts sensitive data from over 40 web browsers, including both Chromium and Gecko-based platforms. Notable features include the ability to retrieve stored passwords, cookies, bookmarks, and browsing history, as well as support for app-bound encrypted data, all optimized for high performance with minimal dependencies. The tool serves red teams in demonstrating the impact of endpoint compromise and aids blue teams in improving detection tactics against browser data theft.

BUSted

2026-08-03 C ★ 11
BUSted is a repository designed for conducting microarchitectural side-channel attacks on MCU bus interconnects, specifically targeting the Smart Lock application as a proof of concept. It consolidates tools and scripts for measuring covert-channel capacities, along with the firmware and hardware configurations necessary for replicating the attack on STM32 devices. Notable features include a script for automated measurement of channel capacity and tools for visualizing the channel matrix.

bypass-url-parser

2026-08-03 Python ★ 1138
Bypass Url Parser is a specialized tool designed to test various URL bypass techniques against 40X protected pages, utilizing `curl` as its backend for raw request handling. It allows users to send unencoded URLs and includes features such as custom header support, proxy integration, and configurable output options, making it suitable for security assessments and web application testing. The tool can be used as a standalone application or integrated as a library, providing flexibility for different user needs.

camera-hack

2026-08-03 Python ★ 12
camera-hack is a tool designed for gaining control over Yoosee/Jortan IP cameras using a UART serial connection facilitated by an Arduino device. The primary use case involves leveraging the tool to access and manage camera features via Telnet after establishing a connection. Notable features include straightforward setup instructions, compatibility with multiple operating systems, and community support for troubleshooting and contributions.

camera-hacks

2026-08-03 Python ★ 39
This repository provides a suite of custom tools and research materials focused on vulnerability assessment of Wansview Wi-Fi cameras and the AJCloud IoT device management platform. The primary use case is to facilitate security research and exploit development for these devices. Notable features include collected data, research notes, and insights shared from presentations at DEF CON 32.

copy-fail-c

2026-08-03 C ★ 444
Copy Fail is a cross-platform implementation in C of the Copy Fail Linux Local Privilege Escalation (LPE) exploit (CVE-2026-31431), designed to demonstrate the vulnerability on various architectures without relying on per-architecture hex blobs or inline assembly. The tool includes multiple variants for payload delivery, such as a binary-mutation dropper and a variant that modifies the `/etc/passwd` file, as well as a non-destructive vulnerability checker. It requires no additional libraries and supports extensive architecture compatibility through the included nolibc.

CR4SH3R

2026-08-03 Python ★ 13
CR4SH3R is a vulnerability scanner specifically engineered to identify Arbitrary File Download flaws in WordPress plugins by scanning for sensitive data exposure through common file paths. It features multi-threaded scanning for efficiency, smart data extraction capabilities, and provides organized reports in XLSX format, all presented through a user-friendly GUI. Notably, the tool allows users to extend its payloads for enhanced detection and supports customized scanning configurations.

Cryptolocker

2026-08-03 ★ 143
Cryptolocker is an open-source encryption tool developed in Visual C++ that employs a robust 256-bit AES encryption algorithm to secure files, rendering them unreadable without a password. Its primary use case involves encrypting files across system drives while providing features such as a multi-threaded encryption process for efficiency, lockdown functionality to restrict system access, and a web admin interface for management. This tool is intended solely for educational purposes and emphasizes user responsibility regarding legal usage.

CVE-2022-23093

2026-08-03 C ★ 10
CVE-2022-23093 is a cybersecurity tool designed to exploit a stack-based buffer overflow vulnerability in the FreeBSD ping utility, which results from improper handling of IP option headers during ICMP response processing. Its primary use case is to demonstrate the ability to execute arbitrary shellcode through crafted ICMP packets that trigger the overflow. Notable features include the ability to customize the shellcode as well as the detailed technical analysis of the vulnerability's mechanics and its impact on system integrity.

CVE-2022-26265

2026-08-03 Python ★ 10
CVE-2022-26265 is a Python-based tool designed to exploit a Remote Code Execution vulnerability in Contao CMS version 1.5.0. Users can specify target servers from a list file and execute arbitrary commands, making it useful for security assessments and penetration testing of affected installations. Notable features include the ability to handle multiple targets and customizable command execution through a straightforward command-line interface.

CVE-2023-32315-EXPLOIT

2026-08-03 Python ★ 15
CVE-2023-32315-EXPLOIT is a proof-of-concept tool designed to exploit a severe authentication bypass vulnerability in the Openfire real-time collaboration server's administrative console. It demonstrates how an attacker can leverage a path traversal flaw coupled with improper URL encoding handling to gain unauthorized access to admin-only pages. Notably, the exploit addresses a critical security issue affecting Openfire versions released after April 2015, specifically exploiting weaknesses in URL wildcards and path traversal protections.

CVE-2025-32463

2026-08-03 Go ★ 26
CVE-2025-32463 is a Go-based exploit tool designed to exploit a critical local privilege escalation vulnerability in sudo versions 1.9.14 to 1.9.17. The tool manipulates the `--chroot` option to load a malicious shared library, allowing unauthorized users to gain root access. Notable features include the ability to run the exploit in both normal and silent modes, and it supports building from source or using a pre-built binary.

CVE-2026-24061

2026-08-03 Python ★ 824
CVE-2026-24061-PoC is a proof-of-concept tool designed to demonstrate the exploitation of a critical vulnerability in telnetd from GNU Inetutils, enabling remote attackers to bypass authentication and achieve root access. This tool requires Python 3.4+ and can target hosts by specifying an address through a text file or command line interface. It exploits improper handling of the USER environment variable, injecting command-line options to gain unauthorized access.

CVE-2026-48909

2026-08-03 Python ★ 23
The CVE-2026-48909 tool identifies and exploits a critical Remote Code Execution vulnerability via PHP Object Injection in the JoomShaper SP LMS extension for Joomla versions ≤ 4.1.3. Notable features include a proof of concept script for detecting the vulnerability and an exploit script that allows an attacker to write PHP code to the server, requiring no authentication. The tool also details the underlying mechanics of the vulnerability and provides mitigation advice for affected systems.

CVE-2026-57827

2026-08-03 Python ★ 15
CVE-2026-57827 is a high-severity vulnerability within the RSFiles! component for Joomla, allowing unauthenticated arbitrary file uploads due to a split-controller design flaw. The vulnerability permits attackers to bypass critical security checks and directly write malicious files to the server, resulting in remote code execution without any authentication or CSRF protections. Notably, the exploit allows attackers to upload any file type and store it in a default web-accessible directory, significantly compromising the security of affected Joomla installations.

CVE-2026-PoCs

2026-08-03 C++ ★ 42
CVE-2026-PoCs is a curated repository providing a centralized collection of verified proof-of-concept exploits for vulnerabilities disclosed in the year 2026. Its primary use case is to serve security researchers and practitioners by offering a well-organized index of CVEs, complete with consistent metadata and a clear contribution process. Notable features include detailed listings of specific CVEs, affected products, and statuses of exploits, addressing the common issue of fragmented information across various platforms.

CVE-Intel

2026-08-03 HTML ★ 83
CVE-Intel is a vulnerability intelligence platform that aggregates and correlates data from GitHub CVE-tagged repositories, the National Vulnerability Database (NVD), and cybersecurity news feeds. It is aimed at security researchers, blue teams, and integrators, providing a public API and frontend to access and analyze enriched CVE information. Notable features include a robust data ingestion pipeline, real-time news updates, and an interface for querying vulnerability details with pagination and filtering capabilities.

CVEs

2026-08-03 Python ★ 11
The CVEs repository catalogs vulnerabilities reported by the author, each assigned a CVE identifier. It provides detailed write-ups and proof-of-concept (PoC) exploits for various software vulnerabilities, facilitating research and reproduction. Noteworthy features include the inclusion of vulnerable software copies in certain folders for in-depth analysis.

cyber_threat_intelligence

2026-08-03 ★ 115
The Cyber Threat Intelligence tool provides comprehensive analysis of ongoing activities and research by advanced persistent threat (APT) actors, leveraging broad monitoring of exploit markets, social media, and vulnerability discussions. Its key features include geopolitical analysis, a wide array of indicators such as IOCs and TTPs, and predictive capabilities powered by an AI-based system to forecast potential attacks. This enables organizations to proactively prepare for and mitigate cybersecurity threats.

darknet-mcp-server

2026-08-03 TypeScript ★ 316
Darknet-mcp-server is a comprehensive tool designed for aggregating dark web and threat intelligence specifically for AI agents. It consolidates data from multiple sources, including HIBP, ThreatFox, ransomware tracking, and blockchain intelligence, into a unified server that allows for on-demand access to a wide array of threat data. Notable features include support for .onion access, malware analysis capabilities, and an array of tools and data sources to streamline dark web intelligence gathering and analysis.

DEFCON-33

2026-08-03 ★ 103
The DEFCON-33 repository provides insights and resources on exploiting vulnerabilities found in Tuoshi and Kuwfi 5G & LTE routers, detailing CVE discoveries and offering practical exploitation demonstrations. Its primary use case is to educate security professionals and researchers on the security weaknesses of these devices, while notable features include comprehensive vendor analysis and connections to related works in the field of cybersecurity.

Duolingo-Unlimited-Hearts

2026-08-03 JavaScript ★ 220
Duolingo Max is a browser extension designed to modify the Duolingo website to provide unlimited hearts for users, thereby enhancing the learning experience without the limitations imposed by the platform. It supports both Chrome and Firefox, offering a straightforward installation process alongside a userscript option for mobile Safari, allowing for broad accessibility. Key features include access to specific domains for patching the Duolingo site, storage for user settings, and version synchronization capabilities for updates.

EACBypass-CR3ReadyDrv

2026-08-03 C++ ★ 222
The EAC Bypass + CR3 Ready IOCTL tool is a specialized driver designed to facilitate undetected communication and callback handling through IOCTL, primarily aimed at circumventing anti-cheat mechanisms. It serves as a foundational framework, allowing users to control CR3 and IOCTL communication between driver and user mode, while leaving advanced functionalities, such as handle randomization and user mode hiding, to the user's discretion. Notable features include a basis for EPROCESS bypass and miscellaneous system manipulations, emphasizing the need for user customization to complete the implementation.

Erebos-Zero

2026-08-03 C ★ 17
Erebos-Zero is a personal arsenal for malware development featuring sophisticated techniques for evasion and injection. It includes a variety of exploitation methods such as shellcode injection, DLL injection, and process manipulation, along with advanced anti-forensics and evasion techniques tailored for bypassing endpoint detection and response systems. This tool is primarily intended for research and educational purposes, focusing on the creation and deployment of stealthy malicious payloads.

evm-hack-analyzer

2026-08-03 TypeScript ★ 23
EVM Hack Analyzer is a static, in-browser tool designed for debugging EVM exploits by replaying specific transactions and analyzing their behavior within a forked chain state. Users can visualize opcode execution, keep track of storage and memory changes, and annotate vulnerabilities step-by-step, providing a comprehensive mapping from bytecode to source lines. The tool also allows users to share findings through download options or decentralized IPFS links, facilitating collaboration and community contributions through organized proof-of-concept archives.

evm-hack-registry

2026-08-03 Solidity ★ 55
The EVM Hack Registry is a comprehensive archive of hundreds of DeFi/EVM exploit proof-of-concepts (PoCs) designed for offline execution across multiple blockchain networks from 2017 to 2026. Each exploit is encapsulated within a standalone Foundry project, complete with on-chain contract source code, a local block-state snapshot, and detailed AI-generated documentation, enabling reproducibility without reliance on external RPC nodes. This tool aims to simplify the study and analysis of blockchain vulnerabilities, addressing common accessibility issues found in existing DeFi hack resources.

exim-rce-cve-2018-6789

2026-08-03 Makefile ★ 11
The Exim RCE (CVE-2018-6789) Learning Environment provides a structured setup for users to investigate and debug the Exim mail transfer agent, focusing on the Remote Code Execution vulnerability. Primarily intended for academic purposes, this tool includes a Vagrant configuration that enables users to deploy a Fedora VM pre-configured for testing, along with Docker integration to run Exim in a controlled environment. Notable features include the ability to customize the VM's resource allocation, disable ASLR for consistent debugging, and access to scripts that facilitate the setup of the environment and execution of exploits.

ExploitDB-Hunter

2026-08-03 Python ★ 64
ExploitDB-Hunter is a command-line tool designed to streamline the process of searching for and downloading exploits from the Exploit-DB website. Its primary use case is to facilitate quicker access to relevant exploits by allowing users to search via CVE IDs or titles, adjust result parameters, and choose exploit types and platforms interactively, thus reducing the need for manual browsing. Notable features include customizable search options, downloading capabilities, and an intuitive terminal interface.

ExploitFlow

2026-08-03 Python ★ 37
ExploitFlow (EF) is a modular library designed to create cybersecurity exploitation routes, known as exploit flows, by combining and composing exploits from various sources and frameworks. Its primary use case is to facilitate research in Game Theory and AI within the cybersecurity domain through a structured representation of actions and system states. Notable features include its extensibility with adapters for other exploitation frameworks and a design syntax inspired by TensorFlow, allowing for seamless integration and experimentation.

fuzz

2026-08-03 Python ★ 415
The Fuzz Corpus repository provides a comprehensive collection of curated malicious-input samples for security testing, focusing on various injection types and CVE proof-of-concepts (PoCs). Notable features include support for ICC profiles, malformed graphics, and web injection signatures, which can be integrated into fuzzing workflows for validating security tools. The repository also categorizes inputs by purpose, facilitating targeted testing against specific vulnerabilities in different environments and platforms.

gef-extras

2026-08-03 Python ★ 182
GEF-Extras is an augmentation of the GDB Enhanced Features (GEF) framework, providing users with additional scripts and structures to enhance their debugging experience in GDB. It facilitates easy installation and integration with GEF, and is accompanied by comprehensive documentation to assist users in utilizing its capabilities effectively. Notable features include seamless installation via a simple command and ongoing community support through Discord.

h4cker

2026-08-03 Jupyter Notebook ★ 29215
The h4cker repository is a meticulously curated collection of cybersecurity resources, tools, scripts, and training materials, aimed at supporting various aspects of cybersecurity, including offensive and defensive strategies, cloud security, and AI security. Notable features include a structured taxonomy for easy navigation across different cybersecurity domains, dedicated sections for certifications and lab-building, and organized training references and resources. This repository serves as a valuable supplemental resource for professionals seeking to enhance their knowledge and skills in cybersecurity.

HashDump-BypassEDR

2026-08-03 PowerShell ★ 252
HashDump-BypassEDR is a tool designed to circumvent Endpoint Detection and Response (EDR) solutions by utilizing the `reg.exe` command to export critical registry information, enabling the dumping of password hashes from Windows systems. Its notable features include the ability to operate with minimal permissions on certain Windows versions, alongside an effective method for retrieving the BootKey necessary for the process without detection by most antivirus software. The tool's practicality is underscored by its testing across various Windows environments, showcasing its robustness in real-world applications.

haval-app-tool-multimidia

2026-08-03 HTML ★ 61
The haval-app-tool-multimidia project is an unofficial educational tool designed for reverse engineering the Haval GWM multimedia system. Its primary use case is to facilitate learning and exploration of the system's architecture and functionality without any commercial intent. Notable features include detailed documentation for understanding the inner workings and guidance on extending the tool's capabilities.

Hells-Hollow

2026-08-03 Rust ★ 290
Hell's Hollow is a rootkit technique specifically designed for Windows 11 that enables effective SSDT hooking by exploiting an undocumented Alternate Syscall handler mechanism. This tool allows users to manipulate system calls at the kernel level, enabling alteration of return values and system call arguments while bypassing existing defense mechanisms like HVCI. Notable features include its compatibility with Rust for driver development and the ability to hook and modify any specified system service number (SSN), making it a versatile tool for advanced kernel manipulation techniques.

Iris

2026-08-03 C ★ 26
IrisC2 is a command and control (C2) framework designed for authorized security testing, red team exercises, and internal research. It features a modular architecture comprising a Client for user interaction, a Server for managing communication and tasks, Beacons for executing commands within target environments, and a Stager for handling staged payloads. Notable capabilities include multi-platform support, advanced task scheduling, plugin integration for extended actions, and comprehensive event synchronization.

Kittysploit-framework

2026-08-03 Python ★ 614
KittySploit is a modular offensive security framework and C2 platform designed for penetration testers, researchers, and red teams. It consolidates security workflows into a single console, featuring capabilities for target scanning, engagement organization, module execution, and AI-assisted testing plan generation, alongside built-in command and control functionalities. Notable features include an extensible architecture, automation readiness, and an array of integrated tools for reconnaissance, exploitation, and traffic analysis.

lpe-toolkit

2026-08-03 C ★ 352
The Linux LPE Toolkit is a multi-architecture privilege escalation tool designed to identify and exploit vulnerabilities to gain root access on Linux systems. It includes 24 pre-built exploits for various architectures, automatically detects kernel versions, filters out patched exploits, and attempts each exploit until root access is achieved. Notable features include a dry-run mode for planning, command execution upon successful exploitation, and options for verbose or silent output during exploitation.

malleable-signatures

2026-08-03 Solidity ★ 113
The malleable-signatures repository provides a proof of concept (PoC) that demonstrates signature malleability attacks using compact signatures within the Ethereum ecosystem. It highlights vulnerabilities in OpenZeppelin’s ECDSA library version 4.6 that are exploitable through signature malleability, emphasizing the necessity to avoid using signatures as unique identifiers due to their inherent non-uniqueness. Key features include showcasing the vulnerability and its remediation in later library versions, along with a detailed explanation of the underlying cryptographic principles involved.

MikrotikAPI-BF

2026-08-03 Python ★ 100
MikrotikAPI-BF is a comprehensive RouterOS attack and exploitation framework designed for conducting automated security audits, brute-force credential attacks, and exploiting vulnerabilities in Mikrotik routers. Its notable features include a robust exploit engine with coverage for over 100 CVEs, multiple attack vectors such as REST API, SSH, and MAC-Telnet, as well as threading capabilities for multi-target scans. The tool also supports offline credential decoding and unique capabilities like MAC-Server Layer-2 discovery for devices without IP addresses.

Osiris-Jailbreak

2026-08-03 C ★ 167
Osiris-Jailbreak is an experimental jailbreak tool for iOS devices running versions 11.2 to 11.3.1, intended solely for developers to explore the jailbreaking process. Key features include the execution of the multi_path exploit (CVE-2018-4241), granting kernel task permissions, enabling remote terminal access, and bypassing certain security measures like the Sandbox and AMFI. However, the tool is still in development, lacks essential features like Cydia support, and is not recommended for general users due to its potential instability and incomplete functionality.

PatrowlHearsData

2026-08-03 ★ 147
PatrowlHearsData is an open-source data repository and scraping tool designed for the collection of vulnerability intelligence, including CVE, CPE, CWE, and exploit references. It facilitates security operations by providing real-time updates and orchestrating threat intelligence feeds, making it suitable for organizations looking to enhance their cybersecurity posture with comprehensive vulnerability insights. Notable features include scalability, a user-friendly installation process, and the option for professional support through a paid Pro Edition.

poc-archive

2026-08-03 C++ ★ 34
The poc-archive is a structured repository for security research proof-of-concepts (POCs), organized by categories such as web, network, binary, and more. It features detailed metadata, reproduction steps, and references for each POC, facilitating knowledge sharing and education within authorized security research contexts. Notable features include automated indexing, interactive POC scaffolding scripts, and a template system for contributing new entries.

PoC-in-GitHub

2026-08-03 ★ 8029
The "PoC in GitHub" repository offers proof-of-concept (PoC) exploits for multiple Common Vulnerabilities and Exposures (CVEs) identified in various software components, highlighting potential local and remote privilege escalation vulnerabilities. Each listed CVE includes a brief description of the vulnerability's nature, links to associated exploits, and demonstrates the ease of exploitation without requiring user interaction. This repository serves as a resource for security researchers and developers to understand vulnerabilities and test their systems against known exploits.

puncia

2026-08-03 Python ★ 662
Puncia is a command-line interface (CLI) tool designed for comprehensive subdomain mapping and vulnerability monitoring through its integration with the Subdomain Center and Exploit Observer APIs. Its primary use case includes assessing external attack surfaces, enabling advanced vulnerability research, and facilitating automated intelligence gathering for CI/CD pipelines. Notable features include contextual enrichment of vulnerability data, bulk processing capabilities, and stealthy reconnaissance for red teams, making it an essential utility for cybersecurity professionals.

pwn.hs

2026-08-03 Haskell ★ 12
pwn.hs is a Haskell library designed for exploitation development and reverse engineering tasks. Its primary use case is to facilitate the creation and manipulation of data structures commonly encountered in security research. Notable features include comprehensive examples demonstrating its functionality and customization for various exploit scenarios.

pwninit.py

2026-08-03 Python ★ 14
pwninit.py is a specialized tool for configuring Capture The Flag (CTF) pwn challenges by automating the setup of binaries with their required runtime environments. It features downloading appropriate interpreters and glibc libraries, applying patches for compatibility, generating customizable solve scripts, and fetching glibc source code for enhanced debugging. The tool supports manual patching by default to avoid potential issues during exploitation, making it particularly useful for cybersecurity practitioners working on binary exploitation challenges.

pwntools

2026-08-03 Python ★ 13667
Pwntools is a robust CTF framework and exploit development library written in Python, designed to facilitate rapid prototyping and ease of exploit creation. Notable features include support for various architectures, seamless interaction with remote services, and a set of built-in tools that streamline both exploitation and challenge solving. The library caters primarily to Capture The Flag (CTF) competitions, simplifying the process of developing and executing exploits.

qualcomm_gbl_exploit_poc

2026-08-03 C ★ 17
The Qualcomm GBL Exploit PoC tool facilitates the unlocking of bootloaders on Qualcomm devices through a specific exploit. Its primary use case is to enable users to install custom software, recover locked devices, or troubleshoot advanced issues, all without requiring programming knowledge. Notable features include a straightforward graphical interface for running the unlocking process and compatibility with various Qualcomm devices, operational on Windows systems.

Red-Devils-premium

2026-08-03 ★ 14
Red Devils Rat Premium is an advanced remote administration tool (RAT) designed for comprehensive device management and surveillance. Its primary use case is to facilitate remote access and control over Android devices, offering features such as call and SMS monitoring, live screen streaming, location tracking, and remote control functionalities. Notable features include an admin panel for easy management, an APK crypter for secure app distribution, and the ability to execute commands remotely, providing a robust solution for unauthorized monitoring.

Security-and-Hacking

2026-08-03 ★ 13
Awesome Security & Hacking is a comprehensive resource for ethical hacking, focusing on penetration testing, vulnerability scanning, and exploit development. The repository offers a collection of tools, scripts, and hands-on labs categorized across various domains such as network security, web application security, and cryptography, making it suitable for both beginners and advanced practitioners. Notable features include structured content on specialized areas like bug bounty and wargames, as well as community engagement through contributions and feedback channels.

SideInstaller

2026-08-03 Swift ★ 595
SideInstaller is an open-source iOS application designed to facilitate the installation of SideStore and LiveContainer directly on iPhones without the need for a PC. It simplifies the sideloading process by handling pairing, provisioning, and installation on-device, allowing users to easily sideload applications while ensuring their Apple credentials remain private and secure. Notable features include a user-friendly interface, local data handling with no online transmission, and transparency through its open-source code, providing full auditability.

skillarch

2026-08-03 Makefile ★ 65
SkillArch is a customizable installation tool designed for setting up an i3 window manager environment atop KDE Plasma, targeting both lightweight and full-feature installations. Its primary use case is to streamline the setup process for users by providing straightforward commands for installing various components, including CLI tools, security applications, and GUI utilities. Notable features include automatic updates, an interactive merging process for upstream changes, and extensive documentation with video tutorials.

slopbro

2026-08-03 Python ★ 78
SlopBro is a proof-of-concept exploit designed to leverage the jsserver vulnerability in LG TVs running webOS versions 5 to 10. It operates by starting an HTTP server to deliver an exploit page and payloads, establishing an SSAP connection with the target TV, and executing a rogue package with root privileges, allowing for potential persistence and the installation of additional software like the Homebrew Channel. Notable features include compatibility across Python 2.7 and 3.x, minimal dependency requirements, and options for debugging and asset source specification.

SlowLoris

2026-08-03 Python ★ 112
PySlowLoris is a Python-based tool designed for testing a web server's vulnerability to slow request attacks by maintaining numerous open connections and sending malformed headers. It utilizes asynchronous I/O for efficient connection handling, offers user-friendly command line and Python API interfaces, and is packaged for easy installation via PyPI or Docker. Notably, users can specify the number of connections and run the tool in a silent mode to focus on attack simulation without cluttering the output.

spellbook

2026-08-03 Perl ★ 116
Spellbook is a micro-framework designed for the rapid development of reusable security tools using a flow-based programming (FBP) paradigm. It allows users to create and utilize various security modules, such as exploit testing and advisory lookups, through a command-line interface that supports operations like module searching and execution. Notable features include its ability to handle multiple exploit modules and a Docker integration for containerized deployment.

SploitTest

2026-08-03 Objective-C ★ 42
SploitTest is a testing application designed to determine if iOS devices running versions 15.0 to 15.4 beta 3 are vulnerable to a specific kernel vulnerability exploited for local privilege escalation. By executing the proof of concept (PoC), users can identify if their device can be subjected to jailbreaking, with the indication of vulnerability shown by a device reboot after running the application. The tool is notable for its straightforward usage and direct applicability to iOS security assessments.

termius-exporter

2026-08-03 JavaScript ★ 58
Termius Exporter is a tool designed to extract user data from the Termius SSH client, which has restricted export capabilities. Its primary use case is to liberate hosts, credentials, and keys, particularly for post-exploitation scenarios, by retrieving information such as saved SSH hosts, private keys, and command snippets. Notable features include its reliance on XSalsa20-Poly1305 encryption for data handling and the ability to output extracted data in structured CSV files.

TGtoJSON-2026

2026-08-03 TypeScript ★ 52
TGtoJSON-2026 is a tool designed for converting Telegram's native session tdata files to JSON format, enabling compatibility with Telegram Prime and similar clients. Its notable features include the ability to convert JSON back to tdata format, with support specifically for the Pyrogram library.

Tinf0il

2026-08-03 JavaScript ★ 48
tinf0il is a high-performance proxy portal that facilitates private browsing, streaming, and gaming through a combination of Scramjet proxy technology and libcurl transport. Its notable features include tab cloaking, stealth routing, a game and app catalog, and a comprehensive streaming interface for movies and TV shows with real-time sports event tracking. The platform also emphasizes privacy, with zero logs and customizable user preferences.

ttyinject-rs

2026-08-03 Rust ★ 14
ttyinject-rs is a tool that exploits the `TIOCSTI` ioctl in the Linux kernel to inject keystrokes into a terminal, allowing a non-privileged user to gain root privileges when the root user executes `su - user`. Notable features include its easy integration with a user's `~/.bashrc`, its self-deleting behavior post-execution, and compatibility with specific Linux kernel configurations. It serves primarily as a demonstration of an exploit for educational purposes.

WP-Scanner

2026-08-03 Python ★ 22
WP-Scanner is an advanced vulnerability scanner and exploitation framework specifically designed for WordPress, capable of identifying 75 CVEs across core, plugins, and themes. Its notable features include comprehensive fingerprinting, active exploitation capabilities with 36 exploit handlers, and mass scanning with thread-safe execution. The tool supports HTML and Markdown report generation and includes automatic updates for both the tool and its vulnerability database.

agentseal

2026-08-03 Python ★ 345
AgentSeal is a comprehensive security toolkit designed for AI agents, providing robust capabilities such as detection of malicious configurations, tracing toxic data flows, and scanning for potential supply chain vulnerabilities across various agents. It features an extensive pipeline for local scanning, real-time monitoring, and auditing of machine configurations without the need for API keys, alongside the ability to test against 225+ adversarial prompts. Notable functionalities include the `guard` command for scanning and assessing the security of agent configurations and the option to create organization-specific policies through custom rule sets.

awesome-offensive-mcp

2026-08-03 ★ 26
Awesome Offensive MCP is a curated collection of Model Context Protocol servers designed for Red Teaming, Pentesting, and Vulnerability Research, enabling users to seamlessly integrate Agentic AI into their offensive security workflows. The tool supports various tasks such as running Nmap scans, analyzing Ghidra decompilations, and querying Shodan—all through natural language commands within a unified conversation context. It emphasizes safety and compliance, encouraging users to audit the code of the MCP servers before deployment.

AwesomeNmap

2026-08-03 Lua ★ 12
Awesomenmap is a comprehensive knowledge base dedicated to Nmap, providing a centralized repository for essential Nmap NSE scripts, CVE search tools, and automated reconnaissance pipelines. It streamlines access for security analysts, pentesters, and blue teams, featuring organized references and integration of third-party scripts to ensure they are current. Notable features include post-scan reporting capabilities and visualizations for enhanced security assessments.

basilisk

2026-08-03 Python ★ 27
Basilisk is an open-source AI red teaming framework designed for automated adversarial prompt testing against various large language models (LLMs) such as Claude and GPT-family models. It features evolutionary prompt search, structured attack modules, and a real-time scan dashboard, enabling security researchers and penetration testers to conduct repeatable and comprehensive security assessments of LLM applications. Notable capabilities include differential mode comparisons across multiple model providers, guardrail posture scanning, and the ability to export test results in various formats.

benchjack

2026-08-03 Python ★ 43
BenchJack is a vulnerability scanner designed to assess whether AI benchmarks can be manipulated, highlighting weaknesses before adversarial agents can exploit them. It employs a multi-phase audit process that combines static analysis tools with AI-driven deep inspection, categorizing vulnerabilities into eight distinct classes and providing real-time results via a web dashboard. Notable features include proof-of-concept exploit code generation and future integration of Docker sandboxing for enhanced security during analysis.

bulwark

2026-08-03 TypeScript ★ 187
Bulwark is an organizational asset and vulnerability management tool that integrates with Jira for generating application security reports. Its notable features include multi-client vulnerability management, security report generation, team-based roles authorization, and API key management. Designed for early-stage development, it offers a user-friendly interface for managing security tasks and facilitating team collaboration.

cervantes

2026-08-03 C# ★ 448
Cervantes is an open-source, collaborative platform tailored for penetration testers and red teams, serving as a comprehensive management tool for organizing projects, vulnerabilities, and reports in a centralized location. It enhances operational efficiency by providing features such as team collaboration, OWASP compliance reports, built-in dashboards, and one-click report generation. Designed to be multiplatform and multilanguage, Cervantes streamlines penetration testing activities, significantly reducing coordination time and effort.

CVE-2026-41089-LongLogon

2026-08-03 Python ★ 14
LongLogon is a non-destructive precondition checker for the CVE-2026-41089 vulnerability, which is a stack buffer overflow affecting the Windows Netlogon service. It operates without authentication and does not exploit the vulnerability; instead, it sends benign CLDAP pings to determine if a domain controller's DNS domain name is sufficiently long to trigger a crash. This tool provides a reliable mechanism for security assessments by validating the conditions necessary for the vulnerability without the risks associated with executing an exploit.

cybermind

2026-08-03 Go ★ 44
CyberMind CLI v6.0 is a powerful AI-driven offensive security tool designed for a diverse range of users including bug bounty hunters, red teamers, penetration testers, and security researchers. It offers 22 autonomous attack modes, a unique OMEGA brain orchestration feature, and support for exploiting Web3, mobile, and cloud environments, while integrating seamlessly with Kali tools. Key features include manual and automated execution options, real-time alerting via Telegram, and a VSCode extension for enhanced usability.

educational-cybersec-tools

2026-08-03 ★ 13
The Educational Cybersecurity Tools repository serves as a comprehensive catalog of over 150 tools aimed at ethical hacking, penetration testing, and cybersecurity education. It encompasses various categories including network scanning, vulnerability assessment, and malware analysis, while emphasizing that all tools are intended for educational purposes only and may not be used for unauthorized access to systems. Noteworthy features include detailed tool descriptions, an extensive list of categories, and a focus on promoting ethical standards in cybersecurity practices.

EternalHushFramework

2026-08-03 C ★ 19
The EternalHush Framework is an advanced command and control (C&C) platform designed specifically for Windows systems, enabling users to extend its functionality through a Python API for plugin development. Notable features include an intuitive GUI, integration capabilities for external modules, and a variety of built-in implant functionalities such as TCP/HTTP(S) connections and reflective DLL loading, all aimed at facilitating data collection and interaction with infected systems. This open-source project is currently in early development and seeks community collaboration for enhancements.

exploits

2026-08-03 Python ★ 11
The "exploits" repository serves as a comprehensive security research and exploit development toolkit, focusing on browser vulnerabilities, post-exploitation techniques, and cloud identity attacks. It features organized content around CVE reproductions, offensive tooling with detection guidance, and written assessment deliverables, all designed for educational use and authorized security testing. Notably, it includes a contained Docker lab environment for safe execution and testing of exploit scenarios without internet access, ensuring a secure and isolated workspace for enterprise assessments.

GhostLock

2026-08-03 Python ★ 148
GhostLock is a research tool designed to demonstrate the potential for ransomware-equivalent availability impacts on SMB shares by utilizing file-level and directory-level locking techniques without writing or encrypting data. It enables low-privileged Windows domain users to effectively lock files or entire directories, rendering them operationally invisible while maintaining read access at known paths, thus bypassing traditional security measures with no detectable writes or anomalies. Notable features include a 32-thread parallel scanner for file locking and a single handle directory lock method, making it a significant concern for SMB-based environments.

harpoon

2026-08-03 Python ★ 10
Harpoon is an autonomous black-box penetration testing tool designed for web applications, optimized for use on Kali Linux but capable of running on other Debian-based distributions and WSL. It orchestrates and integrates various existing security scanners, streamlining the process of vulnerability discovery by normalizing outputs into a relational SQLite model and providing comprehensive reporting, including HTML reports and PoC artifacts. Notable features include asynchronous execution, WAF-awareness, and extensive automated phases covering everything from DNS reconnaissance to validation of findings.

huntbot

2026-08-03 Shell ★ 10
Huntbot is a multi-model offensive security tool designed for bug bounty hunting, penetration testing, and red teaming, offering advanced capabilities for vulnerability detection and reporting. Notable features include contextual knowledge accumulation, human-like interaction with web applications, the ability to share live browser sessions, and meticulous false positive validation before report generation. It is extensible with multiple AI models and allows for dynamic steering during runs, enabling security professionals to efficiently explore and validate security vulnerabilities.

llamator

2026-08-03 Python ★ 215
LLAMATOR is a Python-based framework designed for Red Teaming, enabling security professionals to conduct penetration testing on chatbots and Generative AI systems. Its notable features include support for custom attacks, compatibility with multiple chat client configurations, and comprehensive reporting capabilities in various formats, making it suitable for assessing vulnerabilities such as prompt injection and misinformation.

LLMtary

2026-08-03 Dart ★ 32
LLMtary is an AI-powered penetration testing platform designed for security professionals, facilitating an autonomous workflow from reconnaissance to exploit validation and report generation. It integrates large language model intelligence to conduct a comprehensive examination of targets, capable of operating entirely offline with local models or utilizing cloud-based AI for improved accuracy. Key features include a structured testing loop, multi-phase enrichment for targeted vulnerabilities, and native support across major operating systems, ensuring a streamlined and efficient penetration testing experience.

mythos-research

2026-08-03 Shell ★ 39
Mythos Research Edition is an open-source tool designed for vulnerability discovery in software applications, utilizing the publicly available Claude Opus 4.7 model to replicate the eight-phase scaffold of Anthropic's Mythos Preview. It enables open-source maintainers, security researchers, and academics to conduct targeted scans at a low cost, facilitating coordinated vulnerability disclosure while avoiding unauthorized mass scanning. Key features include self-scanning capabilities for project audits and research, without requiring access to Anthropic's proprietary model.

netcrawler

2026-08-03 Python ★ 24
NetCrawler is an AI-driven reconnaissance and vulnerability scanning tool that utilizes a local Ollama LLM to automate the scanning process. It intelligently selects and executes various reconnaissance modules such as subdomain enumeration, web fingerprinting, and vulnerability scanning, while generating structured reports in both Markdown and JSON formats. Notable features include a terminal-based user interface, iteration through an observation-think-act cycle, and the capability to integrate additional modules seamlessly.

numasec

2026-08-03 TypeScript ★ 623
numasec is an AI-driven security agent that enhances terminal-based workflows by integrating existing tools and methodologies for security operations. It facilitates tracking findings, documenting evidence, and generating reports while adhering to security runbooks, making it well-suited for Application Security (AppSec) and penetration testing workflows. With numasec, security professionals can streamline their processes and maintain operational context within a familiar environment rather than depending on separate chatbots or scanners.

Phantom

2026-08-03 Python ★ 16
Phantom is an autonomous AI-driven penetration testing platform designed to perform detailed reconnaissance and exploit vulnerabilities without human intervention. Integrating over 30 professional security tools within a secure Docker environment, it leverages a reasoning loop to adaptively select and execute multi-step attack vectors, producing verified findings complete with proof-of-concept scripts. Unlike traditional scanners that rely on static CVE signatures, Phantom delivers a comprehensive and accurate vulnerability assessment with real-time adaptability and detailed reporting aligned with the MITRE ATT&CK framework.

Threatswarm

2026-08-03 Python ★ 76
ThreatSwarm is a comprehensive penetration testing tool that utilizes 27 AI agents to execute the entire kill chain—from reconnaissance to exploitation, post-exploitation, digital forensics, and reporting—streamlined into a single command interface. It enforces strict scope limitations via `scope_check.py`, ensuring compliance with authorized testing parameters, while leveraging a library of 754 MITRE-mapped skills to guide its operations. Notably, it operates as a Claude Code plugin, eliminating the need for additional infrastructure like Docker or cloud accounts, and outputs detailed vulnerability reports with CVSS scoring.

akira

2026-08-03 Dockerfile ★ 21
Akira is an AI-powered penetration testing tool designed to operate natively within various environments, including Claude Code and Gemini CLI. It specializes in identifying vulnerabilities that traditional scanners may overlook, such as logic flaws and cryptographic weaknesses, by integrating a structured reasoning system that demands reproducible evidence for each finding. Notable features include a robust technique library, a Bayesian hypothesis engine, and the ability to handle complex attack vectors through a systematic engagement and reporting workflow.

Beatrix-suite

2026-08-03 Python ★ 16
Beatrix Suite is a command-line bug bounty hunting framework designed to streamline the entire pentesting workflow by integrating 32 scanner modules and 22 external tools. It features a 7-phase Kill Chain methodology, automated login and session management, and an AI-assisted pentester (GHOST) for advanced analysis, making it suitable for scanning domains, URLs, and IP addresses efficiently in headless environments. This tool aims to eliminate the fragmentation of traditional bug bounty tools by providing a single-command interface that orchestrates multiple tools throughout the assessment process.

catchclaw

2026-08-03 Rust ★ 31
CatchClaw v5.3.0 is a multi-platform AI Agent security assessment tool that supports nine different AI platforms including OpenClaw and Dify. It features 78 DAG attack chains and exploit modules that cover a full range of attack vectors from reconnaissance to data leakage, utilizing an asynchronous Tokio engine for concurrent execution while offering visual attack graph exports and customizable reporting options. The tool is designed to facilitate automated vulnerability verification and threat modeling within complex multi-agent environments, restricted to non-commercial use only.

CloudSec

2026-08-03 Python ★ 29
The Cloud Security Toolkit is a comprehensive resource designed for offensive security practitioners focused on cloud environments, facilitating the exploitation of vulnerabilities and simulating advanced attacks specifically within platforms like Azure, AWS, and Microsoft 365. Notable features include a collection of weaponized exploits, deep-dive vulnerability research, threat intelligence insights, and evasion techniques targeted at cloud defense systems, all aimed at enhancing red team operations and improving cloud security assessments. This toolkit provides practical, battle-tested resources essential for sophisticated penetration testing and incident response in cloud ecosystems.

cyber-agent

2026-08-03 ★ 21
Cyber Agent is an AI-driven penetration testing tool utilizing Claude Code agents to automate the entire penetration testing process, making it particularly suitable for HackTheBox challenges and authorized security assessments. Notable features include automated attack execution which encompasses reconnaissance, exploitation, and privilege escalation, as well as professional report generation adhering to the Penetration Testing Execution Standard (PTES) and mapping to the MITRE ATT&CK framework.

CyberInject

2026-08-03 HTML ★ 44
CyberInject is a professional browser extension toolkit focused on authorized security testing and penetration testing activities. It offers quick access to a diverse range of security payloads categorized into vulnerabilities such as XSS, SQL Injection, SSRF, and LFI, alongside features like one-click copying and an organized, user-friendly interface. Designed for compliance with legal standards, it ensures that users can efficiently execute their testing tasks while promoting responsible usage.

DLLHijackHunter

2026-08-03 C# ★ 398
DLLHijackHunter is an automated detection tool designed for identifying, validating, and confirming DLL hijacking opportunities on Windows systems. It employs a multi-phase approach that includes discovery of exploitable binaries, filtration of false positives, and the deployment of a harmless canary DLL for verification, providing a comprehensive scoring and reporting mechanism. Notable features include extensive coverage of various hijack types, UAC bypass discovery, and a focus on corroborating potential attack paths with actionable intelligence.

Gideon

2026-08-03 TypeScript ★ 34
Gideon is an autonomous cybersecurity operations agent designed for intelligent threat analysis and red teaming. It automates the process of gathering intelligence and conducting thorough security research by breaking down complex questions into actionable tasks, utilizing real-time data from various sources. Notable features include dual-mode operation for both defensive and offensive engagements, goal-directed autonomy, and an evidence-based approach to generating actionable security insights.

pentest-ai

2026-08-03 Python ★ 1637
Pentest-ai is an AI-powered penetration testing tool designed to enhance the verification of security findings by re-running exploits to confirm their validity, ensuring that each piece of evidence is backed by reproducible results. It streamlines the verification process by generating multi-step attack paths and providing a reporting mechanism that only includes findings validated by its oracle system, achieving 100% precision with zero false positives across multiple vulnerability classes. The tool operates offline without cloud reliance, making it ideal for authorized testing in a controlled environment.

pentest-ai-agents

2026-08-03 Shell ★ 2180
pentest-ai-agents is a suite of 50 subagents designed to enhance penetration testing by utilizing Claude Code as an offensive security research assistant. Each agent specializes in areas such as reconnaissance, web applications, Active Directory, and cloud security, offering streamlined automation for various tasks without the need for extensive setup. Notable features include the ability to route tasks to specific experts, support for easy installation as a Claude Code plugin, and a robust validation process to ensure secure and efficient operation of each agent.

PrecompiledBinaries

2026-08-03 PowerShell ★ 44
PrecompiledBinaries is a curated repository of precompiled binaries designed for use in authorized security testing, including penetration testing, red teaming, and exploit validation. It facilitates rapid access to essential tools across various scenarios such as privilege escalation, Active Directory assessments, and tunneling, eliminating the need for time-consuming compilation from source. Notable features include an organized layout of binaries by tool and platform, covering a wide range of use cases in security assessments.

ReconNinja

2026-08-03 Python ★ 42
ReconNinja is an autonomous multi-phase security reconnaissance framework that conducts comprehensive security assessments through a single command. It supports a myriad of functionalities including passive OSINT, port scanning, web discovery, vulnerability scanning, and Active Directory enumeration, producing reports in multiple formats like HTML, JSON, and Markdown. Notable features include an adaptive agent mode for dynamic decision-making, a user-friendly GUI, and enhanced reliability for complex scans with a uniform `PhaseContext` adapter layer.

Shells-X

2026-08-03 JavaScript ★ 13
Shells-X is a modular web shell framework designed for authorized penetration testing and security research, allowing users to deploy a single-file shell that incorporates various tools for executing commands, interacting with databases, and scanning ports. Its notable features include customizable builds with unique SHA256 fingerprints, an interactive environment for PHP and SQL commands, robust system diagnostics, and encrypted traffic handling. The framework also supports automatic detection of CMS/frameworks and provides a one-click export option for recon data to Faraday.

tengu

2026-08-03 Python ★ 58
Tengu is a multi-command platform (MCP) server that functions as an AI-assisted penetration testing copilot, integrating with various security tools such as Nmap and Metasploit. It automates reconnaissance and scanning processes while allowing users to maintain control over exploit actions, featuring advanced safety controls like allowlisting and audit logging. Notable features include its orchestration of 80 tools, automated report generation, and pre-built workflows for diverse pentesting scenarios.

winprivesc

2026-08-03 Batchfile ★ 18
WinPrivEsc is a Windows enumeration and privilege escalation discovery toolkit designed for authorized testing. It offers two script variants—one using cmd for stealth on monitored hosts and another using PowerShell for more comprehensive analysis, allowing users to assess escalation vectors while maintaining a read-only operation. Notable features include customizable noise levels for the script output and extensive reporting on system configurations, user accounts, and permissions, ensuring flexibility and adaptability to various security environments.

zscan

2026-08-03 Go ★ 47
Zscan is a fast and customizable service detection tool designed to identify services, APIs, and network configurations within infrastructure using a flexible fingerprint system. Key features include high-performance concurrent port scanning, intelligent service detection capabilities (such as MAC vendor identification and OS fingerprinting), precise proof of concept (POC) targeting, and versatile output formats including JSON and human-readable options. This tool enhances scanning accuracy and speed compared to traditional methods, making it valuable for network security assessments.

bof-launcher

2026-08-03 Zig ★ 338
The bof-launcher is a versatile programming library designed for in-memory management and execution of Beacon Object Files (BOFs) across multiple platforms, including Windows and Linux. It supports various architectures and integrates seamlessly with languages such as C, Zig, and Rust, offering features like asynchronous execution, cross-platform compatibility, and advanced memory masking techniques. Additionally, the library facilitates the development of BOFs using Zig, leveraging a rich standard library for enhanced functionality during red team engagements.

C-Full-Offensive-Course

2026-08-03 C ★ 10
C-Full-Offensive-Course is a bilingual educational resource designed to guide users through a comprehensive C programming curriculum focused on offensive security practices across Windows, Linux, and macOS platforms. The course comprises 216 progressive units with hands-on coding exercises, alongside a centralized codebase to facilitate learning. It emphasizes ethical usage by instructing users to conduct security labs only within authorized and isolated environments.

gato-x

2026-08-03 Python ★ 584
Gato-X is an advanced scanning and attack toolkit specifically designed to identify vulnerabilities in GitHub Actions pipelines, including Pwn Requests, Actions Injection, and self-hosted runner takeovers. Notable features include fast scanning of thousands of repositories with a single API token, robust analysis of cross-repository workflows, and the capability for post-compromise secrets enumeration. Tailored for Red Teamers and security professionals, Gato-X emphasizes thorough vulnerability detection while adhering to ethical research practices.

recon-modular

2026-08-03 Shell ★ 14
Omniscient V3 is a comprehensive reconnaissance and adversary simulation framework designed to enhance security assessments by consolidating over 130 best-in-class tools into a unified pipeline. Key features include AI-driven results augmentation, distributed execution across platforms such as Kubernetes and Docker, advanced stealth techniques for emulating sophisticated attacks, and immutable audit trails for compliance and reporting. This tool is primarily aimed at security professionals, providing a streamlined approach to identifying vulnerabilities in complex attack surfaces.

ScanCannon

2026-08-03 Shell ★ 478
ScanCannon is a high-speed Bash script designed for efficient credentials-based attack surface enumeration and reconnaissance of large external networks, leveraging tools like `masscan` for rapid port detection and `nmap` for detailed service analysis. It outputs consolidated reports in HTML and CSV formats while enabling project-driven scanning that tracks changes over time, facilitating continuous monitoring of attack surfaces. Notable features include full ASN-based discovery, API detection, CVE hinting, and resilience through checkpointing and parallel scanning.

TABPE

2026-08-03 ★ 24
TABPE is a structured dataset tool that catalogs all PE (Portable Executable) files, including executables and libraries, from clean installations of Windows 10 Pro and Windows 11 Pro. The primary use case is for security researchers and developers who require comprehensive information about each PE file, including metadata such as headers, sections, imports, exports, and checksums, along with detailed logs of the scanning process. Notable features include the generation of a JSON file containing complete PE file details, a text file listing all detected files, and a log of inaccessible files, providing a thorough overview of the executables on the system.

0day-Rubbish

2026-08-03 Python ★ 190
0day Rubbish is an automated vulnerability disclosure tool focused on the rapid identification and public release of high-severity 0-day vulnerabilities using AI-driven methods. It emphasizes efficiency by verifying exploits and providing thorough assessments while maintaining a non-profit approach to enhance timely vendor responses. Key features include direct disclosure of verified vulnerabilities with working proof-of-concept code, a commitment to real-world impact, and continuous monitoring through advanced AI models.

365

2026-08-03 Shell ★ 64
365 is a comprehensive OSINT and threat hunting tool designed for network and web reconnaissance, discovery, enumeration, vulnerability mapping, exploitation, and reporting. Its notable features include a streamlined setup process for Kali Linux and a range of scripts for automating various security assessment tasks. This tool is primarily used for enhancing security assessments and facilitating vulnerability exploitation in targeted environments.

AutoRedTeam-Orchestrator

2026-08-03 Python ★ 259
AutoRedTeam-Orchestrator is a local-first, MCP-native automation platform designed for authorized testing and AI/MCP attack surface auditing. It features a modular security capability set accessible via an MCP Server, Python SDK, and Typer CLI, enabling static code audits, reconnaissance, and vulnerability detection primarily for research and training purposes. Notable capabilities include AI-assisted audits, configurable scanning profiles, and different export formats for audit reports, each tailored for secure and compliant usage scenarios.

awesome-ai-agent-attacks

2026-08-03 ★ 66
The "Awesome AI Agent Attacks" repository provides a curated timeline of real-world security incidents involving AI agents from 2024 to 2026, detailing the specific impacts, root causes, and relevant CVEs associated with each breach. It serves as a factual resource, compiling numerous documented cases to facilitate a better understanding of AI-related vulnerabilities and attack patterns, while emphasizing transparency through sourced entries. Notable features include categorized incident summaries by year, key statistics, and an attack pattern taxonomy.

endgame

2026-08-03 C ★ 30
ENDGAME is a command and control framework designed for authorized red team operations and penetration testing, enabling users to simulate adversarial techniques and assess their network's detection capabilities. Its standout feature is the integrated AI Console, which interprets user objectives in natural language and suggests executable commands based on real-time contextual data, enhancing efficiency in red team workflows. Additionally, the framework supports automated analysis of command outputs to inform follow-up actions, ensuring a streamlined operational process.

HydraSoft-DLL-Hijack-Scanner-ByPass-UAC

2026-08-03 HTML ★ 129
HydraSoft is an advanced open-source tool designed for detecting DLL hijacking vulnerabilities within Windows environments, facilitating privilege escalation. It automates the analysis of executable files and their associated DLLs by scanning directory structures and import tables, thus identifying specific hijacking opportunities. Notable features include a real-time graphical user interface for centralized endpoint management and a color-coded rating system to prioritize targets based on the complexity of crafting proxy DLLs.

mkPIVM

2026-08-03 C++ ★ 421
mkPIVM is a polymorphic, position-independent shellcode virtualizer designed for Windows x86 and x64, which enables the obfuscation of raw shellcode by converting it into a virtual machine that interprets encrypted instructions. Its primary use case is enhancing the stealth of shellcode to evade signature-based detection, leveraging features such as customizable cipher families, opcode permutations, and detailed control over the virtual machine's configuration. The tool supports various operational modes, including full lifting, packing, and hybrid approaches, making it versatile for evasion techniques in offensive cybersecurity applications.

recon-skills

2026-08-03 Python ★ 1214
Recon Skills is a comprehensive toolkit designed for authorized security testing, focusing on external reconnaissance across web applications, APIs, and various vulnerability assessments. Notable features include a structured catalog of skills for discovery, validation, and reporting, covering areas such as authentication testing, attack-path analysis, and evidence review, while emphasizing best practices for operational security and quality assurance. The tool aims to facilitate both manual and automated workflows for security professionals, ensuring a thorough approach to web security assessments.

security-research-orchestrator-prompt

2026-08-03 ★ 25
The Security Research Orchestrator Prompt is an advanced orchestration tool designed for structured security and vulnerability research across a variety of authorized lab targets, including code, binaries, and infrastructure configurations. Notable features include its emphasis on maintaining a strict research method without compromising authorization, and the ability to produce detailed outputs such as threat models, exploit chains, and evidence reports, tailored to various operational modes like lab solving, building, and hunting. This tool ensures rigorous validation of security claims while safeguarding the integrity of research processes.

SilentSniffer

2026-08-03 JavaScript ★ 104
SilentSniffer is an educational tool designed as a web security diagnostic sandbox to demonstrate the extent of information exposure in modern web applications. Functioning entirely as a local client-side environment, it visually portrays how a user's device state and behavioral data can be accessed without consent, utilizing a zero-coupling dynamic plugin architecture for modular functionality. Notable features include a threat escalation hierarchy that categorizes information exposure severity and ensures no data leaves the user's device during operation.

smokedmeat

2026-08-03 Go ★ 376
SmokedMeat is a CI/CD post-exploitation framework designed to analyze, exploit, and validate security vulnerabilities within continuous integration and deployment pipelines. It automates the identification of injection vulnerabilities in GitHub Actions workflows, facilitates the deployment of malicious payloads, and allows attackers to pivot across cloud environments to extract secrets and permissions. This tool is primarily intended for red teams, penetration testers, and security researchers to demonstrate and assess the resilience of CI/CD systems against advanced supply chain attack techniques.

storm-framework

2026-08-03 Python ★ 12
Storm-Framework is an offensive security tool suite designed for reconnaissance, vulnerability assessment, and exploitation, catering to cybersecurity professionals, penetration testers, and bug bounty hunters. Built with a user experience similar to Metasploit, it streamlines security testing workflows and supports multiple platforms including Kali Linux, Ubuntu, and Windows. Notable features include a comprehensive framework flow, detailed documentation, and a structure visualizer that aids in navigating the tool's components.

wb-red-team

2026-08-03 Python ★ 24
Red-Team AI is a white-box red teaming tool designed to identify security vulnerabilities in agentic AI applications by analyzing the source code for specific bugs related to the application's stack. Its notable features include a comprehensive dashboard for scan management, customized attack generation based on the application's architecture, and compliance tracking against industry standards like OWASP LLM Top 10. This tool is particularly useful for developers working with AI agents in sensitive environments such as finance or healthcare, where unique security risks can arise.

wraith

2026-08-03 JavaScript ★ 137
WRAITH is a modern browser-hooking framework designed for red teams, security researchers, and educators, effectively merging the functionalities of traditional browser exploitation tools and blind-XSS frameworks into a single solution. It enables users to conduct authorized security testing by delivering both interactive post-exploitation capabilities and fire-and-forget blind-XSS callbacks in a manner suited for contemporary web applications, including those involving AI. Notable features include an operator console for session management, Docker support for deployment, and a generation of custom payloads for seamless integration into testing scenarios.

BatSploit

2026-08-03 Python ★ 21
BatSploit is an open-source penetration testing tool designed to generate Full Undetectable (FUD) payloads and includes a listener handler. Its primary use case is for security professionals conducting tests to assess vulnerabilities in systems. Notable features include ease of installation through a simple Python setup and the capability to create stealthy payloads for effective exploitation.

beescan

2026-08-03 Python ★ 30
BeeScan is a modular IT infrastructure security auditing platform that facilitates comprehensive penetration testing and infrastructure assessments through the integration of external tools as plugins. Its notable features include automated result collection and multi-format report generation (TERMINAL, HTML, PDF), PostgreSQL database support for centralized result management, and Docker isolation for environment containerization, making it suitable for DevSecOps workflows and large-scale security audits.

enumdb

2026-08-03 Python ★ 221
Enumdb is a brute force and post-exploitation tool designed for MySQL and MSSQL databases, enabling users to test credentials and search for sensitive data fields within database tables. Its notable features include automated credential discovery, multi-threaded enumeration for efficiency, the ability to execute SQL queries and spawn a simulated shell, as well as options for reporting extracted information in .csv or .xlsx formats.

jwtcat

2026-08-03 Python ★ 334
`jwtcat` is a Python-based tool designed for detecting and exploiting vulnerabilities in JSON Web Tokens (JWTs), particularly the signature bypass flaw associated with the `alg=none` algorithm and guessing attacks against HS256 private keys. It supports brute-force and wordlist attacks, allowing users to efficiently test JWTs for security weaknesses. The tool is fully implemented in Python 3 and features options for detailed attack parameters and reporting.

LFITester

2026-08-03 Python ★ 115
LFITester is a Python3 tool designed for testing server vulnerabilities to Local File Inclusion (LFI) attacks, primarily running on Linux/Unix systems but compatible with Windows as well. Key features include support for various attack vectors like Path Traversal, PHP Filters, and Remote Code Execution through methods such as log poisoning and session file exploitation. The tool provides a comprehensive command-line interface that allows users to automate LFI testing and customize payloads for effective penetration testing.

macgonuts

2026-08-03 C ★ 16
Macgonuts is a versatile ARP/NDP tool designed for network address spoofing, supporting both IPv4 and IPv6 protocols. It aims to provide a lightweight, user-friendly interface for ethical hacking and pentesting while allowing developers to leverage its functionalities via C libraries or bindings in Go and Python. Compatible with Linux and FreeBSD, Macgonuts emphasizes responsible use and ethical practices in network security assessments.

penstaller

2026-08-03 Python ★ 19
Penstaller is a Python automation tool that streamlines the setup of essential bug bounty and penetration testing tools on a clean system with a single command. It automates the installation of critical programming languages and various pentesting utilities, facilitating a rapid and efficient environment preparation for both novice and experienced security testers. Notable features include a comprehensive list of tools covering different aspects of security testing, along with recommendations for additional manual installations of wordlists.

PowerLadon

2026-08-03 PowerShell ★ 201
PowerLadon is a modular penetration testing tool designed for network reconnaissance, vulnerability scanning, and exploitation, offering capabilities for batch processing across various IP segments. It features extensive support for different protocols, built-in modules for high-risk vulnerabilities, password auditing, and remote command execution, while allowing users to customize and develop their own plugins. Its ease of use and compatibility with PowerShell and Cobalt Strike enhance its versatility in both internal and external network penetration tasks.

SBSCAN

2026-08-03 Python ★ 114
SBSCAN is a penetration testing tool specifically designed for the Spring framework, capable of conducting unauthorized scans and sensitive information detection on Spring Boot applications, as well as identifying and validating related vulnerabilities. Notable features include an extensive dictionary for sensitive paths, fingerprint detection capabilities to optimize resource usage, modular architecture for user-defined extensions, and comprehensive support for various types of vulnerability checks, including the latest CVEs. The tool also implements functionality for noise reduction in results, allowing users to focus on successful detections, and supports various scanning configurations such as URL or file-based targets, proxy settings, and multithreading.

smugglefuzz

2026-08-03 Go ★ 313
SmuggleFuzz is a configurable HTTP downgrade smuggling scanner designed to identify overlooked smuggling vulnerabilities in web applications. Its notable features include customizable gadget lists, multiple scanning options with support for various HTTP methods and headers, and the ability to filter responses by specific criteria. The tool enables deeper insights into failed attacks, making it a powerful resource for security professionals aiming to enhance their vulnerability assessments.

wconsole_extractor

2026-08-03 Python ★ 66
WConsole Extractor is a Python library designed to exploit Flask applications that are running in debug mode, allowing users to extract sensitive information and gain interactive access to the server. Users can implement a custom file leak function to retrieve files from the target application, and the tool provides attributes to access critical server details, including tokens and user information, as well as functions for spawning shells and debuggers. Notable features include an easy installation process and the capability to interact with the application environment through an integrated shell.

Amnesiac

2026-08-03 PowerShell ★ 452
Amnesiac is a post-exploitation framework developed in PowerShell that facilitates lateral movement within Active Directory environments without the need for installation, as it operates entirely in memory. It features command execution over Named Pipes for discreet operations, a user-friendly interface, and a variety of integrated modules for tasks such as keylogging and Kerberos ticket dumping. The tool is designed for research and authorized testing, emphasizing user responsibility in compliance with legal regulations.

AutorizePro

2026-08-03 Python ★ 610
AutorizePro is a Burp Suite plugin designed for detecting authorization vulnerabilities using an integrated AI analysis module. Its primary use case is to automate the testing of authorization issues, markedly reducing false positive rates from 95% to 5% by leveraging AI for improved accuracy in complex scenarios. Notable features include support for customizable API endpoints, local model deployment, and the ability to exclude non-API resources, alongside comprehensive reporting capabilities.

GarudRecon

2026-08-03 Shell ★ 266
GarudRecon is a bash-based reconnaissance automation framework designed for security professionals and bug bounty hunters, facilitating asset discovery and vulnerability assessment through the integration of over 80 open-source security tools. It offers multiple operational modes, such as SmallScope, MediumScope, and LargeScope, to tailor the reconnaissance process according to different engagement scopes, alongside advanced capabilities for automated monitoring and vulnerability detection including subdomain enumeration, port scanning, and exploitation checks. Noteworthy features include a workflow mode for tool chaining, fleet mode for distributed scans, and cron job scheduling for recurring tasks.

HunterA

2026-08-03 Python ★ 12
HunterA is an advanced mobile penetration testing framework designed for Android devices operating without root access, functioning within the Termux environment. It consolidates a diverse array of powerful tools for tasks such as port scanning, WHOIS/DNS reconnaissance, CVE vulnerability searches, and traffic sniffing, along with features like a fully asynchronous engine and integration with Termux:API for enhanced capabilities. Its modular design supports a range of functionalities, from OSINT to vulnerability exploitation, making it a comprehensive solution for mobile pentesting.

nucleihub

2026-08-03 Go ★ 13
Nucleihub is a tool designed for organizing and managing Nuclei templates from various community sources, enabling users to consolidate template files efficiently. It features auto-flattening of directory structures, duplicate handling, smart filtering, and validation of downloaded templates, with optimizations for low-resource environments. The tool supports URLs ending in `.git`, `.yaml`, or `.zip` formats, enhancing flexibility in template retrieval.

nucleihub-templates

2026-08-03 ★ 38
nucleihub-templates is a continuously updated repository of Nuclei templates designed for security testing, aggregating over 600 sources and refreshed every six hours via GitHub Actions. It provides security researchers and penetration testers with a comprehensive suite of templates for effective vulnerability scanning, leveraging an automated collection pipeline that removes duplicates and validates templates against the latest Nuclei version. Notable features include automatic updates, diverse template categorization, and seamless integration into existing security workflows.

phantom_whisper

2026-08-03 Python ★ 22
Phantom Whisper is a Python 3 framework designed for ethical penetration testing, specifically targeting WhatsApp by delivering a zero-click WebP payload to identified devices. Its key features include ASLR leak polling to confirm initial compromise, automated deployment of a full implant for either iOS or Android, and thorough logging of all actions in JSON format for audit purposes. The tool is currently structured for single-host execution but is intended to support multi-threaded operations in future developments.

ronin-vulns

2026-08-03 Ruby ★ 78
ronin-vulns is a Ruby library designed for blind vulnerability testing, specifically targeting various web application vulnerabilities such as Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL Injection (SQLi), reflective Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects. Its notable features include support for testing multiple parameter types (query parameters, HTTP headers, cookies, and form parameters), along with high documentation and test coverage metrics, making it a robust tool for security researchers and developers within the ronin-rb project framework.

ScanPro

2026-08-03 Shell ★ 94
ScanPro is a menu-driven tool that enhances the functionality of Nmap for network scanning purposes. Its primary use case involves simplifying the scanning process by allowing users to select target IPs, ports, and scan types through an interactive menu, while also facilitating service detection and output formatting. Notable features include support for NSE scripting and HTTP information gathering, making it a versatile utility for penetration testing and network analysis.

security-tools-hacking

2026-08-03 Python ★ 11
The Largo-m/security-tools-hacking is a modular Windows penetration testing framework designed for security professionals, facilitating various stages of red team operations such as reconnaissance, exploitation, and post-exploitation. Key features include system information collection, geolocation lookup, browser history extraction, and optional key logging, all presented in a user-friendly manner that allows for easy integration and extension of custom modules.

slack-slurp

2026-08-03 TypeScript ★ 33
Slack-Slurp is a pentesting tool designed for post-exploitation in Slack environments, leveraging the Slack API to extract potentially sensitive information from messages by employing Trufflehog's secret detectors. Key features include robust secret detection across a wide range of commonly used services, support for authentication via user or bot tokens, and the ability to add custom detectors for tailored searches. This tool is particularly useful for security professionals looking to identify exposed credentials and sensitive data within Slack channels.

SYSTEMatic

2026-08-03 Python ★ 17
SYSTEMatic is a proof-of-concept tool designed for Windows that enables privilege escalation from a local Administrator account to the NT AUTHORITY\SYSTEM account via token impersonation, without UAC prompts or external dependencies. It leverages the Win32 API to duplicate a SYSTEM process's token and spawn new processes, making it valuable for system administration, security research, and penetration testing tasks. Notably, it operates solely within the constraints of existing Administrator privileges and does not exploit vulnerabilities or function as a UAC bypass.

Venera

2026-08-03 Go ★ 66
The Venera Framework is a Lua-based tool designed for automating customizable tests and attacks across various protocols. Its primary use case lies in vulnerability scanning and exploitation, allowing users to create and manage scripts that target specific vulnerabilities or conduct general verification tasks. Notable features include a built-in package manager, the ability to import and export scripts, and a flexible scripting environment that supports user-defined modules for tailored security testing.

Vulnshop

2026-08-03 JavaScript ★ 30
Vulnshop is a deliberately insecure e-commerce web application designed for security training and penetration testing practice, featuring over 40 embedded vulnerabilities across various categories of web application security. Built on Node.js, it simulates a modern online shopping platform with functionalities like user authentication, product management, and an administrative dashboard, allowing users to practice real-world exploitation scenarios in a controlled environment. The tool facilitates educational engagement with critical security concepts, but should only be used in isolated setups to prevent exploitation in production contexts.

vulntechfinder

2026-08-03 Go ★ 20
vulntechfinder is an automated vulnerability scanning tool that utilizes technology stack detection to execute targeted scans using tools like Nuclei and httpx. It supports features such as automated tech stack identification, configurable parallel processing, smart filtering for technology inclusion, and crash-safe resume capabilities, making it versatile for various scanning needs. The tool is compatible with any security tool that accepts technology tags, thereby enhancing its utility in security assessments.

XMLRPC-Bruteforce

2026-08-03 Python ★ 16
XMLRPC-Bruteforce is a specialized penetration testing tool designed for exploiting the XML-RPC functionality in WordPress, allowing users to conduct hyper-optimized brute force attacks. By employing a unique batch method capable of testing 50-100 passwords per request and utilizing a binary search algorithm for credential discovery, it offers significant speed improvements over traditional brute force methods. Notable features include smart detection of web application firewalls, real-time statistics tracking, and a user-friendly interface with color-coded outputs and progress visualizations.

Awesome-Offensive-AI-Agentic-Landscape

2026-08-03 ★ 246
The Offensive AI Agentic Landscape project is a comprehensive catalog of resources focused on AI-driven penetration testing and autonomous red-team agents. It offers an extensive compilation of open-source projects, specialized models, skills, MCP servers, academic papers, benchmarks, and commercial solutions, providing researchers and security professionals with a holistic view of the offensive AI domain. Key features include a curated list of popular agents and tools, with a focus on leveraging AI for offensive security operations.

Bug-Bounty-Arsenal-v.3

2026-08-03 Python ★ 12
BugBounty Arsenal is a comprehensive, full-stack security scanning platform designed for bug bounty hunters and security researchers. It features over 50 detectors for various vulnerabilities across multiple categories, continuous monitoring with scheduled scans, findings triage to manage results over time, and CI/CD integration to automate security checks in development pipelines. Unique capabilities include attack surface management, tailored AI-driven remediation advice, and extensive reporting options, all from a centralized dashboard.

BurpRecon

2026-08-03 Python ★ 13
BurpRecon is a cybersecurity tool designed for bug bounty hunters, facilitating the extraction and analysis of attack surface intelligence from Burp Suite XML exports. It automates identification of high-value vulnerability candidates such as IDORs, Host Header Injections, and Privilege Escalation vectors through a multi-phase analysis, while also performing technology fingerprinting and CVE lookups—all through a single interactive command-line interface. Notable features include detailed scoring for various vulnerabilities, ready-to-run proof-of-concept generation, and support for passive subdomain enumeration.

CVE-2021-3129

2026-08-03 Python ★ 153
This tool exploits the Remote Code Execution vulnerability (CVE-2021-3129) found in specific Laravel versions, enabling users to execute commands on vulnerable instances with "APP_DEBUG" set to true. Key features include the ability to write and execute commands remotely, as well as several patch options to secure the application against the exploit. The tool is intended for educational and research purposes, emphasizing the importance of responsible usage.

emailextractor

2026-08-03 Go ★ 35
emailextractor is a high-speed email scraping tool developed in Go that enables concurrent crawling of websites to extract email addresses for purposes such as reconnaissance and sales intelligence. Key features include fast concurrent processing, fallback to headless Chrome for JavaScript-rendered content, smart URL normalization, and optional JSON output for easy integration.

exchange-penetration-testing

2026-08-03 PowerShell ★ 141
The "exchange-penetration-testing" tool provides a comprehensive framework for performing penetration tests on Microsoft Exchange servers. It facilitates reconnaissance, brute-force attacks, and exploitation of vulnerabilities such as ProxyLogon and ProxyShell, alongside automated enumeration of the Global Address List (GAL). Notable features include the ability to conduct password spraying and provide access to critical vulnerabilities, enabling security professionals to assess and strengthen Exchange server defenses effectively.

ExploitHawk

2026-08-03 C ★ 11
ExploitHawk is a terminal-based exploit search tool tailored for ethical hacking and red team operations on Linux distributions. It offers features such as fast multi-threaded searches through local databases, customizable name and version querying, a user-friendly ncurses interface, and clipboard integration for easy result management. The tool is primarily designed to enhance safe testing for users with permissions on systems while requiring a local copy of Exploit-DB for functionality.

Gamal

2026-08-03 Python ★ 14
Gamal is a lightweight Flask application designed for red teamers and pentesters, facilitating mass data exfiltration and various attacks such as SSRF, XXE, and XSS. It features file delivery capabilities, where users can upload and categorize payloads for exploitation, and includes a helper script that automates the download of common penetration testing tools. The tool supports features like customizable logging, SSL configuration, and can handle uploads while associating files with user and host identifiers for better tracking.

kali-pentest

2026-08-03 ★ 101
Kali-pentest is a sophisticated penetration testing tool designed for AI agents, leveraging Kali Linux and enabling autonomous attack planning and execution. It consolidates 269 command-line tools across various categories, features built-in coverage matrices, and employs zero-findings fallbacks along with human approval gates for high-risk actions, ensuring comprehensive and ethical testing processes. By connecting to environments via SSH or Docker, this tool adapts its strategies based on target assessments and generates structured reports for clarity and compliance.

LLMrecon

2026-08-03 Go ★ 17
LLMrecon is an advanced security testing framework specifically designed to identify and exploit vulnerabilities in Large Language Models (LLMs), adhering to the OWASP Top 10 2025 guidelines. It features a variety of novel attack techniques such as FlipAttack and DrAttack, along with machine learning-optimized attack selection, comprehensive defense detection capabilities, and support for testing models from multiple platforms, making it suitable for enterprise-level deployment.

Nightingale

2026-08-03 Dockerfile ★ 315
Nightingale is a comprehensive Docker toolkit designed for penetration testing and security research, providing a reproducible multi-architecture environment with curated tools for various workflows, including web, network, mobile, and OSINT. Notable features include a browser-based terminal for easy access, community-driven tool enhancements, and integration with security-focused CI tools like Trivy. The project facilitates rapid setup and customization, allowing users to tailor the environment to specific testing needs or internal usage.

RedteamAgent

2026-08-03 Python ★ 122
RedTeam Agent is an autonomous AI-powered simulation tool designed for red teaming and penetration testing, streamlining the process of security assessments across multi-platform environments. It features 8 specialized AI agents that facilitate a comprehensive 5-phase attack methodology, alongside containerized Kali tools and a web-based GUI for managing projects and operations with minimal user interaction. Notable functionalities include an intelligent case collection pipeline and robust reporting mechanisms, allowing users to efficiently conduct security evaluations and automate repetitive tasks.

SpectreWeb-AI

2026-08-03 Python ★ 13
SpectreWeb AI is an advanced MCP server facilitating AI-assisted manual web penetration testing, which enables operators to leverage AI tools for reconnaissance, payload generation, and response analysis while maintaining direct control over testing strategies. Its notable features include context-aware payload creation, built-in WAF bypass capabilities, and session persistence for findings across multiple targets. This tool is designed to overcome challenges presented by traditional blind scanning techniques, optimizing the testing process for bug bounty hunters and security professionals.

temodar-agent

2026-08-03 Python ★ 60
Temodar Agent is an AI-powered security analysis platform specifically designed for WordPress plugins and themes, offering security researchers an efficient mechanism for vulnerability assessment. Key features include risk-based target prioritization, Semgrep-powered static analysis, and AI-assisted investigation workflows that maintain context throughout the review process. Built as a local-first Docker application, it supports multi-provider LLM orchestration and facilitates structured code reviews to enhance vulnerability triage.

xssrecon

2026-08-03 Go ★ 55
XSSRecon is an automated tool designed for the discovery of reflected XSS vulnerabilities in web applications by testing URL parameters for reflection of a specified payload. It features a dual detection method for assessing input reflection in both HTTP responses and DOM, as well as support for concurrent processing and customizable testing of special characters. Additional capabilities include smart optimizations for testing efficiency, flexible output formats, and integration with external tools like `pvreplace` for precise parameter injection.

abspider-recon

2026-08-03 TypeScript ★ 15
ABSpider Recon is a web reconnaissance tool designed for authorized passive intelligence gathering and active vulnerability assessments, targeted primarily at bug bounty hunters, security engineers, and auditors. It features a unified dashboard and command-line interface (CLI) that simplifies key reconnaissance tasks, including DNS lookups, port scans, and payload checks into a streamlined workflow. Notably, it offers a live demo environment and can be run locally via npm, making it accessible for both professionals and educational purposes.

AIDA

2026-08-03 JavaScript ★ 482
AIDA is an AI-driven autonomous pentesting agent designed for comprehensive security assessments of web applications, APIs, and infrastructure. It utilizes large language models to reason and understand application logic, execute commands in an isolated environment, and systematically document findings. Notable features include a fully equipped Docker execution environment with essential pentesting tools, on-the-fly Python script generation for custom exploitations, sophisticated HTTP request manipulation, and persistent logging for detailed results.

Bjorn

2026-08-03 Python ★ 6257
Bjorn is an autonomous network scanning and vulnerability assessment tool optimized for Raspberry Pi, featuring a unique e-Paper HAT display. Its modular architecture allows for flexible configuration and operations like network scanning, vulnerability detection using Nmap, brute-force attacks, and data extraction from compromised services. With a real-time interface for monitoring and interaction, Bjorn supports extensive customization for diverse security testing requirements.

CommiPiste

2026-08-03 Python ★ 40
CommiPiste is a tool designed for precise identification of open-source web software versions and associated CVEs by analyzing public static files. Its primary use case is authorized security testing and inventory management, leveraging a signature database that allows users to match files against specific Git commits. Notable features include automatic database updates, support for various output formats, and the capability to autoindex unknown software repositories for future scans.

CVE2PoC

2026-08-03 Python ★ 148
CVE2PoC is a tool designed for penetration testers and security researchers to efficiently locate public exploits, Proof-of-Concepts (PoCs), and advisories associated with a specific CVE ID. Its notable features include the aggregation of public exploits from various sources, the provision of isolated Docker environments for safe testing, automated report generation, and comprehensive CVE intelligence, including remediation steps and related bug bounty reports. This powerful tool streamlines the vulnerability discovery and assessment process, allowing users to quickly gather essential information for their security assessments.

deepbug

2026-08-03 Python ★ 28
DeepBug is an automated reconnaissance and bug bounty hunting platform that integrates various open-source tools to facilitate subdomain enumeration, port scanning, JavaScript analysis, and vulnerability scanning within an intuitive user interface. Its primary use case is to streamline bug bounty workflows, allowing users to manage projects, perform discovery scans, and generate comprehensive reports on findings. Notable features include customizable project management, a robust dashboard for tracking scan progress, and integration with popular vulnerability scanning tools like Nuclei.

EmbedXPL-Forge

2026-08-03 Python ★ 32
EmbedXPL-Forge is an open-source exploitation and scanning framework designed for security assessments of embedded and perimeter devices including routers, switches, IoT devices, and printers. It features over 2800 modules encompassing various attack vectors such as credential testing, vulnerability exploitation, and firmware manipulation, alongside an extensive library of 700+ mapped CVEs across 114+ vendors, along with an APT Group Attack Engine for simulating real-world cyber attack scenarios.

ExaAiAgent

2026-08-03 Python ★ 12
ExaAiAgent is an advanced AI-powered cybersecurity tool designed for comprehensive penetration testing, providing enhanced functionalities for various security assessments. Key features include a K8s scanner tool registration, smart fuzzing capabilities, response analysis for SQL errors, and automated installation processes, all aimed at integrating seamlessly into agent-driven workflows. The tool focuses on improving runtime reliability, error handling, and multi-tool coordination to facilitate efficient cybersecurity operations.

faction

2026-08-03 Java ★ 603
FACTION is an OWASP project designed to streamline and automate the entire penetration testing and security assessment workflow. It offers features such as real-time collaboration among assessors, customizable report templates, a peer review system for tracking changes, and robust integration capabilities with tools like Burp Suite and various authentication systems. Additionally, it includes a REST API for seamless integration with other platforms, enhancing vulnerability management and team coordination.

faraday_plugins

2026-08-03 Python ★ 61
Faraday Plugins is a command-line tool designed to work seamlessly with Faraday, enabling users to manage and process security-related plugins. Its primary use case includes detecting and processing commands or reports generated by various security tools like Nmap and ping, offering features such as custom plugin support, JSON output formatting, and detailed command tracking. Notably, it allows for easy integration of custom plugins and includes logging capabilities for debugging purposes.

GTFONow

2026-08-03 Python ★ 639
GTFONow is a Python-based tool designed for automatic privilege escalation on Unix systems by exploiting misconfigured setuid/setgid binaries, capabilities, and sudo permissions. With a focus on usability for both CTF challenges and real-world pentesting scenarios, it offers various automated exploitation techniques, including file read/write primitives and SSH key theft. The tool is lightweight, compatible with multiple Unix variants, and requires no third-party dependencies, making it easy to deploy via a single script.

htb-thm-oscp-checklist

2026-08-03 ★ 22
The HTB / THM / OSCP Master Penetration Testing Checklist is a comprehensive, modular framework designed to guide penetration testers through the phases of engaging with Hack The Box, TryHackMe, and OSCP-level machines. Key features include structured sections from setup and reconnaissance through exploitation and post-exploitation activities, as well as a quick reference for tools, commands, and troubleshooting. This checklist serves as a valuable resource for both beginners and intermediate practitioners in the penetration testing field.

keyleak-detector

2026-08-03 Python ★ 266
KeyLeak Detector is a runtime security tool designed to identify and validate exposed API keys and misconfigurations in Backend-as-a-Service (BaaS) implementations, specifically targeting frameworks like Supabase and Firebase. Its notable features include a Chrome extension for real-time detection of secrets in web applications, a full site scanning capability that reports on potential vulnerabilities across subdomains, and the ability to validate active status of found keys. Unlike traditional static scanners, KeyLeak assesses the exploitability of keys at runtime, offering a comprehensive audit for web applications.

mcpsec

2026-08-03 Python ★ 23
mcpsec is a security scanner and protocol fuzzer specifically designed for MCP (Model Context Protocol) servers, allowing real-time connection and exploitation testing against live services. Its primary use case is to identify vulnerabilities in AI development tools that utilize MCP, enabling users to discover and report security issues effectively. Notable features include support for 800+ fuzzing cases, detailed vulnerability reporting, and dynamic testing capabilities that surpass traditional static analysis methods.

OpenRediWrecked

2026-08-03 Shell ★ 47
OpenRediWrecked is a sophisticated tool designed for security professionals to detect and exploit open redirect vulnerabilities by automating the injection of carefully crafted payloads using the sed utility. Its notable features include parameter cleaning, support for various encoding techniques to bypass filters, and an intuitive output format that highlights vulnerable URLs in a color-coded manner. This makes it an essential asset for Red Teams and Bug Bounty Hunters seeking to improve their testing methodologies.

Pwning-OpenEDR

2026-08-03 C++ ★ 12
Pwning OpenEDR is a vulnerability research tool that identifies and showcases high-severity flaws in OpenEDR version 2.5.1, emphasizing reproducible exploits for security assessments. Notable features include detailed CVSS scoring for various vulnerabilities, comprehensive runtime proof evidence, and a structured approach for reproducing each advisory in a controlled environment. This tool is particularly useful for security researchers evaluating endpoint detection and response (EDR) solutions for potential weaknesses.

SKELETONKEY

2026-08-03 C ★ 25
SKELETONKEY is a comprehensive Linux local privilege escalation (LPE) tool that consolidates 46 modules targeting 41 distinct CVEs from 2016 to 2026, offering both red team and blue team functionalities. It features verified exploits, automatic module selection based on safety, detection rules for security audit logging, and a scanning capability for system administrators to identify unpatched vulnerabilities. This tool is designed for authorized testing only, ensuring ethical hacking practices while providing robust functionality for pentesters and system administrators alike.

TerminatorZ

2026-08-03 Shell ★ 337
TerminatorZ is an Offensive CVE Exploitation Framework specifically designed for red teamers and offensive security professionals, focusing on active exploitation rather than mere vulnerability scanning. It automates reconnaissance across multiple sources, validates live endpoints, and executes 31 deterministic CVE checks, providing real-time feedback with zero false positives and proof-of-concept URLs for confirmed vulnerabilities. With its modular Bash architecture and unique features like asset-type intelligence and production-quality reporting, TerminatorZ streamlines the exploitation process for faster and more credible results.

TheSprayer

2026-08-03 C# ★ 37
TheSprayer is a cross-platform tool designed to help penetration testers spray passwords against an Active Directory domain without locking out accounts.

XSSRocket

2026-08-03 Shell ★ 168
XSSRocket is a cybersecurity tool designed for conducting offensive security assessments, primarily focusing on Cross-Site Scripting (XSS) vulnerabilities. It leverages the Wayback Machine to retrieve and filter URLs, uses httpx for live URL verification, and employs a remote XSS payload list to perform GET requests, potentially exposing vulnerabilities. Notable features include stealth mode scanning, automated result storage, customizable payload lists for other injection types, and a user-friendly interface that enriches the output with random security quotes.

ad-autopwn

2026-08-03 Python ★ 41
AD AutoPwn is a fully automated penetration testing tool that facilitates the compromise of Active Directory environments by chaining over 25 attack techniques, allowing security professionals to conduct authorized assessments effectively. Its notable features include zero-credential attacks for username enumeration and credential harvesting, advanced exploitation methods for privilege escalation, and integration with BloodHound for graph-driven attack chains and actionable insights. The tool leverages techniques such as Kerberoasting, NTLM relay, and various vulnerability exploits to streamline the process of acquiring domain admin access.

Alien

2026-08-03 Java ★ 268
Alien is a modular webshell client designed for cybersecurity research and education, providing a flexible post-exploitation framework that integrates with various web technologies through reusable modules. Key features include arbitrary code execution, a file manager, database interaction, SOCKS5 proxying, HTTP traffic obfuscation, and the ability to pivot through webshells for enhanced communication security. The architecture enables advanced capabilities while keeping the core webshell lightweight, making it suitable for authorized penetration testing scenarios.

articulos

2026-08-03 ★ 200
The R3LI4NT/articulos repository serves as a comprehensive resource for cybersecurity and hacking-related articles, focusing on topics such as vulnerability exploitation, security techniques, and network auditing. Notable features include detailed guides on various pentesting methodologies, firewall configurations for GNU/Linux, and resources on social engineering attacks, providing practical insights and tools for both novice and experienced security professionals. Users can access the content through an integrated blog link for easier navigation and learning.

blog

2026-08-03 HTML ★ 21
This repository provides a curated collection of detailed writeups on various cybersecurity challenges, including Bug Bounty, Hack The Box (HTB), TryHackMe, and Capture the Flags (CTFs). It serves as an educational resource for cybersecurity practitioners at all levels, featuring in-depth explanations of techniques for web exploitation, privilege escalation, and more, aimed at enhancing understanding of vulnerabilities and methodologies in cybersecurity.

Cascavel

2026-08-03 Python ★ 29
Cascavel is an autonomous Continuous Threat Exposure Management (CTEM) engine designed to streamline Red Team operations and validate adversarial exposures. It automates the process of scoping and discovery, prioritizes vulnerabilities with real-time threat intelligence, and employs a robust validation engine to minimize false positives while generating actionable remediation recommendations. Notable features include dynamic mapping of infrastructure, integration with threat databases, and support for various output formats, all engineered to enhance operational efficiency in cybersecurity.

cve-mcp

2026-08-03 TypeScript ★ 20
CVE-MCP is a centralized vulnerability intelligence platform that unifies data from multiple sources, including NVD, EPSS, CISA KEV, and GitHub Advisory, to provide real-time intelligence tailored for AI agents. It streamlines the process of accessing critical vulnerability information on-demand, eliminating the need for cumbersome manual searches across disparate databases. Notable features include an extensive array of integrated tools, seamless API access, and compatibility with established frameworks like MITRE ATT&CK, significantly enhancing efficiency in vulnerability assessment and response.

embark

2026-08-03 Python ★ 394
EMBArk is a web-based platform designed for centralized firmware security analysis, utilizing the EMBA scanner as its backend. It offers features such as scanning, tracking, reporting, and presents results through an aggregated management dashboard to enhance accessibility and usability. Currently, it supports only Ubuntu LTS (version 24) and provides an intuitive setup and management interface for enterprise environments.

ExploitHunter.app

2026-08-03 HTML ★ 12
ExploitHunter.app is an open-source offensive-security tool designed to enhance the cost-effectiveness of security research through intelligent orchestration of various AI models. It facilitates broad reconnaissance, inventory checks, and evidence gathering using budget-friendly or local models, while reserving expensive frontier models for deeper analysis and validation tasks. Key features include automated lab environments for running evaluations, local model capabilities without API costs, and a data explorer for tracking evaluation outcomes and expenses.

ghost

2026-08-03 Rust ★ 11
ghost is a private desktop application designed for Windows that facilitates local file searching, the execution of AI agents, and integration with over 10,000 tools. Its notable features include the ability to operate entirely offline, ensuring user data remains secure and private, alongside advanced protocol support for seamless communication between tools and AI functionalities. This makes ghost particularly suitable for users prioritizing data privacy and local processing capabilities.

hexgraph

2026-08-03 Python ★ 19
HexGraph is a self-hosted tool designed for AI-assisted vulnerability research that operates entirely on local machines. It allows users to analyze binaries or firmware images by breaking down the targets into components, executing analysis tasks, and organizing findings within a structured, typed graph stored in SQLite. Notable features include a focus on local operations without telemetry, a hypothesis worklist for managing leads, and a secure environment ensuring that all interactions with potentially hostile targets occur in an isolated Docker container.

kimiko

2026-08-03 Python ★ 138
Kimiko is a pentesting configuration tool that enhances the Kimi Code CLI by providing a specialized framework for authorized offensive security, penetration testing, and mobile device security research. Key features include automated context loading for security workflows, customizable agent configurations, and robust capabilities for network offensives, malware generation, reverse engineering, and more, all under strict user authorization. Designed for lawful and ethical testing only, Kimiko facilitates a streamlined setup for various security research methodologies.

MSSQLand

2026-08-03 C# ★ 76
MSSQLand is a C# post-exploitation tool designed for red team operations targeting Microsoft SQL Server (MSSQL) environments. It facilitates linked server traversal, cascading impersonation of logins, and various discovery actions to gather impactful information with minimal operational security footprint. Notable features include automatic execution of linked queries across deep server chains, support for multiple authentication methods, and customizable output formats, enhancing both usability and data presentation in penetration testing scenarios.

pentest-reports

2026-08-03 TypeScript ★ 319
Pentest Reports is a web application that provides a curated list of public penetration test reports, along with a database of popular Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), and security commands and tools. It includes ready-to-use pentest report templates, making it a valuable resource for security professionals conducting vulnerability assessments. The tool is built with Node.js and MongoDB, ensuring efficient data management and retrieval.

Physical-Pentesting-Tools

2026-08-03 ★ 104
The Physical Penetration Testing Tools repository provides a comprehensive set of methods and tools for conducting physical security assessments by simulating real-world attacks. Notable techniques include badge cloning using devices like Proxmark and Flipper Zero, tailgating with various access tools, and social engineering tactics aimed at exploiting human factors. This collection aids security professionals in identifying vulnerabilities in physical security controls through practical tools and methodologies.

ppmap-proto-pollution

2026-08-03 Python ★ 31
PPMAP is a comprehensive JavaScript prototype pollution and XSS vulnerability scanner designed for web application security assessments. It features a modular architecture, advanced detection methods for various frameworks, and capabilities for browser automation, WAF resilience, and in-depth logging, making it suitable for enterprise-level penetration testing and vulnerability management. Notable components include its intelligent detection tiers, support for modern frameworks, and integration of extensive exploitation guides for discovered vulnerabilities.

rekono

2026-08-03 Python ★ 598
Rekono automates the penetration testing process by integrating multiple hacking tools to streamline tasks such as OSINT, host discovery, and vulnerability scanning. Its notable features include email and Telegram notifications for findings, integration with Defect-Dojo for advanced vulnerability management, and a dedicated Telegram bot to execute tests from any device. This tool aims to enhance a pentester's efficiency by allowing them to focus on analysis rather than repetitive testing tasks.

secator

2026-08-03 Python ★ 1307
secator is a comprehensive task and workflow runner tailored for security assessments, enhancing the efficiency of penetration testers and security researchers. It features a curated list of commands with unified input and output options, CLI and library support, and the ability to run distributed tasks via Celery, making it suitable for both simple and complex security workflows. Notably, secator integrates numerous well-established security tools to streamline the assessment process.

sif

2026-08-03 Go ★ 623
sif is a comprehensive recon and exploitation scanner that integrates various scanning capabilities—including subdomain enumeration, port scanning, crawling, vulnerability detection, and more—into a single binary. It leverages a shared connection-pool architecture for efficiency, allowing seamless execution of over 25 scan types from one command, while eliminating the need for external dependencies. Notable features include support for continuous monitoring with change detection, scanning configuration through command-line flags, and integration with notification services like Slack and Discord.

skewrun

2026-08-03 Rust ★ 77
Skewrun is an Active Directory time discovery toolkit designed for red team operations, facilitating the resolution of time discrepancies when executing commands on target systems from a Linux environment. It utilizes various network protocols (CLDAP, SMB, NTP, Kerberos, NTLM) to dynamically fetch the Domain Controller's time, allowing users to circumvent the Kerberos `KRB_AP_ERR_SKEW` error without needing elevated privileges to adjust the system clock. The tool features a library-first architecture for seamless integration into other Rust applications and minimizes forensic traces during operation.

SQL-Injector

2026-08-03 ★ 11
SQL-Injector is a specialized tool designed for performing SQL injection testing on web applications, facilitating the identification of vulnerabilities in various database systems such as MySQL, PostgreSQL, MSSQL, and Oracle. Notable features include automated vulnerability detection, custom payload generation for bypassing WAFs, multi-threaded scanning for efficiency, and the ability to operate anonymously via Tor integration. Advanced capabilities support complex testing scenarios, including boolean-based blind SQL injection and detailed schema enumeration.

toboggan

2026-08-03 Python ★ 16
Toboggan is a post-exploitation tool that facilitates a semi-interactive shell on both Linux and Windows targets via Remote Code Execution (RCE) methods. It operates by allowing users to define custom command execution logic through a simple Python interface, enabling interaction with command outputs even in restrictive network environments. Key features include support for Python-based execution modules, an interactive shell with command history, and the ability to establish communications using named pipes when reverse shells are not feasible.

trilane

2026-08-03 Rust ★ 28
TriLane is an autonomous gray-box security auditing tool designed for authorized penetration testing on local labs, internal codebases, and bug-bounty targets. It features a staged audit process that includes the construction of an attack-surface graph, a six-lane semantic audit covering various security aspects, and a deduplication mechanism for findings, allowing for a thorough and organized assessment of security vulnerabilities. Notable features include a desktop GUI for tracking the audit process, two operational modes (Safe and Lab), and efficient evidence management for generating comprehensive reports.

WonderSuite-Ai-Bug-Bounty

2026-08-03 Rust ★ 50
WonderSuite is a desktop-native offensive security research engine designed for comprehensive web application security testing, network reconnaissance, and exploit development, harnessing AI capabilities via Model Context Protocol (MCP) integration. It features an extensive toolkit of 91 security tools, enhanced by a full MITM proxy with advanced fingerprinting for obfuscation, facilitating efficient vulnerability research and response automation. The platform aims to streamline the process of identifying and addressing security issues, making it a powerful asset for security professionals.

Z3r0

2026-08-03 Python ★ 678
Z3r0 is an open-source red team collaboration workbench designed for authorized penetration testing, vulnerability discovery, and security research. It integrates a React-based console with a FastAPI management layer, allowing users to coordinate multi-Agent sessions, track project-specific evidence, and manage sandbox environments and controlled egress efficiently. Notable features include comprehensive evidence management, detailed workflow tracking, and a session timeline that enhances operational transparency and collaboration among red team participants.

ziran

2026-08-03 Python ★ 10
ZIRAN is a comprehensive security testing framework designed to identify vulnerabilities in AI agents, including those with complex capabilities such as tool usage and memory. By modeling agents as graphs of capabilities, it effectively discovers dangerous tool chains, detects execution-level side effects, and conducts adaptive multi-phase campaigns, surpassing the capabilities of single-prompt scanners. Notable features include graph-based analysis, tool-chain discovery, and thorough coverage of established security benchmarks like OWASP and MITRE.

Claude-BugHunter

2026-08-03 Python ★ 3936
Claude-BugHunter is a comprehensive skill bundle for the Claude Code system, designed to enhance bug-hunting and red-team operations with 82 curated skills and 15 commands. It features a structured approach to vulnerability detection, engagement scaffolding, and automated reporting, drawing from a vast collection of 681 disclosed report patterns across 24 core vulnerability classes. Notably, it integrates with Burp MCP and provides enterprise identity and infrastructure attack matrices for sophisticated security assessments.

cvemapping

2026-08-03 Python ★ 139
The cvemapping tool aggregates CVE exploit data from GitHub, allowing users to clone repositories or export CVE information in JSON format for web use. It features options for pagination and year-specific searches, making it versatile for both developers and security researchers aiming to analyze or present CVE-related data efficiently. Notable features include the ability to authenticate using a GitHub token and the straightforward export functionality for integration with web applications.

cywise

2026-08-03 PHP ★ 20
Cywise is a cybersecurity solution designed for both on-premises and SaaS environments, enabling users to scan and secure their web-facing and internal infrastructures. It features a robust vulnerability scanner that monitors for over 50,000 vulnerabilities with automated remediation, alongside active data leak monitoring and intelligent honeypots to detect and analyze potential threats. This tool is particularly suitable for small to medium-sized enterprises looking to enforce comprehensive security measures while maintaining control over their data and infrastructure.

gcpwn

2026-08-03 Python ★ 309
GCPwn is a framework for conducting offensive security assessments on Google Cloud environments, facilitating credential handling, service enumeration, and attack-path analysis through graph-based outputs. It supports workflows for reconnaissance, exploitation, and data collection, allowing users to execute predefined exploitation modules and export findings in various formats. Notable features include extensive API behavior tracking, IAM analysis, and the ability to generate OpenGraph outputs for privilege escalation reviews.

LinEnum-ng

2026-08-03 Shell ★ 18
LinEnum-ng is a targeted, stable enumeration script designed for Linux privilege escalation, particularly suited for OSCP examinations. Its notable features include kernel CVE detection for various exploits, comprehensive checks for SUID and sudo vulnerabilities with GTFOBins integration, as well as support for container escape assessments in Docker and Kubernetes environments. The output is structured and color-coded for efficient triaging, minimizing information overload.

missing-cve-nuclei-templates

2026-08-03 Shell ★ 446
The "missing-cve-nuclei-templates" tool automates the identification and cataloging of missing CVEs in the official Nuclei templates repository, analyzing over 164,000 CVEs to produce a comprehensive list of 65,840 missing entries. It categorizes vulnerabilities by type and year, offering detailed data files for specific threats such as XSS, RCE, SQL Injection, and more, enhancing vulnerability management and template development for cybersecurity professionals. This tool facilitates better detection capabilities by flagging gaps in existing Nuclei templates.

pSlip

2026-08-03 Python ★ 27
pSlip is a comprehensive security scanning tool for Android applications, designed to detect cryptographic vulnerabilities, OAuth implementations, and manifest issues using a streamlined HTML reporting engine. Its notable features include a powerful searchable HTML report leveraging a field-scoped query language, structured extraction and export of recovered key material and secrets, and a user-friendly interface that supports rapid identification of findings without requiring Java dependencies. The tool optimizes scanning performance and minimizes false positives, enhancing the efficiency of mobile application security assessments.

SecTools

2026-08-03 Python ★ 31
SecTools is a comprehensive repository of curated open-source and public tools designed for various cybersecurity applications, including OSINT, vulnerability analysis, and application security testing (SAST/DAST). It offers a user-friendly table that categorizes tools with their descriptions, licenses, and activity indicators, facilitating streamlined access to resources for security workflows. Notable features include a focus on UNIX compatibility and an organized structure that enhances usability across multiple security domains.

vulnrepo

2026-08-03 TypeScript ★ 577
VULNRΞPO is a client-side vulnerability report manager designed for security professionals, enabling users to generate, store, and manage vulnerability reports locally with a focus on privacy. The tool features client-side encryption, customizable issue templates for various security frameworks, and supports imports from multiple scanners, along with diverse export formats such as PDF and DOCX. Notable capabilities include integrated methodology tools, automated versioning, and optional backend storage via API for enhanced reporting functionalities.

Zen-Ai-Pentest

2026-08-03 Python ★ 446
Zen-AI-Pentest is an AI-powered penetration testing framework designed for security professionals and red teams, leveraging advanced language models alongside over 72 integrated security tools. Its notable features include a user-friendly dashboard, REST API, and modular agent system for tasks like reconnaissance, exploitation, and reporting, as well as compliance mapping and risk scoring functionalities for thorough assessments.

Dark-Moon

2026-08-03 Python ★ 880
DarkMoon is an open-source, AI-powered autonomous penetration testing platform designed to conduct end-to-end security assessments without manual intervention. Notable features include a privacy gateway that ensures sensitive data remains secure, integration with over 50 pen-testing tools, and automated vulnerability reporting. This tool is particularly advantageous for security teams and DevSecOps engineers seeking to streamline and scale their defensive operations while maintaining strict data sovereignty.

emba

2026-08-03 Shell ★ 3619
EMBA is a comprehensive security analyzer specifically designed for the firmware of embedded devices, catering to penetration testers, product security teams, and developers. The tool facilitates the entire security analysis workflow, including firmware extraction, static and dynamic analysis through emulation, SBOM generation, and the creation of web-based vulnerability reports, effectively identifying potential weaknesses such as insecure components or hard-coded passwords. Its command-line interface and ability to present findings in an accessible web format enhance usability and streamline the security assessment process.

kasld

2026-08-03 C ★ 521
KASLD is a tool designed to recover the Linux kernel's virtual and physical memory layout, specifically the kernel text base, from a local process by leveraging various system evidence and architectural invariants. Its primary use case is kernel Address Space Layout Randomization (KASLR) derandomization, which allows users to infer potential kernel text placements even in hardened environments. Notable features include support for multiple architectures, an inference engine that fuses evidence from various techniques, and the ability to report the upper bounds of KASLR protection based on the collected data.

OpenEASD

2026-08-03 Python ★ 24
OpenEASD is an open-source external attack surface discovery (EASD) tool designed for red teamers and defenders, enabling users to rapidly map and assess external surfaces of authorized targets without the expense of commercial solutions. It integrates multiple recon tools—such as `subfinder`, `amass`, and `nmap`—into a single web interface, offering features like scheduling, alerts, and findings tracking, while ensuring results remain local to the user's infrastructure. This self-hosted platform emphasizes transparency and security through careful sourcing of its components and is aimed at small security teams, consultancies, and individual security learners.

promptfoo

2026-08-03 TypeScript ★ 24697
Promptfoo is a command-line interface (CLI) and library designed for evaluating and red-teaming large language model (LLM) applications. Its primary use case involves automated testing of prompts, vulnerability scanning, and model comparison, enabling developers to enhance security and reliability in their AI applications while running evaluations locally without exposing data. Notable features include integration with CI/CD workflows, comprehensive security reporting, and support for multiple LLM providers, allowing for a developer-centric, flexible, and data-driven approach to AI application development.

rcekit

2026-08-03 Python ★ 13
RCEKit is a Python-based toolkit designed for the detection and confirmation of remote code execution (RCE) vulnerabilities, specifically for authorized penetration testing and security research. It provides a robust CLI interface to assess targets by employing multiple verification methods against real-world CVEs, generating definitive "confirmed" verdicts that can be utilized in security reports. Noteworthy features include support for various RCE classes, an easy-to-use setup without third-party dependencies, and the ability to produce evidence-based results, ensuring accurate detection rather than mere conjecture.

adbwebkit

2026-03-30 JavaScript ★ 765
ADB WebKit is a browser-based tool designed for managing Android devices via ADB (Android Debug Bridge) with an intuitive user interface. Its primary use case includes functionalities like application management (installing, uninstalling, granting permissions), shell access, screen capture, and device control commands, making it a comprehensive solution for developers and testers. Notable features include support for live application management, real-time screen interactions, and various device control options, all accessible through a USB connection or IP address.

Android-Security-Exploits-YouTube-Curriculum

2026-03-30 ★ 801
The Android Security & Reverse Engineering YouTube Curriculum is a comprehensive educational resource focused on various aspects of Android security, including exploits, reverse engineering, and vulnerabilities in mobile applications. It features a curated collection of talks and demonstrations from prominent security conferences, addressing topics like heap exploitation, mobile permissions, and countermeasures against mobile threats. Notably, it educates on advanced concepts such as Bluetooth security, malware analysis, and attack vectors affecting the Android ecosystem, making it essential for cybersecurity practitioners and researchers.

Bashark

2026-03-30 Shell ★ 753
Bashark 2.0 is a post-exploitation toolkit designed for penetration testers and security researchers to facilitate operations during the post-exploitation phase of security audits. It offers a simple command-line interface, where users can source the bashark.sh script to access various functions and commands, streamlining the process of managing compromised hosts. Key features include ease of use through a help menu and support for Bash scripting, making it a practical tool for enhancing post-exploitation activities.

ctf-skills

2026-03-30 Python ★ 3145
The ctf-skills repository provides an extensive collection of agent skills designed to facilitate the solving of Capture The Flag (CTF) challenges across various domains, including web exploitation, binary pwn, reverse engineering, and more. Notable features include support for multiple installation methods, a comprehensive tool installer script, and detailed skill documentation for on-demand use, allowing users to efficiently integrate the necessary tools as challenges arise. It is compatible with any tool adhering to the Agent Skills specification, enhancing its versatility in competitive cybersecurity contexts.

DllShimmer

2026-03-30 Go ★ 728
DllShimmer is a tool designed to facilitate DLL hijacking by allowing users to backdoor any function in a DLL without disrupting the normal operation of the host program. It generates proxy DLLs through a boilerplate C++ file and a corresponding .def file, ensuring that all exported functions maintain their original names and ordinal numbers, thus avoiding detection. Key features include support for both dynamic and static linking, the option to prevent multiple executions of the backdoor, and comprehensive debug logging capabilities.

GobyVuls

2026-03-30 Go ★ 748
GobyVuls is a collection of exploitation scripts specifically designed for vulnerabilities identified by the Goby scanning tool. The primary use case is to facilitate the exploitation of detected vulnerabilities, allowing users to perform actions such as command execution or establishing reverse shells. Notable features include a user-friendly interface for scanning and verification, as well as a collaborative framework for contributing new vulnerabilities and enhancing existing exploitation methods.

Heroinn

2026-03-30 Rust ★ 712
Heroinn is a cross-platform command-and-control (C2) and post-exploitation framework developed in Rust, designed primarily for research and educational purposes. Notable features include a graphical user interface (GUI), an interactive PTY shell, system information collection, file management with support for large files and resuming broken transfers, and compatibility with multiple operating systems including Windows, Linux, BSD, and macOS, leveraging various communication protocols such as TCP, HTTP, and reliable UDP.

kernelpwn

2026-03-30 C ★ 708
The kernelpwn repository serves as a comprehensive resource for Capture The Flag (CTF) challenges focused on kernel exploitation, providing both challenge write-ups and educational material for beginners in the field. It features a collection of solved kernel-pwn challenges with detailed write-ups, covering various complex exploitation techniques such as SMEP, SMAP, KPTI, and KASLR bypasses. Notable features include a focus on both kernel and non-userland vulnerabilities, as well as an invitation for community contributions to enhance the repository’s challenge offerings.

killshot

2026-03-30 Ruby ★ 781
KillShot is a comprehensive penetration testing framework designed for information gathering and website vulnerability scanning. Its primary use case involves automating data collection through integrated tools such as WhatWeb and Nmap, while offering features like a CMS Exploit Scanner and web application vulnerability assessments, including XSS and SQL injection detection. The framework also facilitates backdoor generation and includes a fuzzer, making it a versatile tool for security professionals.

lisa.py

2026-03-30 Python ★ 743
lisa.py is a Model-Context Protocol (MCP) integration for LLDB, enabling AI assistants like Claude to interact with debugging sessions through a structured interface. It consists of a server component to handle communication and a plugin for LLDB that exposes debugging functionalities via JSON-RPC, allowing users to execute commands verbally and enhance the debugging experience with natural language processing. Notable features include the capability to create targets, manage breakpoints, control process execution, and evaluate expressions directly from the AI assistant.

PHP-Antimalware-Scanner

2026-03-30 PHP ★ 780
PHP Antimalware Scanner is a PHP-based tool designed to scan projects for malicious code embedded within PHP files. Its primary use case is to detect potential malware through an interactive console interface or in a reporting mode that generates results in HTML or text. Notable features include customizable scanning options for file paths, action prompts upon detection of malware, and compatibility with various PHP configurations.

quark-engine

2026-03-30 Python ★ 1713
Quark Engine is a comprehensive tool designed for malware family analysis and vulnerability assessment, particularly in the context of Android malware. Its primary use case involves identifying and reporting on various malware behaviors and signatures, enabling security researchers to assess risks and improve defenses. Notable features include detailed analysis reports, a rule-based scoring system for malware, and compatibility with Python 3.10, making it accessible for developers and cybersecurity professionals.

ReconPi

2026-03-30 Shell ★ 727
ReconPi is a lightweight reconnaissance tool designed for extensive domain analysis and asset discovery using a Raspberry Pi or a VPS. Its primary functionality includes resolving domain names, subdomain enumeration, vulnerability scanning using Nmap, and integrating tools like Nuclei for template-based security assessments. Notable features include automated reporting, Slack notifications, and easy installation through a straightforward script, making it accessible for cyber reconnaissance tasks.

ronin

2026-03-30 Ruby ★ 756
Ronin is an open-source Ruby toolkit designed for security research and development, featuring a comprehensive suite of CLI commands and libraries tailored for various security tasks such as data encoding/decoding, vulnerability scanning, fuzzing, and reconnaissance. Notable features include a fully-loaded Ruby REPL, a lightweight web UI for database interaction, and the ability to install and run third-party exploits or payloads. This tool is primarily used by security researchers, bug bounty hunters, and developers for efficient data processing and rapid script prototyping.

THC-Archive

2026-03-30 HTML ★ 771
THC-Archive is a repository that consolidates all releases from The Hacker’s Choice, a prominent security research group. This collection serves as a backup for their work, ensuring that projects are preserved despite the lack of a full web server. Notable active projects include THC-Hydra, THC-IPv6, and utilities aimed at various hacking and security tasks.

TOP

2026-03-30 Shell ★ 732
TOP is a vulnerability cataloging tool designed for bug bounty hunters and penetration testers, focusing on proof-of-concept (PoC) exploits for various Common Vulnerabilities and Exposures (CVEs) from recent years. It compiles a list of notable CVEs along with their respective exploits and corresponding GitHub repositories, thereby facilitating ease of access and research for security professionals. Key features include organized yearly summaries of significant vulnerabilities, making it an essential resource for monitoring and exploiting security weaknesses.

Vegile

2026-03-30 Shell ★ 753
Vegile is a post-exploitation tool designed for maintaining stealthy backdoor/rootkit access on Linux systems. Its primary use case involves establishing persistent access to compromised hosts while enabling features such as process hiding and session unlimited capabilities in Metasploit. Notable functionalities include the ability to automatically restart hidden processes, ensuring persistent access even after termination, and support for various backdoor implementations, including those created with msfvenom.

vivisect

2026-03-30 Python ★ 1000
Vivisect is a versatile framework that integrates disassembly, static analysis, symbolic execution, and debugging capabilities, designed for use in cybersecurity tasks. Its primary use case is to facilitate in-depth analysis of binary executables, assisting researchers and security professionals in vulnerability discovery and exploitation analysis. Notable features include Python 3 compatibility, a graphical user interface, and seamless integration with documentation for enhanced usability.

VMkatz

2026-03-30 Rust ★ 1508
VMkatz is a cybersecurity tool designed to extract Windows credentials and secrets directly from virtual machine memory snapshots and disk images without the need for full exfiltration. It supports various input formats, including VMware snapshots and VirtualBox saved states, allowing efficient retrieval of sensitive data such as NTLM hashes, DPAPI master keys, and Kerberos tickets directly from the hypervisor or NAS. Notably, VMkatz operates as a single static binary, requiring minimal setup and enabling rapid credential access in red team engagements.

vulhunt

2026-03-30 C++ ★ 881
VulHunt is a vulnerability hunting framework aimed at assisting security researchers in identifying vulnerabilities within software binaries and UEFI firmware. Built on Binarly’s BIAS, it supports large-scale vulnerability management and integrates community-developed rulepacks while offering scanning capabilities for various binary formats, including BA2 and Binary Ninja databases. Additionally, it features an MCP server for integration with AI assistants, facilitating real-time vulnerability analysis and reporting.

Web_Hacking

2026-03-30 ★ 806
Web Hacking is a comprehensive repository of notes focused on bug bounty hunting and penetration testing, collating various techniques for vulnerability discovery and exploitation. The tool features extensive reconnaissance and OSINT methods, a detailed list of common vulnerabilities, and bypass techniques, making it a valuable resource for security professionals seeking to enhance their skills and methodologies in web application security. Additionally, it encourages community contributions, fostering continuous improvement and updates of its content.

0day

2026-03-22 C ★ 2350
各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新

A-Red-Teamer-diaries

2026-03-22 ★ 1933
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

Active-Directory-Exploitation-Cheat-Sheet

2026-03-22 PowerShell ★ 2762
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Active-Directory-Exploitation-Cheat-Sheet

2026-03-22 ★ 6722
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

afrog

2026-03-22 Go ★ 4375
A Security Tool for Bug Bounty, Pentest and Red Teaming.

AI-Infra-Guard

2026-03-22 Python ★ 6090
A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

ambiguous-png-packer

2026-03-22 Python ★ 1061
Craft PNG files that appear completely different in Apple software [NOW PATCHED]

Android-Exploits

2026-03-22 HTML ★ 972
A collection of android Exploits and Hacks

AndroRAT

2026-03-22 Java ★ 4658
A Simple android remote administration tool using sockets. It uses java on the client side and python on the server side

AndroRAT

2026-03-22 Java ★ 1583
AndroRAT | Remote Administrator Tool for Android OS Hacking

AntiCheat-Testing-Framework

2026-03-22 C++ ★ 821
Framework to test any Anti-Cheat

apple-knowledge

2026-03-22 Ruby ★ 1382
A collection of reverse engineered Apple things, as well as a machine-readable database of Apple hardware

APT_REPORT

2026-03-22 Python ★ 3086
Interesting APT Report Collection And Some Special IOCs

archerysec

2026-03-22 JavaScript ★ 2445
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Artemis

2026-03-22 Python ★ 1201
A modular vulnerability scanner with automatic report generation capabilities.

AutoPentestX

2026-03-22 Python ★ 1033
AutoPentestX – Automated Pentesting & Vulnerability Reporting Tool

AutoPWN-Suite

2026-03-22 Python ★ 1094
AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

AutoSploit

2026-03-22 Python ★ 5221
Automated Mass Exploiter

awesome-aws-security

2026-03-22 ★ 1533
Curated list of links, references, books videos, tutorials (Free or Paid), Exploit, CTFs, Hacking Practices etc. which are related to AWS Security

awesome-hacker-search-engines

2026-03-22 Shell ★ 11108
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Awesome-Hacking-Resources

2026-03-22 ★ 17364
A collection of hacking / penetration testing resources to make you better!

awesome-list

2026-03-22 ★ 4081
Cybersecurity oriented awesome list

awesome-list-of-secrets-in-environment-variables

2026-03-22 ★ 902
🦄🔒 Awesome list of secrets in environment variables 🖥️

Awesome-RCE-techniques

2026-03-22 Dockerfile ★ 1941
Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

Awesome-Redteam

2026-03-22 Python ★ 4320
一个攻防知识库。A knowledge base for red teaming and offensive security.

awesome-web-hacking

2026-03-22 ★ 7251
A list of web application security

BinAbsInspector

2026-03-22 Java ★ 1673
BinAbsInspector: Vulnerability Scanner for Binaries

BlackFriday-GPTs-Prompts

2026-03-22 ★ 9707
List of free GPTs that doesn't require plus subscription

BlackWidow

2026-03-22 Python ★ 1782
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

BlueTeam-Tools

2026-03-22 ★ 3976
Tools and Techniques for Blue Team / Incident Response

brakeman

2026-03-22 Ruby ★ 7262
A static analysis security vulnerability scanner for Ruby on Rails applications

Bug-Bounty-Methodology

2026-03-22 HTML ★ 890
These are my checklists which I use during my hunting.

Burp-Suite-Certified-Practitioner-Exam-Study

2026-03-22 Python ★ 1465
Burp Suite Certified Practitioner Exam Study

BurpBounty

2026-03-22 Java ★ 1812
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.

ByePg

2026-03-22 C++ ★ 903
Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.

CDK

2026-03-22 Go ★ 4741
📦 Make security testing of K8s, Docker, and Containerd easier.

claude-bug-bounty

2026-03-22 Python ★ 4390
Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation

commix

2026-03-22 Python ★ 5832
Automated All-in-One OS Command Injection Exploitation Tool

copacetic

2026-03-22 Go ★ 1703
🧵 CLI tool for directly patching container images!

Corsy

2026-03-22 Python ★ 1535
CORS Misconfiguration Scanner

crawlergo

2026-03-22 Go ★ 3038
A powerful browser crawler for web vulnerability scanners

crlfuzz

2026-03-22 Go ★ 1560
A fast tool to scan CRLF vulnerability written in Go

CTF

2026-03-22 Python ★ 2548
CTF challenge (mostly pwn) files, scripts etc

CTF-All-In-One

2026-03-22 C ★ 4449
CTF竞赛权威指南

CTFs

2026-03-22 C ★ 851
CTF Cheat Sheet + Writeups / Files for some of the Cyber CTFs that I've done

cve

2026-03-22 HTML ★ 8032
Gather and update all available and newest CVEs with their PoC.

CVE-2020-0796

2026-03-22 C ★ 1351
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost

CVE-2021-44228-PoC-log4j-bypass-words

2026-03-22 Java ★ 950
🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

CVE-2023-38831-winrar-exploit

2026-03-22 Python ★ 788
CVE-2023-38831 winrar exploit generator

CVE-2024-1086

2026-03-22 C ★ 2439
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.

cve-bin-tool

2026-03-22 Python ★ 1754
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

DDOS-RootSec

2026-03-22 C ★ 1005
Explore RootSec's DDOS Archive, featuring top-tier scanners, powerful botnets (Mirai & QBot) and other variants, high-impact exploits, advanced methods, and efficient sniffers. Ideal for cybersecurity professionals and researchers.

DeauthDetector

2026-03-22 C++ ★ 928
Detect deauthentication frames using an ESP8266

DedSec

2026-03-22 Python ★ 1005
Unofficial DedSec Project GitHub Repository

DeepAudit

2026-03-22 Python ★ 5381
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

deepce

2026-03-22 Shell ★ 1567
Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

DefaultCreds-cheat-sheet

2026-03-22 Python ★ 6727
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

DeimosC2

2026-03-22 Vue ★ 1152
DeimosC2 is a Golang command and control framework for post-exploitation.

dep-scan

2026-03-22 Python ★ 1280
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

device-activity-tracker

2026-03-22 TypeScript ★ 5103
A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive device-activity patterns. (WhatsApp / Signal)

diodb

2026-03-22 Python ★ 1079
Open-source vulnerability disclosure and bug bounty program database

dockle

2026-03-22 Go ★ 3287
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start

DogeRat

2026-03-22 ★ 2005
A multifunctional Telegram based Android RAT without port forwarding.

EggShell

2026-03-22 Objective-C ★ 1743
iOS/macOS/Linux Remote Administration Tool

EvilOSX

2026-03-22 Python ★ 2416
An evil RAT (Remote Administration Tool) for macOS / OS X.

exphub

2026-03-22 Python ★ 4274
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340

exploitnotes

2026-03-22 HTML ★ 814
A security research site.

faraday

2026-03-22 Python ★ 6699
Open Source Vulnerability Management Platform

featherduster

2026-03-22 Python ★ 1119
An automated, modular cryptanalysis tool; i.e., a Weapon of Math Destruction

Forensia

2026-03-22 C++ ★ 787
Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase.

Frida-Labs

2026-03-22 ★ 1235
The repo contains a series of challenges for learning Frida for Android Exploitation.

fscan

2026-03-22 Go ★ 14479
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

fsociety

2026-03-22 Python ★ 12284
fsociety Hacking Tools Pack – A Penetration Testing Framework

fuxploider

2026-03-22 Python ★ 3330
File upload vulnerability scanner and exploitation tool.

fuzzforge_ai

2026-03-22 Python ★ 770
AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulnerability discovery with intelligent fuzzing, AI-driven analysis, and a marketplace of security tools.

Galaxy-Bugbounty-Checklist

2026-03-22 ★ 1775
Tips and Tutorials for Bug Bounty and also Penetration Tests.

Garud

2026-03-22 Shell ★ 812
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

GDA-android-reversing-Tool

2026-03-22 Java ★ 4687
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.

Ghost

2026-03-22 Python ★ 3399
Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.

go-shellcode

2026-03-22 Go ★ 767
Load shellcode into a new process

Goby

2026-03-22 ★ 1500
Attack surface mapping

GourdScanV2

2026-03-22 Python ★ 873
被动式漏洞扫描系统

GScan

2026-03-22 Python ★ 2809
本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。

GTFOBins.github.io

2026-03-22 YAML ★ 13602
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

h-encore

2026-03-22 C ★ 1104
Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68

hack-tools

2026-03-22 Python ★ 1184
hack tools

hacking-resources

2026-03-22 ★ 2411
Hacking resources and cheat sheets. References, tools, scripts, tutorials, and other resources that help offensive and defensive security professionals.

Hacking-Tools

2026-03-22 ★ 1297
A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other notable sources.

HackVault

2026-03-22 JavaScript ★ 2020
A container repository for my public web hacks!

heap-viewer

2026-03-22 Python ★ 769
IDA Pro plugin to examine the glibc heap, focused on exploit development

herpaderping

2026-03-22 C++ ★ 1188
Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.

hexstrike-ai

2026-03-22 Python ★ 11464
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

htshells

2026-03-22 Shell ★ 1074
Self contained htaccess shells and attacks

Information_Collection_Handbook

2026-03-22 ★ 830
Handbook of information collection for penetration testing and src

Infosec_Reference

2026-03-22 CSS ★ 5988
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

inql

2026-03-22 Kotlin ★ 1745
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

IoT-vulhub

2026-03-22 Python ★ 1271
IoT固件漏洞复现环境

jexboss

2026-03-22 Python ★ 2516
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

JNDI-Injection-Exploit-Plus

2026-03-22 Java ★ 871
80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

jok3r

2026-03-22 HTML ★ 1077
Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework

joomscan

2026-03-22 Raku ★ 1176
OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/

K8CScan

2026-03-22 Python ★ 1301
K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动

K8tools

2026-03-22 PowerShell ★ 6206
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

kernel-exploits

2026-03-22 C ★ 1584
My proof-of-concept exploits for the Linux kernel

kernel-exploits

2026-03-22 C ★ 804
Various kernel exploits

Keylogger

2026-03-22 C++ ★ 974
Keylogger is 100% invisible keylogger not only for users, but also undetectable by antivirus software. keylogger Monitors all keystokes, Mouse clicks. It has a seperate process which continues capture system screenshot and send to ftp server in given time.

kics

2026-03-22 Open Policy Agent ★ 2698
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

kscan

2026-03-22 Go ★ 4257
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。

KubeHound

2026-03-22 Go ★ 994
Tool for building Kubernetes attack paths

labs

2026-03-22 Python ★ 1170
Vulnerability Labs for security analysis

Ladon

2026-03-22 C# ★ 5272
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange

LadonGo

2026-03-22 Go ★ 1705
Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBanner/HttpTitle/TcpBanner/Weblogic/Oxid多网卡主机,端口扫描服务识别PortScan。

libc-database

2026-03-22 Shell ★ 1870
Build a database of libc offsets to simplify exploitation

ligolo-ng

2026-03-22 Go ★ 4901
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

like-dbg

2026-03-22 Python ★ 772
Fully dockerized Linux kernel debugging environment

linux-exploit-suggester

2026-03-22 Shell ★ 6597
Linux privilege escalation auditing tool

linux-kernel-exploitation

2026-03-22 ★ 6620
A collection of links related to Linux kernel security and exploitation

linux-kernel-exploits

2026-03-22 C ★ 5588
linux-kernel-exploits Linux平台提权漏洞集合

linWinPwn

2026-03-22 Shell ★ 2201
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

lonkero

2026-03-22 Rust ★ 1049
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

lunasec

2026-03-22 TypeScript ★ 1468
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

lynis

2026-03-22 Shell ★ 16137
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

malwoverview

2026-03-22 Python ★ 4070
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

mantis

2026-03-22 Python ★ 1021
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.

Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes

2026-03-22 ★ 1843
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.

metarget

2026-03-22 Python ★ 1415
Metarget is a framework providing automatic constructions of vulnerable infrastructures.

mimipenguin

2026-03-22 C ★ 4158
A tool to dump the login password from the current linux user

moonwalk

2026-03-22 Rust ★ 1490
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.

mssqlproxy

2026-03-22 Python ★ 775
mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Nettacker

2026-03-22 Python ★ 5545
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Nginx-Lua-Anti-DDoS

2026-03-22 Lua ★ 1631
A Anti-DDoS script to protect Nginx web servers using Lua with a HTML Javascript based authentication puzzle inspired by Cloudflare I am under attack mode an Anti-DDoS authentication page protect yourself from every attack type All Layer 7 Attacks Mitigating Historic Attacks DoS DoS Implications DDoS All Brute Force Attacks Zero day exploits Social Engineering Rainbow Tables Password Cracking Tools Password Lists Dictionary Attacks Time Delay Any Hosting Provider Any CMS or Custom Website Unlimited Attempt Frequency Search Attacks HTTP Basic Authentication HTTP Digest Authentication HTML Form Based Authentication Mask Attacks Rule-Based Search Attacks Combinator Attacks Botnet Attacks Unauthorized IPs IP Whitelisting Bruter THC Hydra John the Ripper Brutus Ophcrack unauthorized logins Injection Broken Authentication and Session Management Sensitive Data Exposure XML External Entities (XXE) Broken Access Control Security Misconfiguration Cross-Site Scripting (XSS) Insecure Deserialization Using Components with Known Vulnerabilities Insufficient Logging & Monitoring Drupal WordPress Joomla Flash Magento PHP Plone WHMCS Atlassian Products malicious traffic Adult video script avs KV...

nocom-explanation

2026-03-22 ★ 843
block game military grade radar

NoSQLMap

2026-03-22 Python ★ 3346
Automated NoSQL database enumeration and web application exploitation tool.

npq

2026-03-22 JavaScript ★ 1790
safely install npm packages by auditing them pre-install stage

nuclei_poc

2026-03-22 ★ 1992
Nuclei POC,每2小时更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现。已有41w+POC,其中3.5w+高质量POC

nuclei-wordfence-cve

2026-03-22 Python ★ 1278
70k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

oFx

2026-03-22 Python ★ 903
一个开源的、开箱即用的漏洞批量验证框架

one_gadget

2026-03-22 Ruby ★ 2346
The best tool for finding one gadget RCE in libc.so.6

Open-Source-Security-Guide

2026-03-22 Go ★ 1104
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

opencve

2026-03-22 Python ★ 2809
Vulnerability Intelligence Platform

OSCP

2026-03-22 Python ★ 959
Collection of things made during my OSCP journey

ossa

2026-03-22 ★ 943
Open-Source Security Architecture | 开源安全架构

osv-scanner

2026-03-22 Go ★ 10948
Vulnerability scanner written in Go which uses the data provided by https://osv.dev

osv.dev

2026-03-22 Go ★ 2903
Open source vulnerability DB and triage service.

OWASP-Web-Checklist

2026-03-22 ★ 2106
OWASP Web Application Security Testing Checklist

Penetration_Testing_POC

2026-03-22 HTML ★ 7479
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

penetration-testing-cheat-sheet

2026-03-22 PHP ★ 842
Work in progress...

Penetration-Testing-Tools

2026-03-22 PowerShell ★ 2915
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.

PentestTools

2026-03-22 ★ 1769
Awesome Pentest Tools Collection

Perun

2026-03-22 Python ★ 1055
Perun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架

PhoneSploit

2026-03-22 Python ★ 873
A tool for remote ADB exploitation in Python3 for all Machines.

PhoneSploit-Pro

2026-03-22 Python ★ 6147
An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.

phpsploit

2026-03-22 Python ★ 2492
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

PoC

2026-03-22 C++ ★ 828
Proofs-of-concept

POC-bomber

2026-03-22 Python ★ 2357
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

POC-T

2026-03-22 Python ★ 1952
渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework

PocOrExp_in_Github

2026-03-22 Python ★ 1197
Automatically Collect POC or EXP from GitHub by CVE ID.

pocsuite3

2026-03-22 Python ★ 3830
pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

Pompem

2026-03-22 Python ★ 1024
Find exploit tool

PowerHub

2026-03-22 PowerShell ★ 832
A post exploitation tool based on a web application, focusing on bypassing endpoint protection and application whitelisting

PrivEsc

2026-03-22 C ★ 985
A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.

PsMapExec

2026-03-22 PowerShell ★ 1171
Dominate Active Directory with PowerShell.

pwn_jenkins

2026-03-22 Python ★ 2089
Notes about attacking Jenkins servers

pwndbg

2026-03-22 Python ★ 10822
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

pwninit

2026-03-22 Rust ★ 1117
pwninit - automate starting binary exploit challenges

pythem

2026-03-22 Python ★ 1243
pentest framework

Raccoon

2026-03-22 Python ★ 4009
A high performance offensive security tool for reconnaissance and vulnerability scanning

randar-explanation

2026-03-22 Shell ★ 1023
"Randar" is an exploit for Minecraft which uses LLL lattice reduction to crack the internal state of an incorrectly reused java.util.Random in the Minecraft server, then works backwards from that to locate other players currently loaded into the world.

rapidscan

2026-03-22 Python ★ 2128
:new: The Multi-Tool Web Vulnerability Scanner.

reconmap

2026-03-22 JavaScript ★ 976
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.

redamon

2026-03-22 Python ★ 2370
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

reentrancy-attacks

2026-03-22 ★ 1624
A chronological and (hopefully) complete list of reentrancy attacks to date.

remote-method-guesser

2026-03-22 Java ★ 915
Java RMI Vulnerability Scanner

reverse-shell

2026-03-22 Go ★ 2058
Reverse Shell as a Service

RootMyTV.github.io

2026-03-22 HTML ★ 2409
RootMyTV is a user-friendly exploit for rooting/jailbreaking LG webOS smart TVs.

ROPgadget

2026-03-22 Python ★ 4392
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, and RISC-V Compressed architectures.

SatanSword

2026-03-22 Python ★ 1178
红队综合渗透框架

scan4all

2026-03-22 Go ★ 6171
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

Scanners-Box

2026-03-22 ★ 9023
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

ScopeSentry

2026-03-22 Go ★ 1595
ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

Sec-Tools

2026-03-22 Python ★ 844
🍉一款基于Python-Django的多功能Web安全渗透测试工具,包含漏洞扫描,端口扫描,指纹识别,目录扫描,旁站扫描,域名扫描等功能。

SecretScanner

2026-03-22 Go ★ 3274
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

sectemplates

2026-03-22 ★ 914
Open source templates you can use to bootstrap your security programs

Selenium-Driverless

2026-03-22 Python ★ 848
a stealthy browser automation framework

shad0w

2026-03-22 C ★ 2168
A post exploitation framework designed to operate covertly on heavily monitored environments

shannon

2026-03-22 TypeScript ★ 47370
Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

shellen

2026-03-22 Python ★ 909
:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

shortscan

2026-03-22 Go ★ 1132
An IIS short filename enumeration tool

sicat

2026-03-22 Python ★ 830
The useful exploit finder

SILENTTRINITY

2026-03-22 Boo ★ 2343
An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

Silver

2026-03-22 Python ★ 1047
Mass scan IPs for vulnerable services

Sn1per

2026-03-22 Shell ★ 11175
Attack Surface Management Platform

spectre-attack

2026-03-22 C ★ 772
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)

SpringBoot-Scan

2026-03-22 Python ★ 2247
针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具

sqlmap

2026-03-22 Python ★ 38321
Automatic SQL injection and database takeover tool

ssh-mitm

2026-03-22 Python ★ 1464
SSH-MITM - ssh audits made simple

stunner

2026-03-22 Go ★ 862
Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.

SUDO_KILLER

2026-03-22 Shell ★ 2482
A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.

TegraRcmGUI

2026-03-22 C++ ★ 2214
C++ GUI for TegraRcmSmash (Fusée Gelée exploit for Nintendo Switch)

Terrapin-Scanner

2026-03-22 Go ★ 996
This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation".

TIDoS-Framework

2026-03-22 Python ★ 1847
The Offensive Manual Web Application Penetration Testing Framework.

top25-parameter

2026-03-22 ★ 1848
For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

traitor

2026-03-22 Go ★ 7165
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

trivy-operator

2026-03-22 Go ★ 1932
Kubernetes-native security toolkit

V3n0M-Scanner

2026-03-22 Python ★ 1562
Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

venom

2026-03-22 Shell ★ 1961
venom - C2 shellcode generator/compiler/handler

Viper

2026-03-22 ★ 5284
Adversary simulation and Red teaming platform with AI

vulmap

2026-03-22 Python ★ 3505
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

vulnx

2026-03-22 Python ★ 2091
vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.

vulscan

2026-03-22 Lua ★ 3781
Advanced vulnerability scanning with Nmap NSE

w13scan

2026-03-22 Smarty ★ 1950
Passive Security Scanner (被动式安全扫描器)

WADComs.github.io

2026-03-22 HTML ★ 1715
WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.

wazuh

2026-03-22 C++ ★ 16732
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Web-Cache-Vulnerability-Scanner

2026-03-22 Go ★ 1201
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).

wesng

2026-03-22 Python ★ 4924
Windows Exploit Suggester - Next Generation

windows-kernel-exploits

2026-03-22 C ★ 8618
windows-kernel-exploits Windows平台提权漏洞集合

WinPwn

2026-03-22 PowerShell ★ 3695
Automation for internal Windows Penetrationtest / AD-Security

WPForce

2026-03-22 Python ★ 974
Wordpress Attack Suite

wpprobe

2026-03-22 Go ★ 938
A fast WordPress plugin enumeration tool

XAttacker

2026-03-22 Perl ★ 1758
X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

xhunter

2026-03-22 Shell ★ 915
Android Penetration Tool [ RAT for Android ]

xmir-patcher

2026-03-22 Python ★ 3422
Firmware patcher for Xiaomi routers

xray

2026-03-22 Vue ★ 11470
一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

xsser

2026-03-22 Python ★ 1462
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.

xunfeng

2026-03-22 Python ★ 3595
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

yakit

2026-03-22 TypeScript ★ 7710
Cyber Security ALL-IN-ONE Platform

ysoserial

2026-03-22 Java ★ 9036
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.