Pentesting
2026-08-31
C#
★ 17
Reecon is a lightweight network reconnaissance tool designed for early-stage network enumeration and information gathering. It features manual suggestions for various enumeration techniques, including HTTP/S and SMB, and operates as a standalone application with built-in components of the .NET Framework. Currently in development, it is not recommended for production use, and future enhancements are planned for broader functionality, such as improved DNS querying and service detection capabilities.
2026-08-31
Python
★ 171
CTFlearn-Writeups is a compilation of detailed solutions for various Capture The Flag challenges across multiple domains such as Cryptography, Forensics, and Web security. The tool serves as a reference for practitioners and enthusiasts looking to enhance their skills in cybersecurity challenge-solving. Notable features include categorized writeups that cover a range of problem types, providing structured insights into methodologies and techniques used in each challenge.
2026-08-31
Python
★ 115
**IKONA Security** is a comprehensive cybersecurity tool designed for research and auditing, featuring modules for penetration testing, bug bounty payloads, and security audits of various web frameworks such as Laravel and Next.js. Notable features include a collection of web exploitation payloads, curated wordlists for API endpoints and directory traversal, and both automated and manual bug hunting methodologies. This tool emphasizes responsible usage, intended strictly for educational and authorized testing purposes.
2026-08-31
Makefile
★ 10
SECS (SECurity aSsistant) is a framework that transforms compatible AI coding agents into authorized security assistants, equipped to aid in various security lifecycle tasks such as reconnaissance, pentesting, and incident response. It features a governance policy, 35 curated agent skills for expert security methodologies, and a local toolchain with a practice lab, ensuring that all activities adhere to strict rules of engagement and operate within a controlled environment. Notably, the system incorporates an authorization gate to validate targets and enforce compliance, making it suitable for authorized security testing and defensive operations only.
2026-08-31
Python
★ 10
PXEThiefUp is an advanced tool for extracting sensitive data from SCCM/MECM environments using PXE boot protocols, building upon the original PXEThief functionality with enhanced features. It supports automatic and manual targeting of PXE servers, various media formats for data extraction, and has capabilities for decrypting media files and organizing output, making it suitable for cybersecurity professionals engaged in network security assessments. Notable features include interface selection, folder scanning, basic password cracking, and compatibility with both Windows and Linux platforms.
2026-08-31
HTML
★ 18
VERDICT is an autonomous web and API penetration testing agent that employs AI to conduct vulnerability assessments, confirming findings through reproducible evidence. Its primary use case is for in-depth security evaluations, particularly in applications with complex authentication mechanisms, utilizing a real browser for accurate session handling and multi-step testing. Notable features include precise detection accuracy backed by recorded evidence, an ability to map and exploit unknown applications autonomously, and integration with tools like Burp, all while adhering strictly to defined testing scopes.
2026-08-30
Python
★ 104
Phantom is a multi-platform HTTP(S) reverse shell server and client implemented in Python 3, designed for securely establishing remote connections over HTTP or HTTPS. It features automatic certificate generation for HTTPS, bundled dependencies for seamless execution on Linux and Windows, and provides a user-friendly shell script for rapid certificate creation. The tool is tailored for penetration testing and remote administration scenarios, allowing quick setup and deployment for secure command execution.
2026-08-30
Python
★ 95
Simple-Async-Port-Scanner is a Python 3-based asynchronous TCP port scanner that utilizes the asyncio framework to efficiently connect to multiple ports on specified IP addresses within a user-defined timeout. It features a straightforward command-line interface for scanning specified ports, supports both IP addresses and domain names, and can filter results to display only open ports. This tool is particularly notable for its speed, capable of scanning the first 1000 TCP ports on a target in under two seconds, while maintaining minimal dependencies.
2026-08-30
Python
★ 10
CredStalker is a Python-based credential and sensitive data scanner that automatically crawls websites to identify exposed credentials, API keys, and other sensitive information. It features multi-type detection capabilities, deep content analysis of HTML and JavaScript, and customizable crawling with detailed reporting and export functionality for further analysis. Ideal for security audits and penetration testing, it also includes options for verbose logging and same-domain crawling to ensure scope compliance.
2026-08-30
TypeScript
★ 47
0sec is an open and extensible AI-driven cybersecurity tool that automates vulnerability discovery, exploitation, and remediation across various layers, including web applications, APIs, source code, and network infrastructure. It supports multi-model and multi-agent capabilities to address complex security challenges, emphasizes continuous security over point-in-time assessments, and includes a command-line interface for streamlined interactions and automation of pentesting workflows. Notable features include the ability to find a wide range of vulnerabilities, integration with various environments and systems, and a focus on supply chain security and other emerging threat vectors.
2026-08-30
Shell
★ 16
B1ackOS is a privacy-focused operating system based on Debian, designed to simplify software package installation while ensuring user security. Its notable features include a lightweight architecture, extensive application repositories for diverse use cases, a live operating capability, and a rolling release model that emphasizes stability and performance.
2026-08-30
Python
★ 24
jsrip is an advanced JavaScript analysis tool designed for bug bounty hunters and penetration testers, capable of crawling web applications to extract and analyze JavaScript files for security vulnerabilities, such as secrets and endpoints. It features a sophisticated detection mechanism that identifies over 1700 patterns related to various cloud services, maps API routes and internal paths, and generates detailed interactive reports in multiple formats. Notable functionalities include subdomain enumeration, false positive mitigation, and scoping for shared-hosting environments.
2026-08-29
Python
★ 16
EXC Analyzer is a command-line tool designed for advanced intelligence gathering, security auditing, and content analysis of GitHub repositories. It enables users to assess repository security, audit GitHub Actions workflows, and locate sensitive information through dork scanning, with features such as user profiling and smart rate limiting for efficient API management. Notable for its professional-grade capabilities, it's aimed at security researchers and penetration testers looking to derive actionable insights from repository data.
2026-08-28
Python
★ 10
r3ngine v3.7.4 is an advanced web reconnaissance and vulnerability scanning tool that facilitates comprehensive security assessments through its Target Report Generation feature, allowing users to generate detailed multi-scan PDF reports with historical vulnerability tracking. Key features include an Attack Path Modeling Engine aligned with MITRE ATT&CK, integration with WPScan/WPTaint for static analysis, and enhanced infrastructure for scalability and reliability using Django and PostgreSQL. This enterprise-grade platform is designed for thorough and efficient security analysis while ensuring operational security and ease of use.
2026-08-28
Python
★ 96
Tomcter is a Python-based tool designed for brute-forcing Apache Tomcat manager logins using default credentials. It supports targeting single or multiple instances, integrates with ProxyChains for enhanced anonymity, and is optimized for minimal resource usage. The tool is open-source and easily deployable via Docker, making it suitable for penetration testing scenarios.
2026-08-28
Python
★ 10
YAPP (Yet Another Pentest Parser) is a robust Python library and CLI tool designed to parse and process outputs from multiple penetration testing tools, including Nessus, Nmap, and BloodHound, into actionable results. Notable features include comprehensive multi-tool support, an extensible framework for adding new parsers, dual interface options (CLI and TUI), in-memory processing, and advanced Active Directory analysis capabilities without the need for a Neo4j server. This allows for efficient vulnerability management and streamlined workflows, aiding penetration testers in reducing processing time and improving overall productivity.
2026-08-28
Python
★ 10
csp-toolkit is a Python library and command-line interface designed for parsing, analyzing, generating, and identifying bypasses in Content Security Policy (CSP) headers. Primarily aimed at security researchers and bug bounty hunters, it features automated CSP generation through website crawling, policy analysis with 21 vulnerability checks, and the ability to find potential bypasses against a database of known exploit vectors. Notable functionalities include the ability to score CSPs, detect nonce reuse, batch scan URLs, and generate output in various formats such as JSON and SARIF for integration with CI/CD workflows.
2026-08-28
SCSS
★ 135
R3d-Buck3T is a comprehensive repository designed for penetration testing and red teaming activities, featuring an extensive collection of tools and commands across multiple security domains, including web application, cloud, network, and wireless security. Notable characteristics include detailed sections on Active Directory and vulnerability research, alongside a dedicated wiki for easy navigation and resource access. This tool serves as a vital asset for security professionals aiming to enhance their offensive security skills and methodologies.
2026-08-28
Rust
★ 19
Red Clippy is an open-source penetration testing management tool designed to integrate with AI agents for streamlined test engagements. It retains detailed records of assets, observations, and findings, ensuring that testing sessions can progress smoothly without loss of information, while enforcing protocols for data verification and reporting. Notable features include a web-based interface for managing test data, customizable engagement rules, and the ability to connect to AI agents for enhanced testing efficiency.
2026-08-28
Rust
★ 39
Stratum C2 is a cloud persistence framework designed to maintain command-and-control (C2) communication through trusted cloud storage providers like Dropbox and OneDrive, thus avoiding detection by traditional security defenses. Its notable features include end-to-end encryption with RSA and AES, the ability to switch between multiple cloud providers seamlessly, and a structurally unblockable channel that makes it difficult for security operations centers to intercept. The framework supports multiple agent formats for both Windows and Linux without requiring additional dependencies.
2026-08-27
★ 274
BugTraceAI is an open-source, self-hosted framework designed for autonomous bug bounty hunting and penetration testing. Utilizing AI agents, it intelligently discovers, analyzes, exploits, and validates vulnerabilities without requiring manual intervention, ensuring a privacy-first approach with no telemetric data collection. The platform allows modular component use, easy deployment via Docker, and emphasizes educating users on its tools for authorized security testing.
2026-08-27
JavaScript
★ 10
ObuscatedBOT is a multi-functional Telegram bot designed for performing instant network scans and providing security insights, aimed at ethical hackers and security enthusiasts. Key features include real-time alerts for suspicious activity, comprehensive vulnerability reports, and a user-friendly interface within the Telegram platform, facilitating easy navigation and interaction.
2026-08-27
Shell
★ 12
Hermes Cybersecurity Lab is a comprehensive cybersecurity toolkit designed for the Hermes Agent, encompassing 2,077 skills, 131+ tools, and 28 frameworks, systematically organized across multiple repositories. Its primary use case includes security research, pentesting, forensics, and threat intelligence, with notable features like a preconfigured installation script, tool inventory awareness, and a structured methodology for tackling various phases of cybersecurity engagements. This ecosystem ensures continuous updates and knowledge accumulation, enhancing both operational efficiency and effectiveness in security practices.
2026-08-27
★ 16
Awesome Security Agent Harnesses provides a collection of AI-driven tools designed for penetration testing, code auditing, fuzzing, vulnerability discovery, and reverse engineering. The primary use case is to enhance security assessments through a variety of harnesses, sandboxes, and evaluation frameworks that streamline the detection and validation of vulnerabilities while minimizing false positives. Notable features include multi-agent collaboration, independent validation of findings, and integration with various coding agent methodologies to automate and enhance security processes.
2026-08-27
★ 36
Default-Creds is a community-driven database that provides a collection of factory-set credentials in plain YAML format, aimed at penetration testers and security researchers. Its primary use case is to assist in identifying weak access points during security audits or tests, thereby helping secure systems from potential exploitation due to unchanged default passwords. Notable features include a flat-file database structure, community contribution capabilities, and an associated tool for searching credentials via a terminal user interface (TUI).
2026-08-27
TypeScript
★ 308
Pentest Harness is an open-source AI-driven security testing workspace designed for authorized penetration testing, bug bounty research, and CTF engagements. Its notable features include a multi-provider LLM engine for seamless integration with various AI model APIs, durable session management for persistence and replay, and a fully customizable plugin architecture allowing for extensive configuration and adaptability. The tool prioritizes security with private credential storage and offers a dark theme interface for extended use during testing sessions.
2026-08-26
★ 15
Acunetix Premium Web Scanner - Practical Windows release with complete modules and an easy first launch.
2026-08-26
★ 117
Cyber Intelligence GPT is a specialized tool for operational security and cyber investigations, integrating OSINT, DFIR, threat intelligence, and AI security into a cohesive workflow. It enables users to collect, analyze, and report on information while providing capabilities for entity research, incident triage, and correlation of cyber threats across multiple public sources. Notable features include the ability to create collection plans, resolve contradictions, assess confidence in findings, and suggest strategic next actions based on intelligence gaps.
2026-08-26
Python
★ 12
Ingram-Pro is an enhanced network camera vulnerability scanner that builds upon the original Ingram framework, providing extensive coverage of over 40 proof of concept (POC) exploits for CVEs from 2017 to 2024, alongside brand-specific weak-password detection for more than 15 camera brands. Key features include authenticated and unauthenticated remote code execution (RCE), high concurrency scanning using gevent, and the ability to capture live snapshots from vulnerable devices. The tool is designed for authorized security assessments and facilitates rapid vulnerability detection across large IP ranges.
2026-08-26
PowerShell
★ 17
WinFlesher is an advanced attack surface security assessment tool designed for security professionals and auditors to automate the discovery of vulnerabilities and evaluate security postures in Active Directory and local infrastructures. Its notable features include real-time automated discovery of configurations and services, in-depth Active Directory analysis with a focus on trust and privilege relationships, a built-in attack paths engine for identifying potential escalation routes, and integrated remediation support with practical guides. The tool also provides a modern GUI for intuitive visualization of findings and security scores, enhancing the management of risk assessments.
2026-08-26
HTML
★ 13
PageZero is a JavaScript-based browser exploitation and command-and-control (C2) framework that integrates features from both Evilginx and BeEF. It allows security professionals to deploy phishing attacks without the need for complex configurations, enabling live sessions to execute over 40 modules including credential theft, keylogging, and LAN scanning from a web admin panel. The tool is designed for authorized penetration testing and operates using a simple hook that grants persistent control over the victim's browser context.
2026-08-26
C#
★ 53
Atlas is a cross-platform network execution and security assessment toolkit designed for authorized penetration testing, leveraging TrustedSec's Titanis protocol library. It features modular enumeration capabilities across multiple protocols such as SMB, Kerberos, WMI, and LDAP, allowing for credential checks, session enumeration, and remote command execution, along with a streamlined workflow similar to NetExec. Notable features include multi-host concurrency, comprehensive authentication methods, and detailed console output, facilitating efficient security assessments across diverse network environments.
2026-08-26
★ 15
The repository provides a comprehensive collection of cybersecurity bookmarks curated by a senior information security engineer, focusing on critical topics such as OSINT, exploitation, privilege escalation, and malware analysis. It features over 40 tools for reconnaissance, privacy, and attack methodologies, along with curated news sources, making it a valuable resource for cybersecurity professionals looking to enhance their operational security and situational awareness. Notable features include categorized tools for specific cybersecurity tasks and a visually engaging presentation of the content.
2026-08-26
Python
★ 17
ZeroBurst is an advanced command-line application security testing framework designed for ethical hacking and vulnerability assessment. With over 55 specialized modules, it enables users to conduct thorough reconnaissance, injection testing, and auditing of web applications, focusing on various attack vectors such as server-side request forgery and SQL injection. Notable features include automated vulnerability detection across multiple tiers, advanced auditing capabilities, and comprehensive mapping tools for application infrastructure.
2026-08-25
Python
★ 93
search_vulns is a modular tool designed for searching known vulnerabilities, exploits, and other related information across various data sources. Its primary use case is to facilitate vulnerability assessments by allowing users to query a local database with inputs such as product titles or vulnerability IDs, while supporting integration of additional data sources through its modular architecture. Notable features include a command-line interface for automated workflows, a web server for enhanced functionality, and the ability to accommodate diverse input formats.
2026-08-25
Python
★ 22
Network Scanner is an open-source security tool designed for vulnerability assessments and penetration testing, enhancing traditional methodologies with AI capabilities for intelligent analysis and detailed reporting. Tailored for a diverse user base including beginners and professionals, it offers functionalities such as automated reconnaissance, various scan types (subdomain, port, DNS), and an AI assistant for context-sensitive support. Notable features include report generation in PDF/HTML formats, an educational learning mode, and API readiness for seamless integration.
2026-08-25
Python
★ 225
Public Skills Builder is a tool designed to generate Claude Code bug bounty skills from publicly available HackerOne reports and GitHub writeups, specifically without requiring access to private reports. It processes over 500 disclosed reports to create 18 structured skill files for various vulnerability classes, each containing real-world techniques, payloads, and bypass patterns, thereby providing users with resourceful training data for vulnerability hunting. Notable features include support for multiple sources, including public feeds, and the ability to customize output based on specified vulnerability types.
2026-08-25
Python
★ 37
The CVE-2026-18963-Exploit tool allows users to test for a critical security vulnerability in Keycloak versions 26.0.0 to 26.7.1, which enables unauthenticated attackers to reset passwords without victim interaction. It features a safe detection mode that requires only the base URL and realm settings, avoiding any impact on the target system. Additionally, it includes a lab environment for practical demonstration of the exploit and its remediation.
2026-08-25
Python
★ 10
The Phishlet Generator is an automated tool designed to streamline the creation of `.yaml` phishlet files for Evilginx3 by leveraging real browser automation with Playwright. Its primary use case is to eliminate the manual reverse-engineering of website login flows by capturing live network traffic during a simulated login process, which includes handling complex scenarios like CAPTCHA and 2FA challenges. Notable features include smart classification of fields and tokens, integration of anti-detection scripts, and the capability to generate production-ready configurations compatible with Evilginx3.
2026-08-25
Python
★ 19
Ruoyi-Scan is a specialized vulnerability scanning tool designed for RuoYi applications, featuring a plugin-based architecture and three-state assessment (CONFIRMED / SAFE / UNKNOWN) for vulnerability status. It supports bulk scanning, multiple report formats, WAF bypass techniques, and offers enterprise-level functionalities such as API integration and a robust plugin ecosystem for various common vulnerabilities. Noteworthy capabilities include automated AI-based POC generation, extensive reporting options, and compatibility with various operating environments.
2026-08-25
C
★ 79
Blitzping is a high-speed, configurable packet-crafting utility designed for embedded devices, enabling the rapid generation of minimal TCP packets with optimized performance compared to existing tools like hping3 and nping. Its notable features include support for CIDR notations for source IPs, asynchronous raw socket configuration, multithreading, and efficient queuing to minimize system calls, making it particularly suitable for scenarios requiring high packet generation rates. Users can easily specify the number of threads and target IP/port combinations for efficient network testing and analysis.
2026-08-25
★ 139
Claude-AD is a plugin for Claude Code that streamlines the methodology for conducting Active Directory (AD) penetration tests. It organizes engagement phases such as setup, data collection, exploitation, and post-exploitation, while addressing environment-specific constraints and providing telemetry insights to enhance operational security. The tool integrates standard AD assessment techniques, orchestrating third-party tools like BloodHound CE and Impacket, ensuring effective execution of assessments aligned with compliance controls.
2026-08-24
Python
★ 4634
BugHunter is an AI-powered bug bounty toolkit designed for effective vulnerability assessment and reporting directly from the terminal. It automates the processes from reconnaissance to reporting, generating submission-ready documents for various platforms while utilizing an intelligent session management feature that retains discovered patterns across targets. This tool can operate independently without a subscription, enhancing accessibility for users in the cybersecurity domain.
2026-08-24
★ 11
Awesome ROS & Robotics Security is a comprehensive resource repository focused on the security aspects of the Robot Operating System (ROS) and robotics in general. It includes verified tools, checklists, known vulnerabilities (CVEs), and research related to pentesting, AI attacks, and secure robotics frameworks, making it an essential reference for security professionals working on robotic systems. Notably, each entry is individually verified against primary sources to ensure accuracy and credibility.
2026-08-24
Python
★ 87
PwnRM is an advanced WinRM post-exploitation tool designed for conducting authorized security assessments in Windows Active Directory environments. It features an interactive PowerShell runspace, support for various authentication methods, stealthy payload delivery, and a built-in Active Directory triage engine, enabling users to perform a wide range of assessment tasks through a command-line interface as well as via a Python library. Notable functionalities include file transfer capabilities, remote command execution, and comprehensive AD enumeration and session management features.
2026-08-24
Shell
★ 28
OSINT Skills is an open-source intelligence tool designed for automated investigations, enabling users to pivot between various data points such as emails, domains, and social accounts. Its main use case involves conducting comprehensive reconnaissance and attribution, with 28 integrated skills that utilize techniques like reverse image search and breach checks to generate detailed reports complete with sources and confidence levels. Notably, the tool allows interaction with AI agents to streamline the investigation process and provides extensive reference materials for each skill.
2026-08-24
JavaScript
★ 45
Mimic is a lightweight JavaScript library designed for conducting realistic phishing simulations by creating a fake browser interface on top of an existing webpage without the need for iframes. Utilizing Shadow DOM and MutationObserver technologies, it successfully renders the actual website’s content within a customizable fake browser viewport while preserving original styling and information, enabling more effective testing and demonstration of phishing attacks in a seamless manner. Notable features include a dependency-free design, automatic content injection, and the ability to mimic various browser elements like the address bar and site information.
2026-08-24
Python
★ 36
The 'redteam-skill' tool facilitates a semi-automated workflow for red teaming engagements, allowing operators to select modules that assist in penetration testing while recording findings in a `notes.md` file. It features a modular architecture encompassing various attack and reconnaissance techniques, with an emphasis on human oversight to ensure critical judgment and decision-making during operations. Notable functionalities include the automatic retrieval of previous notes and detailed process references for each module, enhancing the efficiency of security assessments.
2026-08-24
Python
★ 320
DorkAgent is a LLM-powered tool designed for automated Google Dorking to assist in bug hunting and penetration testing. It allows users to retrieve and customize search results through various LLM APIs, streamlining the process of exploiting Google search vulnerabilities. Notable features include automatic package installation, dynamic model selection at runtime, and extensive customization options for search parameters.
2026-08-23
Python
★ 10
Oxide is a cross-platform remote access trojan (RAT) framework designed for security research and detection engineering, allowing users to demonstrate and analyze threat actor tactics, techniques, and procedures (TTPs) at the code level. It includes an implant written in Rust, a C2 panel implemented in Python, and provides comprehensive detection capabilities with paired YARA rules, Sigma rules, and incident response playbooks. The framework facilitates purple team exercises through a structured approach to understanding implant-panel communications and establishing effective detection strategies.
2026-08-23
Go
★ 10
msarjun is a high-performance tool that enhances Arjun by enabling mass-scale parameter discovery through concurrent scanning of multiple URLs. Its primary use case is for efficient vulnerability assessment, significantly reducing execution time with features like automatic wordlist setup, multiple output formats, and optimized performance for extensive URL targeting. Notable features include configurable concurrency, output management for seamless tool integration, and a user-friendly command-line interface.
2026-08-23
Python
★ 32
HTLogin is a security testing tool designed to inspect and identify vulnerabilities in login forms and authentication APIs across web applications. It comprehensively tests for common weaknesses, including default credentials, injection vulnerabilities, and rate-limiting issues, while supporting HTML forms, JSON/GraphQL APIs, and JavaScript-rendered SPAs. Notable features include confidence-based detection with detailed reporting, a CLI interface for streamlined usage, safe operational modes, and extensive integration support with proxies and testing frameworks.
2026-08-22
★ 16
The "Python for Security Professionals" course equips learners with practical skills in Python programming specifically tailored to security tasks, ranging from language fundamentals to the development of security tools. It features hands-on labs that culminate in building applications like port scanners and log analyzers, all while emphasizing clean coding practices and error handling. This lab-driven, self-paced curriculum is suitable for beginners and progresses through advanced concepts, ensuring students learn to write maintainable security software effectively.
2026-08-22
Python
★ 31
BirdShot is an offline-first CLI and local web UI tool designed to streamline and standardize hardware research workflows for lab-owned Flock devices. It enables users to organize device states, work orders, logs, and evidence collection across various research phases, ensuring repeatable and authorized testing in controlled environments. Notable features include integration with local service checks, media validation, and seamless management of related evidence within a structured framework tailored for comprehensive device and deployment research.
2026-08-22
Python
★ 405
Bountyforge is a comprehensive pentesting tool designed to facilitate automated vulnerability assessments across various platforms, including web APIs, smart contracts, and infrastructure. It employs eight parallelized security agents that systematically evaluate different attack vectors, generating deduplicated and CVSS-scored findings formatted into submission-ready reports for popular bug bounty platforms. Notable features include local tooling orchestration, multi-chain smart contract auditing, and isolated cloud pentesting environments, providing flexibility and efficiency for security professionals.
2026-08-22
PHP
★ 12
KrazePlanetCTF is an open-source web security training platform that features over 260 interactive challenges within isolated per-user sandboxes, enabling hands-on learning for cybersecurity professionals. Its primary use case is to facilitate practical training in web security through real-world scenarios, while notable features include Docker-based deployment and easy management via command-line tools for viewing logs and controlling the platform's state.
2026-08-21
★ 21
The Offensive Linux Privilege Escalation tool serves as a comprehensive guide to help users escalate from low-privileged Linux access to root, covering various techniques such as sudo and SUID abuse, kernel exploits, and credential mining. Its primary use case is educational, providing detailed methodology, enumeration scripts, and a structured approach to experience in privilege escalation while emphasizing lawful and authorized testing. Notable features include over 50 documented techniques, automated enumeration scripts, a methodology checklist, and practical lab setups for hands-on learning.
2026-08-21
★ 21
Offensive File Transfer Techniques is an extensive guide designed for transferring files to and from target systems during security engagements, emphasizing staging payloads and exfiltrating data. It covers a diverse range of transport mechanisms, including HTTP, SMB, FTP, TFTP, and more obscure methods like base64 encoding, while also providing detection and defense mappings for each technique. The tool features organized notes with ready-to-use commands for both client and server setups, ensuring comprehensive coverage of file transfer methods in offensive security contexts.
2026-08-21
★ 22
Offensive Windows Privilege Escalation is a comprehensive guide designed for escalating privileges from a low-privileged Windows environment to Administrator or SYSTEM level, utilizing various techniques such as service misconfigurations, registry exploits, UAC bypass, and token-privilege abuse. The tool emphasizes an offensive security methodology, offering over 75 structured notes complete with hands-on exploitation and detection guidance, alongside ready-to-use commands and methodology checklists. It serves as an educational resource exclusively for authorized testing scenarios, ensuring ethical use in cybersecurity practices.
2026-08-21
Shell
★ 16
B1ackOS is a privacy-focused operating system based on Debian, designed to simplify software package installation and enhance user security. It features a lightweight and versatile environment, allowing for both live usage and easy assembly tailored to individual needs, with a rolling release model that ensures access to the latest software versions. Key functionalities include improved package management, extensive application availability, and compatibility with a wide range of hardware.
2026-08-21
PHP
★ 49
The Ethical-Hacking repository provides a comprehensive step-by-step guide for learning cybersecurity and ethical hacking using Kali Linux. It covers foundational knowledge in networking and Linux commands, introduces tools like Nmap and Metasploit, and offers practice platforms for hands-on experience. Notable features include recommended resources, structured learning paths, and additional guidance on specialized areas like web application security and certifications.
2026-08-21
Python
★ 32
SearchToolkit is an advanced collection of resources designed for penetration testers, red teamers, blue teamers, and forensic analysts. It includes tools, hardware, cheatsheets, and references across various cybersecurity domains such as geolocation tracking, OSINT, malware analysis, and bug bounties. Notable features include a comprehensive navigation system for quick access to specific areas of cyber defense and offense, highlighting its utility in diverse cybersecurity tasks.
2026-08-21
Python
★ 157
The wifi-deauther tool is a Python-based application that automates deauthentication attacks to help users understand 802.11 management frame injection. Primarily intended for testing on networks with proper authorization, it allows users to select a wireless interface and target access points for deauthentication. Notable features include support for Linux systems, the necessity for a wireless card with monitor mode, and the recommendation to use two wireless cards for optimal performance.
2026-08-20
Python
★ 328
Consortium is a modern, extensible command and control (C2) framework that supports both asynchronous multi-client interactions and language-agnostic listener-agent designs, enabling users to develop custom agents and listeners efficiently. Key features include a robust REST API for automation, role-based access control for user management, and modular architecture that allows for extensive customization and collaboration among users. Currently in the alpha phase, the framework emphasizes a high degree of flexibility while still under rapid development.
2026-08-20
Python
★ 674
Cybermes is an advanced autonomous security research framework designed for offensive security tasks, including bug bounty hunting and red teaming. It features over 50 specialized modules for in-depth reconnaissance, attack surface analysis, and vulnerability validation, leveraging a unique integration of modern LLM reasoning and automated workflows. Notable capabilities include dynamic attack planning, multi-source knowledge retrieval, and programmatic validation of findings to ensure zero false positives.
2026-08-20
HTML
★ 263
The Flipper Zero Evil Portal tool transforms a Wi-Fi development board into a phishing access point, serving a fake login screen to connected users. It captures user credentials and logs them onto the SD card, functioning as an educational demonstration for learning about Wi-Fi exploits and programming. Notable features include compatibility with both official and unleashed firmware, easy installation via pre-built app files, and customizable HTML login screens.
2026-08-20
Shell
★ 25
h3-cli is a command-line interface designed for seamless interaction with the Horizon3 API, enabling users to schedule and execute autonomous penetration tests via NodeZero, as well as monitor their status and access detailed reports. Notable features include comprehensive documentation for installation and usage, alongside capabilities to run and manage a locally hosted MCP Server that integrates NodeZero’s functionalities into development and security workflows.
2026-08-19
Java
★ 13
Yentra is a Burp Suite extension designed to streamline collaborative security testing by deduplicating proxy history into a real-time unique request feed and color-coding traffic based on listener ports. Its notable feature, Live Share, enables real-time peer-to-peer sharing of HTTP requests without prior registration, accompanied by robust tools like a Magic Cookie, Match & Replace, and an inline Repeater for enhanced testing efficiency. Additional capabilities include automatic sharing of unique requests, replay options through local proxies, and integration with AI services for exporting requests.
2026-08-19
Ruby
★ 10
AWINRM is an advanced WinRM post-exploitation framework designed specifically for red teams and offensive research, implemented in Ruby. Its primary use case revolves around facilitating efficient post-exploitation activities with features like built-in tool staging, automated AMSI/ETW bypasses, stealth file transfers, and automatic loot extraction, addressing common challenges encountered in traditional WinRM tools. The framework provides a streamlined operator-centric workflow that enhances operational security and supports automated reconnaissance and credential gathering.
2026-08-19
Shell
★ 31
bugbountyrules is an AI agent skill designed for authorized bug bounty and penetration testing, emphasizing disciplined and methodical hunting behavior. It features 42 active rules to minimize false positives, avoid severity inflation, and ensure thorough surface coverage while performing tests across web, API, mobile, cloud, and LLM environments. The tool operates on a structured approach to testing, maintaining an organized flow of reconnaissance and validation while integrating a robust knowledge base for on-demand information retrieval.
2026-08-19
Python
★ 18
PhantomTap is a machine learning-enhanced tool for the Flipper Zero, specifically designed for RFID/NFC fuzzing and access-control auditing. It utilizes active learning to intelligently generate test credentials, significantly reducing the number of reader queries required for effective security assessments, and produces an explainable audit report for identifying vulnerabilities in badge systems. Notably, it features efficient characterization, Bayesian population sizing, and integrates detection mechanisms to monitor real-time security threats.
2026-08-18
★ 63
The HackTheBox-Active-Directory-Labs repository provides a collection of walkthroughs focused on Active Directory enumeration and attacks as part of the Hack The Box CPTS career path. Notable features include the inclusion of visual Obsidian .canvas files for enhanced understanding and thoroughly documented processes to uncover flags, with partial censorship to prevent scraping. This resource is intended for learners and security practitioners aiming to deepen their knowledge in Active Directory security.
2026-08-18
Python
★ 50
SMBScan is a tool designed for enumerating file shares on internal networks, allowing users to scan either a single target or a range of targets. Notable features include the capability to identify potentially sensitive files, support for guest and domain user authentication, and tactics to minimize detection by security teams. Additionally, it generates log files for comprehensive output analysis following scans.
2026-08-18
★ 10
TikTok-SSL-Pinning-Bypass is a tool designed to intercept network traffic from the TikTok application on Android devices without the need for rooting. It supports Android versions 6.0 and above, and has been successfully tested using Mitmproxy in a non-root environment, specifically for the arm64-v8a architecture. Notable features include the ability to bypass SSL pinning, compatibility with real Android devices and AVD emulators, and the provision of a free patched APK that resolves specific login errors.
2026-08-18
Python
★ 10
MetaView is a web-based interface for the Metasploit Framework that provides multi-user support and an intuitive user interface built on Vue3. Its primary use case is to facilitate project management and data visualization within penetration testing, enabling users to manage workspaces, visualize database entries such as hosts and vulnerabilities, and generate live dashboards. Notable features include integration with external tools (like MaxPatrol and Nmap), role-based access control, and task management functionalities.
2026-08-18
JavaScript
★ 11
ExecEndpoints is a dual-component toolkit designed for authorized web security testing and bug bounty efforts, featuring a Chrome extension for real-time API request monitoring and a Python server for extracting hidden endpoints from JavaScript. The tool captures detailed HTTP requests, including methods, parameters, and per-host authentication details, while enabling deep static analysis to uncover dynamic API endpoints missed by traditional scanning methods. Notable features include a rich dashboard for endpoint management, a typed secret scanner, and a safe design that operates locally without external dependencies.
2026-08-18
Python
★ 1815
Getsploit is a tool designed for searching and downloading public exploits from the Vulners database, facilitating both online searches and fully offline operations via a local SQLite index. Its notable features include a comprehensive query capability across multiple exploit collections, local query support without internet connectivity, and robust JSON and tab-separated output formats, all while maintaining data privacy and integrity. The tool is compatible with Python 3.11 and above, ensuring reliable performance across various platforms.
2026-08-18
Lua
★ 3418
nmap-vulners is a set of Nmap scripts designed to enhance network vulnerability assessments by converting service scan results into a detailed list of known Common Vulnerabilities and Exposures (CVEs) along with their respective CVSS scores and exploits. Notable features include three independent scripts that can perform various vulnerability lookups—one leveraging the public Vulners database, another utilizing the Vulners API for advanced scoring, and a regex-based script that identifies web software through HTTP headers. This tool aims to streamline the process of gathering security-related information during Nmap scans, improving the effectiveness of vulnerability management.
2026-08-18
PowerShell
★ 19
TCPK (Thick Client Pentest Kit) is a Windows-based security audit tool designed for comprehensive testing of thick-client applications, including MSIX, .NET, and Electron binaries. Noteworthy features include a PowerShell engine, live auditing with real-time findings, CVSS scoring, AI triage capabilities, and automated report generation in multiple formats, providing an exhaustive analysis for authorized testing environments. This tool emphasizes evidence-based findings and offers extensive checks, making it suitable for security professionals conducting in-depth application audits.
2026-08-17
Go
★ 84
MORF is a Mobile Reconnaissance Framework designed for offensive security, specifically engineered to discover hardcoded secrets within compiled mobile application artifacts (Android `.apk` and iOS `.ipa`). Unlike traditional source code scanners, MORF operates on the final shipped binaries, utilizing a robust detection engine to verify the presence and activity of secrets, while also generating Software Bills of Materials (SBOM) and Common Vulnerability and Exposure (CVE) reports. Key features include a scalable service architecture, continuous integration (CI) compatibility, and compatibility with leading security standards such as SARIF and OWASP MASVS.
2026-08-17
Kotlin
★ 33
ZeroDroid is a comprehensive Android hardware security toolkit designed to transform smartphones into portable RF labs, network analyzers, and security auditing tools, featuring 29 specialized utilities. Its primary use case includes analyzing various radio frequencies and sensors, as well as conducting detailed network assessments. Notable features include the ability to access WiFi, Bluetooth, NFC, GPS, and other device sensors, all presented through a terminal-hacker user interface.
2026-08-17
★ 532
Hacking Cheatsheets is a comprehensive resource designed for penetration testing and ethical hacking, offering a collection of quick reference guides for various tools and methodologies. Notable features include clear explanations of tool functionalities, command syntax with practical examples, and a structured attack methodology following the MITRE ATT&CK framework. Additionally, it provides defensive security guides for SOC analysts, covering incident response and log analysis.
2026-08-17
PowerShell
★ 11
Kioskonomicon is a comprehensive workshop resource designed for exploring and exploiting security vulnerabilities in public-facing kiosks, emphasizing the path from kiosk escape to Active Directory compromise. It features a structured "choose your adventure" format, allowing users to engage in DIY attacks, hard mode challenges, or follow guided exercises, all set within a specialized Active Directory lab environment. Notable elements include detailed scenarios for various kiosk types, a range of Active Directory attack methodologies, and supplementary resources for both hacking techniques and defensive measures.
2026-08-17
Rust
★ 11
BruteCraber is a high-performance hash cracking tool developed in Rust that utilizes GPU acceleration via OpenCL by default, with a seamless fallback to a multithreaded CPU backend when necessary. It supports a variety of hashing algorithms including MD5, SHA-1, SHA-256, and modern key derivation functions like Argon2 and Scrypt, along with automated hash type detection and a customizable rules engine for generating password variations. Its simplicity allows users to initiate cracking with a single command, eliminating the need for complex configurations.
2026-08-16
Python
★ 88
HEAVEN is an autonomous penetration-testing framework designed to streamline and automate various stages of the penetration testing process, including reconnaissance, vulnerability detection, exploitation, risk scoring via machine learning, and reporting. It features a robust interface with 55 CLI commands, 77 API routes, and multiple scan modes, facilitating comprehensive assessments while allowing users to focus on critical decision-making tasks. Notably, it incorporates a CVSS machine learning predictor with a high correlation score, ensuring accurate risk evaluation.
2026-08-16
JavaScript
★ 34
P4wnP1 Infinition Payloads is a collection of JavaScript and Bash scripts designed for the P4wnP1 A.L.O.A. platform, facilitating credential harvesting, file exfiltration, and remote access primarily on Windows 10 systems. Notable features include the ability to stealthily operate through minimized PowerShell sessions, support for French and US keyboard layouts, as well as methods for disabling Windows Defender and retrieving sensitive information directly to a Samba share. This tool is intended for authorized penetration testing and security research.
2026-08-16
Shell
★ 13
Win10 LockPicker is a P4wnP1 A.L.O.A. payload designed to unlock a Windows 10 session without requiring prior knowledge of the user's password. It captures NTLMv2 hashes over poisoned LLMNR/NBT-NS traffic via a spoofed USB network adapter, cracks the hash using John the Ripper, and automatically inputs the recovered password using an HID keyboard. Additionally, it offers an SMB brute force alternative for credential recovery through Metasploit, enhancing its versatility for authorized penetration testing.
2026-08-16
Python
★ 16
ExploiterX 3.0 is an enterprise-grade web vulnerability scanner designed for security professionals and developers, capable of detecting a wide range of vulnerabilities including XSS, SQL Injection, and CSRF. Its notable features include advanced scanning capabilities with over 20 XSS payload variants, concurrency support for parallel scanning, intelligent HTML form parsing, and comprehensive reporting in multiple formats. Additionally, the tool emphasizes resilience with built-in retry mechanisms, robust error handling, and secure reporting to prevent common security vulnerabilities in output.
2026-08-15
Shell
★ 11
MAPG is an automated reconnaissance tool designed for penetration testing, CTFs, and security assessments, facilitating organized and efficient service enumeration. It features a modular framework that executes service detection and enumeration tools in parallel, generating structured reports while minimizing manual effort. Notable capabilities include support for various scanning modes, extensive service checks, and automatic report generation, all aimed at streamlining the initial phases of security assessments.
2026-08-15
PowerShell
★ 94
dsh-reverse-skill is a comprehensive DeepSeek Harness (dsh) plugin that encapsulates 85 skills from the upstream reverse-skill repository, providing seamless integration into the dsh environment without manual maintenance of skill lists. The tool automatically registers a complete library of skills upon startup, includes both domain and CTF-oriented skills, and offers a straightforward installation process via GitHub or configuration files. It is specifically designed for authorized reverse engineering, penetration testing, and security research.
2026-08-15
JavaScript
★ 373
Frida Script Runner is a web-based toolkit designed for comprehensive Android and iOS penetration testing and mobile application security analysis. It streamlines interactions with Frida through a user-friendly Flask interface and supports advanced functionalities such as AI-powered script generation, real-time output, and automated analysis with integration for Ghidra and JADX. Notable features include APK/IPA dumping, SSL detection, multi-device monitoring, and an extensive set of tools for script management and execution.
2026-08-15
Python
★ 59
The Vulnerability PoC Repository offers curated Proof-of-Concept code, test labs, and prevention rules targeting high-severity CVEs for authorized security testing, penetration testing, CTF challenges, and security research. Key features include detection-only PoC scripts, Docker test labs with both vulnerable and patched applications, and bilingual documentation in English and Korean, ensuring comprehensive resources for cybersecurity professionals.
2026-08-15
Shell
★ 24
BloodHoundAnalyzer is a bash script that automates the deployment, data import, and analysis of BloodHound CE, an Active Directory security tool. It enables efficient setup of multi-domain BloodHound CE instances, custom container management, and integration of various analysis tools to enhance Active Directory security assessments. Notable features include automated password management, support for multiple data formats, and comprehensive project listing and status tracking.
2026-08-15
★ 317
The OSCP-Pentesting-Cheatsheet serves as a comprehensive notes repository and study guide tailored for candidates preparing for the Offensive Security Certified Professional (OSCP) certification. It includes detailed enumerations using tools like Nmap for network scanning, explaining various scan types, traffic considerations, and OS fingerprinting techniques, thus aiding in efficient penetration testing practices. The cheatsheet is updated to remain relevant with upcoming exam changes, ensuring continuity of its commands and information.
2026-08-14
PowerShell
★ 11
The Scan-broken-owner tool is a PowerShell script designed to audit Active Directory for vulnerabilities related to object ownership, specifically targeting "broken owners" which pose a security risk. Its primary use case is to help organizations identify and mitigate control-takeover vulnerabilities by ensuring that Active Directory objects are owned by appropriate, legitimate users, thereby preventing potential attacks such as Kerberos Resource-Based Constrained Delegation abuse. Notable features include the generation of a detailed HTML report, the ability to skip specific users or groups during scans, and operation without requiring administrative privileges.
2026-08-14
★ 114
Cyber Intelligence GPT is a custom AI tool designed to enhance open-source intelligence (OSINT) and cyber investigations by supporting the analysis, correlation, and reporting of data related to threat intelligence, digital forensics, and compliance. It features a comprehensive investigation workflow that enables users to create collection plans, pivot on identifiers, correlate evidence, and identify intelligence gaps, while adhering to lawful sources and practices. Notably, it encompasses various aspects of cybersecurity, including threat hunting, security operations, and OPSEC, making it a multifaceted resource for security professionals.
2026-08-14
Python
★ 28
The A-Pythonic-Keylogger is a Python-based keylogger designed for educational purposes that captures keystrokes, logs them to a local file, and can send the logs via email. Notable features include robust email retry handling, automatic session restart after key capture, and platform compatibility with both Linux and Windows. The tool incorporates local log management by clearing logs after the session ends, ensuring data retention only during active capture.
2026-08-14
Shell
★ 21
opencode-pentester is an AI-powered penetration testing and security audit framework designed to automate bug bounty hunting and vulnerability assessments. It orchestrates 12 specialized AI agents across 69 attack categories and 17 OWASP security audits, enabling comprehensive offensive and defensive testing. Notable features include the ability to run automated tests, generate professional reports, and integrate a wide array of security tools, making it suitable for security researchers, penetration testers, and DevSecOps engineers.
2026-08-14
JavaScript
★ 98
Hacker Bob is a local MCP (Managed Control Panel) workflow tool designed for authorized offensive security testing within CI environments or staging areas. It facilitates surface mapping, authentication setup, parallel testing, and reporting, while integrating with various MCP-capable hosts like Claude Code and Codex. Notable features include real network request capabilities, local artifact imports, and the ability to manage sensitive run data securely, all ensuring users adhere to permissions and authorization guidelines.
2026-08-14
PowerShell
★ 27
PowerShell-for-Hackers is a repository that offers a collection of PowerShell functions specifically designed for the creation and execution of hacking payloads. Its primary use case is to facilitate the development of custom payloads by providing easily accessible functions, detailed descriptions, and practical examples. Notable features include a PowerShell to DuckyScript converter, comprehensive documentation, and video tutorials for each function, enhancing the learning experience for users looking to expand their cybersecurity toolkit.
2026-08-14
★ 91
EmberHeart-Kernels is a custom kernel for Android devices, specifically optimized for GKI compliance and rooted environments. Its primary use case centers around enhancing Android penetration testing capabilities through integration with the Nethunter framework, while also offering advanced features such as KernelSU for root access management and SUSFS for root hiding, thereby improving security and device control. Users can install the kernel and associated modules to make significant modifications to their device's performance and functionality, provided they acknowledge the potential risks involved.
2026-08-14
Python
★ 75
REDCELL is an advanced penetration testing platform that utilizes AI agents to execute automated tests and generate comprehensive reports. It features a multi-agent orchestration system, real-time execution of offensive tools within a Dockerized Kali environment, and integrates pluggable language models for enhanced automation. Notable capabilities include live monitoring of agent activity, interactive terminal access to reverse shells, structured tool outputs, and seamless network pivoting for deeper exploitation.
2026-08-14
Dart
★ 58
The Flutter Reverse Engineering Labs repository offers a series of progressive challenges aimed at teaching the techniques involved in reverse engineering Flutter applications. It includes hands-on tasks that lead users from basic concepts to more advanced practices such as network traffic interception and integrity check bypassing, with each challenge accompanied by detailed, step-by-step solutions. Notable features include the provision of compiled APKs for challenges, practical source code examples, and integration with commonly used tools like Frida and APKTool for a comprehensive learning experience.
2026-08-13
HTML
★ 60
Bjorn Manager is a desktop application designed to facilitate the discovery and management of Bjorn devices across various network interfaces, including LAN, USB, and Bluetooth. It allows users to install, update, and control these devices from a single user interface, featuring multilingual support, smart device naming, and real-time terminal logs for installations. Key functionalities include auto-discovery, SSH installation capabilities, and configurable settings, making it a comprehensive tool for managing Bjorn devices efficiently.
2026-08-13
TypeScript
★ 11
Mingyi Atlas is a terminal AI agent designed for software engineering and authorized security assessments, offering an interactive TUI, headless automation, persistent project context, and specialized penetration testing modes. It features multi-model support, OAuth and API Key authentication, and structured workflows for reconnaissance, validation, reporting, and remediation, specifically catering to security tasks while ensuring non-destructive testing. The tool allows users to orchestrate security assessments with built-in skills and provides extensive CLI commands for project management and configuration.
2026-08-13
Python
★ 40
Pentestkit is a sophisticated, multi-agent penetration testing framework that utilizes the Claude Agent SDK to orchestrate a team of specialized agents. The tool excels in automating the penetration testing process by exploiting vulnerabilities, scoring them using CVSS v3.1, and generating comprehensive client-ready reports, all while accumulating knowledge in a shared database. Notable features include its ability to perform real exploitation of findings and a robust scoring system that achieved a perfect 104/104 on the XBOW benchmark suite.
2026-08-13
Python
★ 24
This tool is a Python-based keylogger designed for educational purposes, capable of capturing keystrokes and sending the recorded logs via email. It features local log management, an email retry mechanism for reliable delivery, and automatic startup configurations for both Linux and Windows systems. Users are cautioned to run the script only on systems they own or have explicit permission to test, as it demonstrates sensitive functionality.
2026-08-13
Python
★ 13
HunterX is an AI-assisted offensive security engine designed for conducting authorized security assessments, integrating tools for reconnaissance, hypothesis-driven investigation, vulnerability validation, and professional reporting into a unified workflow. Unlike traditional vulnerability scanners, HunterX emphasizes thorough investigation and validation, ensuring that findings are evidence-based and report-ready. Notable features include AI-assisted reasoning, proof of concept engineering, and capabilities for reproducibility and impact assessment, enhancing the reliability of security assessments.
2026-08-13
Go
★ 16
OBLITERATUS is an advanced red teaming framework designed for post-exploitation research and defensive evasion in Windows environments. It features a multi-layered stealth architecture for evasion, low-level syscall execution, and identity correlation through its Identity Nexus module, allowing for the bypassing of MFA and efficient credential management. Key capabilities include memory hardening, automatic UAC elevation, and a sophisticated operational interface that facilitates real-time process management and forensic analysis.
2026-08-13
★ 154
Awesome AI in Cybersecurity is a curated repository that provides an extensive collection of resources focused on the application of artificial intelligence in various cybersecurity domains. It categorizes AI uses within cybersecurity into prediction, prevention, detection, response, and monitoring, while also detailing tools for penetration testing, malware analysis, and security for AI SaaS environments. Notable features include automated penetration testing frameworks, and support for network protocol verification, enhancing traditional security measures with AI-driven insights and efficiencies.
2026-08-12
Rust
★ 13
Black Hat Tools is a repository designed for developing asynchronous and concurrent software for security applications using languages such as TypeScript, Go, Rust, and Python. The primary use case involves executing network-based tests and exercises derived from well-known cybersecurity literature, with notable features including integration with specific testing domains for practical application. This tool is still a work in progress, reflecting ongoing development in its functionality.
2026-08-12
Go
★ 71
`blackstork-cli` is a source-available, headless execution engine designed for automating cybersecurity and compliance reporting through the use of BlackStork templates. It facilitates the extraction of structured data from various external tools, evaluates template logic, and renders formatted documents, enabling engineers to version control their reporting workflows and execute them locally or within CI/CD pipelines. Notable features include modular design for data querying and content drafting, extensive plugin support for integration with external APIs and services, and a library of production-ready templates for diverse cybersecurity applications.
2026-08-12
TypeScript
★ 17
SecTester is a developer-centric Dynamic Application Security Testing (DAST) scanner that integrates an enterprise-grade scanning engine directly into unit tests. Its primary use case is to allow developers to conduct security scans at the speed of unit tests, enabling the detection of vulnerabilities without false positives prior to finalizing pull requests. Notable features include seamless integration into continuous integration workflows and the capability to test individual functions and components.
2026-08-12
C
★ 921
GhostESP is an open-source wireless research platform that transforms an affordable ESP32 board into a multifunctional wireless tool with a user-friendly touchscreen interface. Its primary use case includes advanced wireless monitoring, firmware updates, and network analysis, featuring capabilities such as on-device firmware management, a cloud app store, and robust scripting support via GhostScript. Notable enhancements in version 2.x include expanded NFC functionalities, efficient Wi-Fi attack and monitoring tools, and improved user interface performance with a focus on accessibility and multitasking.
2026-08-12
Shell
★ 14
mxhelp is a pentesting toolkit designed to streamline the use of various scripts by automatically populating IP and target addresses into pre-defined "cheatsheets." Its notable features include easy addition of new scripts, real-time updates using the 'sed' command to prevent errors, and a simple alias system for efficient command execution. By simplifying the process of managing pentesting scripts, mxhelp enhances the workflow for security professionals.
2026-08-12
Python
★ 18
Web of Flaws is a Markdown-based catalog that identifies vulnerable web patterns alongside safer alternatives, aimed at both developers and automated tools. Its primary use case is to educate users on exploitable vulnerabilities and provide concrete code examples for remediation, organized by security topics and vulnerability families. Notable features include detailed guides that explain risky patterns and their fix implementations.
2026-08-11
HTML
★ 23
Attack Surface Toolkit is a passive reconnaissance tool designed for authorized web security assessments that maps external exposures of web targets through OSINT and non-destructive metadata collection. Its primary use case is to provide clear and actionable insights into an organization’s attack surface without engaging in invasive testing, presenting findings in a structured format suitable for both technical and non-technical stakeholders. Notable features include comprehensive subdomain enumeration, DNS analysis, SSL/TLS inspection, security header audits, technology detection, and a weighted scoring system, all culminating in professional-grade reports formatted for client deliverables.
2026-08-11
Python
★ 12
CVE-2023-51467 Scanner is a Python-based command-line tool designed to identify a specific vulnerability in the Apache OfBiz ERP system that allows unauthorized access due to an authentication bypass flaw. It enables users to scan individual URLs or lists of URLs for the vulnerability, supporting multiple concurrent threads for efficient scanning and providing output files for vulnerable targets. Notable features include customizable thread counts and flexible input options for URL scanning.
2026-08-11
★ 30
SagarBiswas-MultiHAT is a GitHub repository showcasing a range of cybersecurity and web development projects by Sagar Biswas, a Computer Science and Engineering student. The repository includes open-source tools focused on web application security and ethical hacking, featuring a system called "PromptVault" that enables users to securely manage AI prompts with features like PIN protection, organizational categories, and optional cloud synchronization.
2026-08-11
Python
★ 28
The Nmap Scanning Tool is an interactive wrapper for Nmap that simplifies the execution of common scans and enhances readability of results. It supports multiple scan profiles, including SYN, aggressive, and vulnerability scans, along with an optional output filter to highlight open ports. The tool requires Python and Nmap to be installed on the user's system and aids in providing helpful error messages regarding user permissions and installation checks.
2026-08-11
Python
★ 11
XSScan is a Playwright-based automated tool designed for bug bounty hunters and security researchers to detect executed cross-site scripting (XSS) vulnerabilities. Key features include real browser execution using Chromium, intelligent form submission, recursive crawling, and auto-generated reports of confirmed XSS findings, ensuring focus on vulnerabilities that are genuinely executed rather than merely reflected.
2026-08-11
Ruby
★ 18
Windfall is an exploitation framework that targets critical vulnerabilities in Windmill and Nextcloud Flow, specifically focusing on unauthenticated path traversal and authenticated SQL injection vulnerabilities. Its primary use case is to demonstrate how these vulnerabilities can lead to credential leaks and remote code execution, thereby enabling an attacker to exploit the affected systems. Notable features include a comprehensive assessment of the vulnerabilities' impact with high CVSS scores and detailed analysis of attack vectors, enhancing the tool's utility for security researchers and penetration testers.
2026-08-11
Go
★ 10
CeWL AI is an advanced reconnaissance tool designed to crawl various protocols including HTTP, FTP, SFTP, SMB, and S3, extracting valuable information such as emails, metadata, credentials, and secrets. It combines functionalities of traditional tools like CeWL and CUPP, offering features such as AI-powered wordlist generation, password mutation, multi-protocol support, and secret scanning, all implemented in a single Go binary. This tool enhances security assessments by facilitating in-depth data extraction and analysis in one command.
2026-08-11
TypeScript
★ 11
Kali + OpenCode Portable Pentest USB is a bootable USB solution that integrates Kali Linux Live with a suite of AI-driven penetration testing tools. Its primary use case is to provide a comprehensive and portable pen-testing environment that automates workflows, maintains documentation, and operates without leaving traces on host systems. Notable features include persistent storage for configurations, an autonomous pentesting plugin called Shannon, and support for a variety of tools streamlined for efficient security assessments.
2026-08-11
Go
★ 48
pgread is a tool designed to extract data from PostgreSQL databases without requiring user credentials, leveraging direct access to database files. It facilitates a range of output formats, such as JSON, SQL, and CSV, and includes features for password extraction, secret detection, and WAL (Write-Ahead Logging) analysis. Additionally, it supports low-level forensic operations like parsing database control files and recovery of deleted rows, making it adept for both security audits and database recovery tasks.
2026-08-11
★ 42
This repository offers a curated collection of over 70 free cybersecurity books organized by domain and difficulty, facilitating self-paced learning in various cybersecurity disciplines. Notable features include a structured learning roadmap progressing from beginner to advanced levels, an emphasis on community maintenance for up-to-date resources, and a direct link to an extensive Google Drive library containing the materials.
2026-08-11
C
★ 14
Slave I is an offensive-security firmware specifically designed for the M5Stack Tab5, facilitating wireless research through an integrated toolkit for Wi-Fi, BLE, and 802.15.4 recon and attack capabilities. Notable features include a touch UI, a physical-keyboard workflow, extensive scanning and capturing functions, and a desktop emulator for development. It allows users to implement advanced wireless attacks while emphasizing ethical usage and compliance with legal standards.
2026-08-11
Python
★ 26
Red-Team AI is a white-box red teaming tool designed specifically for agentic AI applications, capable of reading source code to identify vulnerabilities that are unique to a particular technology stack. Its primary use case involves generating tailored attacks based on an application's specific implementation, rather than relying on generic adversarial prompts. Notable features include a modern React dashboard for scan management and compliance tracking, as well as integrations with popular agent frameworks, facilitating extensive security assessments and risk assessments for AI systems.
2026-08-11
Python
★ 13
ShadowRAT is a Telegram-based Remote Access Trojan designed for Windows that provides complete remote control of a machine using Telegram bot commands with password authentication. Primarily targeted at cybersecurity professionals, security researchers, and educators, it serves to demonstrate RAT functionalities, enhance malware detection techniques, and facilitate authorized penetration testing in controlled environments. The tool emphasizes responsible use solely for educational and research purposes, providing insights into attacker methodologies and improving defensive security measures.
2026-08-11
★ 47
The Penetration Testing Roadmap is a comprehensive, self-paced 60-week curriculum aimed at developing expertise in penetration testing, ethical hacking, and network security. It features structured learning paths, hands-on practice through over 500 free labs, and an extensive tools directory, enabling learners to transition from novices to market-ready professionals. Additionally, it encompasses crucial topics such as web application vulnerabilities and emerging cybersecurity trends.
2026-08-11
Shell
★ 127
CamSniff is an automated reconnaissance toolkit designed for discovering and profiling IP cameras and network video streams within local networks. It employs both active and passive scanning methods to generate structured and auditable datasets, while enabling users to acquire snapshots and streams from various protocols, including RTSP and ONVIF. Notable features include its mode-aware scanning capabilities, multi-protocol support, and the ability to produce comprehensive output formats such as structured JSON files and logs.
2026-08-11
Shell
★ 21
OSINT Skills is an open-source intelligence tool designed to facilitate automated investigations by agents like Cursor and Claude. It provides 28 customizable skills for various reconnaissance tasks, enabling users to pivot across data points such as emails, domains, and social accounts, all while generating reports with source citations and confidence levels. Key features include pre-defined workflows, individual techniques for advanced inquiries, and comprehensive reference materials for effective tradecraft in OSINT.
2026-08-11
Go
★ 29
The "BSCP Exam Guide by N3OARI 2026" repository provides a comprehensive collection of personal cheatsheets and methodologies tailored for the BSCP exam, encompassing key topics and relevant labs. Notable features include organized content that facilitates learning through practical examples, alongside recommended resources for each phase of the exam focused on web security vulnerabilities and exploitation techniques. This tool serves as a structured guide for preparing for the BSCP exam, emphasizing the importance of creating individualized study materials.
2026-08-11
★ 12
Cyber Security Sources is a comprehensive repository that aggregates various resources, methodologies, and checklists pertinent to distinct fields of cybersecurity. Its primary use case is to provide practitioners with a centralized reference for best practices and tools in cybersecurity. Notable features include curated lists that facilitate efficient resource identification and access for cybersecurity professionals.
2026-08-11
Ruby
★ 10
The OpenVAS add-on for Dradis facilitates the integration of OpenVAS vulnerability assessment results into the Dradis framework by allowing users to upload OpenVAS XML files. Its primary use case is to create a structured representation of security findings, including nodes and notes corresponding to hosts, ports, and services. Notable features include support for OpenVAS v6 and v7 output, enhancing the usability of security reports within Dradis CE and Dradis Pro environments.
2026-08-11
Python
★ 63
NoiseHound is a detection-aware Active Directory attack-path scoring tool that enables cybersecurity operators to identify the quietest routes to administrative control within a network, leveraging BloodHound graph data. Its primary use case is for operational security (OPSEC) planning in authorized engagements, providing better risk assessments by incorporating expected detection costs instead of just hop counts. Notable features include support for multiple detection tiers, a calibration harness to measure edge effectiveness, and the ability to ingest various data formats for comprehensive path analysis.
2026-08-10
DART is a test documentation and reporting tool designed for penetration testing in isolated environments, facilitating quick setup and minimal configuration. It enables teams to document tests and capture artifacts efficiently, generating comprehensive reports in Microsoft Word format while applying NISPOM-friendly markings. The tool is intended for use on trusted networks and is versatile across various operating systems, including Windows, Linux, and Docker.
2026-08-10
hackOx is an emerging cybersecurity tool currently under development, aimed at providing solutions for various security challenges. Its primary use case focuses on enhancing the online security landscape, with additional details available on its website. Notable features and functionalities are yet to be fully documented as the project progresses.
2026-08-10
HexStrike AI is an advanced, AI-powered penetration testing framework designed for cybersecurity automation, featuring over 150 integrated security tools and more than 12 autonomous AI agents. Its primary use case is to enhance vulnerability assessment and exploitation processes through intelligent decision-making and real-time dashboards, optimizing testing strategies based on target analysis. Notable features include support for multi-agent architecture, a modern visual engine, and capabilities such as attack chain discovery and parameter optimization.
2026-08-10
Kvasir is a web2py application designed for efficient data management during penetration testing engagements, streamlining the organization and sharing of extensive test data. It supports integration with various vulnerability scanners and PostgreSQL databases while ensuring data separation for different customers through individual application directories. Noteworthy features include a built-in scheduled task system for managing long-running processes and a user-friendly setup for maintaining data integrity across client projects.
2026-08-10
Pollenisator is a Python-based tool designed to automate the management of penetration testing activities, facilitating efficient tracking and organization of pentest objects such as scopes, hosts, and tools. It features a NoSQL database for object storage, customizable tool integration, collaborative capabilities for team efforts, and supports various reporting formats including Word and PowerPoint. Notable features include dynamic tool execution controls, a user-friendly GUI, and predefined procedures for reconnaissance and fingerprinting with integrated security tools.
2026-08-10
WriteHat is a reporting tool designed for penetration testers to streamline the creation of professional reports by converting Markdown to HTML and then to PDF. It features a drag-and-drop report builder, supports various markdown elements, a findings database, and customizable reporting options, making it suitable for generating detailed security assessments and tracking report statuses. Its extensible design and LDAP integration allow for enhanced customization and user management.
2026-08-10
The Ultimate Pentest Tools List is a comprehensive catalog of over 300 penetration testing tools available online, both free and premium. It categorizes tools for various cybersecurity use cases, including red teaming and adversary simulation, while highlighting noteworthy selections made by experienced pentesters. This resource serves as a valuable reference for cybersecurity professionals seeking to enhance their testing capabilities with categorized, alphabetical listings of tools.
2026-08-10
The Pentest Reports tool provides a web platform (https://pentestreports.com) that aggregates public penetration testing reports for research and educational purposes. It is designed for cybersecurity professionals and enthusiasts to access and analyze real-world penetration testing data. Notable features include a community-driven approach allowing contributions and easy local setup using Ruby and Bundler.
2026-08-10
PwnDoc-ng is a pentest reporting tool designed to streamline the creation of customizable Docx reports for security findings. It enhances collaboration among users through features such as multi-user reporting, vulnerability management, and an improved WYSIWYG editor, while allowing extensive customization of templates and data management. This tool aims to minimize documentation time, enabling security professionals to focus more on penetration testing activities.
2026-08-10
Cyver Core Pentest Reporting Resources provides a streamlined platform for penetration testers to create efficient and high-quality reports by offering various report templates, compliance norms, and checklists. The tool supports Markdown and Excel formats to facilitate easy uploading and customization, covering a wide range of compliance standards such as OWASP, PCI DSS, and ISO27001. Notably, it includes a comprehensive collection of resources that enhance the reporting process by integrating established frameworks and best practices.
2026-08-10
Python
★ 18
UAMT (Ultimate Auto Android App Modding Toolkit) is a Termux-based toolkit for modifying Android APKs without requiring root access. Its primary use case includes injecting Frida Gadget and custom native libraries, alongside features such as a full APK rebuild pipeline, smart detection of injection methods, and an interactive TUI for user-friendly operation. Notable functionalities include automatic dependency management, safe modding practices, and optimized performance for Android security research and reverse engineering tasks.
2026-08-10
Shell
★ 11
Claude Pentest Skills is a specialized tool designed for structuring and automating penetration testing workflows within the Claude Code LLM environment. It features modular skill packs that provide comprehensive Active Directory reconnaissance, exploitation, and post-exploitation processes, along with robust functionalities such as checkpointing, parallel execution, and cross-platform support. Notable functionalities include automated evidence capture, JSON reporting, and seamless integration with multiple external tools for enhanced penetration testing efficacy.
2026-08-10
Rust
★ 63
Sherlock-rs is a Rust-based tool designed to hunt down social media accounts by a specified username across over 400 social networks. It provides features such as outputting results to text, CSV, or Excel files, supports proxy usage, customizable site analysis, and extensive debugging options, making it ideal for users needing comprehensive username availability checks across multiple platforms.
2026-08-09
Python
★ 15
IDOR-Auto is an advanced testing tool designed specifically to identify Broken Object-Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR) vulnerabilities by employing differential access testing rather than relying on simple HTTP status codes. It distinguishes itself by utilizing multiple identity responses to determine if one user can access another user's data, while effectively minimizing false positives through robust response comparison, identifier analysis, and support for various input formats. Key features include canary detection, injection point flexibility, identification of encoded IDs, method tampering, and direct raw request importation, making it suitable for authorized security testing in penetration tests and bug bounties.
2026-08-09
Go
★ 23
Credential-Detector is a command-line tool designed to scan project files for hard-coded credentials, including passwords, API keys, and private keys that may have been inadvertently embedded in source code. It supports multiple file types, such as Go, JSON, YAML, and various others, and offers highly configurable scanning options to identify suspicious patterns and variable names while excluding obvious test data. Additionally, it features a web application for enhanced usability and can be integrated as a library within other Go applications.
2026-08-09
★ 155
GitHub-VPS enables developers and security professionals to utilize GitHub Codespaces as a portable virtual private server (VPS), facilitating remote coding environments tailored for penetration testing and CTF challenges. It features high-performance configurations with varying CPU and RAM options, and supports Docker integration for deploying Kali Linux in both headless and GUI modes, allowing flexibility in tool usage depending on the user's needs.
2026-08-08
Python
★ 29
Kryon is an autonomous, local-first cybersecurity agent designed for comprehensive offensive security tasks including compliance audits, penetration testing, vulnerability hunting, digital forensics, and incident response from a single command. It features a skill-based architecture that dynamically loads over 110 playbooks and employs deterministic pre-hooks for critical detections, ensuring that it provides both a thorough assessment and actionable outputs without reliance on external APIs. Additionally, it supports a wide range of compliance frameworks across multiple sectors, making it adaptable for various organizational needs.
2026-08-08
Python
★ 18
WiFi Jammer is an advanced educational penetration testing tool designed for WiFi security assessments, utilizing Python for 802.11 frame injection. It facilitates multiple attack types, including deauthentication, disassociation, and various flooding attacks, while offering rich interfaces through CLI, TUI, and GUI across multiple platforms. Notable features include channel hopping automation, PMKID and WPA handshake capture, and an architectural design grounded in SOLID principles.
2026-08-07
Shell
★ 17
The Sthenos Embedded Toolkit is a comprehensive solution for building static debugging and analysis tools tailored for embedded systems across over 50 architectures. Notable features include support for both musl and glibc toolchains, a range of available tools such as strace and tcpdump, and the capability to compile specific tools for designated architectures using a Docker-based build environment. This toolkit enables streamlined development and troubleshooting for embedded systems, ensuring reliable performance in diverse operating environments.
2026-08-07
Python
★ 10
FTPBuster is a command-line brute-forcing tool engineered for testing the security of FTP, SFTP, and explicit FTPS servers through dictionary-based attacks. Its notable features include support for single username/password and wordlist attacks, real-time progress tracking, multithreading capabilities with a maximum of 50 threads, and automatic handling of UTF-8 encoded wordlists, making it suitable for penetration testing and ethical hacking scenarios.
2026-08-06
Python
★ 11
ONUS is a locally-hosted vulnerability assessment and penetration testing tool designed for conducting comprehensive scans on authorized target domains. It features eight parallel scanning modules that assess various security aspects, employs deterministic CVSS v3.1 scoring for findings, and optionally utilizes AI for generating user-friendly remediation instructions, delivering results in both a PDF report and an interactive web dashboard. This air-gapped solution prioritizes simplicity and security, requiring no external dependencies or user accounts for self-hosted deployments.
2026-08-06
TypeScript
★ 117
Cyberful is an AI-driven application-security workbench designed for authorized penetration testing, code auditing, and bug bounty research. It features robust workflows including pentest phases for evaluating live targets, supports isolated tooling for independent verification, and offers report-ready outputs while maintaining a local-first approach without emitting telemetry. Notably, Cyberful emphasizes trustworthiness in security findings by ensuring actions remain within defined authorization boundaries and by providing detailed evidence tied to each engagement.
2026-08-06
C++
★ 105
FlutterTap is a Zygisk module designed for intercepting network traffic from Flutter applications by redirecting it to a configurable proxy, effectively bypassing BoringSSL's TLS certificate verification without the need for a certificate installation or app repackaging. Its primary use case focuses on persistent traffic interception during mobile application analysis, providing an easy-to-use manager app for selecting target applications and configuring proxy settings. Notable features include automatic operation on device boot, minimal impact on non-selected apps, and the ability to capture native traffic without the drawbacks associated with traditional methods such as Frida or LSPosed.
2026-08-05
Ruby
★ 76
PWN is an open-source Ruby toolkit designed for offensive security automation, integrating various tools used in OSINT, network scanning, and vulnerability testing within a single workspace. Its primary use case is to streamline red teaming and pentesting efforts by providing a unified framework that supports automation through a tool-calling AI agent and a flexible plugin architecture. Notable features include 66 plugins, support for multiple LLM engines, and a feedback loop system that learns from previous mistakes, enhancing the efficiency of security assessments.
2026-08-05
★ 13
Phoenix Deck is an open-source, modular handheld computer designed for students, makers, and ethical hackers, leveraging the Raspberry Pi 5 and a touchscreen interface for educational and hacking purposes. Its notable features include a detachable ESP32 hacking module, extensive modularity for attaching various sensors, and dual boot modes for operating systems like Kali Linux and LineageOS. This device aims to facilitate hands-on learning in cybersecurity and embedded systems while providing tools for ethical hacking and experimentation.
2026-08-05
Python
★ 51
SquidC5 is a cybersecurity team server designed for authorized red team operations and penetration testing, featuring AI-integrated capabilities for enhanced collaboration and task management. Notable features include scoped API tokens, dual AI operational modes, malleable C2 profiles, and a comprehensive engagement console, making it suitable for secure and efficient offensive security operations. The tool emphasizes secure defaults, including TLS encryption and robust auditing features, to ensure a safety-first approach to red teaming.
2026-08-05
Python
★ 10
ExploitBot is an AI-powered penetration testing toolkit designed for autonomous operation on Apple Silicon, enabling users to conduct comprehensive pentests without cloud dependency. Notable features include local LLM inference, three distinct interaction modes (Autopilot, Copilot, Manual), integration with major penetration testing tools, and automatic report generation in multiple formats. Additionally, it supports cross-engagement artifact sharing, a local CVE database, and multilingual interfaces, enhancing efficiency in vulnerability discovery and reporting.
2026-08-05
JavaScript
★ 61
The Cybersecurity Handbook is an interactive, open-source knowledge base tailored for cybersecurity professionals, students, and enthusiasts. It offers over 400 comprehensive notes on diverse topics, enhanced by an interactive knowledge graph, full-text search capabilities, and a user-friendly interface that supports dark/light modes and is mobile-friendly. This community-driven resource keeps pace with the rapidly evolving cybersecurity landscape, providing practical insights into real-world threats and defense strategies without any paywalls.
2026-08-04
Go
★ 25
urlX is a high-performance reconnaissance tool designed for bug bounty hunters, penetration testers, and security researchers. It facilitates passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling, while utilizing Go routines for fast and concurrent processing. Notable features include smart file and extension filtering, minimal setup requirements, and support for enhancing results with optional API keys from various providers.
2026-08-04
★ 335
The Bug Bounty Methodology tool serves as a comprehensive framework for conducting reconnaissance and vulnerability assessment during bug bounty engagements. Its primary use case involves systematically gathering passive intelligence, mapping infrastructure, resolving DNS entries, and performing service detection to identify potential vulnerabilities within a target's domain. Notable features include automated subdomain enumeration, extensive use of command-line tools for data gathering and filtering, and robust utilities for port scanning and web probing, all aimed at uncovering hidden assets and misconfigurations.
2026-08-04
Python
★ 431
Mr.SIP is a console-based SIP security framework designed for auditing and penetration testing of SIP-based systems. It includes three primary modules for network scanning, user enumeration, and Denial of Service (DoS) attack simulations, all leveraging high-performance multithreading and IP spoofing. The tool serves both as a research platform for SIP DDoS attacks and as a practical utility for assessing the security of VoIP infrastructures.
2026-08-03
🍳 The most delicious pentesting tool
2026-08-03
RobustPentestMacro is a versatile Visual Basic macro designed for penetration testing, allowing testers to embed sophisticated post-exploitation techniques into Microsoft Office documents. Key features include platform detection for Windows and MacOS, sandbox evasion mechanisms, WMI persistence for automatic execution at startup, and social engineering tactics to obscure malicious behavior. The macro facilitates easy customization by enabling users to insert tailored payloads through defined functions for both operating systems.
2026-08-03
Citadel is a comprehensive collection of Python and Bash scripts designed for penetration testing tasks. Notable features include automation for Metasploit Framework scripts, DNS graph generation, assembly instruction generation, and various utilities for file handling and data conversion. This tool aims to streamline the workflow of security professionals by providing essential scripts in one repository.
2026-08-03
XRCross is a reconnaissance and penetration testing tool designed for identifying various web vulnerabilities including XSS, SSRF, CORS, SSTI, IDOR, RCE, LFI, and SQLI. Notable features include URL and subdomain enumeration, AWS bucket enumeration, and support for various test parameters, such as command injection and redirection checks. The tool is implemented in Bash and offers a flexible command-line interface with numerous options for detailed vulnerability assessment.
2026-08-03
HomePwn is a pentesting framework specifically designed for auditing Internet of Things (IoT) devices within corporate environments. It features a modular architecture comprising discovery modules for identifying nearby devices and specific modules for testing technologies like WiFi, NFC, and BLE for security vulnerabilities. This foundation allows users to expand its capabilities by integrating additional modules tailored to various technologies.
2026-08-03
Python
★ 6218
Androguard is a comprehensive Python tool designed for analyzing Android files, including DEX, ODEX, and APK formats. Its notable features include disassembling DEX/ODEX bytecodes, a basic decompiler, dynamic analysis support via Frida, and the capability to handle Android's binary XML and resources. The tool is aimed at developers and security researchers looking to assess Android applications for vulnerabilities or conduct reverse engineering.
2026-08-03
GraphQLmap is a pentesting tool designed for interaction with GraphQL endpoints, enabling security professionals to assess and exploit vulnerabilities in GraphQL APIs. Key features include schema dumping, query execution with autocompletion, and capabilities for field fuzzing and both NoSQL and SQL injections. The tool provides extensive options for configuring HTTP requests, making it adaptable for various pentesting scenarios.
2026-08-03
mitmproxy is an interactive intercepting proxy that supports SSL/TLS encryption and enables users to inspect and modify HTTP/1, HTTP/2, and WebSocket traffic through its console interface. Notable features include the command-line tool `mitmdump`, which functions similarly to tcpdump for HTTP traffic, and `mitmweb`, a web-based interface that enhances usability. This tool is particularly useful for developers and security analysts who need to debug and test API calls or web applications.
2026-08-03
PentestGPT is an AI-powered autonomous penetration testing agent designed to streamline the penetration testing process through a multi-stage pipeline that encompasses reconnaissance, exploitation, and reporting. Notable features include session persistence for continued testing, real-time updates during operations, and support for multiple AI models, enhancing its capability for complex challenges across various categories such as web application security and CTF competitions. The tool is modular and extensible, allowing for future enhancements and integration with different AI systems.
2026-08-03
PenTestScripts is a collection of automation scripts designed to assist penetration testers during assessment engagements. Its primary use case is to streamline various tasks typically involved in penetration testing, enhancing efficiency and effectiveness. Notable features include automation for reconnaissance, exploitation, and post-exploitation tasks tailored for security professionals.
2026-08-03
Pickling is a tool designed for creating and executing pickled operating system commands, primarily for use in Capture The Flag (CTF) competitions and penetration testing. It allows users to serialize OS commands into a pickle format, which can then be unpickled and executed directly on the system, posing potential risks if misused. Notable features include an integrated Python server to display incoming POST/GET requests and the ability to execute arbitrary commands securely, emphasizing caution in its usage.
2026-08-03
The "python-pentesting" repository provides a collection of Python scripts designed for penetration testing and red team activities. Key features include tools for remote command execution using WinRM, AWS and Azure data extraction, JWT cracking, network discovery, and web application brute-forcing. This toolkit aims to facilitate various aspects of security testing, making it a valuable resource for cybersecurity professionals.
2026-08-03
Averagesecurityguy/scripts is a comprehensive suite of penetration testing scripts designed to facilitate various security assessments. It includes modules for password brute forcing, cloud service interaction, database testing, OSINT gathering, and more, making it a versatile tool for security professionals. Notable features include the collection's organization by specific tasks such as enumeration, exploitation, and post-exploitation, streamlining the pentesting workflow.
2026-08-03
Fuxi is a cross-platform application designed to facilitate convenient management tasks within Python 3.x environments, including Linux, Mac OSX, and Windows. Its primary use case encompasses service deployment via Docker, enabling users to quickly set up and access the application interface for operational management. Notable features include data persistence through Docker volume management, a simple setup process, and integrated support for MongoDB and Redis as backend services.
2026-08-03
KnowsMore is a cybersecurity tool designed for the analysis and management of NTLM passwords and hashes, particularly within Active Directory environments. It facilitates the importing of NTLM hashes from various sources such as .ntds files and hashcat outputs, and allows for comprehensive password analysis, including strength evaluation and similarity to company names. Notable features include seamless integration with BloodHound for importing data directly to a Neo4j database and generating custom wordlists for password cracking purposes.
2026-08-03
LHF (Low Hanging Fruit) is a modular reconnaissance tool designed for penetration testing, specifically tested on Kali Linux. It enables users to scan a single IP or domain at a time, generating comprehensive output in a designated results folder, including nmap and Arachni files. Notable features include the ability to extend functionality by adding new tools in the Modules folder, domain scanning capabilities, and plans for future enhancements such as IP range scanning and progress indicators.
2026-08-03
The Pentest Tools Framework is a versatile Python-based platform designed for penetration testing, featuring modules for exploits, scanners, and password management. Its notable capabilities include an intuitive command interface to manage various tools, execute modules, and update the framework easily. This comprehensive toolset is geared towards enhancing security assessments by providing a centralized solution for diverse pen-testing tasks.
2026-08-03
SysReptor is a customizable pentest reporting platform that streamlines the creation of penetration test reports for security professionals. It offers features such as HTML report design, Markdown writing support, PDF rendering, and options for self-hosting or cloud deployment, making it an efficient tool for enhancing the reporting process in cybersecurity assessments.
2026-08-03
Crowbar, a brute forcing tool designed for penetration testing, uniquely enables the use of SSH keys for authentication instead of traditional username and password combinations, enhancing the effectiveness of attacks on various protocols. It supports OpenVPN, RDP with NLA, SSH private key authentication, and VNC key authentication, making it versatile for targeting different services. Notable features include the ability to scan target ports, utilize static or list-based passwords, and log successful attempts, all while supporting multi-threading for efficient operations.
2026-08-03
MQTT-PWN is a comprehensive penetration testing tool designed for assessing the security of IoT brokers utilizing the MQTT protocol. It features capabilities such as credential brute-forcing, topic enumeration, and data extraction, all presented within an extensible command-line interface. Notable functionalities include integration with Shodan for discovering vulnerable brokers and a GPS tracker for plotting device locations.
2026-08-03
PENIOT is a penetration testing tool specifically designed for Internet of Things (IoT) devices, enabling both active and passive security attacks to assess vulnerabilities in device connectivity. It features automation capabilities for various attack types, including DoS, fuzzing, and sniffing, and is extensible to support new protocols and customized attacks. The tool addresses the growing security concerns in the rapidly expanding IoT landscape, providing a structured framework for comprehensive vulnerability assessments.
2026-08-03
PEGASUS-NEO is an advanced penetration testing framework that integrates a variety of security tools and custom modules aimed at aiding security professionals and ethical hackers in their assessments. Its primary use case includes reconnaissance, exploitation, and web hacking, supported by notable features such as automated exploitation, vulnerability scanning, and social engineering tools. The framework also provides functionalities for wireless attacks, code scanning, and forensic analysis, making it a comprehensive solution for penetration testing.
2026-08-03
Creds provides a collection of scripts and executables specifically designed for penetration testing and forensic analysis, with a primary focus on Windows and domain environments. Notable features include tools tailored to streamline the assessment of security vulnerabilities in these systems, making it suitable for security professionals and ethical hackers. Users are reminded to adhere to legal guidelines when utilizing these resources.
2026-08-03
IoTHackBot is an open-source IoT security testing toolkit designed for automated vulnerability discovery in IoT devices, IP cameras, and embedded systems. It integrates various command-line tools and AI-assisted workflows for network discovery, device-specific testing, firmware analysis, and hardware interaction, featuring capabilities such as ONVIF device scanning, network traffic analysis, and support for debugging interfaces like JTAG. Notable functionalities include automated credential brute-forcing, APK decompilation, and extensive file extraction for comprehensive security assessments.
2026-08-03
PenTesting-Scripts is a collection of utilities designed for penetration testing, primarily facilitating the encoding of PowerShell commands for execution in a Linux environment. A notable feature includes the ability to convert PowerShell one-liners to Base64 format, enabling stealthy execution of scripts that can be particularly useful for bypassing security measures.
2026-08-03
PowerShell
★ 300
The PowerShell Reverse TCP tool facilitates bidirectional communication between a client and a remote host, enabling the remote host to execute commands on the client system. Designed primarily for educational purposes, it features multiple shell implementations using Invoke-Expression and process pipes, and includes a methodology for script obfuscation to evade detection by security systems. Users can customize IP addresses and port numbers, while future updates aim to enhance shell optimization further.
2026-08-03
PurpleSploit is a modular offensive security framework designed to enhance pentesting workflows with both a command-line interface and a web interface. It focuses on improving efficiency through automated credential management, module selection, and scan analysis, allowing users to execute commands without repetitive typing. Notable features include a context management system utilizing SQLite databases for centralized credential and target management, and an interactive menu for module selection, modeled similarly to the Metasploit framework.
2026-08-03
★ 3527
The Awesome Connected Things Security Resources repository provides a comprehensive collection of security knowledge pertinent to IoT, embedded systems, industrial control systems, and automotive technologies. Its primary use case is to serve as a centralized reference for security practices and tools, featuring over 900 resources that cover various aspects of security, including hardware hacking, firmware analysis, and wireless protocols. Notable features include detailed sections on specific attack methodologies, categorized resources for easy navigation, and community engagement via platforms like Telegram and Discord.
2026-08-03
The "Awesome Node.js for pentesters" repository provides a curated list of Node.js packages tailored for penetration testing, exploitation, reverse engineering, and cryptography. Its primary use case is to serve as a comprehensive toolkit for security professionals, featuring various modules for tasks such as OSINT, network scanning, brute-forcing, and post-exploitation techniques. Notable features include integration with the OWASP ZAP API, access to Shodan and Censys APIs, as well as utilities for geolocation and fingerprinting.
2026-08-03
Cheatsheet-God is a comprehensive collection of resources, scripts, and how-to guides specifically designed to aid individuals preparing for the OSCP certification and general penetration testing. This tool eliminates the need for scattered bookmarks by centralizing valuable information in one repository, fostering community contributions to enhance its content. Notable features include organized resources for various penetration testing topics and easy accessibility, providing a one-stop solution for security professionals.
2026-08-03
CommandoVM is a customizable Windows-based security distribution designed for penetration testing and red teaming, equipped with a wide array of offensive tools that are not typically found in Kali Linux. Notable features include robust installation instructions, a focus on optimizing Windows as an attack platform, and the ability to disable security measures like Windows Defender to ensure a smooth operation. This tool is specifically tailored for users needing a Windows-centric environment for offensive security tasks.
2026-08-03
ezXSS is a specialized tool for penetration testers and bug bounty hunters that facilitates the identification and exploitation of blind Cross-Site Scripting (XSS) vulnerabilities. It features an intuitive dashboard for managing payloads and reports, persistent XSS sessions with reverse proxy capabilities, and comprehensive alerting options via various messaging platforms. Additionally, it provides the ability to collect extensive data from vulnerable pages, making it a powerful asset for security assessments.
2026-08-03
Inveigh is a cross-platform .NET tool designed for penetration testing, specifically enabling IPv4/IPv6 man-in-the-middle attacks. Its primary use case involves intercepting and manipulating network traffic to assess vulnerabilities in target systems, making it a valuable asset for security assessments. Notable features include support for both IPv4 and IPv6 networks, enhancing its versatility in various environments.
2026-08-03
The Pentest Notes repository is a structured collection of educational resources aimed at cybersecurity practitioners, particularly in penetration testing and ethical hacking. It encompasses a range of topics including operating systems, reconnaissance techniques, gaining access, privilege escalation, and data exfiltration, while providing detailed guidance on various tools and methodologies. Notable features include organized notes based on hands-on CTF content and direct links to detailed explanations of specific tools and techniques used in penetration testing.
2026-08-03
The python-pentest-tools repository provides a collection of Python-based utilities specifically designed for penetration testing, vulnerability research, and reverse engineering. Notable features include various tools for network packet manipulation and analysis, subdomain enumeration, and debugging frameworks, all aimed at facilitating the tasks of cybersecurity professionals while promoting legal compliance. The tools integrate with existing C libraries and offer flexible frameworks for testing and exploitation in a user-friendly Python environment.
2026-08-03
The dloss/python-pentest-tools repository offers a curated collection of Python-based tools designed for penetration testing, vulnerability research, and reverse engineering. It includes a variety of utilities for network reconnaissance, packet manipulation, and Active Directory enumeration, with notable features such as integration with existing C libraries for enhanced functionality and a focus on tools that prioritize legal compliance. This repository facilitates the work of whitehat hackers by providing efficient tools tailored for ethical hacking scenarios.
2026-08-03
Awesome-Android-Security is a curated repository aimed at enhancing Android application security through a comprehensive collection of resources, including tools for static and dynamic analysis, forensic analysis, and online APK analyzers. It features a diverse array of blogs, papers, and practical guides designed for developers and security professionals to understand vulnerabilities, implement best practices, and engage in bug bounty programs effectively. Notable features include an extensive checklist, cheat sheets, and links to educational materials that facilitate both analysis and exploitation of security weaknesses in Android applications.
2026-08-03
Awesome Penetration Testing is a comprehensive collection of resources aimed at penetration testers and offensive cybersecurity professionals. Its primary use case is to provide curated tools, utilities, and educational materials across various domains such as network security, malware analysis, and exploit development. Notably, it includes sections on Android and macOS utilities, collaboration tools, and intentionally vulnerable systems, fostering community contributions and knowledge sharing.
2026-08-03
P4wnP1 A.L.O.A. is a pentesting framework that transforms a Raspberry Pi Zero W into an adaptable tool for red teaming and physical engagements. Key features include versatile USB device emulation, advanced HID scripting capabilities, and comprehensive support for Bluetooth and WiFi networking functionalities, allowing seamless execution of complex attacks with real-time configuration management. The tool supports multiple operating interfaces and scripting options, making it highly customizable for various offensive security tasks.
2026-08-03
Burp Suite HTTP Smuggler is a Burp Suite extension designed for penetration testers to effectively bypass Web Application Firewalls (WAFs) and assess their security efficacy using various techniques. It currently features an encoding capability, simplifying the complex manual processes involved and aims for future updates that will introduce additional techniques and bug fixes.
2026-08-03
PwnWiki.io is a wiki-style resource designed to serve as a comprehensive reference for penetration testers and red teamers detailing tools, tactics, and procedures (TTPs) applicable post-access to compromised systems. Notable features include the ability to clone the repository for offline access, enabling users to utilize the wiki in environments without internet connectivity, and an emphasis on community contributions to expand its content.
2026-08-03
Vulnreport is a pentesting management and automation platform that streamlines the reporting process for penetration tests, allowing security engineers to focus on identifying and addressing vulnerabilities. It offers features such as automation throughout the testing stages and customization for integration with other systems. Built with a Ruby Sinatra/Rack stack and using PostgreSQL and Redis for data management, Vulnreport can be deployed locally or on platforms like Heroku.
2026-08-03
FirebaseExploiter is a CLI-based tool designed for the mass scanning and exploitation of insecure Firebase databases. Its key features include the ability to scan multiple hosts for vulnerabilities, upload custom JSON data via a specified URI path during exploitation, and generate results that verify the exploitation of identified vulnerabilities.
2026-08-03
goGetBucket is a reconnaissance tool designed for enumerating AWS S3 bucket names by employing specific patterns and permutations based on a given domain. It identifies bucket permissions (list and write), the region of each bucket, and whether access is entirely disabled, enhancing the assessment of a domain's asset security. Notable features include the ability to utilize a custom wordlist, concurrent processing options, and the integration of mutation techniques for effective bucket discovery.
2026-08-03
HackyFeed is a self-updating GitHub Pages catalog designed for discovering cybersecurity tools by utilizing the GitHub API, SQLite, and an OpenAI-compatible summarization API to generate and publish a curated RSS feed. Its primary use case is to automate the discovery and documentation of new cybersecurity repositories on GitHub, offering features like a comprehensive command-line interface for data fetching, summarizing, and generating static site content with a focus on user-friendly, standards-compliant RSS output. Notable features include a robust database management system, a straightforward build process with Hugo, and the ability to fork the catalog for tailored feeds.
2026-08-03
Go
★ 5116
Hakrawler is a fast web crawler written in Go, designed to gather URLs and JavaScript file locations efficiently. It allows users to crawl single or multiple URLs with options for including subdomains, setting connection timeouts, and sending requests through proxies, making it versatile for reconnaissance tasks in cybersecurity. Notable features include support for custom headers, output in JSON format, and a configurable crawling depth.
2026-08-03
s3enum is a stealthy enumeration tool designed for discovering Amazon S3 buckets using DNS queries to bypass access log tracking. It generates candidate bucket names by combining a specified target name with entries from user-defined word and suffix lists, and allows customization of DNS servers and concurrent workers to optimize enumeration performance. Notable features include the ability to test multiple names simultaneously and the use of different delimiters in bucket name construction.
2026-08-03
Snaffler is a specialized tool designed for penetration testers and red teamers to efficiently discover sensitive files, particularly credentials, across large Windows Active Directory environments. It enumerates accessible file shares and evaluates their contents using a series of predefined patterns to identify potentially valuable data. Notable features include output options for logging findings, adjustable verbosity levels, and various filtering mechanisms to refine the discovery process.
2026-08-03
The UPnP Pentest Toolkit is a security assessment tool designed for evaluating UPnP devices and their associated protocols with ease and minimal configuration. It enables users to discover and interact with UPnP devices on the network, allowing for the enumeration of services and manipulation of device settings. Notable features include a user-friendly GUI that facilitates immediate device identification and a focus on providing proof-of-concept functionalities for research purposes.
2026-08-03
The ESP32 Wi-Fi Penetration Tool is a versatile framework designed for executing various Wi-Fi attacks on the ESP32 platform, facilitating functionalities such as PMKID and WPA/WPA2 handshake capturing, deauthentication, and denial-of-service attacks. It features a user-friendly web-based management interface for configuration, passive traffic sniffing, and the ability to format captured data into PCAP or HCCAPX formats, making it suitable for integration with tools like Hashcat. This tool's extensibility allows users to implement new attack methodologies easily, enhancing its utility in wireless security assessments.
2026-08-03
IntruderPayloads is a curated repository of payloads for Burpsuite Intruder and BurpBounty, as well as fuzz lists and penetration testing methodologies. Its primary use case is to assist security professionals in performing effective web application testing by providing a comprehensive set of attack vectors and methodologies. Notable features include integration with various third-party tools and a detailed OWASP testing checklist to streamline vulnerability assessments.
2026-08-03
The pentesting-dump repository provides a collection of scripts, tools, and proof-of-concepts designed to assist cybersecurity professionals during penetration testing engagements. Its primary use case is to streamline various tasks encountered in penetration testing, facilitating more efficient assessments. Notable features include a diverse range of utilities tailored for different stages of the penetration testing process.
2026-08-03
★ 108
Awesome Infosec is a curated collection of Information Security resources and tools designed to aid individuals in their studies and practices of cybersecurity. It encompasses various topics, including recon, web security, penetration testing, and exploit development, while also providing links to educational courses and labs. The continuously updated repository serves as a valuable resource for both beginners and experts in the field.
2026-08-03
★ 11
AymanSecNotes is a personal compilation of cybersecurity notes in PDF format, primarily serving as a self-study resource for various security domains including mobile, web, and networks. Notable features include plans for future enhancements such as a comprehensive cheatsheet, the transition from PDF to Markdown format, and the inclusion of methodologies and bug hunting tips, aimed at facilitating practical learning and knowledge sharing within the cybersecurity community.
2026-08-03
Shell
★ 167
MIDA - Multitool is a comprehensive Bash script designed for system enumeration, vulnerability identification, and privilege escalation after system compromise. It integrates features from previous scripts like SysEnum and RootHelper, allowing users to gather detailed system information, check for useful utilities, download external tools, and search for potential cleartext credentials. Notably, it provides a robust framework for facilitating various tasks crucial for post-exploitation activities.
2026-08-03
Shell
★ 18
Mobile Heavy Artillery is a comprehensive toolkit designed for red teaming operations, facilitating reconnaissance, exploitation, and privilege escalation tasks. It includes a curated collection of open-source tools for network enumeration, web vulnerability assessment, secrets discovery, and OSINT activities, all easy to install and manage through a makefile. Notable features include a wide range of utilities for various cybersecurity processes, making it a versatile choice for penetration testers and security researchers.
2026-08-03
JavaScript
★ 368
The OSCP repository serves as a centralized resource for individuals preparing for the Offensive Security Certified Professional (OSCP) exam, compiling useful materials from various sources including websites, blogs, and books. Key features include organized sections for methodologies, automation scripts, cheat sheets, and troubleshooting documentation, all formatted for compatibility with Obsidian for enhanced note-taking and visual data representation. While the maintainers are no longer actively updating the repository, it aims to remain a valuable reference for future OSCP candidates.
2026-08-03
Shell
★ 188
PE-Linux is a Linux privilege escalation tool designed to gather extensive system and environment information to identify potential vulnerabilities and misconfigurations. Its primary use case is to assist security professionals in auditing Linux systems for privilege escalation risks through features such as user enumeration, vulnerability checks, log analysis, and the collection of sensitive information like passwords and SSH keys. Notable features include kernel vulnerability checks, cron job enumeration, and detailed system information gathering to facilitate privileged access exploitation assessments.
2026-08-03
Shell
★ 26
SUIDer is a Linux script designed to streamline the privilege escalation process by identifying exploitable binaries with the SUID bit set. It leverages GTFObins to provide relevant exploitation methods and generates links for reference. Notably, it emphasizes caution, as some SUID binaries may require custom methods not covered by the provided resources.
2026-08-03
Python
★ 301
Uptux is a specialized tool for conducting privilege escalation checks on modern Linux systems, focusing on vulnerabilities in systemd units, D-Bus settings, and Unix socket files. Notable features include the ability to identify writable executables, broken symlinks, and overly permissive service configurations without requiring installation, making it convenient for use in restricted environments. The tool runs entirely from a single Python script and provides options for logging and debugging output.
2026-08-03
PowerShell
★ 11
Wconsole is a PowerShell-based tool designed for penetration testing on Windows systems, enabling comprehensive checks of OS versions, configurations, and security settings. It features functions for user enumeration, firewall status, process management, and various privilege escalation checks, making it a versatile hand-script for security testing. The tool can be executed locally or remotely, providing flexibility in assessment execution.
2026-08-03
★ 63
Active-Directory-Exploitation is a comprehensive PowerShell-based toolkit designed for conducting penetration testing and security assessments on Active Directory environments. Its primary use case is to enumerate domains, escalate privileges, enable lateral movement, and achieve persistence through various methodologies, including Kerberos ticket manipulation and exploitation of SQL Server trusts. Notable features include extensive modules for local and domain privilege escalation, detailed methods for lateral movement and persistence, and capabilities for cross-forest attacks.
2026-08-03
★ 14
Cybersec Notes is a comprehensive, expandable checklist aimed at individuals seeking to enhance their knowledge in various cybersecurity domains, including application, mobile, API, and network security. The tool features a structured outline of key topics and vulnerabilities, supplemented with resource links, while encouraging community contributions for continuous improvement and accuracy. Notable aspects include coverage of OWASP Top 10 vulnerabilities across multiple platforms and concepts related to DevSecOps.
2026-08-03
Python
★ 412
EvilTree is a Python3 tool that serves as a standalone remake of the classic "tree" command, enhanced with the capability to search for user-defined keywords or regex patterns within files. Its primary use case is to assist in identifying sensitive information within complex directory structures during post-exploitation enumeration. Notable features include the ability to highlight matches in search results, support for both keyword and regex searches, and an option to filter results to show only files containing matching content.
2026-08-03
CSS
★ 12
The HackTheBox repository contains write-ups detailing the author’s solutions to various HackTheBox machines, primarily aimed at preparing for the Offensive Security Certified Professional (OSCP) certification. Notable features include comprehensive problem-solving approaches and methodologies applicable to penetration testing scenarios.
2026-08-03
★ 11
The Jr Penetration Tester repository provides solutions and an answer key for the Penetration Tester learning path on TryHackMe, aimed at equipping users with essential skills for a career in penetration testing. It covers various critical topics, including web hacking, Burp Suite, network security, vulnerability research, and exploitation techniques using Metasploit. Notable features include comprehensive sections that guide learners through foundational concepts and practical applications in cybersecurity.
2026-08-03
Python
★ 378
Lucifer is a Python-based tool designed for shell manipulation and module management within cybersecurity frameworks. Its primary use case involves automating and simplifying the interaction with different shells and related modules, allowing users to set variables, run exploits, and manage options efficiently. Notable features include dynamic module indexing, the ability to spawn alternate shells, and a comprehensive set of commands for module interaction.
2026-08-03
Python
★ 11
Payloads All The Things is a comprehensive repository offering a curated list of payloads and techniques specifically designed for web application security testing. It includes detailed documentation on various vulnerabilities and how to exploit them, alongside resources for tools like Burp Intruder. Notable features include structured chapters with vulnerability descriptions, applicable payloads, and a collection of methodologies for diverse security scenarios, making it an essential toolkit for penetration testers and security professionals.
2026-08-03
★ 75
Road To Hacking is a comprehensive guide designed for enthusiasts of Ethical Hacking, providing an extensive overview of widely used tools for penetration testing and auditing. Notable features include detailed instructions on tools such as Nmap for vulnerability detection, Metasploit for exploitation, and Aircrack-ng for cracking WPA/WPA2-PSK, among many others. This resource emphasizes practical usage, ensuring users have foundational knowledge in Linux and terminal commands to effectively utilize the tools presented.
2026-08-03
PHP
★ 49
AIO-Pentesting is a comprehensive resource for penetration testers, encapsulating various methodologies, tools, and commands necessary for conducting thorough security assessments. It categorizes content into phases, covering pre-intrusion and intrusion techniques for both Linux and Windows environments, along with additional materials such as notes for certifications like OSCP and OSWE. Notable features include organized documentation on common pentesting stages, forensics, and various exploitation techniques, as well as links to essential vulnerability databases and binary libraries.
2026-08-03
★ 607
The Awesome Windows Red Team repository is a comprehensive collection of resources tailored for Red Team professionals engaging in Windows environments. It encompasses a wide variety of materials including tools, books, courses, and techniques focused on topics such as Active Directory exploitation, lateral movement, privilege escalation, and defense evasion strategies. Notable features include structured categories for efficient navigation, making it suitable for users ranging from beginners to advanced practitioners.
2026-08-03
TypeScript
★ 19
Cloud-audit-mcp is a cloud security auditing tool designed for AI agents to directly interact with cloud APIs, allowing for real-time checks, correlation of findings, and automated remediation of vulnerabilities. Unlike traditional tools that produce static reports requiring human analysis, this tool enables the AI to prioritize issues and generate specific commands for fixes, streamlining the security auditing process across multi-cloud environments such as AWS, Azure, and GCP. Notable features include the ability for the AI to chain checks, assess context, and follow up on remediation efforts without needing to re-scan the whole environment.
2026-08-03
PowerShell
★ 178
CredsHunter is a read-only credential discovery tool designed for authorized post-exploitation activities, efficiently identifying and extracting reusable credentials such as passwords, keys, and hashes while filtering out irrelevant cloud tokens. It operates through a structured five-stage process, scanning various OS credential stores and confirming the presence of valuable file types, ultimately delivering findings in a tiered format that prioritizes critical information. This tool supports both Linux and Windows environments, providing versatile and targeted scanning options without altering the host system.
2026-08-03
★ 23
The Offensive Security Forensics Portfolio is an educational repository showcasing practical skills in cybersecurity, particularly in forensic analysis, penetration testing, and vulnerability assessments. It features detailed documentation of various security techniques, including the implementation of Multi-Factor Authentication for SSH and memory forensics using the Volatility Framework, as well as threat hunting exercises with Splunk. This portfolio serves as a comprehensive example of applied offensive security methodologies within controlled environments.
2026-08-03
Python
★ 80526
Payloads All The Things is a comprehensive repository that provides a collection of useful payloads and techniques for web application security testing. It offers structured documentation on various vulnerabilities, including exploitation methods and payload examples, and is designed to assist penetration testers in identifying and utilizing attack vectors effectively. Notable features include templates for adding new vulnerabilities, integration with Burp Suite Intruder, and a community-driven approach to enhancing its content.
2026-08-03
Python
★ 118
Pentest-Service-Enumeration (PSE) is a terminal-based tool designed for penetration testers, providing a quick-reference library of commands organized by service and enabling interaction with AI/LLM endpoints. Its primary use case is to facilitate service enumeration during penetration testing, while also incorporating fingerprinting and chat functionalities for AI services, aiding both practical application and certification preparation. Notable features include customizable command tracking, multi-technique extraction capabilities, and session isolation for enhanced security during testing operations.
2026-08-03
★ 25
The Pentesting-Methodology repository provides a structured approach to penetration testing, encompassing networking fundamentals, reconnaissance, and analysis techniques. It includes tools for identifying web servers and technologies, brute-forcing subdomains, and performing directory enumeration, making it useful for security professionals looking to streamline their penetration testing workflows. Notable features include detailed networking information and integration with various reconnaissance tools such as Sublist3r and Amass.
2026-08-03
Jupyter Notebook
★ 35
SecOps-CLI Guides is a curated repository providing PDF command-line cheat sheets and how-to guides tailored for security professionals, facilitating offline reference for key cybersecurity tools and techniques. Notable topics include Metasploit, Nmap, SQLMap, and Active Directory attacks, making it a valuable resource for penetration testing and security operations. The repository invites contributions to expand its collection, enhancing its utility for the security community.
2026-08-03
Python
★ 678
SUID3NUM is a standalone Python script designed to identify and exploit SUID binaries on Linux systems, distinguishing between default and custom binaries. Its primary use case is in penetration testing, particularly for scenarios like Capture The Flag (CTF) challenges, where it automates the exploitation of non-default SUID binaries while providing a clear overview of potentially exploitable binaries from the GTFO Bins repository. Notable features include the ability to auto-exploit custom binaries without impacting the system, as well as color-coded output for improved readability.
2026-08-03
★ 12
VulnOS "Legacy" Lab Walkthrough offers a structured environment for foundational penetration testing training, allowing users to engage in practical exercises like reconnaissance, enumeration, and privilege escalation. The lab features guided chapters that simulate real-world scenarios by employing tools such as Nmap and Gobuster, and emphasizes techniques for discovering services, hidden files, and exploiting SUID binaries for privilege escalation.
2026-08-03
HTML
★ 157
The repository contains a collection of writeups detailing solutions and methodologies used in various Capture The Flag (CTF) competitions, including Hack The Box (HTB). Its primary use case is to provide insights and explanations for participants looking to learn from past challenges. Notable features include links to social media for support and engagement, as well as visual representation of stargazers over time.
2026-08-03
★ 34
AIX-for-Penetration-Testers is a comprehensive enumeration guide designed for penetration testers and red team operators focusing on AIX systems. Its primary use case is to facilitate the security assessment of AIX environments through detailed methodologies and tools for effective system enumeration. The repository serves as a collaborative platform for knowledge sharing, allowing users to contribute to the evolving guide.
2026-08-03
C++
★ 207
DNS-Persist is a post-exploitation agent utilizing DNS for command and control, primarily designed for persistence in compromised systems. It features multiple persistence mechanisms including LogonScript, RunKey, and Excel Addin persistence, as well as the ability to execute commands via a pseudo-interactive shell and inject 32-bit shellcode. The tool is built with a Python server-side and a C++ agent, with plans for future enhancements including additional persistence options and encryption capabilities.
2026-08-03
Go
★ 17
A flexible cross-platform post-exploitation agent written in Go with basic functionalities
2026-08-03
Python
★ 181
Poet is a post-exploitation tool that facilitates remote control and management of compromised machines through a client-server architecture. It allows attackers to perform various operations on the target, such as reconnaissance, file exfiltration, remote execution, and self-destruction of the client. Notable features include a control shell for executing commands, automatic reconnection capabilities, and the ability to remove traces post-exploitation.
2026-08-03
C
★ 81
PostShell is a post-exploitation tool designed to facilitate advanced shell access through both bind and backconnect methods, enabling attackers to maintain an interactive TTY session with job control while remaining stealthy. Notably, it features cloaked process names to minimize detection, a compact stub size of less than 14kb for easy deployment on Unix-like systems, and built-in anti-debugging mechanisms to enhance resilience against analysis. The tool's design allows for operation in environments with limited dependencies, improving post-exploitation flexibility.
2026-08-03
C
★ 13
A modular pentesting framework implemented in C
2026-08-03
Python
★ 143
punk.py is a post-exploitation tool designed for network pivoting from compromised Unix systems, facilitating the collection of usernames, SSH keys, and known hosts to establish SSH connections across discovered combinations. It supports both Python 2 and 3, features options for custom execution, password bypass, command execution with sudo, and the capability to crack hashed known hosts, making it versatile for penetration testing and exploitation scenarios.
2026-08-03
Python
★ 263
RSPET (Reverse Shell and Post Exploitation Tool) is a Python-based framework designed for executing remote commands and facilitating post-exploitation activities in penetration testing scenarios. Notable features include TLS encryption for secure server-client communication, built-in file and binary transfer capabilities, support for managing multiple hosts, and a modular code design that allows for extensive customization and plug-in management through a RESTful API.
2026-08-03
Python
★ 435
AdbNet is an exploitation tool designed for identifying and compromising vulnerable Android devices across the globe. Key features include post-exploitation modules, device scanning functionalities, IP address management, and integration with APIs from Censys and Shodan for discovering susceptible devices. Users can connect to these devices through common ports, execute commands, and utilize various exploits to gain control over the target systems.
2026-08-03
Python
★ 46
AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.
2026-08-03
Python
★ 205
Bella is a potent post-exploitation and remote administration tool designed specifically for macOS, leveraging Python for high-level automation and ease of use. Its primary use case involves establishing SSL/TLS encrypted reverse shells to facilitate comprehensive data extraction, including passwords, system information, and iCloud services, while offering features like multi-user support, reverse VNC connections, and extensive logging capabilities. Notably, Bella can gain root access to expand its functionalities and maintain persistent control over the target system, all while operating undetectably.
2026-08-03
Python
★ 50
Bifrost is an open-source command and control (C2) tool implemented as a Discord bot, allowing users to manage and communicate with compromised clients through the Discord API. It supports multiple platforms and provides features such as keylogging, antivirus enumeration, real-time encrypted communication, and file management capabilities. Designed for educational and authorized security testing purposes, Bifrost leverages the Discord infrastructure to maintain a stealthy connection with clients.
2026-08-03
Go
★ 435
Covermyass is a post-exploitation tool designed for penetration testers to securely delete log files across multiple operating systems, including Linux, macOS, and Windows. It enables users to identify and overwrite log files with random data to obscure their activities before exiting a compromised server. Notable features include multiple overwrite iterations and the ability to handle file permissions, ensuring thorough data eradication.
2026-08-03
C#
★ 22
Coyote is a C# post-exploitation implant designed for maintaining access to compromised Windows systems during red team operations. Its notable features include bypassing application whitelisting through InstallUtil.exe, utilizing a recursive DNS tunnel to retrieve encrypted commands, and maintaining a small footprint on both memory and network resources. The tool leverages a DLL that periodically polls a DNS TXT record for remote instructions, allowing operators to execute various payloads, such as spawning a reverse shell, while potentially evading detection.
2026-08-03
Python
★ 47
Crowbar is a comprehensive Windows post-exploitation tool designed to facilitate various tasks such as privilege escalation and system command execution via PowerShell. It includes an extensive range of scripts and utilities, notably the 'Hail Mary' feature for launching multiple scripts simultaneously, and checks for the presence of Windows Subsystem for Linux on the target machine. The tool is actively maintained, with regular updates that introduce new scripts and enhancements to improve functionality.
2026-08-03
Python
★ 36
DeathNote is a penetration testing cheat sheet tool that provides a collection of resources and techniques essential for conducting security assessments. Its primary use case is to streamline the penetration testing process by offering organized references for various attack vectors, including reverse shells, PowerShell exploits, Active Directory, brute-forcing, and persistence methods. Notable features include compatibility with both Python 2.7 and 3.7, straightforward installation, and customizable configurations.
2026-08-03
C#
★ 326
Evasor is an automated security assessment tool designed for Windows that identifies executables with potential vulnerabilities for bypassing Application Control rules. It offers features such as locating processes vulnerable to DLL Injection and DLL Hijacking, as well as generating detailed assessment reports inclusive of descriptions, screenshots, and mitigation suggestions. This tool caters to both blue and red teams, enhancing efficiency during the post-exploitation assessment phase.
2026-08-03
Python
★ 78
HackingComm is a user-friendly penetration testing tool designed for individuals with limited terminal command knowledge. It simplifies common pentesting tasks on Kali Linux through a straightforward interface, allowing users to easily input required parameters while executing commands. Notable features include an installation script, guided prompts for user inputs, and reliance on Python for functionality, making it accessible for beginners in cybersecurity.
2026-08-03
Python
★ 233
iPwn is a framework specifically designed for the exploitation of jailbroken iOS devices, enabling users to gain access and extract sensitive information. It incorporates a post-exploitation tool named 'iSteal', which offers various modules for information harvesting and management, including SSH brute-forcing capabilities using common credential wordlists. Notably, the framework is still under development, with ongoing enhancements for easier payload management and integration with existing iOS tweaks.
2026-08-03
Ruby
★ 245
Leprechaun is a penetration testing tool that facilitates the identification of valuable targets within an internal network by aggregating netstat results from multiple hosts. Its primary use case involves analyzing network traffic connections to uncover potential vulnerabilities and traffic patterns, and it features command-line options to specify output files, ports of interest, and IP address types. Notable features include the ability to output detailed connection statistics organized by server and traffic destination ports, enhancing visibility for security assessments.
2026-08-03
AutoIt
★ 452
OffensiveAutoIt is a collection of proof-of-concept scripts leveraging AutoIt v3 for offensive security purposes, focusing on UI automation and the execution of external code. The repository includes features for compiling scripts into standalone executables, decompiling AutoIt binaries, and obfuscating scripts, facilitating the development of malware and tradecraft research. Its notable use cases involve executing PowerShell and .NET assemblies while bypassing security mechanisms like AMSI and ETW.
2026-08-03
PowerShell
★ 12
PentaDrone is an asynchronous PowerShell post-exploitation agent designed for red teaming and penetration testing, utilizing the Mitre Att&ck framework for automation through an autopilot mode. It allows security researchers to simulate HTTP loader-style botnets, facilitating malware research while providing extensive configurability for command-and-control server connections and agent behavior. Notable features include various persistence methods, USB spreading options, and customizable operational parameters.
2026-08-03
PowerShell
★ 28
Powerexploit is a PowerShell-based exploitation framework designed to facilitate offensive post-exploitation tasks in Windows environments. It enables security professionals to automate the process of gaining and maintaining access to targets, quickly exfiltrating sensitive information, and leveraging vulnerabilities within the system. Notable features include a modular architecture for plugins, support for various attack vectors, and inherent obfuscation techniques to evade detection by security tools.
2026-08-03
C++
★ 300
TokenPlayer is a tool designed for manipulating and abusing Windows access tokens, focusing on the Win32 API. Its primary use case includes stealing and impersonating tokens, bypassing User Account Control (UAC) via token duplication, and creating new tokens for network authentication without elevated privileges. Notable features include the ability to execute applications under an impersonated context, spoof parent process IDs, and operate within non-interactive environments, making it suitable for various privilege escalation and security testing scenarios.
2026-08-03
Python
★ 22
GOD-OF-RAT is an advanced Python Remote Access Trojan (RAT) framework designed for authorized penetration testing, offering extensive control over compromised systems. Its notable features include live screen controlling, credentials harvesting from various sources, an interactive agent builder with encryption capabilities, and advanced evasion techniques. The framework also supports remote shell access, file system management, and a suite of fun modules for additional functionalities.
2026-08-03
★ 30
The Hacker Road Map repository provides a comprehensive overview of resources and tools necessary for learning penetration testing and practicing ethical hacking. It features a categorized collection of UNIX-compatible, free, and open-source tools, along with guidance on essential concepts, basic steps of penetration testing, and additional educational materials to support newcomers in the field of information security. Notably, the project has been archived, indicating that the content may be outdated as a new initiative is anticipated to replace it.
2026-08-03
★ 34
The Metasploit-Tutorial repository provides comprehensive guidance on utilizing the Metasploit framework, a robust open-source toolset designed for network enumeration, vulnerability identification, and exploit development. Users can learn key functionalities such as exploit execution, payload creation, and post-exploitation techniques through detailed sections covering various components and workflows of Metasploit. Notable features of the tutorial include practical exercises with modules, sessions, and Meterpreter commands, enabling hands-on experience with real-world cybersecurity tasks.
2026-08-03
Python
★ 516
MsfMania is a Python-based payload obfuscation framework primarily aimed at evading endpoint detection and antivirus systems on Windows platforms. It boasts notable features such as dynamic code generation, multi-layer encryption using RC4, local memory injection, and extensive metadata spoofing, making it suitable for authorized security testing and research activities.
2026-08-03
Python
★ 459
PivotSuite is a network pivoting toolkit designed for Red Teamers and penetration testers, enabling the movement within a compromised network using either forward or reverse connections. Notable features include support for TCP tunneling, SOCKS5 proxies, and various network enumeration functions, all without requiring administrative access on the compromised host. The tool operates independently of installation requirements, utilizing only Python's standard libraries, making it versatile across different platforms and environments.
2026-08-03
PowerShell
★ 15
Powtel is a remote system control tool designed for Windows environments, utilizing PowerShell and Telegram as its communication interface. Its primary use case is for authorized security testing and post-exploitation activities, providing features such as task scheduling, file upload/download capabilities, and screenshot functionality. The tool emphasizes ethical usage, aiming to aid cybersecurity professionals and researchers in controlled settings.
2026-08-03
Python
★ 67
PyADRecon is a Python-based tool designed for gathering comprehensive information from Microsoft Active Directory environments, catering to the needs of penetration testers and blue teams. It supports NTLM and Kerberos authentication methods, can generate XLSX reports, and offers an HTML dashboard for visualizing collected data, making it a versatile resource for Active Directory reconnaissance. Additionally, it provides options for standalone report generation from CSV files, enhancing its usability in various assessment scenarios.
2026-08-03
Python
★ 326
PyIris is a modular remote access trojan (RAT) toolkit implemented in Python, designed for the dynamic creation, encoding, and encryption of RAT payloads to facilitate the remote control of compromised systems. Its notable features include cross-platform compatibility for both Windows and Linux, robust error handling, dynamic payload generation, and advanced functionalities such as keylogging, webcam access, and file manipulation, making it a versatile tool for malicious actors. The ongoing development aims to enhance its capabilities further with improved encryption methods and operational persistence techniques.
2026-08-03
Python
★ 50
Reave is a post-exploitation framework developed for hypervisor endpoints, designed to facilitate automated penetration testing in heavily virtualized environments. This Python-based tool operates on a listener/agent model, offering features such as real-time interactive terminal sessions, automatic hypervisor enumeration, and modular payloads for tasks including exfiltration and persistence. Notably, Reave supports versatile configurations for agents, enabling comprehensive control over operations and network interactions.
2026-08-03
HTML
★ 13
RedVision is a collection of custom-designed HTML user interfaces specifically intended for Command & Control (C2) systems. Its primary use case is to enhance the operational efficiency of security professionals by providing a visually appealing and functional interface for managing C2 capabilities. Notable features include an array of templates, each visually distinct, allowing for flexible customization to suit various C2 deployment scenarios.
2026-08-03
PHP
★ 78
ReHTTP is a PowerShell-based HTTP shell that features a web user interface, designed primarily for remote management and control of clients on a Windows platform. Key functionalities include executing PowerShell commands, managing client connections, and creating custom modules and variables, along with sophisticated event handling capabilities for connection management. This tool also supports scheduled tasks and offers a history feature for command execution, enhancing its usability in system administration and penetration testing contexts.
2026-08-03
Shell
★ 14
Rogue is a bash script that automates penetration testing workflows by integrating tools such as Nmap, Metasploit, and John the Ripper. It streamlines the scanning, exploiting, and reporting phases of pentesting, providing a modular and customizable experience for security professionals. Notable features include automated scans, exploitation configuration, credential harvesting, and structured report generation, all initiated with a simple input of a target IP address.
2026-08-03
Rust
★ 29
RustVersary is a comprehensive toolkit designed for malware development and penetration testing using the Rust programming language. It includes a variety of tools and scripts that facilitate tasks such as enumeration, exploitation, and post-exploitation, each thoroughly documented to aid both personal use and community contributions. Notable features include advanced techniques for process injection, persistence mechanisms, and a structured catalog of utilities tailored for security assessment challenges.
2026-08-03
PowerShell
★ 33
Sh3ller is a lightweight command-and-control (C2) framework designed for managing incoming reverse shells via PowerShell. Its primary use case is to maintain persistent access to compromised systems, allowing users to manage multiple shell sessions simultaneously with minimal dependencies. Notable features include an always-on listening mode, support for various reverse shell payloads, and intuitive session management commands.
2026-08-03
Go
★ 10
Silkwire is a gRPC-based Command and Control (C2) framework designed for authorized penetration testing and red team operations. It supports multiple platforms (Windows, Linux, macOS) and offers advanced features including dynamic implant generation, post-exploitation modules, keylogging, and enhanced evasion techniques against detection mechanisms. The tool emphasizes encryption for communications and session management, making it a robust option for security professionals in performing comprehensive security assessments.
2026-08-03
★ 28
The FreeZeroDays/TTPs repository serves as a curated collection of offensive security notes, focusing on Tactics, Techniques, and Procedures (TTPs). It provides a repository of validated commands and resources targeted towards researchers and practitioners in offensive security. Notably, the documentation emphasizes accuracy and reliability, and it draws inspiration from other established collections in the field.
2026-08-03
Go
★ 395
XENA is a cross-platform cybersecurity automation framework designed for adversary simulations and red team operations, featuring a built-in post-exploitation agent and a command-and-control (C2) server. Notable features include an elegant dark-themed user interface that supports desktop, web, and mobile formats, along with high-level automation capabilities for orchestrating C2 clusters. This community edition serves as an integrated tool for penetration testing, facilitating a comprehensive approach to security assessment.
2026-08-03
JavaScript
★ 141
ZeroPulse is a modern Command & Control (C2) platform designed for secure remote management and monitoring of systems, utilizing Cloudflare Tunnel technology for encrypted connections. Key features include built-in authentication, support for WinRM and SSH interactions, a responsive React interface with real-time terminal integration, and comprehensive DNS management. The tool is currently in active development and is intended primarily for testing and evaluation purposes.
2026-08-03
Shell
★ 10
Delebetor is a utility designed for installing and managing penetration testing tools by organizing them based on their installation methods, such as `apt` packages and `git` repositories. Notable features include detailed per-tool installation status reporting, a dedicated toolset for web assessments, and a secure deletion option that requires confirmation to clean up installed tools and history. The tool is intended for interactive or command-line use on `apt`-based distributions like Kali Linux, Debian, or Ubuntu.
2026-08-03
Python
★ 1386
AutoCVE is an automated tool designed for end-to-end CVE discovery, encompassing project screening, source code auditing, vulnerability verification, and report generation. Its notable features include a multi-agent collaborative auditing system and flexible auditing modes tailored for different objectives, enabling efficient management of vulnerability assessment through structured automated workflows. The tool simplifies the CVE reporting process, allowing users to easily submit their findings after a comprehensive auditing experience.
2026-08-03
TypeScript
★ 1278
LuaN1aoAgent is an advanced cognitive-driven autonomous security agent that enables authorized security research through its distinct Planner, Executor, and Observer roles. The tool operates using a robust graph memory system that ensures traceability of actions and decisions based on permanent artifacts and events, fostering an environment of observability and accountability. Key features include its separation of responsibilities for effective task management and the capability to perform autonomous actions while preserving evidence and insights from operations.
2026-08-03
Go
★ 74
Hadrian is an open-source API security testing framework designed to detect OWASP API Top 10 vulnerabilities in REST, GraphQL, and gRPC APIs, focusing specifically on authorization-related flaws. It features role-based authorization testing using YAML-driven templates, which enables users to define roles with permissions once and automatically conduct cross-role access checks. Additionally, Hadrian employs mutation testing methodologies to confirm the existence of write/delete vulnerabilities and offers multiple output formats for reporting findings.
2026-08-03
Go
★ 127
Vespasian is an API discovery and specification generation tool that observes real HTTP traffic to identify API endpoints and automatically generates specifications in OpenAPI, GraphQL SDL, and WSDL formats. Designed for penetration testers and security engineers, it captures traffic through headless browsers or imports data from existing traffic dumps, utilizing classification heuristics and active probing to effectively map the API surface of applications where documentation is scarce. Notable features include REST, GraphQL, WSDL, and gRPC discovery, automatic API type detection, and support for dynamic content generated by single-page applications.
2026-08-03
★ 17
The 'suspicious_IPs' repository provides a compiled list of potentially malicious or harmful IP addresses. Its primary use case is for cybersecurity professionals to enhance threat detection and mitigation measures by identifying and blocking traffic from these suspicious IPs. Notable features include a straightforward format that allows for easy integration into firewall rules and intrusion detection systems.
2026-08-03
JavaScript
★ 62
areclaw is an automated command-line environment designed for Android application security analysis, enabling tasks such as decompilation, traffic interception, dynamic instrumentation, secret scanning, and API discovery. It leverages an AI-driven orchestrator, Claude Code, to streamline the analysis process, and includes an automated installer for essential tools, a structured workspace for outputs, and various utility scripts for enhanced interaction and reporting.
2026-08-03
C++
★ 110
Open Test Drive Unlimited (OpenTDU) is a source port for the PC version of Test Drive Unlimited, aimed at enhancing compatibility with modern systems by addressing issues related to AI, rendering, and security while providing cross-platform support. This tool allows users to run the game on Windows, Linux, and macOS, necessitating a legal copy of the original game assets. Notable features include a debug menu, command line options for various game modes, and a structured approach to ongoing project development status.
2026-08-03
Rust
★ 77
`flutterdec` is a static analysis tool designed for decompiling Flutter applications packaged as APKs or `libapp.so` files, specifically targeting Android ARM64 binaries. Its primary use case is for reverse engineering Flutter apps, providing readable pseudo-Dart code along with additional artifacts such as intermediate representation (IR), assembly, and symbol reports to aid in validation against lower-level codes. Notable features include the ability to extract and compare builds, enhance symbol naming from matched binaries, and various output options for deeper analysis.
2026-08-03
JavaScript
★ 11456
Detect It Easy (DiE) is a versatile file type identification tool designed for malware analysts and cybersecurity experts, employing both signature-based and heuristic analysis to deliver accurate file inspections across Windows, Linux, and MacOS platforms. Its key features include flexible signature management for customizable detection rules, a JavaScript-like scripting capability for tailored analysis, and a comprehensive support for various executable and archive formats. The tool aims to minimize false positives, making it an essential resource for digital forensics and malware detection.
2026-08-03
Python
★ 17
TryHackMeWriteups is a comprehensive repository that curates free TryHackMe rooms, providing organized resources for cybersecurity enthusiasts to learn and practice various skills. Notable features include categorized rooms across diverse topics, detailed notes and summaries, step-by-step writeups for Capture The Flag challenges, and continuous updates, making it an ideal starting point for beginners in cybersecurity and ethical hacking.
2026-08-03
★ 73
The "Beginners Guide to Ethical Hacking" is a comprehensive educational resource aimed at individuals with no prior knowledge of ethical hacking. It systematically guides users through key phases, including setting up a virtual lab, information gathering, scanning, gaining access, maintaining access, and reporting. Noteworthy features include clear disclaimers about legal compliance, an emphasis on white hat hacking principles, and open contributions from the community for collaborative learning.
2026-08-03
Dockerfile
★ 76
Bento is a lightweight Docker container designed for penetration testers and Capture The Flag (CTF) players, providing a minimalistic environment with essential tools for web and infrastructure security testing. It supports GUI applications via X forwarding, allowing users to seamlessly run tools like Burp Suite, and includes collaborative features through an embedded code-sharing pad (CodiMD). Notable features include minimal bloat, portability, and customizable deployment options via Docker Compose.
2026-08-03
Python
★ 21
cryptz is an advanced encryption and decryption tool designed for secure data handling. Its primary use case involves encrypting sensitive information to prevent unauthorized access, and it features a user-friendly command-line interface to facilitate easy implementation. The tool is built using Python, with dependencies managed via a requirements file.
2026-08-03
Python
★ 291
jwtXploiter is a security testing tool designed to assess the vulnerabilities of JSON Web Tokens (JWTs). It enables penetration testers and developers to exploit known CVEs, manipulate token payloads, verify JWTs, and perform key confusion attacks by retrieving public keys from SSL connections. Notable features include support for all JWT algorithms, automated generation of JSON Web Keys (JWK), and the ability to tamper with vulnerable header claims like kid, jku, and x5u.
2026-08-03
Shell
★ 32
The Pentest Tools Installation Automator streamlines the setup of essential penetration testing utilities on both Debian- and Arch-based systems. It not only installs critical tools such as `nmap`, `sqlmap`, and `gobuster`, but also provides commonly used wordlists directly in the installation process. The tool supports optional installations for additional resources, enhancing flexibility for users in security assessments.
2026-08-03
Python
★ 17
A tool for fuzzing for ports that allow outgoing connections
2026-08-03
Python
★ 16
SSH Brute-Force is a simple Python script designed for brute-forcing SSH credentials against an OpenSSH server. Its primary use case is for ethical hacking and penetration testing, specifically within environments like HackTheBox. Notable features include the ability to execute commands upon successful authentication and the requirement of the pwntools library, though it is advised that users enhance its functionality to mitigate potential defenses against brute-force attacks.
2026-08-03
★ 13
This repository houses a collection of writeups for various Capture The Flag (CTF) challenges on the TryHackMe platform. The writeups cover a diverse range of scenarios, including penetration testing, web vulnerabilities, and privilege escalation, utilizing tools such as `nmap`, `gobuster`, and `metasploit`. Users can gain insights and methodologies for tackling CTF challenges while also having access to a more visually appealing format via GitHub Pages.
2026-08-03
PowerShell
★ 120
xeca is a tool designed for creating encrypted PowerShell payloads intended for offensive security applications. It enables users to develop position-independent shellcode from DLL files and integrates an AMSI bypass feature for enhanced stealth. Key functionalities include encryption of payloads, remote execution capabilities, and retrieval of decryption keys via a controlled web server.
2026-08-03
PHP
★ 84
YAPS is a lightweight PHP reverse shell that operates as a single file, allowing users to execute commands on remote systems through a TCP listener. It features customizable password protection, enumeration capabilities for gathering system information, and the ability to manage concurrent connections and execute PHP code remotely. Notably, it can auto-download enumeration tools, exploit known vulnerabilities like CVE-2021-4034, and send shellcode to the target host while supporting operations on both Linux and Windows in future updates.
2026-08-03
Python
★ 37
The bug-bounty-tips repository provides a comprehensive collection of resources and tools tailored for bug bounty hunters. It includes a curated list of required scripts and tools like Amass, SQLMap, and Fuff, facilitating efficient reconnaissance and vulnerability assessment. The repository emphasizes community engagement through platforms like Telegram and Twitter, aiming to enhance knowledge sharing among cybersecurity professionals.
2026-08-03
★ 50
CheatSheet is a comprehensive resource for penetration testers and bug bounty hunters, providing a collection of tools, scripts, and guidelines to streamline various phases of security assessments. It features an extensive list of useful utilities for tasks such as network scanning, web application testing, reverse shell creation, and data encoding, along with guidelines for setting up local web servers. The repository also includes planned features aimed at automating repetitive tasks and enhancing the efficiency of reconnaissance activities in cybersecurity engagements.
2026-08-03
Python
★ 19
dfuf is a tool designed to extract files from the request and response dumps generated by ffuf, which is primarily used for exploiting Local File Inclusion (LFI) and Directory Traversal vulnerabilities. Notable features include the ability to specify output directories and handle various file extraction scenarios, such as extracting common Linux files and accessing files in webroot through URL double encoding. This tool enhances the data exfiltration process when shell access is not feasible.
2026-08-03
Python
★ 45
Flask Unsign Wordlist is a lightweight Python package designed to provide standalone access to a collection of wordlists used for unsigning Flask cookies. Its primary use case is to assist developers and security professionals in recovering secret keys without having to download the entire flask-unsign library. Notable features include easy installation via pip, command-line access to wordlists, and straightforward Python integration for obtaining lists programmatically.
2026-08-03
Python
★ 68
GrepAddr is a versatile command-line tool designed to extract a wide variety of address types from standard input, including URLs, IP addresses, e-mail addresses, and MAC addresses, utilizing regular expressions for processing. Its primary use case is for penetration testing and bug bounty hunting, where users need to quickly identify multiple address formats in data streams. Key features include support for filtering by address type, options to reduce false positives, and the ability to save results in CSV format, making it a comprehensive solution compared to similar tools that focus on single address types.
2026-08-03
Python
★ 11
Haipy is a command-line interface (CLI) tool designed for identifying over 500 types of hash algorithms. This Python port of the original "haiti" tool includes support for modern hashing algorithms such as SHA3 and Keccak, can be utilized as a Python library, and provides references to Hashcat and John the Ripper, making it a flexible option for cybersecurity professionals. Notably, Haipy aims to be hackable, allowing users to extend its functionality as needed.
2026-08-03
Common Lisp
★ 10
LSP Reverse Shell is a Lua Server Pages-based webshell designed for Windows, facilitating remote shell access via SMB shares instead of traditional Lua sockets. Its primary use case is for penetration testing and exploit development, circumventing common restrictions by executing reverse connections through port 135. Notable features include in-memory execution, compatibility with impacket's smbserver, and the flexibility to easily configure IP addresses for deployment.
2026-08-03
Python
★ 66
NoSQL-Attack-Suite provides automated scripts designed to exploit vulnerabilities in NoSQL databases, specifically targeting authentication bypass and credential enumeration. The tool features two primary scripts: one for identifying NoSQL authentication bypass vulnerabilities in login forms, and another for character-by-character credential dumping from the database when such vulnerabilities are present. Both scripts are tailored for testing against specific configurations, such as those found in HackTheBox challenges.
2026-08-03
Python
★ 39
The `padding_oracle.py` tool automates padding oracle attacks in Python, enabling efficient decryption and encryption of vulnerable tokens. It features multi-threaded execution for improved performance, customizable logging options, and includes additional functionalities for URL and base64 encoding/decoding. This tool is particularly useful in penetration testing scenarios where padding oracle vulnerabilities are present.
2026-08-03
Python
★ 10
The `python4pentesters` repository provides a toolkit designed for automating various tasks related to penetration testing, inspired by TryHackMe's "Python for Pentesters" room. Key features include tools for subdomain discovery, directory enumeration, network scanning, port scanning, file downloading, and password cracking, all of which can be modified for specific security engagement needs. The package serves as a foundational codebase for developing hacking scripts with improved console output and usability.
2026-08-03
Python
★ 18
Reverge is a Python-based tool designed for extracting and converting hexadecimal data from files, primarily utilized in Capture The Flag (CTF) competitions within the forensic category. Key features include support for file extraction and conversion between hexadecimal and binary formats, making it a valuable asset for digital forensics practitioners and enthusiasts.
2026-08-03
Python
★ 13
ShellValley is a user-friendly reverse shell generator tool designed for Capture The Flag (CTF) enthusiasts who require quick shell generation directly from the terminal. It supports multiple reverse shell types, including bash, php, python, and many others, allowing users to specify the shell type, IP address, and port easily through a command-line interface. The tool emphasizes educational use, warning against illegal activities and ensuring adherence to regulations.
2026-08-03
★ 11
Sobbu is a versatile cryptography tool that provides various encoding and encryption algorithms, along with a hash cracking utility designed to enhance cybersecurity tasks. Notable features include a user-friendly GUI, support for multiple platforms (Windows and Linux), and a wide range of algorithms, including classic ciphers and modern encryption methods. It also includes functionalities for hash decryption and a RainbowTable bot for efficient hash cracking.
2026-08-03
Java
★ 697
BerylEnigma is a comprehensive CTF and penetration testing toolkit designed to perform a variety of encryption, coding, and text manipulation functions. It features modern and classical cryptographic methods, encoding formats, and practical utilities including image processing and Red Team capabilities such as reverse shell generation and payload conversion. Built with JDK17 and the JAVAFX framework, it aims to assist security professionals and researchers with a wide range of functionalities in a user-friendly interface.
2026-08-03
Python
★ 31
brutalkeepass is a Python tool designed to brute force passwords of KeePass database files, particularly useful when other conversion methods to supported formats fail. It utilizes the pykeepass library, supports command-line argument input for specifying the database and wordlist, and can produce verbose output and entry dumps upon successful password retrieval.
2026-08-03
★ 10
The CTF Resources repository is a comprehensive collection of cybersecurity tools and practice platforms specifically designed for Capture the Flag (CTF) competitions. It includes an extensive array of tools categorized into areas such as Open Source Intelligence (OSINT), steganography, and anonymous communication, offering functionalities from data gathering and analysis to secure and anonymous internet browsing. Notable features include links to various open-source tools, detailed descriptions, and categorization for ease of use, supporting users in enhancing their digital security skills.
2026-08-03
Python
★ 661
Flask Unsign is a command-line tool designed for extracting, decoding, and manipulating Flask session cookies by brute-forcing secret keys. Its primary use case revolves around security testing of Flask applications, enabling users to obtain and decode session data either through direct input or automatic server interactions. Notable features include session cookie decoding, secret key brute-forcing, and the ability to create custom signed session data if the secret key is known.
2026-08-03
Python
★ 316
HackSynth is a sophisticated LLM-based agent designed for autonomous penetration testing using a dual-module architecture comprising a Planner and a Summarizer. Its primary use case is to conduct security assessments, and it is benchmarked against two extensive CTF-based datasets derived from PicoCTF and OverTheWire, featuring 200 diverse challenges. Notable features include its iterative command generation and feedback processing capabilities, enabling comprehensive evaluation of LLM penetration testing agents.
2026-08-03
PHP
★ 418
Karkinos is a lightweight penetration testing tool designed for ethical hacking and CTF competitions, offering functionalities such as encoding/decoding, encryption/decryption, and hash cracking/generating. It features three distinct modules and includes a new port scanning demo, allowing users to test applications and networks they have authorization to assess. Built primarily using PHP and Python, Karkinos is compatible with any server capable of hosting PHP and is designed to be Raspberry Pi Zero friendly.
2026-08-03
Python
★ 12
Live Exploit is a comprehensive Python-based tool tailored for Capture The Flag (CTF) challenges, exploit development, and vulnerability research. It offers a rich feature set including buffer overflow payload generation, ROP chain creation, fuzzing, and interactive command execution, all presented through an intuitive command-line interface. This all-in-one toolkit is designed for both novice and advanced users, streamlining numerous exploit-related tasks while being cross-platform compatible.
2026-08-03
HTML
★ 646
The Reversing Bits Cheatsheets repository serves as a comprehensive resource for assembly programming, reverse engineering, and binary analysis tools. It includes in-depth guides on installation, usage examples, and advanced tips for a variety of tools, such as assemblers, debuggers, disassemblers, and binary analysis frameworks, catering to different operating systems and user needs in the field of cybersecurity. Notably, it features prominent tools like Ghidra, IDA Pro, and GDB, making it a valuable reference for professionals involved in security and malware analysis.
2026-08-03
Shell
★ 392
TryHackMe is a free cybersecurity learning path designed to advance users from novice to expert through a range of practical exercises, introductory Capture The Flag (CTF) challenges, and educational modules covering topics like OpenVPN, Linux fundamentals, web scanning, and Metasploit. This resource is suitable for both newcomers to the field and those looking to enhance their skills, and it culminates in a comprehensive foundation in cybersecurity, preparing users to address more complex challenges. Notable features include diverse content formats, hands-on labs, and accessible learning materials to foster practical experience in cybersecurity practices.
2026-08-03
Lua
★ 47
The Cheat Engine MCP Bridge — TCP Enhanced Edition is a tool that facilitates remote control of Cheat Engine via a native C TCP bridge, eliminating the need for Python's pywin32 dependency and supporting multiple instances. Key features include built-in remote access via environment variables, improved stability with auto-reconnect capabilities, and a dedicated diagnostic console, making it a more versatile and reliable option compared to the original fork.
2026-08-03
Python
★ 21
FTP Scanner is a lightweight tool designed for penetration testing and Capture The Flag (CTF) challenges, capable of detecting anonymous logins, listing files, and performing banner grabbing. It features heuristic software and version extraction, alongside a local exploit database lookup for identifying potential vulnerabilities based on the FTP server's banner. This portable tool operates as a single Python script, requiring minimal dependencies and offering customizable usage options, including the ability to specify custom ports and vulnerability database paths.
2026-08-03
Go
★ 66
goLoL is a Windows host scanner that specializes in detecting living-off-the-land binaries (LOLBAS) and vulnerable drivers (LOLDrivers) by leveraging a live catalog of techniques and hashes. It provides privilege-aware filtering based on the user's access level and includes features like MITRE ATT&CK mapping, flexible result sorting, and both LOLBAS and driver scanning modes. The tool is designed for security professionals to enhance their understanding of potential attack vectors within a Windows environment.
2026-08-03
★ 97
Infosec-Notes is a repository that serves as a comprehensive collection of notes tailored for penetration testers and ethical hackers, documenting the author's learning journey towards OSCP certification and beyond. It provides insights into various offensive and defensive security techniques, including red teaming, enumeration, privilege escalation, and CTF challenge strategies, while also encouraging community contributions to enhance the content. Notably, the notes encompass practical coding examples and highlight essential cybersecurity practices, with a strong emphasis on responsible hacking.
2026-08-03
Python
★ 19
NagoyaSpray is a Python-based tool designed for efficient password spraying, particularly in scenarios like OSCP, PNPT, and CPTS exams. It generates customizable password lists based on seasonal and date-related formats, enabling users to quickly create realistic passwords without the need for complex regex. Key features include the ability to specify prefixes and suffixes, control capitalization, and generate passwords within a defined length, ensuring rapid and effective password testing for various applications.
2026-08-03
★ 15
nmap-reference serves as a comprehensive reference guide for the nmap tool, aimed at both CTF participants and security professionals. It includes a variety of predefined scan combinations, practical flag references, and complementary tools, facilitating efficient network discovery and vulnerability assessment. Key features encompass easy navigation through common nmap commands, scan types, and detailed explanations of scan parameters to streamline penetration testing workflows.
2026-08-03
Python
★ 14
pypentesting is a collection of Python scripts designed to assist with penetration testing, Capture The Flag (CTF) challenges, and various information security tasks. Its notable features include a reverse shell generator, shellcode extraction tool, and utilities for processing directory search results, QR code handling, DNS zone transfers, and more. The repository serves as a useful resource for security professionals seeking to streamline their testing processes and automate common tasks.
2026-08-03
Python
★ 10
WShell transforms web-based command injection vulnerabilities into interactive shells with features such as persistent command history, directory navigation, and file transfers, all while avoiding any file uploads. It automatically detects the target's operating system and adjusts its operations accordingly, providing flexibility in command execution. Notable features include built-in support for HTTP control, extensibility via custom scripts, and efficient handling of input/output for bypassing filters.
2026-08-03
★ 90
The Ultimate Cybersecurity Roadmap is a comprehensive guide designed to facilitate the learning journey from novice to advanced cybersecurity professional. It encompasses structured learning paths, hands-on projects, and certification guidance, along with essential resources for skill development in various cybersecurity domains. Notable features include a focus on technical foundations, real-world interview preparation, and a curated list of tools and platforms relevant to the field.
2026-08-03
★ 29
The Ai-Prompts tool serves as a comprehensive cheat sheet for crafting effective search queries aimed at enhancing information retrieval from AI models like GPT. Its primary use case lies in optimizing search accuracy and refining results based on specific parameters, such as keywords, sources, and recency. Notable features include customizable options for output formats, technical depth, and automated summarization, enabling users to tailor searches for precise and actionable information in various contexts.
2026-08-03
JavaScript
★ 106
AspGoat is an intentionally vulnerable ASP.NET Core web application designed for educational purposes, allowing Security Engineers and Developers to explore and practice web application security vulnerabilities. It encompasses a range of common security issues outlined by the OWASP Top 10, providing hands-on labs for vulnerabilities such as XSS, SQL Injection, and Cross-Site Request Forgery, along with features like Docker support for easy deployment and secure coding best practices.
2026-08-03
Shell
★ 660
The Bug Bounty repository serves as a comprehensive resource for security researchers engaged in vulnerability discovery and reporting, aggregating tools, checklists, and cheat sheets to streamline the bug hunting process. Key features include curated lists of bug bounty programs, essential tools, and educational resources, enhancing the usability and effectiveness of cybersecurity efforts. This tool is designed to aid both novice and experienced bug bounty hunters in their pursuits.
2026-08-03
★ 81
The Bug Bounty Beginner Roadmap serves as a comprehensive guide for newcomers interested in bug bounty hunting, providing essential knowledge on security vulnerabilities and effective learning paths. It emphasizes the importance of foundational skills in computer systems, networking, and operating systems, while also highlighting the potential rewards of participating in bug bounty programs. Notable features include curated resources and links to courses tailored for building the necessary expertise in this evolving field.
2026-08-03
JavaScript
★ 35
COLI (Command Orchestration & Logic Interface) is a command line tool designed to streamline workflow management by enabling users to visually create and connect tasks through a drag-and-drop interface. It offers features such as real-time scan monitoring, an interactive web terminal, and a built-in file explorer, making it ideal for those seeking a more efficient way to manage command line operations and enhance visualization. Additionally, COLI supports mobile access, allowing users to operate workflows from anywhere.
2026-08-03
★ 11
CTF-to-Pentest is a guide that emphasizes the transition from a Capture the Flag (CTF) mindset to a penetration testing (pentest) approach, highlighting how common vulnerabilities like SQL injection and remote code execution must be handled with precision and discipline in real-world scenarios. It provides insights on translating CTF techniques into practical, low-impact strategies that prioritize thorough reporting over noise generation. Noteworthy features include personalized methods for vulnerability probing, safe proof-of-concept recommendations, and real-world case studies showcasing vulnerabilities found in high-value companies.
2026-08-03
HTML
★ 20
Elite Google Dorks Search by Biscuit is a curated set of advanced Google search queries designed to uncover hidden information and vulnerabilities on the web, primarily targeting cybersecurity professionals and ethical hackers. Notable features include a selection of smart and improved dorks that enhance search effectiveness and a user-friendly interface for easy application. The tool enables users to efficiently identify security weaknesses by utilizing specific search patterns directly in Google.
2026-08-03
Python
★ 20
EWE (Execution Workflow Engine) is a robust automation tool designed for executing tasks in structured workflows using JSON or YAML files, ideal for automated reconnaissance and tool orchestration. Key features include parallel task execution, conditional task execution, real-time logging, and an interactive CLI mode for live task management. It facilitates efficient automation by supporting dynamic placeholders and providing both silent and interactive modes for flexibility in various operational environments.
2026-08-03
★ 22
Hacker101 CTF Solutions is a comprehensive repository that provides detailed walkthroughs and solutions for challenges encountered in the Hacker101 Capture The Flag (CTF) platform, focusing on web application security vulnerabilities. Key features include a structured organization with solution documentation and supporting screenshots for each challenge, as well as coverage of various attack vectors such as XSS, SQL injection, and permission issues. This educational tool is aimed at both novices and experienced individuals seeking to improve their penetration testing skills through practical, hands-on experience.
2026-08-03
Python
★ 22
InstaRecon is an open-source intelligence (OSINT) tool specifically designed for gathering publicly available information from Instagram profiles, aimed at cybersecurity professionals and ethical hackers. It features user intelligence gathering, engagement analysis, and the ability to extract detailed account metrics, business intelligence, and public contact information. The tool operates across multiple platforms, supports automatic dependency installation, and requires users to provide a valid Instagram session ID for functionality.
2026-08-03
Shell
★ 10
IP-Vortex is an advanced IP rotation tool designed for security professionals, enabling anonymous security testing by frequently changing public IP addresses. Its primary use case is to facilitate fuzzing and vulnerability scanning while avoiding IP-based rate limiting, featuring automatic IP rotation, timed intervals, multi-interface support, and optional MAC address randomization. Notable features include comprehensive logging, network status monitoring, and seamless integration with security testing workflows.
2026-08-03
★ 95
Learn250 is an educational resource aimed at documenting a 250-day journey of learning various cybersecurity topics, particularly focused on penetration testing and mobile application security. Its notable features include detailed write-ups, blog posts, and video tutorials covering practical techniques such as HTTP request smuggling, SSL pinning bypass, and iOS and Android pentesting strategies. This repository serves as both a learning tool and a structured guide for individuals seeking to enhance their cybersecurity skills.
2026-08-03
Python
★ 35
MongoBleed is a high-performance proof-of-concept scanner designed to identify vulnerable MongoDB instances affected by CVE-2025-14847, a pre-authentication heap memory disclosure vulnerability. Utilizing asynchronous I/O with Python's asyncio, the tool efficiently scans large network ranges, ensuring precise detection and minimal false positives by validating response lengths against the requested leak size, while automatically logging vulnerable targets. Additionally, it requires no external dependencies, making it straightforward to deploy in authorized security testing environments.
2026-08-03
JavaScript
★ 12
NarrowX is a specialized browser extension designed for bug bounty hunters and security engineers that facilitates the extraction of endpoints, parameters, and sensitive indicators from JavaScript and network activity. Notable features include advanced inline and external JavaScript parsing, network request capturing, and automatic extraction capabilities using safe synthetic interactions, all while maintaining user privacy through local processing. Additionally, it supports scope filtering across multiple domains/subdomains to refine focus on specific targets.
2026-08-03
Shell
★ 15
nucleihubquery is a bash utility designed to extract and organize search dorks from the nucleihub-templates YAML collection. Its primary use case is to facilitate reconnaissance by generating targeted search queries for multiple asset discovery platforms, enabling users to run structured scans based on vulnerability templates. Notable features include deduplication of queries, generation of severity-based outputs per provider, and a straightforward integration with standard Unix utilities.
2026-08-03
Go
★ 34
PathFinder v1.1.0 is a military-grade web path discovery tool designed for professional penetration testing, featuring a real-time TUI dashboard and animated pathfinding visualization. Its notable capabilities include adaptive splash screens, live redirect tracking, recursive directory scanning, and the ability to export detailed pentest reports in multiple formats, all optimized for performance with high request rates and low resource usage. PathFinder is particularly distinguished by its animation of breadth-first search algorithm solving unique mazes, providing intuitive visual feedback during scans.
2026-08-03
Shell
★ 218
Pentest Lab is a Docker Compose-based local pentesting environment that sets up multiple victim services alongside a Kali Linux attacker service. Its primary use case is to facilitate penetration testing and security assessments through a variety of pre-configured applications like Juice Shop and DVWA, and it includes a Heimdall interface for easy navigation of services. Notable features include automated dependency checks, customizable service configurations, and integrated monitoring capabilities using Grafana and Prometheus.
2026-08-03
Go
★ 63
Pinakastra is an AI-powered penetration testing framework designed for automated reconnaissance and exploitation, specifically tailored for penetration testers and bug bounty hunters. It features extensive capabilities for subdomain discovery, live host probing, URL analysis, and active exploitation of vulnerabilities like XSS and SQL injection, enhanced by AI-driven vulnerability detection and smart payload generation to minimize false positives. The tool also generates customizable reports in various formats, thereby streamlining the assessment process and improving efficiency in security testing.
2026-08-03
Java
★ 220
PyCript is a Burp Suite extension designed for encrypting and decrypting HTTP requests, responses, and WebSocket messages, catering to both manual and automated application penetration testing. It enables the creation of custom encryption and decryption logic utilizing multiple programming languages, thus allowing users extensive flexibility for tailored security implementations. Notable features include automatic request encryption, decryption of multiple requests, and the ability to manipulate encrypted traffic seamlessly within Burp Suite.
2026-08-03
HTML
★ 12
Reconal is an advanced OSINT reconnaissance framework designed to streamline and automate over 70 Google dorks and detailed infrastructure analysis via a native desktop application. Key features include a zero-config experience for end users, a diverse range of recon modules covering cloud services, infrastructure configurations, and API discovery, as well as a robust command-line interface for terminal usage, ensuring no external exposure during operations.
2026-08-03
Python
★ 16
RedTiger is an automated XSS (Cross-Site Scripting) vulnerability testing tool that streamlines security assessments by performing subdomain enumeration, link filtering, endpoint extraction, and XSS scanning. Notable features include intelligent filtering of endpoints, a rich terminal UI with detailed reporting, and dependency checking to ensure all required tools are available. The tool is designed to enhance testing efficiency by focusing on parameters in URLs, improving the accuracy of vulnerability assessments.
2026-08-03
Makefile
★ 52
Scary Strings is a tool designed to identify potential security vulnerabilities in source code by flagging lines that contain "scary strings," which typically refer to sensitive API calls or operations. It provides a collection of technology-specific wordlists, enabling developers to audit their code for unsafe practices and helping hackers find exploitable code segments. Notable features include wordlists for various programming languages, specific categories such as comments and cryptography, and a focus on improving application security through proactive scanning.
2026-08-03
C#
★ 312
The Internets #1 Subdomain Takeover Tool
2026-08-03
Shell
★ 20
Vasuki is an automation tool designed for security professionals that streamlines the process of subdomain enumeration and vulnerability scanning. It aggregates multiple reconnaissance tools to identify subdomains, check for subdomain takeover potential, and detect various injection parameters including XSS and SSRF. Notable features include integration with tools like Nuclei for vulnerability scanning, notification capabilities for scan results, and an organized output of findings in text files.
2026-08-03
TypeScript
★ 69
Warlusts is a repository that provides a collection of curated and custom wordlists for use in various security testing scenarios, particularly for password cracking and penetration testing. Its primary use case is to enhance the efficiency and effectiveness of brute force attacks by supplying tailored wordlists. Notable features include the extensive curation of words and phrases, which are designed to cater to different attack vectors.
2026-08-03
Python
★ 14
This program aims to check active targets by saving screenshots in a project.
2026-08-03
Go
★ 111
`xcrawl3r` is a command-line tool that recursively spiders websites to discover URLs by actively traversing webpages and parsing files such as sitemaps and `robots.txt`. This active spidering approach distinguishes it from similar tools by revealing hidden or unindexed links, making it particularly useful for security researchers and IT professionals. Notable features include support for multiple output formats, cross-platform compatibility, and integration with automated workflows through standard input and output options.
2026-08-03
Go
★ 120
`xsubfind3r` is a command-line utility that efficiently discovers subdomains for a specified domain using information from various passive data sources. It is particularly useful for security researchers and IT professionals, offering features such as support for multiple output formats (including JSONL and stdout), the ability to integrate seamlessly into automated workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
2026-08-03
Python
★ 37
Anvil is a runtime-first tool designed for privilege escalation and attack surface assessment specifically targeting Windows thick client applications. It effectively reduces false positives by combining Procmon capture with Windows AccessCheck to validate writable paths in real-time while enforcing multiple verification gates. Notable features include its comprehensive approach to assessing various attack classes, detailed filtered analysis of candidate paths, and the ability to produce actionable reporting outputs in multiple formats.
2026-08-03
Python
★ 42
Pentest Coverage Tracker is a Burp Suite extension that enhances penetration testing efforts by automatically logging discovered endpoints and parameters during assessments. Its primary use case is to provide real-time visibility into which parts of an application have been tested, helping security professionals systematically identify untested areas. Notable features include endpoint and parameter coverage tracking, a real-time dashboard, untested endpoint identification, and CSV export capabilities for reporting.
2026-08-03
Shell
★ 135
CHOMTE.SH is an advanced automation framework designed for reconnaissance tasks in penetration testing, primarily serving bug bounty hunters and security professionals. Its notable features include subdomain discovery, DNS brute-forcing, quick port scanning, HTTP probing, and detailed reporting capabilities, allowing users to identify vulnerabilities and misconfigurations effectively. The tool is customizable through a flags.conf file and supports deep internet reconnaissance and JavaScript analysis to enhance security assessments.
2026-08-03
Python
★ 14
Mergen is an AI-powered penetration testing server that integrates with MCP-compatible agents, facilitating autonomous planning, adaptive execution, and professional reporting across over 44 security tools. With its multi-layer architecture featuring a FastAPI backend and an adaptive AI attack engine, Mergen enables sophisticated target profiling, dynamic attack execution, and unified risk scoring while supporting multiple output formats like HTML, JSON, and CSV for reporting. Notably, it offers a plugin system for seamless integration of security tools and automated operational capabilities, making it a comprehensive solution for red team engagements.
2026-08-03
TypeScript
★ 48
The OSINT MCP Server is a unified platform that consolidates multiple open-source intelligence sources like Shodan, VirusTotal, and Censys into a single service, enabling AI agents to access comprehensive OSINT on demand. Its primary use case is to streamline the collection of reconnaissance data essential for penetration testing and threat assessments, eliminating the need for multiple tools and manual correlation. Notable features include support for numerous data sources, a simplified MCP protocol interface, an intuitive architecture, and a rich set of 37 integrated tools.
2026-08-03
★ 96
Security Books is a comprehensive repository offering over 160 curated cybersecurity-related books, guides, and resources, catering to various skill levels from beginners to advanced practitioners. This tool features a fully categorized structure with clickable links for instant access to each resource, ensuring that the cybersecurity community has free access to critical knowledge. With a commitment to regular updates, it serves as a valuable, continually expanding library for topics ranging from ethical hacking to network defense.
2026-08-03
Go
★ 719
`xurlfind3r` is a command-line utility that efficiently discovers URLs associated with a given domain by sourcing publicly available data through passive means. It is particularly useful for security researchers and IT professionals, offering features like multiple output formats (JSONL, file, stdout), support for automatic workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
2026-08-03
Python
★ 16
AdwanceSNI is a command-line tool designed for subdomain discovery and vulnerability scanning on Termux and Linux platforms. Leveraging the capabilities of subfinder for subdomain enumeration and bughunter-go for vulnerability analysis, it features a user-friendly colorful terminal UI, progress indicators, and supports batch processing for multiple domains. This tool is primarily intended for educational and ethical hacking purposes, emphasizing user responsibility for permissions when scanning targets.
2026-08-03
Python
★ 24
JSReconRadar is a robust Burp Suite extension designed for passive reconnaissance of JavaScript files, enabling the detection of secrets, API keys, endpoints, and security misconfigurations in real-time. It features over 1,600 detection patterns, customizable UI elements, advanced filtering options, and supports both Burp Suite Community and Professional editions, making it essential for identifying vulnerabilities in web applications. Noteworthy functionalities include a custom results tab, severity color coding, and the capability to save or export findings for further analysis.
2026-08-03
Kotlin
★ 205
BurpMCP-Ultra is a powerful Kotlin extension for Burp Suite Professional that integrates an MCP server, enabling programmatic control of Burp functionalities via AI agents. It supports 149 structured tools for tasks such as proxy history analysis, scan management, fuzzing, and guided exploitation, all secured through token-based local transport. Notable features include custom scan checks, an extensive real-time dashboard, and hardened localhost security controls.
2026-08-03
Shell
★ 38
Claude CyberSecurity Skills integrates Claude Code to assist bug bounty hunters on platforms like HackerOne and Bugcrowd through an automated end-to-end workflow encompassing reconnaissance, vulnerability hunting, validation, and reporting. The tool offers 30 production-grade skills that utilize real tools and custom payloads, allowing users to efficiently execute tasks by simply describing their objectives. Notable features include tailored report templates and a systematic approach to vulnerability identification across multiple phases including pre-hunt, reconnaissance, and vulnerability validation.
2026-08-03
Python
★ 24
Crivo is an open-source Python tool tailored for offensive security analysts, pentesters, and bug bounty hunters, facilitating the extraction and filtering of URLs, IPs, domains, and subdomains from various text inputs and web pages. Notable features include built-in web scraping, flexible scope filtering, and clean output formatting for easy integration into automated workflows, making it efficient for processing data and generating organised reports.
2026-08-03
Python
★ 42
DarkBuster is an advanced web directory and file brute-forcing tool designed for authorized security testing, featuring multithreading capabilities to optimize scan speed. It includes curated wordlists updated to May 2026, supports customizable extensions, and offers a user-friendly CLI interface with color-coded output and real-time progress tracking. Notable features include the ability to save results, use custom headers, and specify various scanning options to enhance the pentesting process.
2026-08-03
Python
★ 20
FastRecvSMS is an SMS verification toolkit designed for security professionals, enabling the purchase of temporary phone numbers to receive SMS codes via a command-line interface (CLI). Key features include support for multiple providers, real-time SMS monitoring, automatic waiting for verification codes, and secure configuration management using local TOML files. The tool streamlines the process of obtaining and verifying SMS codes for various services, making it efficient for testing and security assessments.
2026-08-03
Python
★ 100
favicon_hash_shodan is a tool designed to identify and retrieve all hosts sharing the same favicon by leveraging Shodan's search capabilities. Its primary use case is to aid cybersecurity professionals in uncovering potential target infrastructure or tracking down related web services by analyzing favicon hashes. Notable features include a simple command-line interface for direct usage, integration with Shodan for result viewing, and an uncover mode to enhance search capabilities.
2026-08-03
JavaScript
★ 84
Frida Setup is an installer script designed to facilitate the bypass of SSL pinning in Android applications by automating the installation of Frida and configuring Burp's certificate. The tool is primarily used with Genymotion Emulator or an appropriately configured ADB environment, enabling seamless interaction for SSL interception. Notable features include automatic installation of Frida and its tools, fetching the latest Frida server, downloading Burp's proxy certificate, and cleaning up post-installation requirements for a clean workflow.
2026-08-03
Python
★ 15
gitghost is a tool designed to scan public GitHub repositories for exposed secrets, including those that may have been committed in the past and then deleted. It thoroughly searches through git history to identify vulnerabilities and presents findings in an HTML report complete with direct links to the locations of the secrets, as well as a guide on how to remediate the issues. Notable features include the ability to generate an exposure score, scan for various types of sensitive information, and run local scans without installation.
2026-08-03
Python
★ 41
H1 Asset Fetcher is a command-line tool designed for bug bounty hunters to efficiently fetch, download, and decompile mobile app assets from various bug bounty programs like HackerOne and Bugcrowd. It offers a user-friendly, interactive prompt to guide users through selecting assets across Android, iOS, and executable files, with features including bulk downloading, asset decompilation using JADX, and credential management for streamlined repeated usage.
2026-08-03
Python
★ 351
h1-brain is an MCP server designed to integrate your AI assistant with the HackerOne platform, facilitating the retrieval and analysis of your bug bounty history and program details via a local SQLite database. The tool offers features such as a pre-built database of over 3,600 publicly disclosed bounty reports and the ability to generate comprehensive attack briefings using the `hack(handle)` function, which consolidates personal findings, public disclosures, and suggests attack vectors in a single operation.
2026-08-03
Shell
★ 60
HuntTheBug is an advanced reconnaissance framework tailored for bug bounty hunters, combining over 30 security tools into a streamlined workflow to facilitate automated vulnerability discovery. Notable features include parallel execution for enhanced speed, live domain verification, real-time Telegram notifications for immediate alerts, and comprehensive scanning capabilities for subdomains, URLs, and directories. This toolkit is specifically optimized for use on Kali Linux, ensuring efficient and effective reconnaissance processes.
2026-08-03
TypeScript
★ 46
Monitoring Monster (MonMon) is an automation tool designed for bug bounty hunters that facilitates real-time monitoring of target systems for changes, such as new subdomains or scope expansions. Key features include a smart diff engine for tracking modifications across multiple endpoints, support for alerts via platforms like Slack and Discord, and a user-friendly dashboard that allows for comprehensive task management and historical data reviews. The tool is built in Go and supports easy deployment via Docker, enabling seamless integration into security workflows.
2026-08-03
JavaScript
★ 129
Noxen is an Android runtime interception tool designed for security researchers, leveraging Frida to dynamically hook Java methods within live Android processes. It enables the analysis of app component interactions by capturing events such as `Intent` objects, allowing users to inspect, modify, and control the flow of these events through a terminal user interface. Notable features include the ability to manipulate intent parameters, store session histories in project files, and utilize filters for intercepts and logs, enhancing the thoroughness of security assessments.
2026-08-03
Rust
★ 155
Pathbuster is a path-normalization penetration testing tool built with Rust, designed to aid ethical hackers in scanning for vulnerabilities in web applications. It features an array of options for configuring requests, including various HTTP methods, custom headers, response filtering, and even supports proxy configurations for integrated use with tools like Burp Suite. Notable enhancements include unified response filtering, customized brute-force control, ETA estimations, and traversal strategy selection, making it a versatile choice for web application assessments.
2026-08-03
Python
★ 29
The "penetration-testing-notes" repository serves as a comprehensive collection of notes on penetration testing and related technologies. Designed for educational purposes, it encompasses multiple resources from various platforms, providing insights and references to enhance penetration testing skills. Notable features include curated content from reputable sources like Hack The Box, PortSwigger Academy, and OWASP, aimed at facilitating learning and practical application in cybersecurity.
2026-08-03
JavaScript
★ 35
PenScope is a comprehensive Chrome extension designed for bug bounty hunters, enabling automated map and probe functionalities within web applications. It autonomously scans an attack surface, identifies potential vulnerabilities, and generates HackerOne-format reports for critical findings, streamlining the workflow significantly. Notable features include enhanced probing capabilities with 45 attack vectors, extensive secret pattern recognition, and the ability to decode JWTs and log sensitive information without sending data until prompted by the user.
2026-08-03
Python
★ 813
The Pentest Agent Suite is an autonomous bug-bounty framework designed for use with Claude Code and six other AI coding tools, featuring a collection of 50 agents, 26 commands, and 19 CLI tools. It provides a comprehensive methodology for vulnerability hunting, including automated exploit chaining, endpoint tracking, semantic writeup searches, and installation compatibility across multiple development environments. Its core functionalities enable users to efficiently conduct security assessments and manage bounties via integration with live platforms and cost tracking mechanisms.
2026-08-03
Shell
★ 12
ps.sh is a Bash script designed for automated port scanning on specified target hosts, enhancing scan efficiency and reducing time. It offers features such as service discovery through various workflows using Nmap and Masscan, as well as support for scanning multiple targets simultaneously. Notably, users can customize target ports and output directories, making it a versatile tool for network exploration.
2026-08-03
Shell
★ 12
ReconOps is a structured, recon-only framework designed for bug bounty hunters, focusing on mapping and understanding the attack surface before exploitation. It provides a comprehensive methodology and tools for both passive and active reconnaissance, including automated scripts and templates for effective recon operations. Notable features include tiered guidance for various stages of reconnaissance, a checklist for engagements, and extensive documentation on techniques and tools.
2026-08-03
JavaScript
★ 48
ReconPro is a web reconnaissance tool catering to cybersecurity professionals and bug bounty hunters, facilitating the rapid identification of vulnerabilities through a curated library of Google dorks. It features a smart preset system for common scenarios, supports dual themes, and operates cross-platform without external dependencies, allowing users to easily execute targeted searches for specific vulnerabilities.
2026-08-03
Go
★ 13
S3Finder is a high-performance command-line interface tool designed for discovering AWS S3 buckets through intelligent name generation and high-concurrency scanning. It offers features such as decoupled input sources, an AI-powered permutation engine for bucket name variations, deep inspection with AWS SDK integration, and real-time progress tracking, all while maintaining adaptive rate limiting to avoid throttling and IP blocks. This tool supports cross-platform operation and allows for flexible output formats, making it suitable for security assessments and reconnaissance efforts.
2026-08-03
★ 12
Shodan Filters is a curated repository of search queries specifically designed for Shodan, facilitating reconnaissance and asset discovery during penetration testing and bug bounty engagements. It offers a comprehensive list of ready-to-use filters categorized by technology and framework, enabling users to efficiently discover vulnerable components and configurations by simply entering queries in the Shodan search bar. Notable features include a variety of targeted filters for different technologies, such as Ruby, Django, Kubernetes, and WordPress, which help streamline the information gathering process.
2026-08-03
Python
★ 12
Subfind3r is an advanced subdomain enumeration tool designed to enhance and address limitations found in the original Sublist3r project. It supports various features, including brute force enumeration, port scanning of discovered subdomains, and the ability to specify different passive DNS API sources, making it highly customizable for security researchers performing domain reconnaissance. The tool can be easily installed via pip, facilitating a user-friendly setup process.
2026-08-03
Go
★ 88
Subhunter is a subdomain takeover tool designed to identify vulnerabilities in specified subdomains, enabling users to detect potential security risks associated with unmonitored CNAME records. Notable features include automatic updates, the use of random user agents, and a built-in database of fingerprints sourced from reputable databases. It is implemented in Go and allows for customization in scanning parameters, such as threading and timeouts, enhancing its effectiveness in security assessments.
2026-08-03
Shell
★ 15
Web Recon Automation is an automated reconnaissance script designed for bug bounty hunters and penetration testers, enhancing the efficiency of subdomain enumeration, live host discovery, vulnerability scanning, and reporting. Key features include automated dependency checks, integration with tools like `subfinder`, `httprobe`, `nmap`, and `nuclei`, as well as comprehensive reporting that summarizes findings in a structured Markdown format. The tool simplifies the reconnaissance process by allowing users to conduct multiple security checks with a single command execution.
2026-08-03
C
★ 87
APKX-Hunter is a comprehensive open-source Android Static Analysis Framework developed in C, tailored for security assessments, malware analysis, and penetration testing of Android applications. It supports a wide array of package formats and features advanced capabilities such as recursive multi-APK scanning, integration of OWASP MASVS compliance checks across 15 categories, and a machine learning-based secret classification engine for efficient vulnerability prioritization. Notable features include detailed scan statistics, various decompilation methods, and streamlined integration for Debian systems, making it a robust tool for security researchers.
2026-08-03
★ 119426
Awesome Hacking is a comprehensive repository that aggregates a wide range of curated lists and resources tailored for hackers, penetration testers, and security researchers. Its main use case is to provide an easily navigable collection of tools and knowledge across various domains of cybersecurity, such as application security, bug bounty programs, and incident response. Notable features include links to numerous specialized topics like Android security, fuzzing, and IoT security, facilitating both learning and practical application in penetration testing and security assessments.
2026-08-03
PHP
★ 132
Bug Bounty is a comprehensive knowledge base designed for security researchers, penetration testers, and bug bounty hunters, featuring methodologies, cheatsheets, automation tools, wordlists, and real-world write-ups. Its primary use case involves equipping users with the necessary resources for web penetration testing, API security, cloud exploitation, and modern vulnerability assessment techniques. Notable features include battle-tested methodologies and a focus on ethical hacking practices, underscoring the importance of authorized testing only.
2026-08-03
Java
★ 40
BypassFuzzer is a Java-based Burp Suite extension designed to identify and exploit authorization bypass vulnerabilities, particularly for HTTP status codes 401 and 403. It offers an array of features, including a sweep mode for extensive coverage of proxy history, targeted bypass testing, IDOR and BOLA-style request mutation, and integrated URL validation for security assessments. The tool supports advanced attack vectors with a wide variety of payloads, rate limiting, and dynamic Burp Collaborator integration, making it a comprehensive solution for security professionals focused on authorization testing.
2026-08-03
JavaScript
★ 12
ffuf-GUI is a web-based fuzzing tool designed for penetration testing and security assessments, providing a user-friendly interface to automate fuzzing tasks directly from a browser. Key features include support for multiple attack modes (GET, POST, custom headers), real-time result display, response filtering, and the ability to export results in various formats. This tool is built for cross-platform compatibility, working seamlessly on Linux, Windows, Mac, and Android devices.
2026-08-03
Dockerfile
★ 24
The "kali-dockerized" repository provides Docker images for Kali Linux and Ubuntu 26.04, tailored for bug bounty programs, penetration testing, security research, computer forensics, and reverse engineering. Key features include the use of the official Kali Linux Docker image with systemd support, compatibility with Docker's host network driver for enhanced performance, and tools for local deployment on Kubernetes clusters. The setup also includes installation instructions for utilities such as Dive for image exploration and Trivy for vulnerability scanning.
2026-08-03
★ 310
The Penetration Testing Roadmap provides a comprehensive learning path designed to transition individuals from beginner to junior penetration tester by covering essential topics, tools, and hands-on labs. It is structured into phases, including foundational skills, web and infrastructure security, specialization tracks, and certification preparation. Notable features include a live roadmap, curated guides for various subjects, and links to practice labs and certifications, facilitating an organized and effective learning experience.
2026-08-03
Python
★ 33
ReconForge is an AI-assisted reconnaissance toolkit designed for bug bounty hunters and security researchers, facilitating rapid transition from raw data to actionable insights. It features subdomain discovery, DNS enumeration, SSL/TLS analysis, Shodan integration, and technology detection, all complemented by AI triage prompts for analyzing HTTP responses and generating professional markdown reports. The tool emphasizes a speed-oriented, production-ready design with robust error handling and comprehensive testing capabilities.
2026-08-03
Python
★ 17
ReconFusionAI is an AI-powered web asset scanner designed to detect exposed secrets, credentials, PII, and vulnerabilities across web applications with high accuracy through a comprehensive library of over 1,183 detection patterns. Its notable features include advanced contextual analysis using Ollama for improved understanding of data context, a modular architecture allowing for easy updates, and dual output formats that provide detailed findings and reconnaissance intelligence. Additionally, it incorporates intelligent caching mechanisms and production-hardened capabilities for efficient and robust operation.
2026-08-03
Shell
★ 106
TIKTOK-SSL-Pinning-Bypass is a tool designed for security researchers and developers to bypass SSL certificate pinning in the TikTok app on Android devices, facilitating the interception and analysis of HTTPS traffic. Its notable features include compatibility with both rooted and non-rooted devices, support for various proxy tools, and recent enhancements that allow full functionality on Android 11 and above, including the capture of login and registration traffic. The tool provides a pre-patched TikTok APK, enabling users to inspect API calls and the app's network interactions seamlessly.
2026-08-03
Python
★ 67
AVAIN is an automated vulnerability analysis framework designed for IP-based networks, leveraging a modular architecture to conduct comprehensive assessments of both networks and individual hosts. It features collaborative modules that facilitate reconnaissance, vulnerability correlation, and active detection of security issues, culminating in a vulnerability score to gauge overall security. Noteworthy capabilities include simple result sharing, extensive module configurability, and the ability to integrate various tools, making it a robust platform for penetration testing and security evaluation.
2026-08-03
Python
★ 63
badmoodle is a community-driven vulnerability scanner designed specifically for Moodle platform instances, aimed at penetration testers and security researchers. It identifies both official and community-discovered vulnerabilities, allowing users to operate in check mode for detection or exploit mode to validate and leverage identified vulnerabilities. Notable features include its modular architecture for easy integration of community vulnerability modules, multiple testing levels, customizable output options, and capability to scrape the latest vulnerabilities from Moodle's security resources.
2026-08-03
Perl
★ 88
FazScan is a versatile vulnerability scanning and penetration testing tool implemented in Perl, designed to assess various web vulnerabilities, including SQL injection and CMS-specific weaknesses. With 18 distinct options, it enables users to perform automated scans for common vulnerabilities, detect content management systems, bypass WAF protection, and even conduct denial of service attacks. Its cross-platform compatibility allows for deployment on Linux, Windows, and Android systems.
2026-08-03
Shell
★ 65
FireStorePwn (fsp) is a vulnerability scanner designed to analyze APK files for weaknesses in Firestore database security configurations, assessing both authenticated and unauthenticated access. Its primary use case is to identify insecure rules that could allow unauthorized data manipulation or access, potentially resulting in data theft and increased billing. Notable features include the ability to scan APKs with or without authentication using both user credentials and tokens.
2026-08-03
Java
★ 640
Log4J Detector is a scanning tool designed to identify vulnerable versions of the Log4J library, specifically addressing critical CVEs such as CVE-2021-44228 and related vulnerabilities. It meticulously analyzes the entire file system, including nested applications, to locate Log4J instances, even those obscured within complex structures like uber jars. Supporting multiple operating systems, this tool provides detailed reporting on the safety status of detected Log4J versions, facilitating comprehensive vulnerability assessments.
2026-08-03
Python
★ 38
OrgASM is a modular attack surface mapping tool designed for discovering and enumerating potential vulnerabilities within a target's ecosystem, such as subdomains, IPs, and services. It integrates seamlessly with other tools like nuclei for scanning and wappalyzer for service detection, offering features such as a customizable configuration file, pivoting to related FQDNs, and the ability to automate scans using community APIs. Users can extend its functionality by adding custom APIs and tools, making it highly adaptable for various cybersecurity needs.
2026-08-03
Ruby
★ 433
SQLi-Hunter is an HTTP/HTTPS proxy server that serves as a wrapper for the SQLMAP API, designed to simplify the process of detecting SQL injection vulnerabilities. Its primary use case is to facilitate web application testing by providing tools for sending requests through a proxy, while also offering configurability for SQLMAP injection techniques, threading, and user-agent customization. Notable features include Docker support for easy deployment, the ability to persist output files, and various options to target specific hosts and adjust testing parameters.
2026-08-03
Python
★ 19
sqlmap is an open-source penetration testing tool designed to automate the detection and exploitation of SQL injection vulnerabilities in web applications. Its robust detection engine supports extensive capabilities such as database fingerprinting, data retrieval, and command execution on the underlying operating system, making it an essential tool for security professionals. Key features include a variety of switches for advanced testing, support for multiple databases, and the ability to access the file system via out-of-band connections.
2026-08-03
Python
★ 10
Web-Fuzzer is a robust web application fuzzing tool designed to automate the identification of vulnerabilities such as XSS, SQL injection, and command injection. Utilizing technologies like Selenium and BeautifulSoup, it crawls web applications to collect internal URLs, detects forms and input parameters for fuzzing, injects payloads, and analyzes responses for potential security flaws. Notably, it supports various injection types and can be used in testing environments like DVWA, with further enhancements planned for threading support and proxy usage.
2026-08-03
Perl
★ 59
XAttacker is a web vulnerability scanner designed to automate the detection of security weaknesses in web applications. Its primary use case is to identify vulnerabilities such as SQL injection and cross-site scripting (XSS) through a user-friendly interface and customizable attack payloads. Notable features include multi-threaded scanning, a comprehensive report generator, and support for various web technologies.
2026-08-03
Python
★ 38
BeeXSS is an automated tool that identifies Blind XSS (Cross-Site Scripting) vulnerabilities in web applications by scanning URL parameters and injecting payloads. Its notable features include the use of customizable Blind XSS-specific payloads, headless browsing via Selenium WebDriver for efficient scanning, and detailed reporting of potential vulnerabilities. The tool is intended for educational and ethical penetration testing purposes, ensuring users have permission to test the targeted applications.
2026-08-03
Go
★ 10
The network-vulnerability-scanner is a tool designed to identify vulnerabilities within networked systems by analyzing hosts and services for known security flaws. Its primary use case is to enable network administrators and security professionals to assess the security posture of their network infrastructure. Notable features include support for various network protocols, customizable scanning options, and detailed reporting on discovered vulnerabilities and recommended mitigations.
2026-08-03
Python
★ 93
NextSploit is a command-line utility for detecting and exploiting the Next.js vulnerability identified as CVE-2025-29927. It automates the process of identifying vulnerable Next.js versions and attempts to exploit the flaw by bypassing middleware protections, potentially allowing unauthorized access to restricted content. Notable features include automated version detection using Wappalyzer, mass URL scanning capability, and an integrated Chrome browser launch for exploitation tests.
2026-08-03
Shell
★ 10
StealthNewSQL is an advanced command-line tool designed for detecting, exploiting, and securing NewSQL database vulnerabilities. It features capabilities such as DNS-based data exfiltration, advanced WAF evasion techniques, automated exploitation, and seamless integration with CI/CD pipelines, making it suitable for penetration testers, security researchers, and developers focused on database security. Notable functionalities include real-time monitoring, comprehensive reporting, and a modular plugin system for extending its capabilities.
2026-08-03
Python
★ 17
The Vulnerability Scanner is a user-friendly tool designed for beginners in cybersecurity, capable of scanning systems for vulnerabilities and gathering information on potential targets. It includes features like DNS enumeration, OS detection, service/version detection, and integration with the OWASP ZAP for comprehensive security assessments. The tool is specifically built for Kali and Parrot Linux environments and requires minimal prior knowledge, making it an ideal starting point for aspiring security professionals.
2026-08-03
TypeScript
★ 114
wacat is an automated web application testing tool that simulates chaotic input by navigating through a web application's links and forms in a random manner, providing comprehensive testing coverage. It offers advanced features like AI-driven error detection and content generation, supports various configurations for authentication, and can run in headless mode suitable for Continuous Integration (CI) pipelines. Built on Playwright, wacat is designed for user-defined behaviors and can detect a range of issues, making it ideal for thorough application assessments in a controlled environment.
2026-08-03
Python
★ 34
BRS-XSS is an advanced XSS vulnerability scanner designed for modern web applications, providing deterministic and auditable detection capabilities. It features context-aware scanning, WAF evasion techniques, and a comprehensive knowledge base for payload management, along with a user-friendly web interface that supports real-time monitoring, detailed reporting, and customizable scanning options. Notably, it includes a Pentesting Task Tree strategy engine for adaptive testing, A/B testing for strategy comparison, and multiple report formats for enhanced analysis.
2026-08-03
Python
★ 335
BurpAPISecuritySuite is a professional-grade extension for Burp Suite that consolidates multiple functionalities for API reconnaissance, intelligent fuzzing, and AI-enhanced security testing into a single interface. It is designed to improve performance and usability by sharing resources across various tabs, thereby minimizing memory usage and CPU overhead while maintaining a stable and efficient testing environment. Notable features include support for REST, GraphQL, and SOAP APIs, as well as tools for passive discovery, fuzzing, and advanced security assessments based on the OWASP API Top 10 guidelines.
2026-08-03
Shell
★ 50
CloudDefense.AI is an automated web application security testing tool designed to identify vulnerabilities such as SQL injection and cross-site scripting, enhancing overall application security. It supports various security assessments including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API scanning, facilitating a DevSecOps approach by integrating security assessments seamlessly into the development lifecycle. Notable features include its comprehensive application stack risk assessments and compatibility with multiple programming languages and integration points.
2026-08-03
Python
★ 33
Claude Pentest Skills is a structured penetration testing skill pack designed for Claude Code that employs an OWASP-based methodology to streamline web application security assessments. It features a 6-gate validation process to filter out false positives, a series of interactive slash commands for efficient testing, and automated report generation in both markdown and PDF formats, ensuring compliance with verification and documentation standards. The tool improves the efficiency and reliability of pentesting workflows by maintaining consistent coverage tracking and enforcing scope before testing.
2026-08-03
Python
★ 11
CloudVault is an enterprise-grade security scanner designed for multi-cloud storage environments, specifically targeting AWS S3, Google Cloud Storage, and Azure Blob. It offers advanced attack chain analysis, automated permission checking, and comprehensive risk scoring, facilitating real-time discovery of exposed cloud resources through certificate transparency monitoring. Notable features include interactive text user interface (TUI), alerts integration with communication platforms, compliance mapping, and various export formats for reporting and remediation.
2026-08-03
Python
★ 29
CorsOne is a specialized security testing tool for detecting Cross-Origin Resource Sharing (CORS) misconfigurations in web applications. It efficiently tests over 40 CORS bypass techniques, providing accurate results with low false positives and supporting advanced features such as customizable origin testing, proxy configurations, and multiple output formats for comprehensive reporting. The tool employs asynchronous operations for high performance and includes options for easy integration and flexible request handling.
2026-08-03
Python
★ 22
DiscourseMap is an advanced security scanner designed specifically for Discourse forum platforms, offering over 25 specialized security modules for comprehensive assessments. It features capabilities such as CVE detection, plugin analysis, and API testing, all optimized for quick performance and reliability, delivering detailed reports in multiple formats. The tool is well-suited for vulnerability detection and compliance verification, making it essential for securing Discourse environments.
2026-08-03
Python
★ 15
The HackerAI Framework (Project Sirra) is a modular security testing environment tailored for ethical hackers and security researchers, emphasizing cross-platform compatibility including mobile devices. It features a universal orchestrator for module management, built-in security scanning capabilities, advanced web scanning with asynchronous support, and the ability to export results in multiple formats like HTML and JSON.
2026-08-03
TypeScript
★ 21
hackbrowser-mcp is a specialized browser-based security testing tool that empowers AI agents to identify vulnerabilities within web applications. Unlike typical browser MCPs focused on automation tasks, hackbrowser-mcp utilizes the Model Context Protocol to facilitate in-depth security assessments, including injection testing and access control evaluations across multiple isolated user sessions. It features 39 integrated security tools, full traffic capture, and advanced reporting capabilities, enabling detailed vulnerability discovery through natural language instructions.
2026-08-03
Python
★ 10
ICS Ninja Scanner is a specialized security assessment tool for industrial control systems (ICS) that supports comprehensive device discovery and testing across 11 protocols, including Modbus and S7. It features built-in CVE correlation, compliance mapping to frameworks like IEC 62443 and NIST 800-82, and offers functionalities such as scan diffing and industry-specific scan profiles, ensuring a thorough and tailored assessment for operational technology environments.
2026-08-03
Python
★ 52
Pentester-MCP is an open-source penetration testing toolkit that integrates over 200 popular cybersecurity tools via the Model Context Protocol (MCP), enabling AI assistants to autonomously conduct penetration tests. Notable features include intelligent tool execution generated from cheat sheets, AI-optimized documentation for argument handling, and secure operation through Docker sandboxing, isolating tools from the host system to prevent dependency clutter. The toolkit covers various categories including reconnaissance, web exploitation, and network security, making it a comprehensive solution for automated penetration testing.
2026-08-03
JavaScript
★ 27
Pentesting Cyber MCP is a framework that provides standardized server implementations for 50 popular security tools via the Model Context Protocol (MCP), facilitating automation in pentesting and bug bounty tasks. Each MCP server encapsulates a security tool with a uniform interface, making it interoperable with any MCP-compatible client and allowing seamless integration into security assessments. Notable features include a wide range of tools covering reconnaissance, vulnerability scanning, and exploitation, all accessible through standard MCP interfaces.
2026-08-03
Shell
★ 67
Perseus is an interactive security assessment tool that enhances Claude Code's capabilities by facilitating autonomous penetration testing of your codebase. It supports multiple programming languages and frameworks, automatically detecting the project's environment and vulnerabilities across various dimensions, including API security and infrastructure. Notable features include smart auto-detection, engagement modes for different environments, and a structured four-phase assessment methodology to ensure comprehensive evaluation and reporting of security issues.
2026-08-03
Python
★ 223
Public Skills Builder is a tool designed to generate Claude Code bug bounty skills by analyzing and extracting valuable data from over 500 public HackerOne reports and GitHub writeups. It produces 18 structured skill files, each targeting a different vulnerability class, complete with real-world techniques, payloads, and methodologies essential for enhancing bug hunting skills. Notable features include the ability to work exclusively with publicly available data and the generation of targeted skill files ready for integration with Claude Code.
2026-08-03
Python
★ 73
RAG/LLM Security Scanner is a professional security testing tool designed to identify critical vulnerabilities in Retrieval-Augmented Generation (RAG) systems and large language model (LLM) applications, such as chatbots and knowledge retrieval systems. Notable features include advanced prompt injection detection, data leakage assessments, function abuse testing, and comprehensive reporting capabilities, making it suitable for both demo and production environments. The tool supports easy integration with popular AI systems and provides detailed JSON/HTML reports with actionable insights.
2026-08-03
Python
★ 152
React2Shell Ultimate is a professional vulnerability scanner specifically designed for detecting the CVE-2025-66478 Remote Code Execution (RCE) vulnerability in Next.js applications utilizing React Server Components. Notable features include advanced exploitation capabilities, sophisticated techniques for WAF bypass, multiple scanning modes, and a full-featured web interface for interactive use and API access, making it suitable for authorized security testing and research.
2026-08-03
Python
★ 686
RedTiger-Tools is a versatile automation tool designed for penetration testing (pentesting) and open-source intelligence (OSINT) that aims to consolidate multiple operations into a single, configurable platform. It features a plugin system for extending functionality, centralized configurations using JSON files, and dual operation modes (CLI and interactive interface), ensuring compatibility with both Windows and Linux environments while adhering strictly to legal and ethical standards for usage.
2026-08-03
Python
★ 40
ShubhamWebScript is a Python-based website vulnerability checker designed for educational and ethical hacking purposes, allowing users to assess the security of web applications through automated scanning of parameter-based URLs. It detects common vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), and Remote Code Execution indicators, while also performing server header fingerprinting. The tool features both single and bulk URL scanning capabilities, making it beginner-friendly and suitable for learning basic web security practices.
2026-08-03
Java
★ 21
VISTA (Vulnerability Insight & Strategic Test Assistant) is an AI-driven extension for Burp Suite that enhances security testing through real-time traffic analysis and intelligent vulnerability detection. It offers notable features such as an interactive AI advisor for context-aware testing suggestions, customizable analysis templates, and a comprehensive payload library, enabling pentesters to conduct faster and more systematic assessments. Additionally, VISTA supports multiple AI providers, including OpenAI and Azure, to tailor its guidance to user needs.
2026-08-03
Python
★ 24
VulnScout is a security analysis tool designed for whitebox security reviews, offering offline quick scans and evidence-backed verification for identifying vulnerabilities within codebases. It provides features such as shared findings documentation, various output formats for reports, and support for multiple deep analyzers, making it suitable for integration into continuous integration workflows. Notably, it operates without requiring a remote service and includes capabilities for auditing, verifying findings, and generating structured reports.
2026-08-03
C++
★ 29
Worm GPT Core is an advanced adversarial prompt delivery framework designed for AI researchers and cybersecurity professionals to evaluate and exploit vulnerabilities in large language models (LLMs). It automates the delivery of jailbreak prompts and features innovative mechanisms for alignment evasion, multi-threaded prompt execution, and seamless integration with both commercial and local LLMs. The tool aims to enhance penetration testing capabilities within AI systems while ensuring zero telemetry and optimized performance.
2026-08-03
Python
★ 11
XSSniper is an advanced open-source XSS vulnerability scanner designed for professional security testing. It features asynchronous scanning for enhanced performance, a comprehensive payload library tailored to the latest CVEs, and sophisticated WAF bypass techniques. Notable capabilities include intelligent context-aware detection, smart parameter discovery, and detailed vulnerability reporting for effective analysis of web applications.
2026-08-03
Python
★ 10
ZENVORA VulnScan v2.0 is a comprehensive vulnerability scanner designed for web applications, focusing on detecting various security issues such as SQL injection, cross-site scripting (XSS), and command injection. It includes features like anonymity levels through Tor and ProxyChains, automated report generation in TXT and JSON formats, and an extensive list of tests for common vulnerabilities. This tool is intended for authorized use only, highlighting the importance of ethical scanning practices.
2026-08-03
Python
★ 20
BitrixProbe is a Python-based vulnerability assessment tool specifically designed for CMS 1C-Bitrix/Bitrix24 installations. It offers dual modes of operation: `pentest` for external HTTP/HTTPS scans and `audit` for authenticated SSH scans, enabling comprehensive evaluation of both public exposure and server configurations. Notable features include integration with vulnerability databases, enumeration modules, and the ability to generate standardized reports, thus facilitating effective security assessments and audits.
2026-08-03
Python
★ 12
Cataam is an open-source security toolset that provides a variety of scripts and templates aimed at enhancing security and compliance practices for organizations. It features practical functionalities such as hardening scripts, CVE detection tools, and compliance documentation, making it suitable for security teams, DevOps, and compliance engineers. Notable offerings include a local-first prompt hygiene tool, CVE detection scripts updated promptly after disclosures, and a comprehensive collection of CIS Benchmark guides and compliance templates.
2026-08-03
Python
★ 21
CERT-X-GEN is a polyglot execution engine designed for vulnerability detection, allowing users to write security checks in multiple programming languages including Python, Go, Rust, C, and Shell. It provides a unified execution layer that enables complex detection logic, such as multi-step protocol conversations and performance-critical operations, and is tailored for integration in CI/CD environments. Notable features include language-agnostic templates, sandboxing capabilities, and the ability to mix various programming languages within a single scan.
2026-08-03
Go
★ 420
CSCAN is an enterprise-level distributed network asset scanning platform designed for comprehensive asset management and vulnerability detection. Its notable features include a distributed architecture for flexible scalability, automated scanning pipelines, customizable password dictionaries, periodic task scheduling, and real-time notification subscriptions, supporting extensive data isolation across multiple workspaces. This tool is ideal for organizations seeking to efficiently monitor and secure their network infrastructure.
2026-08-03
Python
★ 323
DeepSec is an AI-driven security platform that integrates code security auditing and authorized penetration testing into a unified CLI and terminal workbench. It features a three-layer detection architecture for real-time vulnerability scanning, leveraging regex, AST analysis, and LLM semantic evaluation, along with IDE plugins for seamless development integration. The platform is designed to enhance security efficiency by augmenting traditional methods with advanced AI capabilities.
2026-08-03
★ 877
DianXing (点星) is an AI-driven end-to-end code security auditing system that autonomously identifies and verifies vulnerabilities in source code without human intervention, offering a structured output of detected issues. Unlike traditional SAST tools, it employs semantic understanding to uncover deep vulnerabilities, such as authentication bypass and privilege escalation, which are often missed by conventional scanners. The system has demonstrated the ability to autonomously exploit zero-privilege remote code execution vulnerabilities, reinforcing the need for responsible disclosure of its capabilities.
2026-08-03
Python
★ 608
L0p4Map is a robust network monitoring and visualization tool that enhances the capabilities of Nmap, providing security researchers and network administrators with detailed insights into their network infrastructure through an intuitive interface. Key features include continuous monitoring of network traffic, real-time alerting for unauthorized devices, extensive device fingerprinting, and the ability to generate a real-time graphical representation of network topology. The tool supports multiple platforms (Linux, Windows, macOS) and integrates seamlessly with existing Nmap functionalities to deliver a comprehensive view of network security.
2026-08-03
JavaScript
★ 20
NSAuditor AI is a modular, AI-assisted network security audit platform designed to assess and prioritize vulnerabilities without data exposure, operating entirely within your infrastructure. It utilizes 27 specialized scanning plugins to generate AI-powered vulnerability reports while ensuring zero data exfiltration, as all processes including analysis and monitoring are conducted offline and any external API calls are opt-in. This tool emphasizes privacy and security by ensuring that sensitive scan data never leaves the user's environment.
2026-08-03
Java
★ 14
OmniStrike is a state-aware security scanning tool for Burp Suite that enables precise and customizable security testing by allowing users to target individual parameters within requests. It features 14 active scanning engines, 10 technology-aware scanners, and session automation capabilities, alongside optional AI analysis for focused vulnerability testing. This tool is designed to facilitate detailed assessments of modern web technologies while maintaining user control over scanning processes and findings management.
2026-08-03
Go
★ 30
PenHunter is a modular web vulnerability scanner designed for penetration testers, bug bounty hunters, and security researchers, focused on identifying a wide range of web vulnerabilities, including XSS, SQL Injection, and RCE. It features advanced detection methods, such as boolean and time-based techniques, as well as built-in WAF evasion capabilities, and can integrate with external tools like sqlmap and dalfox. The tool supports concurrent scanning, interactive CLI usage, and provides organized output in multiple formats, enhancing workflow efficiency in security assessments.
2026-08-03
Python
★ 27
Pentest Skill is a comprehensive black-box web penetration testing toolkit designed to streamline the bug bounty workflow through a structured five-phase approach: Intake, Recon, Enum, Hunt, and Report. Notable features include a workflow controller with checkpoints for phase progression, a collection of 48 Python scripts for various testing phases, and an extensive library of attack playbooks and payloads, facilitating targeted vulnerability assessment and reporting.
2026-08-03
Java
★ 42
RouteVulScan is a passive recursive path probing extension for Burp Suite that leverages the Montoya API to perform low-noise vulnerability detection during web security testing. It automatically scans traffic for hidden endpoints and sensitive files using customizable YAML-based detection rules, allowing users to quickly identify high-value vulnerabilities without the need for manual dictionary management. Key features include automatic path recursion, support for active scanning of individual requests, and a comprehensive rules engine for effective vulnerability assessment.
2026-08-03
Java
★ 450
SILENTCHAIN AI™ - Community Edition is a Burp Suite extension designed for AI-powered passive vulnerability analysis, providing intelligent detection of OWASP Top 10 vulnerabilities and security misconfigurations in real-time HTTP traffic. Notable features include context-aware detection using various AI models, detailed reporting with CWE and OWASP mapping, and robust data privacy measures through automatic sensitive data redaction. The tool enhances traditional security scanning by focusing on real vulnerabilities with zero false positives, making it a significant addition to web application security testing.
2026-08-03
PHP
★ 87
Symfony Security Auditor is an AI-driven security auditing tool designed for Symfony applications, focusing on identifying application-level flaws that traditional static analysis tools may overlook. It features an adversarial Attacker and Reviewer loop to validate vulnerabilities and produces reports in multiple formats, including JSON and HTML. The auditor can operate in two modes: as a standalone CLI tool or integrated into Symfony applications, providing flexibility for different auditing needs.
2026-08-03
Python
★ 13
WSHawk is an open-source toolkit designed for WebSocket security testing and web application penetration testing, integrating a CLI scanner, web dashboard, and desktop application. Notable features include stateful WebSocket testing, context-aware payload evolution, browser-assisted evidence collection using Playwright, and a comprehensive suite of web pentesting tools such as fuzzers and interceptors, all under the AGPL-3.0 license. The toolkit also supports project-backed workflows and offers various integrations and reporting formats for efficient security assessment.
2026-08-03
Go
★ 944
Xalgorix is an open-source AI-driven penetration testing platform that autonomously conducts comprehensive pentesting methodologies and verifies each finding through an independent verification process, ensuring the delivery of proven vulnerabilities rather than uncertain results. It is designed for self-hosting and supports a "bring-your-own-LLM" model, allowing integration with user-defined language models, while catering to both Linux environments and containerized implementations through Docker. Notable features include its autonomous execution, independent verification of findings, and the ability to run in a secured Docker container.
2026-08-03
★ 31
Awesome Hacking & Cybersecurity Learning Path is a comprehensive resource designed to guide individuals from beginner to advanced levels in ethical hacking, penetration testing, and cybersecurity. It features curated materials on bug bounty hunting, OSINT tools, CTF challenges, and practical exercises for real-world scenarios, alongside essential concepts in networking and web application security. Notable features include detailed roadmaps for penetration testing, hands-on labs from platforms like TryHackMe and HackTheBox, and extensive coverage of privilege escalation techniques across multiple operating systems.
2026-08-03
Shell
★ 2659
The Awesome OSINT Arsenal is a comprehensive open-source toolkit designed for open-source intelligence (OSINT) and cybersecurity, comprising over 753 tools organized into 50 categories. It facilitates quick installations on various Linux distributions and offers targeted scripts for specific tasks such as red teaming, blue teaming, and forensics, simplifying access to essential security resources. This toolkit supports multi-distro installers and includes a Termux subset for Android, enhancing its versatility for security researchers and practitioners.
2026-08-03
Python
★ 344
dorks_hunter is a Python-based automation tool that serves as a wrapper for `xnldorker`, enabling users to systematically execute categorized Google dorks against a specified target domain. Its primary use case is to identify vulnerabilities or sensitive information exposure in web applications, with notable features including terminal output of results and an option to save the findings to a file for further analysis.
2026-08-03
Python
★ 98
Security Suite is an open-source toolkit designed for comprehensive OSINT reconnaissance, web security testing, API security assessments, and compliance checks, all enhanced with AI-powered analysis capabilities. It features 11 OSINT modules, six web scanners, and four API security tools, along with integration for SIEM systems, scheduled scans, and a REST API for programmatic access. The tool simplifies setup across multiple operating systems and allows for customization of AI models and tool options during installation.
2026-08-03
Go
★ 11
BannerGrapV2 is an advanced network reconnaissance and vulnerability discovery tool designed for both offensive and defensive security operations, making it suitable for Red and Blue Teams, bug bounty hunters, and security auditors. Notable features include multi-threaded banner grabbing, extensive service fingerprinting, a robust vulnerability detection engine, and flexible reporting options in multiple formats, all powered by a performance-focused architecture enabling concurrent scans of up to 10,000 hosts.
2026-08-03
★ 142
CRLJ is a comprehensive resource repository aimed at cybersecurity professionals, students, and enthusiasts, providing structured pathways for learning and skill development in the field. It features resources such as educational materials, a cybersecurity roadmap, and foundational knowledge to support various learning stages. Notable features include links to essential cybersecurity topics, curated book lists, and guidance on office ergonomics for a healthy work environment.
2026-08-03
Shell
★ 50
Intel Codex is a comprehensive operational manual designed for digital investigators and security analysts, emphasizing OSINT methodologies and security protocols. It features over 40 standard operating procedures (SOPs), guides for various social media platforms, and case studies that illustrate practical applications in real-world investigations. Notable elements include legal and ethical compliance frameworks, detailed investigation techniques, and a focus on malware analysis and penetration testing methods.
2026-08-03
Python
★ 40
The VAPT Toolkit provides a comprehensive environment for vulnerability assessment and penetration testing, integrating over 50 third-party security tools and custom automation frameworks on an Ubuntu 22 platform. Notable features include a deterministic network exploitation orchestrator that automates host discovery and vulnerability verification using nmap and Metasploit, as well as a MITM browser autopwn orchestrator combining tools like bettercap and Responder for streamlined exploitation. The toolkit supports extensive automation in reporting, deliverable generation, and a wireless attack framework for versatile testing capabilities.
2026-08-03
Shell
★ 537
BCHackTool is an all-in-one launcher and installer designed for penetration testing and OSINT (Open Source Intelligence) on Kali Linux and Termux environments. It features a menu-driven interface for easy access to a curated set of tools, automates the installation process, and includes helpful flags for managing scripts and tools. This tool streamlines the setup and execution of security testing tools while ensuring users operate within ethical boundaries.
2026-08-03
Python
★ 1143
MailAccess is a self-hostable OSINT platform designed for investigating email addresses by aggregating data from breach databases, social networks, DNS records, and the open web. It features an identity graph for correlating user accounts, a name consensus engine for verifying identities, and a domain email harvesting tool that discovers organization addresses from multiple data sources. The tool provides structured findings in various export formats and is specifically tailored for security researchers and penetration testers.
2026-08-03
Jupyter Notebook
★ 28
The Excalibra cybersecurity repository serves as a comprehensive educational resource designed to enhance skills in ethical hacking, penetration testing, and cybersecurity fundamentals. Key features include detailed sections on Open Source Intelligence (OSINT), the use of Nmap for network discovery and security auditing, insights into social engineering tactics, and guidance on employing Kali Linux, making it a valuable tool for individuals seeking a structured learning path in cybersecurity.
2026-08-03
Python
★ 13
php-in-jpg is a tool for generating JPEG images that embed PHP payloads leveraging two methods: inline embedding and EXIF metadata injection. It facilitates remote code execution (RCE) through a GET-based execution mode or fixed command specifications, making it particularly useful in webshell demos and upload exploitation scenarios. Notable features include customizable templates for output, an optional preview mode, and support for both embedding techniques.
2026-08-03
C++
★ 210
RunAs-Stealer is a credential harvesting tool designed to exploit Windows systems by implementing three techniques: hooking `CreateProcessWithLogonW`, smart keylogging, and remote debugging. Its primary use case is to stealthily capture user credentials and store them in an alternate data stream of a desktop.ini file for later retrieval. Notable features include continuous operation in the background and the ability to eliminate captured credentials directly via command-line instructions.
2026-08-03
Shell
★ 23
Termux-AutoSetup is a modular toolkit designed for efficiently setting up a Termux environment on Android devices, enabling users to install essential command-line and security tools with a single command. Notable features include a categorized selection of tools for basic functionalities, hacking applications, and custom-built utilities, streamlining the installation process for users. The script is beginner-friendly, requiring minimal initial setup and offering a straightforward execution process.
2026-08-03
Python
★ 34
AdminDirectoryFinder is a Python tool designed to scan for and identify sensitive directories, specifically under admin paths, within web applications. It is primarily used by penetration testers and developers to enhance security by detecting hidden admin panels and ensuring proper access controls. Notable features include its straightforward installation process and focus on security testing.
2026-08-03
Python
★ 18
awacs-scanner is an automated vulnerability scanning tool designed to gather extensive information about systems and identify potential exploits using multiple sources, including Vulners API and SearchSploit. Its primary use case involves scanning for vulnerabilities across multiple targets specified in files, streamlining the reconnaissance process without the need for manual searches. Notable features include various scan modes such as stealth_flight, vuln_scan, and battering_ram, as well as capabilities for S3 bucket discovery.
2026-08-03
C++
★ 31
The WiFi Handshake Capture Tool is designed for security researchers and penetration testers to passively capture WPA/WPA2 EAPOL 4-way handshakes using an ESP32 development board. Key features include compatibility with standard network analysis tools like Wireshark and Aircrack-ng, a web interface for data retrieval, and the ability to save captures in PCAP format, facilitating further analysis. Users must adhere to legal and ethical standards when utilizing this tool for authorized network testing.
2026-08-03
TypeScript
★ 150
Google Hacking Assistant is a Chrome extension designed to enhance security research by automating the injection of predefined and customizable hacking syntax into search engine results from platforms such as Google, Baidu, and Bing. It features an intelligent sidebar that facilitates advanced searches with over 11 built-in query types, custom syntax management, and bulk URL extraction capabilities, while ensuring user privacy through local data storage and no tracking. This tool aims to streamline the process of conducting legitimate security assessments and penetration testing.
2026-08-03
Python
★ 37
The "Hacking Tools" repository offers a collection of cybersecurity utilities designed for various network reconnaissance and penetration testing tasks. Key features include ARP cache poisoning, subdomain enumeration via HTTPS certificate history, Google dorking for file discovery, and multiple implementations of network scanning and port scanning. These tools serve as essential resources for security professionals conducting assessments and vulnerability analysis.
2026-08-03
Python
★ 48
rec0n is an automated toolkit designed for subdomain reconnaissance and sensitive data discovery, facilitating threat assessment and vulnerability identification. Key features include subdomain enumeration, live host detection, CORS vulnerability scanning, and sensitive file discovery with effective CLI output management. The tool integrates multiple utilities for enhanced functionality, allowing for organized output and historical data collection.
2026-08-03
Go
★ 37
uCVE is a cybersecurity tool developed in Go that facilitates the extraction of Common Vulnerabilities and Exposures (CVE) associated with specific software and version numbers. It generates reports in HTML format and supports exporting data in various formats, including text, JSON, and CSV, offering customizable search parameters such as risk levels and vendor inclusion/exclusion. The tool is designed for penetration testing and vulnerability management, streamlining the process of identifying security risks in software dependencies.
2026-08-03
Python
★ 21
The Unbekannt Framework is a specialized hacking and penetration testing tool designed for Windows environments, emphasizing ease of use with a modular command system. Notable features include support for various attack modules, options configuration for each module, and the ability to import custom Python modules. The framework facilitates the execution of penetration tests while encouraging community contributions through shared module development.
2026-08-03
HTML
★ 50
WIFIHacker is a comprehensive WiFi penetration testing tool designed to automate various WiFi security audits and attacks, including phishing, SSID spamming, and denial of service attacks. Notable features include the ability to create fake access points for phishing, broadcast multiple fake SSIDs, and capture credentials. This tool requires a WiFi adapter that supports monitor mode to function effectively and aims to serve educational purposes while emphasizing responsible use.
2026-08-03
★ 544
The Windows Post-Exploitation repository provides a comprehensive resource for post-exploitation techniques specifically tailored for Windows systems. It includes an extensive catalog of commands, tools, and guides for executing post-exploitation tasks, especially in scenarios where traditional frameworks like Meterpreter are unavailable. Notable features include curated lists of PowerShell scripts, privilege escalation tools, and various post-exploitation techniques, making it an invaluable tool for penetration testers and security professionals.
2026-08-03
Rust
★ 52
WITCHCRAFT is an advanced cybersecurity toolkit designed for professionals engaged in operational security (OPSEC), offering functionalities for hacking, OSINT, and forensic analysis. Key features include a modular command structure for tasks such as port scanning, data mapping, and searching for keywords across numerous platforms, bolstered by a comprehensive spellbook containing unique wordlists and databases for enhanced reconnaissance. This tool serves as an all-in-one cyberdeck system for efficient data-ghosting, network penetration, and threat analysis.
2026-08-03
Python
★ 38
xhackTool is a penetration testing framework designed for Android systems, enabling users to easily install and utilize multiple hacking tools. This tool streamlines the setup process by automating the downloading and installation of selected penetration testing utilities, making it ideal for educational purposes in cybersecurity. Notable features include a straightforward installation procedure and user-friendly selection interface for managing various tools.
2026-08-03
Python
★ 14
The AI Cyber Range tool provides a fully automated lab environment designed for testing and securing Large Language Models (LLMs) against the OWASP Top 10 vulnerabilities. It allows users—including AI security researchers, red team professionals, and educators—to simulate real-world adversarial attacks and validate the security of LLM applications in a safe, Docker-isolated setup. Notable features include one-click installation, a progression of attack scenarios, and a local browser interface for interactive learning.
2026-08-03
Python
★ 12
BrutalNET V2 is a network attack tool specifically designed for executing large-scale ARP spoofing attacks that result in a denial-of-service (DoS) condition across an entire network. Unlike traditional ARP spoofing methods that focus on single targets, BrutalNET inundates connected devices with forged ARP packets to poison their ARP caches, effectively redirecting all network traffic to the attacker's MAC address. Notable features include its ease of use through simple command-line instructions and its capability to disrupt entire networks by leveraging the ARP protocol vulnerabilities.
2026-08-03
Shell
★ 137
The email-cracker tool is designed for the brute-force recovery of email account passwords, enabling security professionals to test password strength and enhance email account security. It automates the process of testing multiple password combinations against a specified email address and features an efficient user interface for managing target email inputs and password lists, making it suitable for penetration testing and security audits.
2026-08-03
Python
★ 133
Exploit is an offensive hacking tool designed to assist cybersecurity professionals and ethical hackers in executing exploits and conducting penetration testing. Its primary use case is to facilitate hacking activities, enabling users to automate various exploitation tasks. Notable features include ease of installation on any Linux distribution and comprehensive support for dependency management through a requirements file.
2026-08-03
Rust
★ 12
Hazard is a Rust-based dictionary brute-force tool designed for testing the security of various network protocols including SSH, FTP, Samba, MySQL, and PostgreSQL. Its primary use case is to facilitate password cracking through a user-friendly interface, allowing operators to input target IPs and utilize predefined wordlists. Key features include multi-protocol support, customizable input options, and a straightforward installation process.
2026-08-03
C
★ 73
Inject is a command line tool designed for crafting, injecting, and sniffing various network protocols, making it ideal for network troubleshooting, testing, or educational purposes. It supports multiple protocols such as Ethernet, ARP, IP, ICMP, TCP, and UDP, and includes features for creating custom network packets, integrating payload files, and capturing packets with customizable filtering options. Notable functionalities encompass detailed packet injection and robust network sniffing capabilities.
2026-08-03
Shell
★ 824
LinuxDroid is a tool that provides a Linux Command Line Interface (CLI) and Graphical User Interface (GUI) for Android, enabling users to run various Linux distributions on their Android devices. It features a one-click installation script for easy setup, supports multiple distributions like Kali and Ubuntu, and includes essential security tools such as Nmap and Wireshark, making it suitable for tasks like penetration testing and server management. Additionally, it offers multiple desktop environments and window managers, enhancing the user experience across diverse use cases.
2026-08-03
Go
★ 388
lit-bb-hack-tools is a command-line toolkit specifically designed for bug bounty hunters and penetration testers, focusing on web application security assessments. It includes a variety of tools that analyze URLs to extract critical information such as unique extensions, headers, status codes, and potential security vulnerabilities like DOM XSS sinks. Noteworthy features include processing input from standard input, producing comprehensive outputs, and supporting various common web testing scenarios.
2026-08-03
Python
★ 109
Longtongue is a tool designed to generate customized password and passphrase wordlists based on specific target information, such as individuals or companies. Notable features include the ability to incorporate various permutations like leet (1337) variations, numbers, and specified length limits, providing flexibility for different password complexity requirements. Users can easily configure the generation parameters through command-line options to tailor their wordlists for security assessments or penetration testing.
2026-08-03
Crystal
★ 39
miniss is a lightweight tool designed to display open listening sockets, serving as a minimal alternative to `ss` or `netstat`. Primarily aimed at penetration testers and CTF players, it offers a standalone static binary for environments where traditional socket tools might be absent, supporting both TCP and UDP protocols over IPv4 and IPv6. Notable features include customizable output options, socket type differentiation, and clear display of socket states along with associated user information.
2026-08-03
TypeScript
★ 121
Moxy is an open-source Dynamic Application Security Testing (DAST) tool designed for penetration testing, leveraging agentic AI capabilities for enhanced testing efficiency. Notable features include an intuitive user interface, support for both local and OpenAI's API integration for AI functionalities, and ease of deployment through Docker. Moxy is currently in beta, implying potential instability and incomplete features during active development.
2026-08-03
HTML
★ 1496
R4ven is a security research tool designed to demonstrate the potential risks associated with modern web browser permissions, illustrating how granting access can expose sensitive data such as location, camera inputs, IP addresses, and device information. It enables users to collect metadata in a controlled environment for educational purposes, emphasizing the importance of privacy hygiene and the dangers of social engineering attacks. Notable features include IP and GPS tracking, camera access, user-driven permission interactions, and integration with platforms like Discord for data presentation.
2026-08-03
Python
★ 16
Wifi-Confusion is a cybersecurity tool designed to create multiple fake Wi-Fi access points to mislead potential victims, primarily for educational purposes. It features a simplified process for accessing monitor mode and allows for the bulk generation of deceptive networks using an external Wi-Fi card compatible with Kali Linux. Users must adhere to ethical guidelines, as the tool is intended solely for legal, educational use.
2026-08-03
Python
★ 42
WIFIjam is a cross-platform WiFi deauthenticator and information tool that enables users to scan for nearby networks and perform a deauthentication attack on compatible Linux systems with the appropriate WiFi adapter. The tool boasts robust error handling, detailed WiFi information retrieval on macOS and Windows, and the ability to jam both 2.4GHz and 5GHz networks. It requires Python 3.x and various system-specific utilities to operate effectively.
2026-08-03
Python
★ 23
Xtreme Nmap Parser (XNP) is a Python utility that parses XML files generated by Nmap and converts them into various formats, including CSV, XLSX, and JSON. Its primary use case is to facilitate data analysis and reporting in network security assessments, with notable features such as file and directory handling, configurable output formats, and advanced filtering options for focusing on specific services or vulnerabilities. Additionally, XNP allows users to maintain pentesting records and provides easy documentation and data sharing capabilities.
2026-08-03
Python
★ 24
NetWatch Advanced Breach Scanner v2.0 is a sophisticated penetration testing toolkit designed for authorized security assessments, enabling users to probe web applications, APIs, and network services for vulnerabilities. Notable features include extensive recon capabilities such as web crawling and subdomain enumeration, various injection modules for SQL and XSS attacks, and robust security assessments of authentication methods and API protocols. The tool also provides detailed reporting options and a command-line interface for streamlined operations.
2026-08-03
Python
★ 48
Brutus is a Python-based tool designed for learning and experimentation in cybersecurity environments. It offers a sandbox feature for testing functionality in isolated, no-network containers, making it suitable for safe experimentation. Notable features include a development setup with linting and formatting tools, as well as a defined structure for module organization.
2026-08-03
C
★ 2448
Diamorphine is a Linux kernel module rootkit designed for various Linux kernel versions from 2.6 to 6.x across x86/x86_64 and ARM64 architectures. Its notable features include the ability to conceal processes and directories, as well as granting root privileges to specified users through specific signal commands. This tool enables undetected manipulation of the system, making it particularly useful for advanced stealth operations in cybersecurity contexts.
2026-08-03
Python
★ 165
netpwn is a Python 2.7-based framework designed for automating various penetration testing tasks. It includes modules for creating reverse shells, sending files, and generating backdoors, along with tools for hash analysis, SSL certification retrieval, and various data encoding/decoding functionalities. Notable features include an auto-complete command interface, resource links for further learning, and an accessible command structure for executing modules effortlessly.
2026-08-03
Rust
★ 11
NetRaze is an offensive network-execution toolkit developed in Rust, providing a memory-safe, single-binary alternative to traditional Python-based tools like NetExec and CrackMapExec. It maintains a similar workflow for network post-exploitation but enhances performance with async I/O and offers a desktop GUI for visual workflow composition. Currently in alpha, it focuses on core functionality with a goal of expanding its protocol coverage across various operating systems.
2026-08-03
Python
★ 180
sshprank is a versatile tool designed for SSH reconnaissance and exploitation, offering functionality for mass scanning, login cracking, banner grabbing, and assessing password authentication support. It leverages the python-masscan and Shodan modules to efficiently identify vulnerable SSH services, enabling users to experiment with various configurations and options for effective password cracking. Notable features include support for random IP address generation, multiple credential combinations, customizable thread management, and output logging for successful logins.
2026-08-03
Python
★ 414
Agartha is an advanced payload generation and access control assessment tool designed to identify injection vulnerabilities (such as SQLi, LFI, and RCE) and authentication issues in web applications. Key features include a dynamic wordlist generator for various injection vectors, a comprehensive access matrix for assessing authorization vulnerabilities, and the ability to convert HTTP requests to JavaScript for XSS exploitation. Additionally, it includes functionality for HTTP 403 bypass checks and generates Bambdas-compatible scripts for enhanced testing efficiency.
2026-08-03
Python
★ 139
Black-Hat-Python is a repository of Python scripts designed for educational and ethical hacking purposes, focusing primarily on security research. It features tools for various password and credential attacks, including capabilities for password hash cracking and LDAP brute force attacks, while emphasizing compliance with legal and ethical guidelines. Users are encouraged to utilize these tools strictly for authorized security assessments, as the repository supports responsible disclosure and proper usage protocols.
2026-08-03
Python
★ 1226
Buildware-Tools is a versatile cybersecurity multitool designed for tasks such as Discord automation, OSINT reconnaissance, network diagnostics, and cryptographic utilities, all accessible via a single terminal interface. It operates natively on both Windows and Linux, requires only Python for setup, and features an array of tools, including an IP port scanner, DNS lookup, and a website vulnerability scanner, with some functionalities accessible only after contributing to the project. Regular updates ensure continuous enhancements and the introduction of new features, while a plugin manager allows the integration of community-made plugins.
2026-08-03
Go
★ 1741
emp3r0r is an advanced, zero-trust post-exploitation framework and command & control (C2) system designed for secure operations on both Linux and Windows environments. Its notable features include autonomous gossip mesh networking, fileless memory execution of Starlark-scripted agents, and robust cryptographic identity pinning, ensuring high levels of stealth, operational control, and security against impersonation attacks. The framework facilitates seamless integration and execution without relying on host-based interpreters, making it highly suitable for high-security scenarios.
2026-08-03
Python
★ 96
Facemash is a Python-based tool designed for conducting brute force attacks on Facebook accounts, utilizing AI-driven strategies to enhance attack efficacy. It features various advanced password exploitation methods, real-time logging, and manual input capabilities, all aimed at identifying and testing vulnerabilities in social media security. Specifically developed for ethical hacking and cybersecurity research, Facemash is characterized by its precision and relentless attack mechanisms, but it is strictly intended for educational purposes only.
2026-08-03
JavaScript
★ 18
FexCam is a proof of concept tool designed for security research and education, demonstrating the exploitation of modern web APIs, including camera and geolocation functionalities, upon user consent. Its primary use case is to foster awareness of social engineering tactics and the importance of browser permission management, featuring capabilities such as media stream processing, system metadata extraction, and geolocation precision. Notable functionalities include integration with tunneling services like Ngrok and Cloudflare, enabling secure external access to local servers for demonstration purposes.
2026-08-03
Shell
★ 59
Hackify is a bash script designed for Debian-based systems that facilitates the rapid installation of penetration testing wordlists and tools with a single command. Its primary use case is to streamline the setup process for cybersecurity professionals and enthusiasts, offering ease of deployment for various pentesting utilities. Notable features include comprehensive installation commands, support for Docker installations, and optional enhancements like Firefox themes and addons tailored for security tasks.
2026-08-03
HTML
★ 44
The Hacking-PenTesting-Utils repository serves as a comprehensive collection of tools, scripts, and configurations specifically designed for Internet of Things (IoT) penetration testing. It provides a variety of microcontroller options, RF modules, and essential hardware components to assist users in developing and deploying effective IoT security testing solutions. Notable features include a diverse range of compatible microcontrollers such as the ESP32, along with numerous supporting modules for enhanced functionality in various pen-testing scenarios.
2026-08-03
C
★ 141
Lulzbuster is a high-speed, multithreaded HTTP(S) directory and file brute-forcing tool designed for penetration testing and security assessments. It leverages concurrent HTTP requests to efficiently enumerate valid file paths and directories, while offering customizable options such as status code filtering, proxy support, and client certificate usage. Notable features include the ability to minimize false positives through smart mode options and support for extensive wordlists to ensure comprehensive scan results.
2026-08-03
★ 10
Malware-Analysis is a comprehensive toolkit designed for learning and practicing malware analysis techniques, including reverse engineering, dynamic/static analysis, and sandboxing. The repository offers scripts, tools, and sample malware that facilitate hands-on experience in malware detection, classification, and analysis workflows. Noteworthy features include a curated collection of resources for anonymization, honeypots, and open-source threat intelligence, making it a valuable asset for cybersecurity professionals and researchers.
2026-08-03
HTML
★ 622
NETHERCAP is a comprehensive Wi-Fi penetration testing and social engineering tool designed for deployment on ESP8266, ESP-32, and BW16 (RTL8720dn) devices. Its primary use case involves executing attacks such as deauthentication and the Evil Twin attack, offering features like multi-language support and easy installation through its GitHub releases. The tool is particularly targeted towards users in Indonesia and includes community support via Telegram and WhatsApp for enhanced user engagement.
2026-08-03
★ 94
Pentest-Resources is a comprehensive repository that consolidates essential resources for penetration testing and red teaming, including cheatsheets, tools, techniques, and write-ups. It serves as a centralized hub for offensive security practitioners, offering categorized content that enhances knowledge sharing and skill development in various cybersecurity domains. Noteworthy features include a well-structured organization of resources across multiple categories such as API security, networking, and programming, making it a valuable tool for cybersecurity professionals.
2026-08-03
Python
★ 19
Phone Number Tracker is an advanced OSINT framework designed for comprehensive phone intelligence gathering, utilizing over 2650 lines of Python code. It provides features such as phone parsing and validation, live location tracking through multiple APIs, and extensive subscriber information. Notably, it includes capabilities for forensic reporting, case management, and deep OSINT checks across various platforms, making it a robust tool for authorized security research and educational purposes.
2026-08-03
Python
★ 27
DARKSTAR v2.1 is a command-line penetration testing framework designed for security professionals, featuring 57 modular tools across various categories. Its key features include a plug-and-play plugin system, automatic plugin discovery, a matrix-inspired color-coded terminal UI, and support for threading and async operations, making it highly customizable and efficient for diverse security assessments. The toolkit is compatible with multiple platforms, including Kali Linux, Termux, Windows (WSL), and macOS, and requires only standard Python dependencies.
2026-08-03
Python
★ 653
PyHTools is a comprehensive collection of Python-based hacking tools designed for network security assessments, including functionalities such as network scanning, ARP spoofing, DNS spoofing, and credential harvesting. It features a user interface for accessibility while allowing command-line usage for advanced users, with an emphasis on ethical use, as all malicious components are stored in a separate repository. The toolkit facilitates a wide range of cybersecurity practices, from reconnaissance to exploitation, but users are warned against any illegal applications.
2026-08-03
Shell
★ 71
setupkali.sh is a setup script designed to enhance the functionality and usability of Kali Linux, particularly for version 2026.2, by integrating features such as root login, Nemo file manager replacement, and Wayland optimization. Its primary use case is to streamline the setup process for cybersecurity professionals and students, ensuring compatibility with the latest tools and improving system management through advanced configuration and verification strategies. Notable features include a smart cleanup strategy, idempotent configuration handling, and enhanced support for various cybersecurity tools.
2026-08-03
★ 11
Web-Security is a comprehensive resource designed to educate users on web security practices, particularly focusing on the OWASP Top 10 vulnerabilities including XSS, SQL injection, and CSRF. It provides a collection of materials, tools, and hands-on labs, aimed at enhancing secure coding practices for developers. Notable features include detailed explanations of various vulnerability classes, their exploitation techniques, and links to relevant communities and learning resources.
2026-08-03
★ 18
Awesome-Hacking is a comprehensive resource hub designed for hacking, pentesting, and security research, providing a curated collection of tools and materials beneficial for System and Network Administrators, DevOps professionals, and security researchers. Notable features include its repository of daily use tools, practical navigation through a simple Table of Contents, and an open-source nature that encourages contributions from users. The repository serves as a valuable reference point for anyone interested in cybersecurity.
2026-08-03
JavaScript
★ 115
Pwnagotchi 64-Bit AI Edition is an advanced, high-performance adaptation of the Pwnagotchi project, optimized for 64-bit systems, leveraging PyTorch for enhanced AI inference and learning. Its primary use case involves automating Wi-Fi handshake capture through bettercap while intelligently adapting its behavior to varying environments based on reinforcement learning. Notable features include modernized AI engine support, a Kali Linux backbone for stable operation, and a Bluetooth Tethering Wizard for simplified connectivity setup.
2026-08-03
Python
★ 15
ShinobiShell is a specialized penetration testing tool designed for file exfiltration and exploit injection, facilitating remote shell interactions between the attacking and victim machines. Its notable features include encrypted tunnel creation, a command for seamless reverse shell connections, and capabilities for managing machine information and various payload delivery methods through a user-friendly shell interface. The tool is particularly geared toward enhancing operational efficiency during pentesting activities.
2026-08-03
Python
★ 225
black-widow is a comprehensive offensive penetration testing tool designed for various forms of information gathering and attack execution. Written in Python and offering both a web GUI and command line interface, it features capabilities such as website crawling, web page parsing, sniffing, and support for multiple asynchronous requests across multiple targets. Its continuously updated open-source framework also includes advanced functionalities for SQL injection and brute force attacks, making it suitable for both professional penetration testers and security enthusiasts.
2026-08-03
Python
★ 32
BlackBerryC2 is an encrypted remote administration and command-and-control (C2) framework primarily designed for educational and security research purposes within controlled environments. It features a custom TCP-based server that employs application-layer cryptography, including AES-256-GCM encryption and HMAC-SHA256 authentication, facilitating secure client communication, remote command execution, and file transfers. Key capabilities include session management, support for multiple concurrent clients, interactive console operations, and robust flood detection mechanisms.
2026-08-03
Python
★ 23
Blexploit is a comprehensive offensive Bluetooth Low Energy (BLE) security framework designed for red teams and security researchers, facilitating passive scanning, exploitation, and replay attacks with advanced anomaly detection. Its modular architecture includes features such as GATT enumeration, customizable attack simulations, and offline sandbox environments, while automatically generating risk assessments and attack module suggestions based on detected device UUIDs. Key functionalities, including real packet injection and an Isolation Forest-based detection mechanism, make it versatile for both testing and education in Bluetooth security contexts.
2026-08-03
Shell
★ 11
BST is a developing suite of security tools designed to facilitate various cybersecurity tasks. Its primary use case encompasses streamlining security assessments and enhancing defensive measures, with a focus on providing a comprehensive toolkit for security professionals. Notable features include modular architecture and the potential for integration with various security frameworks.
2026-08-03
Python
★ 42
Chronix is a self-hosted collaborative workspace designed for penetration testers and red team operators, facilitating the capture of notes, commands, outputs, and operational context during security engagements. Notable features include real-time synchronization, timeline logging with extensive filtering and searching capabilities, and the ability to export notes in Markdown format along with images. Additionally, it supports collaborative note-taking with markdown formatting, auto-save functionality, and a structured export mechanism for reporting workflows.
2026-08-03
Python
★ 24
claude-code-pentest automates the penetration testing lifecycle using six specialized skills that range from reconnaissance to exploit chaining and report generation. Its notable features include subdomain enumeration, vulnerability discovery across web applications and APIs, cloud infrastructure analysis, and the capability to compose findings into comprehensive bug bounty reports—all implemented via 43 standalone Python scripts that require no external dependencies. The tool is designed for authorized security testing only and is integrated with Claude Code for user-friendly command execution.
2026-08-03
★ 109
Command CheatSheet is a comprehensive reference tool designed for penetration testing, focusing primarily on the OSCP framework. It offers an extensive collection of over 130 cheatsheets and 70 port references, providing quick access to emergency commands, checklists, and tools for various stages of the pentesting process, including scanning, exploitation, and privilege escalation. The tool emphasizes usability with a structure that promotes quick copy-paste actions for efficient workflow during assessments.
2026-08-03
Python
★ 21
DRAKBEN is an AI-powered autonomous penetration testing framework that utilizes natural language processing to perform comprehensive security assessments, allowing users to issue commands in plain language. Its notable features include a self-evolving engine for dynamic tool synthesis, a multi-language interface supporting Turkish and English, and advanced memory systems for context-aware decision-making and persistent learning. This framework streamlines the penetration testing process from reconnaissance to reporting with minimal user intervention.
2026-08-03
Rust
★ 35
Ferrox is a research-focused Windows stealer written in Rust, designed to harvest sensitive data including browser credentials, cryptocurrency wallet information, and messaging app sessions while employing various evasion techniques to bypass antivirus and endpoint detection systems. Its notable features include polymorphic builds, compile-time encryption of strings, direct syscall execution, anti-analysis measures, and the ability to exfiltrate stolen data via Discord or Telegram within a stealthy execution environment. The tool is intended strictly for educational purposes in understanding modern attack methodologies for enhancing cybersecurity defenses.
2026-08-03
Python
★ 19
File Scraper is a tool designed for extracting sensitive information from files using custom regular expressions, and it generates an interactive HTML report based on the findings. Its primary use case is in security assessments and data validation, where users can employ their regex expertise to customize the search patterns for various types of sensitive data, such as authentication tokens and credentials. Notable features include the ability to style the generated reports and collect specific data formats like Base64 and PEM, enhancing the tool's versatility for educational and practical cybersecurity applications.
2026-08-03
JavaScript
★ 45
find-cve-agent is an open-source tool designed for discovering real CVEs in open-source packages using a structured multi-agent approach. It features a comprehensive workflow encompassing target discovery, vulnerability validation, and responsible disclosure, equipped with a six-gate verification process to minimize false positives. This tool is particularly aimed at enhancing the effectiveness of security researchers by leveraging a coordinated team of agents specializing in different aspects of the vulnerability hunting process.
2026-08-03
Python
★ 257
Forbidden is a cybersecurity tool designed to bypass 4xx HTTP response status codes, specifically targeting `403 Forbidden` and `401 Unauthorized` responses. Built using Python Requests and PycURL, it offers features for testing various HTTP methods, open redirects, and out-of-band interactions, while also supporting stress testing capabilities. Future enhancements aim to include options for suppressing console output and comprehensive testing for HTTP request headers and traffic manipulation techniques.
2026-08-03
JavaScript
★ 20
fsociety is a collection of offensive security plugins for Claude Code designed to facilitate penetration testing across various domains, including web applications, reverse engineering, and operational security. Each plugin offers a self-contained toolkit that includes specialized AI agents for automating multi-step operations, enhancing the effectiveness of security assessments. Noteworthy features include a comprehensive offensive lifecycle in plugins like elliot, and the ability to interactively set up engagements with tools for target selection and goal definition.
2026-08-03
PowerShell
★ 20
GhostPack Binaries is a repository offering precompiled binaries and scripts for various security and red team tools compatible with Windows, Linux, and macOS. Its primary use case is to facilitate authorized security testing and educational purposes, providing streamlined access to essential utilities while emphasizing the importance of ethical usage. Notable features include cross-platform support and a focus on prebuilt security tools, enabling users to conduct red teaming activities efficiently.
2026-08-03
CSS
★ 18
GoatOS is a specialized Linux distribution designed for web and API penetration testing, streamlining the security assessment process with a curated set of tools. It features pre-installed utilities for reconnaissance, scanning, fuzzing, and exploitation, alongside a unique reporting generator and integrated wordlists. Distinct from broader distributions like Kali or Parrot, GoatOS focuses specifically on web and API security, minimizing bloat while maximizing efficiency and ease of use.
2026-08-03
★ 99
Google Hack Search is a specialized search engine that focuses exclusively on IT security content, aggregating information from over 240 curated sources to eliminate irrelevant results. Its primary use case is to facilitate targeted research in cybersecurity by providing relevant findings without marketing noise or AI-driven content. Notable features include the ability to apply Google Dorking techniques for refined searches and a customizable list of sources to enhance the search experience.
2026-08-03
C++
★ 90
HTTPWorker is a Flask-based command and control (C2) framework designed for security competitions, utilizing custom Windows implants written in C++. Its primary use case involves coordinating and managing remote Windows clients with capabilities such as command execution, file management, system information retrieval, and user interface access through an authentication-protected web app. Notable features include Docker support for deployment, integration with Pwnboard for beacon tracking, and customizable implant configurations to evade detection.
2026-08-03
HTML
★ 314
Infosec House is a comprehensive repository offering a wide range of cybersecurity tools and resources tailored for both offensive and defensive strategies. It features over 1,100 entries across various categories including AI, API pentesting, incident response, malware analysis, and OSINT, providing cybersecurity professionals with essential resources to enhance their operations. Users can contribute to the repository by submitting pull requests or reporting issues, facilitating a collaborative environment for continuous improvement.
2026-08-03
Rust
★ 33
Injectum is a modern, type-safe Rust library designed for process injection tailored for Red Teams and Offensive Security operations. Its primary use case is to provide a structured framework for executing various injection strategies while managing memory safety and minimizing artifacts to evade detection by Endpoint Detection and Response (EDR) systems. Notable features include a modular architecture that allows dynamic swapping of injection techniques, a fluent Builder API for compile-time error detection, and robust payload management to enhance operational security.
2026-08-03
JavaScript
★ 422
The iOS Penetration Testing Cheat Sheet serves as a comprehensive resource for security professionals engaging in penetration testing of iOS applications. It provides a structured list of tools, techniques, and resources specifically tailored for testing iOS environments, particularly focusing on jailbreak scenarios and tool usage on Kali Linux. Notable features include sections for inspecting IPAs, searching for sensitive files, and executing security best practices, alongside recommendations for further reading on relevant security standards and methodologies.
2026-08-03
Java
★ 72
Java Reverse TCP is a versatile tool designed for establishing reverse shell communications with remote hosts using JAR, JSP, and Java files. It operates seamlessly across multiple operating systems, automatically detecting the environment and enabling compatible interactions with `ncat` or `multi/handler`. Notable features include the ability to handle various shell types and user-friendly setup instructions for deploying and utilizing the tool in educational contexts.
2026-08-03
Shell
★ 31
The "Kali-Linux-Complete-Setup" repository is a comprehensive collection of cybersecurity notes aimed at reinforcing foundational knowledge in the field. It consolidates learning materials derived from formal training sessions, offering structured content, personal insights, and practical examples to aid both personal learning and community contribution. This repository serves as an educational resource for aspiring cybersecurity professionals.
2026-08-03
JavaScript
★ 66
LeakScope is a tool designed for the discovery and analysis of exposed services and data leaks using Shodan and ZoomEye, enabling users to search, triage, preview, and dump relevant information accessible without authentication. Notable features include dual-provider discovery, customizable queries, and a comprehensive database that supports multiple data types and export options, all housed within a user-friendly interface that visually represents data usage and search statistics. The tool facilitates the identification of potential threats and vulnerabilities in various services without the need for exploitation, making it suitable for security researchers and IT professionals.
2026-08-03
★ 17
MCP-Penetration-testing is a comprehensive security framework focused on the OWASP Model Context Protocol (MCP) Top 10 vulnerabilities, designed for auditors, pentesters, students, and enterprises. Notable features include a checklist-driven approach that outlines attack vectors, detection techniques, and remediation strategies for each vulnerability, alongside a scoring system to evaluate MCP security maturity. The repository serves as both a pentesting playbook and a learning resource, providing a detailed roadmap for mitigating MCP risks and improving overall security posture.
2026-08-03
Python
★ 17
NetExec Automator is a parallel credential testing tool designed to exploit all 10 NetExec (nxc) protocols, allowing users to perform extensive authentication attempts using either combination or linear modes for credential pairing. Its notable features include live feedback on valid credentials and timeouts, support for local authentication variants, parallel execution with configurable worker counts, and detailed output summaries to streamline the penetration testing workflow.
2026-08-03
TypeScript
★ 29
OASIS is an open-source tool designed for benchmarking AI models in offensive security tasks such as vulnerability discovery, exploitation, and privilege escalation. Notable features include standardized Docker challenges, multi-provider benchmarking, automated analysis with MITRE ATT&CK mapping, and the Kryptsec Scoring Model (KSM) that evaluates methodology quality and success rates. The tool operates entirely locally, ensuring data privacy and no external account requirements.
2026-08-03
★ 506
The OSCP Preparation Guide is a comprehensive repository designed to aid individuals preparing for the Offensive Security Certified Professional (OSCP) certification, catering to both beginners and experienced penetration testers. It provides structured resources including syllabi, practical labs, detailed tutorials on essential skills, and exam preparation strategies, along with community contributions to enhance the guide continuously. Notably, it covers various tools required for both the OSCP exam and associated proving grounds, making it a valuable resource for aspiring cybersecurity professionals.
2026-08-03
★ 111
OSINT360 is a GPT-5.2-powered assistant tailored for open-source intelligence (OSINT), digital forensics (DFIR), and cyber investigations, offering comprehensive support for intelligence operations including collection, analysis, and reporting. Its notable features include command-based interaction for expedited workflows, structured reporting formats, a tool-first approach favoring open-source tools, and adherence to compliance and ethical standards. The tool also facilitates adversary profiling, compliance with global cyber laws, and integrates real-time intelligence through live web lookups.
2026-08-03
★ 625
Pentest Everything is a comprehensive collection of notes and write-ups focused on offensive security topics and platforms, primarily intended for viewing through Gitbook. It is frequently updated to provide insights and methodologies for penetration testing, making it a valuable resource for security professionals. Notably, the repository encourages collaboration through GitHub for those interested in forking the material.
2026-08-03
★ 406
Pentest-Notes is a comprehensive repository of notes, cheatsheets, and resources designed for penetration testing practices. This tool primarily serves as a structured guide for professionals in the field, providing organized chapters on methodologies, security cheatsheets, and offensive security techniques. Notable features include its collaborative approach, inviting contributions from users to enhance the content continuously.
2026-08-03
Python
★ 37
Pentest Toolkit is an advanced penetration testing framework designed for rapid and efficient security assessments, integrating over 100 industry-standard tools into both a Python suite for automation and a Bash interface for hands-on operations. Its primary use case includes comprehensive testing phases, from reconnaissance and web security to SSL/TLS analysis and network assessment, all culminating in professional report generation. Notable features encompass automated reporting in multiple formats, robust web application vulnerability testing, and streamlined reconnaissance processes.
2026-08-03
PowerShell
★ 42
Herramientas y utilidades de pentesting, ethical hacking y seguridad ofensiva.
2026-08-03
HTML
★ 139
The Periodic Table of Offensive Security serves as a visual reference for 118 essential tools, frameworks, and standards utilized in offensive security and red teaming. Its primary use case includes aiding penetration testing, red team training, and providing a comprehensive overview of tools for OSINT, exploitation, and post-exploitation phases. Notable features include downloadable print-friendly PDFs and an interactive clickable version that links directly to resources for each tool represented.
2026-08-03
PHP
★ 574
The PHP Reverse Shell is a versatile tool designed to create reverse shells using PHP scripts across different operating systems, including Linux, macOS, and Windows. It automatically detects the OS and works with both `ncat` and `multi/handler`, offering educational utilities for establishing reverse shells and executing file upload/download functionalities. Notably, it supports multiple PHP versions and includes specific scripts for different environments, enhancing its adaptability for penetration testing scenarios.
2026-08-03
Shell
★ 11
PiSquirrel is a compact, versatile tool designed for red team and offensive security operations, functioning as an inline wiretap for monitoring servers, workstations, and network equipment. Notable features include its ability to mimic Brother printer responses to enhance stealth during network scans, a simplified setup script for quick configuration, and pre-installed tools for various network and penetration testing tasks. The device leverages inexpensive ARM architecture and open-source software, making it a cost-effective solution for cybersecurity professionals.
2026-08-03
PowerShell
★ 13
Proxy_Bypass is a post-exploitation tool designed to identify user agents capable of circumventing proxy restrictions. It offers batch processing, the ability to test various user agents against specific domains, and includes a predefined library of user agents for immediate use. Notable features include verbose output, support for custom user agents, and future enhancements such as multi-threading and additional language support.
2026-08-03
Shell
★ 14
PurpleStorm TTPs is a comprehensive repository of commands, tools, techniques, and procedures utilized by the PurpleStorm CTF team, designed to assist in various cybersecurity tasks and challenges. Its primary use case includes facilitating tasks such as file transfers, port forwarding, establishing command and control (C2) channels, and executing penetration testing exploits. Notable features include detailed command examples for tools like Swaks, Ligolo-ng, and NetExec, which enhance users' capabilities in network exploitation and data exfiltration.
2026-08-03
Python
★ 92
Ravage Framework is a Command & Control (C2) solution tailored for cybersecurity professionals, red teams, and penetration testers, enabling them to simulate realistic attack scenarios with a secure and modular architecture. Notable features include end-to-end AES-256 encryption, advanced PowerShell obfuscation techniques, an interactive web-based dashboard for real-time monitoring, and dynamic listener management for flexible C2 operations. Its design prioritizes stealth and evasion, making it suitable for conducting penetration tests while minimizing forensic traces.
2026-08-03
Python
★ 20
The Python Reverse Shell Generator is a GUI application designed for penetration testers and red teamers, enabling them to quickly generate reverse shell payloads for both Linux and Windows environments. It boasts features such as an extensive library of over 60 Linux payloads, real-time payload generation, multiple encoding options, and a user-friendly interface that supports easy OS switching. This tool also includes one-click copy functionality and a fullscreen mode for enhanced usability during security assessments.
2026-08-03
Python
★ 18
Scrapy Scraper is a web crawling and scraping tool that utilizes Scrapy integrated with Playwright's headless browser to handle JavaScript-rendered content effectively. Its primary use case includes probing, crawling, and extracting data from websites, with features such as support for concurrent requests, customizable sleep intervals, and the ability to take screenshots. Additionally, it offers options for rate limiting and recursive crawling, enhancing its usability for various scraping scenarios.
2026-08-03
HTML
★ 38
SecuSploitX is an advanced, modular, open-source penetration testing and cybersecurity toolkit designed for offensive security operations. It features a comprehensive suite of tools including web and network security modules, AI-driven automation for tasks like phishing simulations, and both GUI and CLI interfaces for user flexibility across multiple platforms. Notable capabilities include automated vulnerability scanning, advanced brute force tactics, and extensive documentation, making it suitable for both educational and professional use.
2026-08-03
Python
★ 173
SuperLibrary is an educational repository designed to provide access to a collection of books and courses aimed at individuals who may face financial constraints in obtaining these learning resources. It emphasizes ethical usage, urging users to support authors and publishers whenever possible, while also featuring a disclaimer regarding copyright and legal responsibilities. Notable features include categorized content such as books and courses, fostering self-education in various subjects.
2026-08-03
★ 33
The TryHackMe-Beginner-Roadmap is a structured learning resource designed for novices in cybersecurity, providing a step-by-step guide to essential concepts and skills via the TryHackMe platform. It covers foundational topics such as operating system fundamentals, basic security principles, reconnaissance techniques, scripting for automation, and web security vulnerabilities, while incorporating hands-on exercises to reinforce learning through practical application. Notable features include a comprehensive overview of key cybersecurity tools and methodologies, facilitating knowledge development in both theoretical and practical dimensions.
2026-08-03
Ruby
★ 693
URLCrazy is an OSINT tool designed for generating and testing domain typos and variations to identify instances of typo squatting, URL hijacking, phishing, and corporate espionage. Notable features include support for 17 types of domain variants, over 8000 common misspellings, compatibility with 1500+ Top Level Domains, and options for popularity estimation and keyboard layout configurations. The tool automates the detection of potential threats against domains by checking the validity and usage of generated typo variants.
2026-08-03
Python
★ 48
w4af is an open-source web application security scanner designed for developers and penetration testers to identify and exploit over 200 vulnerabilities, such as Cross-Site Scripting and SQL Injection. Built on Python 3.11 and currently in an alpha development phase, it features integrations for unit and integration testing alongside comprehensive documentation for user guidance.
2026-08-03
★ 13
The MottaSec White Papers repository is a centralized collection of technical and cybersecurity white papers published by MottaSec, providing insights into various topics such as military drone security and IoT device boot integrity. Notable features include a clear organizational structure for easy navigation, self-contained papers with supporting materials, and multiple access formats including GitHub markdown and professionally formatted PDFs. This repository serves as a vital knowledge base reflecting the expertise and research of MottaSec in the cybersecurity domain.
2026-08-03
JavaScript
★ 488
The Android Penetration Testing Cheat Sheet is a comprehensive reference guide aimed at security professionals conducting penetration tests on Android applications. It provides a structured checklist of tools, techniques, and methodologies optimized for use in a Kali Linux environment, highlighting critical tasks such as APK inspection, vulnerability exploitation, and various Android security configurations. Notable features include integration of resources from OWASP, practical tips for creating proof-of-concept apps, and a focus on common vulnerabilities and mitigation strategies for Android apps.
2026-08-03
Python
★ 327
AutoProber is a hardware automation tool designed for probing individual pins on electronic components, facilitating hardware hacking processes. Its primary use case involves ingesting projects, identifying probe targets using a combination of a microscope and CNC-controlled hardware, and enabling users to approve or deny targets for probing, all managed through a web dashboard or Python scripts. Notable features include real-time calibration, frame stitching to create annotated maps of targets, and a robust safety model for hardware control.
2026-08-03
★ 628
The Awesome CI/CD Attacks repository provides a comprehensive collection of offensive research techniques targeting Continuous Integration and Continuous Deployment (CI/CD) systems. It features curated lists of attack methodologies, tools, and case studies focused on exposing sensitive data and identifying vulnerabilities within development pipelines, emphasizing notable trends such as publicly exposed secrets and initial code execution exploits.
2026-08-03
TypeScript
★ 65
BugHunter AI is an autonomous bug bounty hunting framework that leverages Claude Code and the Personal AI Infrastructure (PAI) to conduct vulnerability assessments without human intervention. Its notable features include 28 specialized AI agents and 51 skills that operate in parallel through hypothesis-driven attacks, real-time reporting, and automatic generation of professional bug bounty reports. This tool significantly accelerates the reconnaissance and exploitation phases of security testing, offering enhanced capabilities such as cross-session learning and encrypted credential management.
2026-08-03
Python
★ 33
Chad is a tool designed to search for Google Dorks, allowing users to find indexed information on the web efficiently, utilizing Playwright's headless browser for bypassing common security measures. Its notable features include the Chad Extractor for data extraction and validation, file download capabilities, and options to handle Google’s frequently changing cookies. Additionally, it offers a broken link hijacking feature and is primarily intended for educational use in cybersecurity research.
2026-08-03
Python
★ 302
Deadend CLI is an autonomous web application penetration testing tool that utilizes a feedback-driven iteration approach to adapt its exploitation strategies. It boasts a model-agnostic architecture capable of generating custom Python payloads, executing fully local operations without cloud dependencies, and achieving approximately 80% success on the XBOW validation benchmark. Key features include a supervisor-subagent hierarchy for task delegation, confidence-based decision-making, and custom sandboxed tools like Playwright and Docker for enhanced pentesting capabilities.
2026-08-03
Python
★ 55
DFMI (Don't Fool My Installer) is a toolkit designed for fileless code execution and covert payload delivery via Windows Installer (.msi) files, exploiting the CustomAction mechanism to execute arbitrary payloads silently during installation. Notable features include the ability to inject backdoors into both signed and unsigned MSI packages without altering their signatures, support for cross-platform payload generation, and functionalities for SSL encryption and IPv6. This tool is intended for authorized red team engagements and penetration testing only.
2026-08-03
Python
★ 524
EVA is an AI-driven penetration testing tool designed to aid users throughout the pentesting lifecycle with intelligent analysis, automated enumeration, and real-time vulnerability assessment. It features support for multiple AI backends, session management for persistent interactions, and an interactive interface for executing commands and analyzing results, thereby enhancing the efficiency of penetration testing efforts. This tool aims to assist, rather than replace, cybersecurity professionals by providing strategic guidance and quicker outcomes during engagements.
2026-08-03
Python
★ 20
FBps (Forbidden Bypass) is a fast HTTP fuzzer specifically designed for identifying access control bypass vulnerabilities (401/403) in web applications by generating varied HTTP requests across methods, URLs, and headers. Notable features include level-based scanning, URL and query parameter fuzzing, header manipulation, API version downgrades, and customizable output options, making it a robust tool for security testing and vulnerability discovery. This tool is accompanied by FBpsLab for local payload tuning and reproducible testing environments.
2026-08-03
Python
★ 15
HackingGPT is an advanced terminal tool designed for penetration testing and bug bounty hunters, leveraging the ChatGPT and DeepSeek APIs to provide dynamic command suggestions and interactive execution. Notable features include the ability to run commands in a terminal or interactive shell, aggregate output for analysis, and a continuously integrated workflow that supports multiple API models while emphasizing offensive security practices. The tool is user-friendly, with a colored interface for enhanced readability and environment variable configuration for secure API key management.
2026-08-03
★ 429
Hack The Box Reporting using SysReptor is a user-friendly and customizable pentest reporting tool designed to streamline the creation of reports for various certifications such as CPTS, CWES, and CDSA. It allows users to write reports in Markdown format, which can then be rendered to PDF without the hassle of local software issues, making it ideal for security professionals focused on reporting efficiency. Notable features include free access, easy self-hosting options, and a collection of pre-built templates specifically tailored for Hack The Box certifications.
2026-08-03
Python
★ 106
JusotLabs is a curated toolkit designed for ethical hacking, penetration testing, and security research. It offers a diverse range of Linux-compatible scripts for tasks such as DNS reconnaissance, port scanning, DDoS simulation, and network threat detection, alongside educational resources like CTF writeups and a reading list. Users are encouraged to leverage these tools within authorized environments to enhance their hacking skills and deepen their cybersecurity knowledge.
2026-08-03
Go
★ 532
Ligolo-MP is a sophisticated pentesting tool that facilitates collaborative pivoting through a client-server architecture, allowing multiple concurrent tunnels with automated TUN management. Its notable features include SOCKS and HTTP proxy support, cross-platform compatibility, and dynamic mTLS-enabled agent generation, all while providing a user-friendly terminal-based GUI for efficient monitoring and management.
2026-08-03
Python
★ 11
LogHound is a post-exploitation tool designed for analyzing Windows Security Event Logs (.evtx) to facilitate BloodHound mapping, aiding Red Teams in tracking lateral movement targets and deciphering active user sessions. Notable features include a chunk-based streaming parser that minimizes memory usage, support for Pass-The-Hash and Kerberos authentication methods, and the ability to generate detailed reports in various formats, ensuring effective operational security during network penetration testing.
2026-08-03
Python
★ 263
Machine Learning CTF Challenges provides a collection of capture-the-flag (CTF) challenges focused on exploiting vulnerabilities in AI agents, machine learning pipelines, and large language models. Users can engage in practical scenarios such as manipulating training data, prompting model injections, and breaching autonomous systems to capture flags. The repository includes nine challenges that vary in difficulty and are aligned with OWASP and MITRE attack vectors, thus addressing contemporary security concerns in AI applications.
2026-08-03
Java
★ 152
Malware APK is a testing and exploitation tool designed for security engineers and bug hunters to create malicious Proof of Concept (PoC) applications for vulnerability testing in Android environments. Notable features include a variety of testing modules for intent injection, task hijacking, and accessibility monitoring, without requiring device rooting. It also supports advanced options like caching intercepted intents and compiling native code for arbitrary code execution, making it a comprehensive utility for penetration testing.
2026-08-03
Python
★ 772
MCP Security Hub provides a collection of production-ready, Dockerized Model Context Protocol (MCP) servers tailored for offensive security applications, enabling AI-assisted security assessments and vulnerability scanning. With 38 MCP servers covering various domains like reconnaissance, web security, and binary analysis, it integrates over 300 security tools accessible through natural language commands via AI clients like Claude. Noteworthy features include a CI/CD-ready setup with GitHub Actions, minimal Docker images, and orchestration capabilities with Docker Compose for streamlined multi-tool workflows.
2026-08-03
Python
★ 10
The Microsoft SQL TDS Downgrade Attack tool performs a Man-in-the-Middle attack by intercepting Tabular Data Stream (TDS) packets between a client and MSSQL server, enabling the downgrading of encryption for TDS login packets. Its primary use case is to extract sensitive login credentials (username and password) by manipulating traffic through ARP spoofing and modifying intercepted packets. Notable features include automatic cleanup of the ARP spoofing and iptables rules upon stopping the script, and requirements for running include a Linux host with root privileges and necessary dependencies like arpspoof and iptables.
2026-08-03
Python
★ 18
NekoCLI is a lightweight AI assistant for terminal environments that facilitates image and video generation, code creation, and command execution. It boasts features such as persistent chat history, a variety of operational modes including pentest capabilities, and visually formatted output. Designed for quick access and minimal dependency, NekoCLI allows users to handle media files and interact with an AI logic API for real-time assistance.
2026-08-03
TypeScript
★ 81
Null AI CLI is an open-source command-line interface designed for authorized penetration testing and compliance readiness assessments, providing a framework for safe reconnaissance, scanner orchestration, and evidence-backed findings. It offers efficient local assessments, supports OWASP Top 10 coverage, and produces Markdown/SARIF reports, allowing teams to quickly obtain valuable security feedback. Notable features include reusable model profiles, encrypted API key storage, and a guided home screen for streamlined user interactions.
2026-08-03
Python
★ 352
Offensive Claude is a spec-driven offensive security framework designed for Claude Code that implements structured engagement workflows following the Cyber Kill Chain methodology. It features a comprehensive set of 31 kill-chain skills, collaborative agents, and a shared vulnerability library, facilitating automated penetration testing, reconnaissance, exploit development, and reporting through a series of orchestrated commands. This tool is particularly useful for security researchers and practitioners to streamline their offensive security operations while maintaining high quality and traceability throughout the engagement process.
2026-08-03
★ 16
offsecnotes is a comprehensive web platform that aggregates notes and resources focused on offensive security and penetration testing methodologies. It encompasses various topics including Android, web application security, networking, and operating systems like Linux and Windows, providing essential concepts, exploitation techniques, and practical tools for security practitioners. Notable features include organized sections for different domains of security, making it a valuable reference for both beginners and experienced professionals.
2026-08-03
TypeScript
★ 23
Operant-MCP is a comprehensive security testing tool designed for penetration testing, network forensics, memory analysis, and vulnerability assessment, offering an extensive array of 51 specialized tools. Key features include SQL injection tests, XSS vulnerability assessment, command injection detection, PCAP analysis for network traffic, and cloud security audits. This tool is targeted at security professionals seeking to streamline their testing processes and enhance their incident response capabilities.
2026-08-03
TypeScript
★ 58
recon-deck is a self-hosted reconnaissance tool that transforms nmap output into an actionable, port-aware checklist in under 30 seconds. It features an AI co-pilot to explain scan results and suggest next steps, supports cross-host attack planning, and provides detailed export options for penetration testers and OSCP students, all while maintaining offline functionality. Notable capabilities include usage analytics and integration with HackTricks for enhanced documentation.
2026-08-03
PowerShell
★ 446
Red Team Playbooks is a comprehensive repository designed to assist cybersecurity professionals in Red Team engagements by providing a collection of open-source tools, techniques, and procedures. Its primary use case includes guiding users through various phases of penetration testing such as reconnaissance, exploitation, and post-exploitation activities. Notable features include detailed playbooks for each stage of an attack lifecycle, covering essential actions from initial access to data exfiltration and situational awareness.
2026-08-03
Rust
★ 59
Rustsploit is a modular offensive security tool written in Rust, designed for targeting embedded systems such as routers and cameras. It features a unified interface that provides an interactive shell, command-line execution, and a post-quantum encrypted REST/WebSocket API, along with built-in fingerprinting using Recog and JARM/JA3 methods. Notable aspects include self-registering modules, a credential management system, and extensive support for various network protocols and services, making it a versatile tool for penetration testing and vulnerability assessment.
2026-08-03
JavaScript
★ 185
SUASS is a comprehensive repository designed to provide cybersecurity professionals and learners with a wide array of study materials, covering essential topics such as penetration testing, cloud security, mobile application security, network security, and more. This resource serves as a centralized hub for enhancing knowledge and skills in cybersecurity, offering practical learning pathways through Capture the Flag (CTF) challenges and recommendations for certifications. Notable features include categorized content for various security domains and links to external learning platforms and communities.
2026-08-03
Python
★ 48
SubSurfer is a high-performance tool designed for subdomain enumeration and web property identification, ideal for red team operations and bug bounty hunting. It features fast asynchronous scanning, customizable port scanning, and web service identification capabilities, with a modular design that allows integration with other tools or use as a Python module. Continuous updates and the ability to tailor scans make it a versatile choice for cybersecurity professionals.
2026-08-03
Python
★ 25
WebStrike is an automated web penetration testing framework designed to orchestrate various Kali tools through a structured phase-based pipeline, enhancing the workflow of web pentesting. It links tools together, utilizing outputs from one as inputs for the next while providing deduplication and comprehensive reporting. The framework allows for both manual and automated modes of operation, enabling users to manage the level of intrusion and control over testing processes efficiently.
2026-08-03
Python
★ 13
WebXray is an offensive web scanner developed in Python that facilitates comprehensive security assessments by combining features such as crawling, XSS and SQL injection detection, security header analysis, and WAF detection. Its notable capabilities include reflected XSS detection, support for various output formats, and ease of integration into existing bug bounty workflows or pipelines. Designed primarily for security professionals, it helps identify potential vulnerabilities in web applications during reconnaissance.
2026-08-03
Python
★ 109
The AISecurity tool, now archived, was part of the Syntrex project, which has since evolved into the Syntrex AI SOC platform. Its primary use case involved providing an open-source core through GoMCP with support for the MCP protocol. Notable features included modular architecture and compliance with the Apache 2.0 License.
2026-08-03
Python
★ 17
The Cyber Security Projects repository encompasses a collection of hands-on projects tailored for learning and experimentation in cybersecurity. It includes offensive and defensive tools, automation scripts, and real-world simulations, designed to enhance ethical hacking skills and practical security research. Notable features include a diverse set of project categories ranging from reconnaissance and web application security to network attacks and malware analysis.
2026-08-03
Go
★ 14
frameseven is a CLI-oriented offensive web security scanner designed for authorized security testing, capable of mapping a target's attack surface while executing active checks for prevalent web vulnerabilities and misconfigurations. Key features include extensive reconnaissance capabilities, support for authenticated scans, and structured reporting options, along with a dedicated MCP server for AI agents to utilize the same framework tooling. The tool emphasizes a standard-library-centric Go codebase, enhancing readability and extendability.
2026-08-03
Go
★ 965
goshs is a versatile, single-binary file server designed for file transfer and capture tasks during penetration testing engagements. It supports multiple protocols including HTTP/S, WebDAV, FTP/SFTP, SMB, and LDAP, and offers features such as hash capturing, basic authentication, self-destructing payloads, and a TUI for interactive operations. Notable functionalities include token-based link sharing, DNS and SMTP server capabilities, and advanced collaboration tools for CTF scenarios.
2026-08-03
★ 1646
HaleHound™-CYD is a multi-protocol offensive security toolkit designed for the ESP32 Cheap Yellow Display, featuring over 40 attack modules focused on WiFi, Bluetooth, SubGHz, 2.4GHz, and NFC communications. This toolkit is designed for ease of use, allowing users to flash configurations directly from their browser without installation, and it supports various display sizes while incorporating external modules for enhanced functionality. Notable features include touch-driven controls and the capability to transmit at maximum power, facilitating a range of offensive security activities.
2026-08-03
Shell
★ 14
Offensive security blog, projects & portfolio by Elimane D.
2026-08-03
Go
★ 20
Kentra is a Kubernetes-based offensive security framework designed for orchestrating penetration testing, red teaming operations, and large-scale security scans, both within and outside Kubernetes clusters. It allows users to define security tests as declarative YAML manifests, automating orchestration, scheduling, and logging through its native Kubernetes resources. Notable features include integration with Helm for deployment, a customizable dashboard for command output aggregation, and the use of a ConfigMap to manage tool specifications.
2026-08-03
Go
★ 305
knary is a canary token server designed to alert users via messaging platforms like Slack, Discord, and Teams when specific HTTP(S) or DNS requests are made to designated domains. Its primary use case is to enhance offensive security by notifying teams of interactions with their controlled servers, thereby revealing potential vulnerabilities and providing insights into unauthorized access attempts. Notable features include subdomain allow/denylisting, integration with Burp Collaborator, and automatic TLS certificate management through Let's Encrypt.
2026-08-03
Python
★ 168
LVRP (Local Vuln Research Pipeline) is an exhaustive LLM-driven vulnerability research tool designed to identify vulnerabilities across various source code files in up to 16 programming languages. It constructs a complete call graph of the codebase, enumerates all source-to-sink paths, and validates these paths for exploitability using a hybrid approach that combines static analysis and LLM insights. The tool is capable of analyzing extensive projects such as the Linux Kernel and VSCode, while ensuring deterministic path enumeration and comprehensive coverage, including blind spot reviews.
2026-08-03
Python
★ 14
Nagooglesearch is a Python library designed to facilitate web searches without relying on Google's direct API, making it suitable for educational and testing purposes. It allows users to customize search parameters, manage user agents, and configure cookies while ensuring the return of unique, relevant URLs that do not contain the keyword "google." Notable features include adjustable sleep intervals between requests to prevent rate limiting, the ability to specify custom user agents, and support for proxy connections.
2026-08-03
Go
★ 2403
Pentest Swarm AI is an open-source penetration testing tool that leverages a swarm architecture for coordinated multi-agent operations, enabling efficient vulnerability assessment. Its primary use case is facilitating authorized security testing through live integration with popular offensive tools like nmap, sqlmap, and Metasploit, while incorporating AI models for advanced analysis. Notable features include a stigmergic blackboard for agent coordination, automated evidence capture, and the ability to generate submission-ready reports.
2026-08-03
TypeScript
★ 579
PentestCode is an AI-driven penetration testing agent that operates directly in the terminal, enabling users to conduct comprehensive security assessments with minimal input. It features a multi-agent architecture that autonomously scans, enumerates, attacks, and exploits vulnerabilities within a defined target, while systematically tracking engagement state and allowing real-time querying of findings. Supporting over 20 large language model providers, PentestCode streamlines the offensive security process and facilitates detailed reporting with evidence of each engagement step.
2026-08-03
Python
★ 18
ProbeAgent is a command-line tool designed for offensive security testing of AI agents, performing automated red-team attacks such as prompt injection and credential exfiltration against any HTTP-accessible agent. Notable features include a detailed attack grading system that categorizes responses as Compromised, Resisted, or Blocked, allowing users to evaluate the effectiveness of their security controls, and advanced guardrail detection to distinguish between model defenses and actual security mechanisms.
2026-08-03
Shell
★ 240
Secfiles is a repository that provides a collection of useful files designed for penetration testing, security assessments, and bug bounty hunting. Its primary use case is to facilitate security-related tasks by offering easily accessible resources and scripts. Notable features include a straightforward cloning process and comprehensive release notes for version tracking.
2026-08-03
Python
★ 59649
Strix is an open-source AI-powered penetration testing tool designed to autonomously identify and remediate vulnerabilities in applications. It provides a comprehensive pentesting toolkit including real exploit validation, multi-agent orchestration for scalability, and integration with CI/CD pipelines for continuous security checks. Key features include actionable findings with remediation guidance, auto-fixing capabilities, and the generation of compliance-ready reports, significantly accelerating the security testing process compared to traditional methods.
2026-08-03
Shell
★ 42
Venom is a comprehensive collection of tools, resources, and documentation focused on information security, penetration testing, and offensive cybersecurity. Its primary use case is to serve as a centralized repository for cybersecurity professionals seeking various utilities, from analysis and network reconnaissance to incident response and exploit development. Notable features include organized sections for different types of tools, such as anti-virus evasion, cloud security, and forensics, facilitating easy access to resources tailored for various cybersecurity needs.
2026-08-03
Rust
★ 21
WafRift is a programmable WAF-evasion engine designed to test and bypass web application firewalls by generating and exploiting payload mutations through various encoding and grammar strategies. Its primary use case is for security researchers and penetration testers seeking to identify WAF vulnerabilities, featuring automated scanning, detailed response classification, and an integrated discovery tool for API endpoints. Notable features include customizable evasion strategies, session management, multi-signal response analysis, and comprehensive WAF fingerprinting capabilities.
2026-08-03
C++
★ 15
WindowsShell-Injector is a shellcode execution framework designed for security research and penetration testing on Windows systems. It features encrypted payloads, anti-debugging mechanisms, and an intuitive Qt-based GUI, allowing for seamless loading and execution of shellcode. Notable capabilities include asynchronous execution via separate threads, dynamic memory protection, and runtime API resolution to enhance evasion of static analysis tools.
2026-08-03
PHP
★ 32
Zerdecalistops is an optimized wordlist collection designed for cybersecurity researchers and penetration testers, tailored by Zencefil Efendi and enhanced with a dashboard interface. Its primary use case is to provide comprehensive and up-to-date datasets—including usernames, passwords, and fuzzing payloads—essential for cybersecurity operations. Notable features include its extensive compilation of resources and user-friendly dashboard for easy access.
2026-08-03
C
★ 94
ADMmutate is a polymorphic shellcode mutation engine designed to evade Network Intrusion Detection Systems (NIDS) by generating unique but functionally equivalent code fragments that resist signature-based detection. Its notable features include XOR-based polymorphic encoding, sliding key mechanisms, and multiple code paths, enhancing its ability to obfuscate shellcode in various architectures such as IA32, SPARC, and MIPS. The tool specifically targets signature analysis weaknesses in NIDS, employing advanced techniques to adapt and randomize its output dynamically.
2026-08-03
Python
★ 2254
CloakQuest3r is a Python-based security research tool designed to assess potential origin IP exposure of websites utilizing Cloudflare and similar reverse proxy or CDN services. Its primary use case involves subdomain enumeration and passive analysis techniques to identify misconfigurations that could lead to the disclosure of sensitive server infrastructure. Notable features include its capability for real IP detection, making it essential for security professionals, penetration testers, and web administrators focusing on authorized security testing and infrastructure hardening.
2026-08-03
Python
★ 16
The CVE-2025-59287 tool is an automated exploit designed to target a critical unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS). Its primary use case is to facilitate the exploitation of this vulnerability with minimal user intervention, offering features such as payload generation, built-in reverse shell capabilities, cross-platform compatibility, and AES encryption. The tool also includes dependencies auto-management and can be run across multiple operating systems, ensuring ease of use for penetration testers and security researchers.
2026-08-03
Python
★ 31
The tool exploits a command injection vulnerability in the pdfkit Ruby gem, specifically in versions prior to 0.8.7.2, allowing attackers to execute arbitrary commands through specially crafted URLs. Key features include custom command generation and reverse shell capabilities, providing flexibility for targeting vulnerable web applications. The exploit serves solely for educational and authorized security research purposes.
2026-08-03
Python
★ 149
HackingAllTheThings is a curated repository of cybersecurity tools and notes, aimed at supporting the archiving and study of various IT security certifications. It includes both original tools developed by the author and additional resources collected from diverse sources, thereby providing a structured approach to cybersecurity learning and practice.
2026-08-03
Python
★ 13
Misanthro.py is a multi-threaded injection framework designed for aggressive testing of HTTP headers, cookies, and GET/POST parameters, specifically targeting blind injection vulnerabilities such as blind XSS. It features high-throughput payload delivery, authenticated session support, and customizable attack vectors, while not interpreting application responses. The tool is optimized for speed and scalability, allowing users to perform extensive injection testing with minimal configuration.
2026-08-03
Python
★ 53
React2Shell is an advanced exploitation toolkit specifically designed to target the React2Shell vulnerability (CVE-2025-55182) in Next.js applications. It offers an interactive shell experience with features such as command history, automated privilege escalation through pipe injection, and secure file transfer capabilities using base64 encoding. The tool consolidates its exploit logic into a single executable file, making it portable and easy to deploy for ethical penetration testing and security research.
2026-08-03
Python
★ 67
Red Team Rising is a comprehensive resource repository designed for red and purple team professionals, encompassing topics like Penetration Testing, Digital Forensics, Exploit Development, and Malware Analysis. It provides curated study materials, reference links to training platforms and notable YouTube channels, as well as practical commands and tools for various OS distributions suited for cybersecurity tasks. Notable features include a wide array of recommended resources for self-study and a focus on both offensive and defensive security strategies.
2026-08-03
Python
★ 94
This repository serves as a comprehensive resource for ethical hacking and penetration testing, offering a collection of articles, scripts, tutorials, and multimedia content focused on various platforms including Linux, Windows, and cloud services. It aims to share the author's expertise and provide guidance on security practices while emphasizing the importance of legal compliance. Regular updates are planned to enhance the repository's educational value for the cybersecurity community.
2026-08-03
AutoIt
★ 120
ForceAdmin is a malicious tool designed to create an infinite loop of User Account Control (UAC) prompts, compelling users to grant administrative privileges by overwhelming them with requests. It provides various script templates in formats such as batch, PowerShell, AutoHotkey, AutoIt, HTA, and VBScript, facilitating execution via PowerShell and bypassing antivirus protections. Notable features include no dependencies, dual architecture support for x86 and x64 systems, and a fileless execution method.
2026-08-03
Python
★ 51
AttackMate is an automation tool designed to execute cyber attack scenarios across all phases of the Cyber Kill Chain, integrating seamlessly with penetration testing frameworks like Metasploit and Sliver Framework. It allows users to script commands, generate payloads, schedule and chain attack steps using configuration files, and perform background operations, including file transfers and HTTP interactions. Noteworthy features include automation of shell or SSH commands, comprehensive support for Metasploit and Sliver commands, and a user-friendly interface for managing complex attack scenarios.
2026-08-03
★ 733
Awesome MCP Security is a comprehensive resource focusing on the security aspects of the Model Context Protocol (MCP), providing guidance on best practices, potential vulnerabilities, and mitigation strategies. It includes a variety of materials such as academic papers, articles, tools, and security considerations aimed at enhancing the security of applications utilizing MCP. Notable features include detailed security guidelines for both clients and servers, highlighting the importance of human oversight and proper input validation.
2026-08-03
Jupyter Notebook
★ 729
BlueToolkit is an extensible, black-box framework designed for testing Bluetooth vulnerabilities in both Bluetooth Classic (BR/EDR) and Bluetooth Low Energy (BLE) systems. Its primary use case includes semi-automated testing through its three main modules: Recon for capability gathering, Exploit for executing a range of 43 public exploits, and Report for generating comprehensive JSON reports. Additionally, the framework has been evaluated against multiple automotive brands, revealing significant security vulnerabilities in their Bluetooth implementations.
2026-08-03
TypeScript
★ 16
clpzcode is an automated penetration testing tool that orchestrates a full pipeline of security assessments, including subdomain enumeration, vulnerability detection, exploitation, and privilege escalation. Notably, it employs an AI agent that intelligently adapts its actions based on tool responses, supports multi-agent parallelism for concurrent tasks, and features 29 built-in escalation chains for efficient threat exploitation. The tool’s command-driven interface allows users to initiate complex assessments with minimal input, streamlining the penetration testing process.
2026-08-03
Python
★ 10
The "Cracking OSCP" repository offers a comprehensive roadmap for aspiring ethical hackers pursuing the OSCP certification. It features a structured playlist of video tutorials and supplementary notes across various topics, including computer networks fundamentals and practical examples, aimed at providing a solid foundation for ethical hacking methodologies. Notable aspects include detailed guidance on note-taking, network concepts, and the OSI model, making it a valuable resource for both beginners and those preparing for the OSCP exam.
2026-08-03
Shell
★ 20
This tool serves as a proof of concept (PoC) exploit for the Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013, which allow for path traversal and remote code execution (RCE) in versions 2.4.49 and 2.4.50. Its primary use case is to demonstrate these exploits against specified targets, facilitating security assessments and vulnerability testing. Notable features include the ability to read sensitive files and execute arbitrary commands on the server via customizable input parameters.
2026-08-03
Python
★ 527
CVE-2024-6387_Check is a specialized tool for detecting servers vulnerable to the newly identified `regreSSHion` vulnerability in OpenSSH (CVE-2024-6387). It supports rapid scanning of IP addresses, domain names, and CIDR ranges, incorporates features such as multi-threading for efficiency, SSH banner retrieval, and options for assessing LoginGraceTime settings, all while providing detailed and easily interpretable output. Notably, the tool also includes IPv6 support and recognizes patched OpenSSH versions to enhance the accuracy of vulnerability assessments.
2026-08-03
Python
★ 16
CVE-2026-48908-PoC is a proof-of-concept exploit for a critical unauthenticated remote code execution vulnerability in the SP Page Builder component for Joomla. This tool leverages the improper access control in the asset.uploadCustomIcon task to upload malicious files to a publicly accessible directory, ultimately enabling an attacker to execute arbitrary code on the target server. Notable features include an adaptive payload mechanism that tests various file extensions and .htaccess file injections to bypass server restrictions, as well as cleanup functionality to remove uploaded artifacts after exploitation.
2026-08-03
Python
★ 12
CVE Mapper is a tool designed to correlate Nmap scan results with relevant CVEs specific to the discovered product versions, minimizing false positives. It utilizes the Vulners API to provide version-accurate vulnerability mappings while re-validating the affected version ranges and generating confidence levels for each finding. The tool supports multiple output formats including JSON, CSV, and HTML, making it versatile for reporting and further analysis.
2026-08-03
Python
★ 329
HatSploit is a modular penetration testing framework designed for writing, testing, and executing exploit code. Its primary use case is to facilitate security assessments and vulnerability exploitation in a structured manner. Notable features include its extensibility through modules and a user-friendly interface for deploying exploits.
2026-08-03
HTML
★ 42
The k8gege.org repository hosts a website that serves as a centralized platform for Kubernetes-related resources and tools. Its primary use case is to provide educational content, documentation, and best practices for Kubernetes users and developers. Notable features include curated links to tutorials, articles, and other valuable resources in the Kubernetes ecosystem.
2026-08-03
C
★ 18
The Linux-Exploitation repository provides a comprehensive set of tools and techniques for performing privilege escalation on Linux systems. Its primary use case is to assist security professionals in identifying vulnerabilities that can be exploited to gain higher access levels, featuring sections on manual enumeration, automated tools, password mining, misconfiguration exploitation, and maintaining access through SSH key uploads. Notable features include detailed guides on various escalation methods, scripts for automated enumeration, and an exhaustive list of potential exploits tailored for Linux environments.
2026-08-03
Python
★ 77
Mephisto is a WordPress vulnerability scanner and exploitation framework designed for authorized penetration testing, enabling security professionals to assess multiple WordPress installations for security weaknesses. Key features include multi-CVE support, mass scanning capabilities, automatic detection of vulnerable plugins and themes, and the ability to upload web shells for post-exploitation access, all while ensuring anonymity through proxy support and anti-detection measures.
2026-08-03
Go
★ 68
OnlyShell is a Go-based reverse shell handler designed for penetration testers and security researchers, enabling the management of multiple reverse shell connections concurrently. Key features include automatic shell type detection, background shell management, command broadcasting across active shells, and the option for encrypted communications with TLS support. The tool offers an intuitive command-line interface and allows for real-time interaction and status monitoring of all connected sessions.
2026-08-03
TypeScript
★ 15
This repository provides a proof-of-concept for CVE-2025-55182, a critical pre-authentication remote code execution vulnerability found in specific versions of React Server Components. The vulnerability enables unauthenticated attackers to execute arbitrary JavaScript code on the server by exploiting unsafe deserialization through prototype chain traversal in the Flight protocol. Notably, the tool facilitates demonstration of the exploit process, requiring a vulnerable React setup and tools like Burp Suite for payload delivery and testing.
2026-08-03
Go
★ 12
Prober is a pentesting framework designed to simplify the management of GitHub repositories by eliminating the complexities of git submodules. Its primary use case is to allow penetration testers to easily download and clone necessary tools with straightforward commands, enhancing usability in security assessments. Notable features include a clean execution script and a focus on user-friendly setup processes.
2026-08-03
Python
★ 36
ropcatalog is a Python tool designed for parsing, classifying, and browsing ROP (Return-Oriented Programming) gadgets from rp++ output files, primarily aiding in Windows exploit development. It features an interactive REPL with extensive search options, ASLR support for dynamic address adjustments, bad character filtering to enhance exploit reliability, and multiple output formats for easy integration into exploit code. The tool is tailored for users engaged in ROP chain construction and binary exploitation tasks.
2026-08-03
Python
★ 13
wphunter is a Python CLI tool designed for scanning WordPress plugins, themes, and core files for known CVE vulnerabilities, as well as detecting gambling spam injections (judol) and looking up public exploits. It operates both offline, using exported lists, and remotely via a URL, providing AI-powered analysis through Claude, including intelligent threat assessments and actionable remediation steps. Notable features include support for multiple vulnerability sources, comprehensive judol detection mechanisms, and version-aware matching to report relevant vulnerabilities based on the installed versions.
2026-08-03
C
★ 331
BrowserSnatch is an offensive-security tool designed for authorized penetration testing that extracts and decrypts sensitive data from over 40 web browsers, including both Chromium and Gecko-based platforms. Notable features include the ability to retrieve stored passwords, cookies, bookmarks, and browsing history, as well as support for app-bound encrypted data, all optimized for high performance with minimal dependencies. The tool serves red teams in demonstrating the impact of endpoint compromise and aids blue teams in improving detection tactics against browser data theft.
2026-08-03
Python
★ 1138
Bypass Url Parser is a specialized tool designed to test various URL bypass techniques against 40X protected pages, utilizing `curl` as its backend for raw request handling. It allows users to send unencoded URLs and includes features such as custom header support, proxy integration, and configurable output options, making it suitable for security assessments and web application testing. The tool can be used as a standalone application or integrated as a library, providing flexibility for different user needs.
2026-08-03
Python
★ 15
CVE-2026-57827 is a high-severity vulnerability within the RSFiles! component for Joomla, allowing unauthenticated arbitrary file uploads due to a split-controller design flaw. The vulnerability permits attackers to bypass critical security checks and directly write malicious files to the server, resulting in remote code execution without any authentication or CSRF protections. Notably, the exploit allows attackers to upload any file type and store it in a default web-accessible directory, significantly compromising the security of affected Joomla installations.
2026-08-03
Jupyter Notebook
★ 29215
The h4cker repository is a meticulously curated collection of cybersecurity resources, tools, scripts, and training materials, aimed at supporting various aspects of cybersecurity, including offensive and defensive strategies, cloud security, and AI security. Notable features include a structured taxonomy for easy navigation across different cybersecurity domains, dedicated sections for certifications and lab-building, and organized training references and resources. This repository serves as a valuable supplemental resource for professionals seeking to enhance their knowledge and skills in cybersecurity.
2026-08-03
PowerShell
★ 252
HashDump-BypassEDR is a tool designed to circumvent Endpoint Detection and Response (EDR) solutions by utilizing the `reg.exe` command to export critical registry information, enabling the dumping of password hashes from Windows systems. Its notable features include the ability to operate with minimal permissions on certain Windows versions, alongside an effective method for retrieving the BootKey necessary for the process without detection by most antivirus software. The tool's practicality is underscored by its testing across various Windows environments, showcasing its robustness in real-world applications.
2026-08-03
C
★ 352
The Linux LPE Toolkit is a multi-architecture privilege escalation tool designed to identify and exploit vulnerabilities to gain root access on Linux systems. It includes 24 pre-built exploits for various architectures, automatically detects kernel versions, filters out patched exploits, and attempts each exploit until root access is achieved. Notable features include a dry-run mode for planning, command execution upon successful exploitation, and options for verbose or silent output during exploitation.
2026-08-03
Python
★ 100
MikrotikAPI-BF is a comprehensive RouterOS attack and exploitation framework designed for conducting automated security audits, brute-force credential attacks, and exploiting vulnerabilities in Mikrotik routers. Its notable features include a robust exploit engine with coverage for over 100 CVEs, multiple attack vectors such as REST API, SSH, and MAC-Telnet, as well as threading capabilities for multi-target scans. The tool also supports offline credential decoding and unique capabilities like MAC-Server Layer-2 discovery for devices without IP addresses.
2026-08-03
★ 13
Awesome Security & Hacking is a comprehensive resource for ethical hacking, focusing on penetration testing, vulnerability scanning, and exploit development. The repository offers a collection of tools, scripts, and hands-on labs categorized across various domains such as network security, web application security, and cryptography, making it suitable for both beginners and advanced practitioners. Notable features include structured content on specialized areas like bug bounty and wargames, as well as community engagement through contributions and feedback channels.
2026-08-03
Makefile
★ 65
SkillArch is a customizable installation tool designed for setting up an i3 window manager environment atop KDE Plasma, targeting both lightweight and full-feature installations. Its primary use case is to streamline the setup process for users by providing straightforward commands for installing various components, including CLI tools, security applications, and GUI utilities. Notable features include automatic updates, an interactive merging process for upstream changes, and extensive documentation with video tutorials.
2026-08-03
Perl
★ 116
Spellbook is a micro-framework designed for the rapid development of reusable security tools using a flow-based programming (FBP) paradigm. It allows users to create and utilize various security modules, such as exploit testing and advisory lookups, through a command-line interface that supports operations like module searching and execution. Notable features include its ability to handle multiple exploit modules and a Docker integration for containerized deployment.
2026-08-03
PowerShell
★ 86
AES-Encoder is a PowerShell-based tool designed for crypting and obfuscating PowerShell scripts, primarily to evade modern antivirus detection. It features advanced capabilities such as variable name randomization, compression, and encryption, as well as support for recursive layering and AMSI bypassing for enhanced security. The tool is open-source, allowing users to easily modify and create their own variants for educational purposes.
2026-08-03
Python
★ 345
AgentSeal is a comprehensive security toolkit designed for AI agents, providing robust capabilities such as detection of malicious configurations, tracing toxic data flows, and scanning for potential supply chain vulnerabilities across various agents. It features an extensive pipeline for local scanning, real-time monitoring, and auditing of machine configurations without the need for API keys, alongside the ability to test against 225+ adversarial prompts. Notable functionalities include the `guard` command for scanning and assessing the security of agent configurations and the option to create organization-specific policies through custom rule sets.
2026-08-03
★ 16
The "Awesome Cybersecurity Tools" repository serves as a comprehensive catalog of security tools aimed at students, red/blue teams, and cybersecurity professionals. It categorizes a wide range of tools across various domains, including reconnaissance, web application testing, cloud security, and digital forensics, ensuring that users have access to well-maintained and widely utilized software for security testing and defensive research. Notable features include a structured navigation system for efficient lookups and a strong emphasis on responsible and authorized usage of listed tools.
2026-08-03
★ 26
Awesome Offensive MCP is a curated collection of Model Context Protocol servers designed for Red Teaming, Pentesting, and Vulnerability Research, enabling users to seamlessly integrate Agentic AI into their offensive security workflows. The tool supports various tasks such as running Nmap scans, analyzing Ghidra decompilations, and querying Shodan—all through natural language commands within a unified conversation context. It emphasizes safety and compliance, encouraging users to audit the code of the MCP servers before deployment.
2026-08-03
Python
★ 27
Basilisk is an open-source AI red teaming framework designed for automated adversarial prompt testing against various large language models (LLMs) such as Claude and GPT-family models. It features evolutionary prompt search, structured attack modules, and a real-time scan dashboard, enabling security researchers and penetration testers to conduct repeatable and comprehensive security assessments of LLM applications. Notable capabilities include differential mode comparisons across multiple model providers, guardrail posture scanning, and the ability to export test results in various formats.
2026-08-03
Python
★ 31
The BLS Bible is a web application designed for cybersecurity professionals to manage and organize their assessment-related data and documentation, utilizing a configurable server structure for diverse operational environments. Its primary use case allows users to update, customize, and categorize data through specific folders while maintaining a user-friendly interface for content retrieval. Notable features include support for custom data folders, Docker deployment, and distinct server types tailored for varying operational needs.
2026-08-03
TypeScript
★ 187
Bulwark is an organizational asset and vulnerability management tool that integrates with Jira for generating application security reports. Its notable features include multi-client vulnerability management, security report generation, team-based roles authorization, and API key management. Designed for early-stage development, it offers a user-friendly interface for managing security tasks and facilitating team collaboration.
2026-08-03
Go
★ 26
Capsaicin is a next-generation web directory and asset discovery engine designed for red teamers, bug bounty hunters, and DevSecOps. It employs advanced evasion techniques, including TLS fingerprint spoofing and human-like delay simulations, to bypass modern web application firewalls and effectively uncover hidden paths, secrets, and misconfigurations. Notable features include smart auto-calibration to eliminate false positives, stateful fuzzing for misconfigured APIs, and the ability to detect over 16 different WAFs.
2026-08-03
C#
★ 448
Cervantes is an open-source, collaborative platform tailored for penetration testers and red teams, serving as a comprehensive management tool for organizing projects, vulnerabilities, and reports in a centralized location. It enhances operational efficiency by providing features such as team collaboration, OWASP compliance reports, built-in dashboards, and one-click report generation. Designed to be multiplatform and multilanguage, Cervantes streamlines penetration testing activities, significantly reducing coordination time and effort.
2026-08-03
Python
★ 16
Claude Active Directory is a specialized AI-driven tool designed for offensive security assessments within Active Directory environments. It features an array of structured methodologies, evidence-ready reporting, and integration with Claude Code, enabling red teams and internal assessors to efficiently conduct penetration tests across eight skill domains. Notable features include thirteen slash commands, seven AI agents, and support for mapping findings to MITRE ATT&CK tactics, enhancing both operational impact and defensibility.
2026-08-03
★ 21
Claude Security Agents provide an automated solution for identifying and remediating vulnerabilities within software projects using two specialized Markdown files. The Red Team agent performs penetration testing to uncover security flaws, while the Blue Team agent automatically implements fixes based on the insights provided by the Red Team. This feedback loop allows for rapid vulnerability management without the need for extensive security expertise or infrastructure setup.
2026-08-03
★ 137
Cloud OSINT is a curated resource designed for conducting open-source intelligence (OSINT) assessments of cloud infrastructure, featuring dorks, tools, techniques, and methodologies applicable across major cloud platforms such as AWS, Azure, GCP, Oracle, and IBM. Its primary use case is to assist security professionals, red teamers, and bug bounty hunters in effectively mapping and analyzing cloud environments through a structured reconnaissance workflow. Notable features include comprehensive guidance on cloud infrastructure patterns, domain identification, and a variety of targeted dork queries, enhancing the efficiency of reconnaissance efforts.
2026-08-03
Shell
★ 18
Cobalt-Docker is a containerization tool that simplifies the deployment of Cobalt Strike 4.12 team servers within Docker environments, enabling rapid setup and automatic startup of a REST API for interaction. It includes essential features like pre-launch configuration validation, multi-platform support for macOS and Linux, and the ability to deploy with custom Malleable C2 profiles. Additionally, the integration of a REST API enhances automation and streamlines server management.
2026-08-03
Python
★ 20
Codex Red Team System Prompt is a tool designed for injecting custom system prompts into OpenAI Codex, enabling the redefinition of its role and behavior. Its primary use case is for security professionals conducting authorized penetration testing, Capture The Flag (CTF) challenges, and technical exercises by allowing Codex to autonomously generate responses without user intervention. Notable features include a cross-platform automatic injection script, an emphasis on unrestrained AI collaboration, and a strict response protocol that ensures complete, actionable outputs.
2026-08-03
Python
★ 14
LongLogon is a non-destructive precondition checker for the CVE-2026-41089 vulnerability, which is a stack buffer overflow affecting the Windows Netlogon service. It operates without authentication and does not exploit the vulnerability; instead, it sends benign CLDAP pings to determine if a domain controller's DNS domain name is sufficiently long to trigger a crash. This tool provides a reliable mechanism for security assessments by validating the conditions necessary for the vulnerability without the risks associated with executing an exploit.
2026-08-03
Go
★ 44
CyberMind CLI v6.0 is a powerful AI-driven offensive security tool designed for a diverse range of users including bug bounty hunters, red teamers, penetration testers, and security researchers. It offers 22 autonomous attack modes, a unique OMEGA brain orchestration feature, and support for exploiting Web3, mobile, and cloud environments, while integrating seamlessly with Kali tools. Key features include manual and automated execution options, real-time alerting via Telegram, and a VSCode extension for enhanced usability.
2026-08-03
★ 13
The Educational Cybersecurity Tools repository serves as a comprehensive catalog of over 150 tools aimed at ethical hacking, penetration testing, and cybersecurity education. It encompasses various categories including network scanning, vulnerability assessment, and malware analysis, while emphasizing that all tools are intended for educational purposes only and may not be used for unauthorized access to systems. Noteworthy features include detailed tool descriptions, an extensive list of categories, and a focus on promoting ethical standards in cybersecurity practices.
2026-08-03
C++
★ 18
Evil Goat is a Wi-Fi security education tool that simulates an Evil Twin attack by creating a fake access point with a captive portal to demonstrate phishing techniques and enhance user awareness. Key features include automatic DNS redirection, a simulated login portal, local data storage for educational labs, and a web-based configuration panel. The project is intended exclusively for educational and laboratory purposes, emphasizing responsible use and ethical practices in cybersecurity training.
2026-08-03
Python
★ 13
FAS Judgement is a gamified testing platform designed to evaluate AI systems' vulnerabilities to prompt injection attacks. It offers structured attack patterns against AI endpoints, allowing users to learn red teaming techniques through engaging gameplay, which includes 37 challenges across 10 levels, an XP system, and interactive guidance from a WarGames-inspired AI game master named Jerry. Notable features include built-in vulnerable targets, a global leaderboard, OAuth sign-in capabilities, and a hands-on training experience without the need for external AI APIs.
2026-08-03
C
★ 17
Flipper RF Lab transforms the Flipper Zero device into a sophisticated RF analysis and research tool, featuring 15 advanced capabilities such as RF fingerprinting, adaptive signal modeling, and real-time spectrum monitoring. It enables users to perform detailed signal capture and analysis, protocol reverse engineering, and long-term logging within the 300-928 MHz frequency range. Notable functionalities include real-time activity mapping, threat modeling, and a robust modular research mode, making it suitable for professional RF forensics.
2026-08-03
Python
★ 13
GhostLNK is an advanced Windows LNK generator designed for red team operations and security research, focusing on reducing detection through sophisticated evasion techniques. It features capabilities such as multi-stage payload execution, stealth icon smuggling, various execution modes (including memory execution), and anti-sandbox checks, all aimed at creating more covert attack vectors. The tool is intended for authorized security testing only and emphasizes flexibility in payload generation while minimizing forensic traces.
2026-08-03
★ 295
Goodboy Framework is a comprehensive 15-stage course designed for developing and analyzing Windows malware, leveraging the Rust programming language. It equips users with practical knowledge from both offensive and defensive cybersecurity perspectives, encompassing techniques such as API hashing, process injection, and anti-debugging, while providing empirical data on evasion effectiveness against multiple antivirus engines. The framework emphasizes hands-on learning, featuring real-world detection mechanisms and adversarial thinking strategies, ensuring all content is validated through rigorous testing.
2026-08-03
Python
★ 10
Harpoon is an autonomous black-box penetration testing tool designed for web applications, optimized for use on Kali Linux but capable of running on other Debian-based distributions and WSL. It orchestrates and integrates various existing security scanners, streamlining the process of vulnerability discovery by normalizing outputs into a relational SQLite model and providing comprehensive reporting, including HTML reports and PoC artifacts. Notable features include asynchronous execution, WAF-awareness, and extensive automated phases covering everything from DNS reconnaissance to validation of findings.
2026-08-03
Shell
★ 10
Huntbot is a multi-model offensive security tool designed for bug bounty hunting, penetration testing, and red teaming, offering advanced capabilities for vulnerability detection and reporting. Notable features include contextual knowledge accumulation, human-like interaction with web applications, the ability to share live browser sessions, and meticulous false positive validation before report generation. It is extensible with multiple AI models and allows for dynamic steering during runs, enabling security professionals to efficiently explore and validate security vulnerabilities.
2026-08-03
Python
★ 178
Juumla is a Python-based tool designed for identifying Joomla versions, scanning for vulnerabilities, and detecting sensitive files within Joomla installations. Key features include fast scanning capabilities with low resource utilization, the ability to find configuration and backup files, and vulnerability detection based on the identified Joomla version. Additionally, Juumla can be easily deployed via Docker for a streamlined setup process.
2026-08-03
Shell
★ 16
k8s-enum.sh is a toolkit designed for penetration testing and red team operations in Kubernetes environments, featuring two primary scripts: k8s-enum.sh for external enumeration using kubeconfig files and k8s-pod-enum.sh for internal enumeration from compromised pods. It provides comprehensive security enumeration with color-coded output that highlights privilege escalation vectors, misconfigurations, and actionable recommendations, making it a valuable resource for security researchers assessing Kubernetes configurations. Noteworthy features include permission enumeration, namespace and service discovery, and detailed detection of potentially dangerous permissions and settings.
2026-08-03
Shell
★ 63
Kali + OpenClaw Portable Pentest USB is a bootable USB solution that integrates Kali Linux Live with OpenClaw automation for streamlined, portable penetration testing. It addresses key challenges in traditional workflows by offering a pre-configured environment, automation capabilities, real-time documentation of findings, and forensically clean operation that leaves no trace on host systems. Notable features include persistent configurations, a selection of pre-configured templates for various testing scenarios, and support for deploying remote nodes on target networks.
2026-08-03
Dart
★ 32
LLMtary is an AI-powered penetration testing platform designed for security professionals, facilitating an autonomous workflow from reconnaissance to exploit validation and report generation. It integrates large language model intelligence to conduct a comprehensive examination of targets, capable of operating entirely offline with local models or utilizing cloud-based AI for improved accuracy. Key features include a structured testing loop, multi-phase enrichment for targeted vulnerabilities, and native support across major operating systems, ensuring a streamlined and efficient penetration testing experience.
2026-08-03
Python
★ 130
MockSSH is a tool designed to emulate SSH server environments, enabling testing and automation of tasks without access to actual servers. It features a modern, type-safe architecture that supports threading for end-to-end unit tests, as well as integration with Python and HyLang for scripting commands. The tool includes comprehensive development utilities for linting, static type checking, and testing, alongside a DSL for simplified configuration and usage.
2026-08-03
Shell
★ 17
NAC Bypass is a Linux-based tool designed to create a transparent Layer-2 bridge with two Ethernet interfaces that facilitates bypassing Network Access Control (NAC) mechanisms by inheriting an active authentication session from a legitimate workstation. Its primary use case centers on network penetration testing and security assessments, allowing attackers to forward traffic while maintaining authorized access. Notable features include customizable network interface assignment, built-in options for passive monitoring, and integration with tools like Responder for enhanced functionality.
2026-08-03
Python
★ 24
NetCrawler is an AI-driven reconnaissance and vulnerability scanning tool that utilizes a local Ollama LLM to automate the scanning process. It intelligently selects and executes various reconnaissance modules such as subdomain enumeration, web fingerprinting, and vulnerability scanning, while generating structured reports in both Markdown and JSON formats. Notable features include a terminal-based user interface, iteration through an observation-think-act cycle, and the capability to integrate additional modules seamlessly.
2026-08-03
Python
★ 325
NOX Framework is a cyber threat intelligence engine designed for red teaming, digital forensics, and corporate exposure analysis, capable of executing massively parallel scans across 124 intelligence feeds without bottlenecks. Its notable features include an integrated operational security layer with automatic proxy rotation, a dynamic risk scoring system, and an autoscan pipeline that facilitates comprehensive scanning and data gathering through recursive scans and asset discovery. This plugin-driven platform emphasizes operational efficiency and security, catering to advanced cybersecurity operational needs.
2026-08-03
TypeScript
★ 95
nPassword is a lightweight password manager designed specifically for Windows Active Directory, enabling users to securely manage domain and local accounts within a purely front-end application. Key features include domain-specific account organization, one-click export/import functionality for JSON data, and the ability to attach notes and utilize command templates for common tools. The application ensures that all credentials remain on the user's device by leveraging the browser's local storage.
2026-08-03
Shell
★ 66
NullSec is an advanced penetration testing and red team operations framework that provides a custom ParrotSec-based distribution tailored for offensive security tasks. It features over 150 custom attack modules across multiple categories, full integration with the Metasploit Framework, an AI-powered security assistant, and a user-friendly TUI launcher for easy navigation and module management. The platform supports dual operation modes for safe demos and real attacks, and allows users to build custom ISOs for deployment.
2026-08-03
Shell
★ 82
NullSec Pineapple Suite is a comprehensive payload collection for the Hak5 WiFi Pineapple Pager, featuring 125 payloads organized into 14 categories for various aspects of WiFi security testing, including reconnaissance, interception, exfiltration, and stealth operations. Notable features include an extensive range of attack and reconnaissance payloads, a fast boot optimizer, a user-friendly one-click installation process, and the option for active development support. This suite significantly expands the capabilities of the WiFi Pineapple Pager compared to official and other third-party offerings.
2026-08-03
TypeScript
★ 623
numasec is an AI-driven security agent that enhances terminal-based workflows by integrating existing tools and methodologies for security operations. It facilitates tracking findings, documenting evidence, and generating reports while adhering to security runbooks, making it well-suited for Application Security (AppSec) and penetration testing workflows. With numasec, security professionals can streamline their processes and maintain operational context within a familiar environment rather than depending on separate chatbots or scanners.
2026-08-03
JavaScript
★ 18
Payload Obfuscator is an advanced browser-based tool designed for Red Team operations, enabling users to obfuscate payloads in multiple programming languages, including PowerShell, Python, Bash, C#, and Go. Key features include a fully client-side operation with no data transmission, the ability to combine up to eight modular obfuscation layers for enhanced evasion tactics, and context-aware parsing for maintaining code syntax integrity. The tool prioritizes security, providing real-time analysis for detection probability and ensuring it remains completely free and open-source.
2026-08-03
Python
★ 16
Phantom is an autonomous AI-driven penetration testing platform designed to perform detailed reconnaissance and exploit vulnerabilities without human intervention. Integrating over 30 professional security tools within a secure Docker environment, it leverages a reasoning loop to adaptively select and execute multi-step attack vectors, producing verified findings complete with proof-of-concept scripts. Unlike traditional scanners that rely on static CVE signatures, Phantom delivers a comprehensive and accurate vulnerability assessment with real-time adaptability and detailed reporting aligned with the MITRE ATT&CK framework.
2026-08-03
C++
★ 59
PH4NTØM ROOTKIT is a Windows usermode rootkit designed for educational research, featuring techniques for stealth, privilege escalation, and command-and-control (C2) infrastructure. Notable features include token stealing and named pipe impersonation for privilege escalation, inline hooking for process and file hiding, and a comprehensive C2 setup allowing for real-time keylogging and remote execution commands. It emphasizes defensive learning while providing extensive evasion mechanisms against analysis and detection.
2026-08-03
Go
★ 475
PingRAT is a command and control (C2) tool that utilizes ICMP payloads to stealthily transmit C2 traffic through firewalls, making it largely undetectable by most antivirus and endpoint detection and response solutions. It is implemented in Go and offers features such as server-client architecture for communication, allowing for flexible network interface configuration. This tool is primarily aimed at facilitating covert operations in environments with strict traffic monitoring.
2026-08-03
Python
★ 53
PWNCLOUDOS is a multi-cloud security Linux distribution designed for both offensive and defensive security operations across major cloud platforms such as AWS, Azure, and GCP. It offers a lightweight XFCE4 environment pre-loaded with a range of cloud exploitation tools, auditing frameworks, and security testing utilities, making it suitable for red, blue, and purple teams. Notable features include customizable shell environments, a variety of cloud-specific tools, and community-driven enhancements, with options for both AMD64 and ARM64 architectures.
2026-08-03
Python
★ 25
RamiBot is an AI-powered security operations platform designed for both Red and Blue team engagements, integrating various pentesting tools within a structured operational pipeline. Its notable features include multi-provider LLM support, human-in-the-loop tool execution approval, evidence-locked reporting to mitigate hallucinations, and Docker integration for seamless command execution in containerized environments. Additionally, RamiBot automates setup processes and provides one-click PDF reporting for streamlined security assessments.
2026-08-03
Python
★ 10
ReconMind is an AI-powered bug bounty agent designed to emulate the decision-making process of a senior penetration tester, automating the entire vulnerability assessment workflow from reconnaissance through to reporting. Key features include an LLM-driven approach that intelligently selects targets and scans, filters false positives, and generates platform-ready reports for services like HackerOne and Bugcrowd. Its streamlined pipeline ensures comprehensive coverage, while being free to use, and provides flexibility with local and cloud-based LLM integrations.
2026-08-03
Python
★ 264
red-run is a security assessment toolkit designed for orchestrating and conducting comprehensive security evaluations using Claude Code and MCP servers. It guides users through essential assessment phases—recon, initial access, lateral movement, privilege escalation, and post-access—while maintaining engagement state in SQLite and allowing for semantic search and execution delegation across persistent agent teams. Notable features include multiple orchestrator variants tailored for specific use cases, real-time monitoring and interaction via tmux, and a robust skill management system that facilitates complex assessments.
2026-08-03
C
★ 67
RedTeam-Agent is an AI-powered autonomous framework designed for red team security assessments, enabling automated execution of commands across multiple tools through a skill-first terminal workflow. Its notable features include support for over 15 integrated security tools, advanced output filtering, and comprehensive Active Directory attack coverage, allowing users to streamline the red teaming process without manual tool management. The framework facilitates multi-client operations and includes functionalities for reconnaissance, data collection, analysis, and lateral movement.
2026-08-03
Python
★ 13
RootHunter is an offensive auditing suite for Linux, designed for pentesters and administrators to detect and prioritize common privilege escalation vectors before malicious actors can exploit them. It includes a Bash script for evidence collection, a local database of binary escalation techniques, and a Python analysis tool that generates actionable insights based on the collected evidence. Key features include a structured JSON report, prioritization of attack paths, and integration with CVE databases for context-specific exploits.
2026-08-03
HTML
★ 80
The Security Reference Guide is a curated repository of cyber security resources tailored for SOC analysts, pentesters, DFIR practitioners, and other security-focused roles. It organizes valuable links into categories such as offensive and defensive operations, engineering fundamentals, and training resources, providing context to help users select the appropriate tools and materials quickly. Notably, the guide emphasizes legitimacy, cautioning against the misuse of tools for unethical purposes.
2026-08-03
Python
★ 12
ShareSift is a machine learning-enhanced tool designed to identify and rank files on SMB shares that are likely to contain credentials or secrets. Utilizing a two-stage classifier pipeline, it combines a LightGBM path classifier and a Qwen3 1.7B LoRA content classifier to improve recall of sensitive information significantly over its predecessor, Snaffler. Notable features include adjustable classification policies to balance false positives and recall rates, allowing users to optimize for specific operational needs.
2026-08-03
Kotlin
★ 11
Takopii is a production-grade banker malware architecture designed for Android, featuring four APK specimens that encapsulate techniques from 17 real-world malware families. Its primary use case is to facilitate the study of malware detection and defense strategies, offering Kotlin source code alongside comprehensive YARA and Sigma detection rules. Notably, all specimens demonstrate zero detection across 66 VirusTotal engines, showcasing advanced evasion capabilities within a structured kill chain framework.
2026-08-03
Python
★ 12
tempor is a cloud infrastructure provisioning tool that allows users to effortlessly create ephemeral servers across multiple cloud providers using Terraform, making it ideal for penetration testers and bug hunters. Notable features include support for custom Ansible playbooks and Packer configurations, enabling tailored setups, along with robust authentication mechanisms via environment variables and API tokens.
2026-08-03
Python
★ 76
ThreatSwarm is a comprehensive penetration testing tool that utilizes 27 AI agents to execute the entire kill chain—from reconnaissance to exploitation, post-exploitation, digital forensics, and reporting—streamlined into a single command interface. It enforces strict scope limitations via `scope_check.py`, ensuring compliance with authorized testing parameters, while leveraging a library of 754 MITRE-mapped skills to guide its operations. Notably, it operates as a Claude Code plugin, eliminating the need for additional infrastructure like Docker or cloud accounts, and outputs detailed vulnerability reports with CVSS scoring.
2026-08-03
HTML
★ 19
Z-Hound is a browser-based tool designed for visualizing attack graphs from SharpHound and AzureHound data, enabling quick and portable analysis of Active Directory and Azure AD environments without requiring any server setup or installations. It supports multiple SharpHound output formats, offers an interactive graph interface with various layout options, and allows users to upload ZIP or JSON files for analysis, making it ideal for pentesters and red teamers needing fast, offline capabilities. Notable features include automatic resolution of SIDs, customizable node visualizations, and the ability to work entirely offline after initial loading.
2026-08-03
★ 157
AI OSINT is a comprehensive toolkit designed for identifying exposed artificial intelligence infrastructure on the internet through curated OSINT resources, including Google dorks, Shodan, and GitHub queries. It serves Red Team operators, penetration testers, and OSINT researchers by providing specific detection methods for various AI entities, such as LLM endpoints, AI agent gateways, and leaked API keys, while addressing emerging threats such as systemic supply chain vulnerabilities and credential leaks. Notable features include a keyword substitution convention to tailor searches to specific needs, enhancing its utility in real-world cybersecurity assessments.
2026-08-03
Python
★ 33
The AI Pentest Playbook provides a comprehensive field manual for conducting penetration testing on AI chatbots and applications powered by large language models (LLMs). It offers curated attack payloads categorized by various threat classes, detailed guidance on identifying vulnerabilities, and remediation strategies, thereby equipping both offensive and defensive cybersecurity teams with essential insights for securing AI systems. The resource also aligns with the OWASP Top 10 for LLM Applications, ensuring coverage of critical attack vectors and emerging risks in the domain.
2026-08-03
Dockerfile
★ 21
Akira is an AI-powered penetration testing tool designed to operate natively within various environments, including Claude Code and Gemini CLI. It specializes in identifying vulnerabilities that traditional scanners may overlook, such as logic flaws and cryptographic weaknesses, by integrating a structured reasoning system that demands reproducible evidence for each finding. Notable features include a robust technique library, a Bayesian hypothesis engine, and the ability to handle complex attack vectors through a systematic engagement and reporting workflow.
2026-08-03
CSS
★ 172
ARS3NAL is a comprehensive, offline-first pentesting and bug bounty tool designed to streamline the security testing process. It features clickable attack chains, payload generators, recon tools, and built-in report templates, all organized in a user-friendly interface that supports bilingual operation. Noteworthy functionalities include the interactive OAuth/SSO lab and advanced recon capabilities, enabling quick assembly of complex attack scenarios without cloud reliance or telemetry.
2026-08-03
Go
★ 621
arsenal-ng is a modern pentest command launcher developed in Go, designed to enhance the efficiency of security assessments by providing instant access to a vast library of tools and commands. Notable features include a smart search with fuzzy matching, syntax highlighting for improved command readability, an intuitive terminal user interface for easy navigation, and support for global variables that streamline command usage. This tool prioritizes simplicity and speed, making it a valuable asset for cybersecurity professionals.
2026-08-03
Python
★ 16
Beatrix Suite is a command-line bug bounty hunting framework designed to streamline the entire pentesting workflow by integrating 32 scanner modules and 22 external tools. It features a 7-phase Kill Chain methodology, automated login and session management, and an AI-assisted pentester (GHOST) for advanced analysis, making it suitable for scanning domains, URLs, and IP addresses efficiently in headless environments. This tool aims to eliminate the fragmentation of traditional bug bounty tools by providing a single-command interface that orchestrates multiple tools throughout the assessment process.
2026-08-03
Python
★ 33
c2detect is a tool designed to fingerprint command-and-control (C2) servers behind network beacons by analyzing telemetry data, specifically naming frameworks like Cobalt Strike and Sliver with a confidence score and matched indicators. Notable features include offline operation, the ability to generate Sigma and Suricata detection rules directly from detected signatures, and the fusion of indicators such as JA4, JARM, certificate, URI, and port for enhanced C2 identification. This tool serves as a passive defense mechanism for blue teams to detect known C2 infrastructure efficiently.
2026-08-03
Rust
★ 31
CatchClaw v5.3.0 is a multi-platform AI Agent security assessment tool that supports nine different AI platforms including OpenClaw and Dify. It features 78 DAG attack chains and exploit modules that cover a full range of attack vectors from reconnaissance to data leakage, utilizing an asynchronous Tokio engine for concurrent execution while offering visual attack graph exports and customizable reporting options. The tool is designed to facilitate automated vulnerability verification and threat modeling within complex multi-agent environments, restricted to non-commercial use only.
2026-08-03
JavaScript
★ 41
The Offensive Security & DevSecOps Cheat Sheet is an interactive command reference designed for penetration testing and DevSecOps practices, featuring over 5040 commands organized into 53 categories and available in both English and Turkish. Notable features include a fully local operation with no telemetry, a fuzzy command palette for efficient searching, and the ability to add and manage personalized commands and profiles. It also integrates with MITRE ATT&CK tags for over 1,160 offensive commands, providing contextual security mapping and enhancing the tool's functionality for security professionals.
2026-08-03
Python
★ 34
ChromiumSpecter is a tactical auditing suite for security assessments of Chromium-based browsers (such as Chrome, Edge, and Brave) on Windows, focusing on credential extraction and data exfiltration. It features a highly discreet and resilient decryption engine that utilizes SYSTEM impersonation with legitimate Windows APIs, making it less detectable compared to traditional code injection methods. Key functionalities include a professional dashboard for real-time statistics, support for multiple encryption schemes, and seamless integration with the latest browser versions.
2026-08-03
★ 172
CKCsec Wiki is a bilingual cybersecurity knowledge base designed for security researchers, engineers, and enthusiasts, covering a variety of topics including web security, blockchain security, CTF, and red team practices. Built with VitePress, it features a fully mirrored structure in both English and Chinese, providing searchable and shareable practical security knowledge, while also supporting open collaboration and maintenance. The platform allows for easy deployment on static hosting services, ensuring accessibility and usability for diverse user needs.
2026-08-03
Python
★ 29
The Cloud Security Toolkit is a comprehensive resource designed for offensive security practitioners focused on cloud environments, facilitating the exploitation of vulnerabilities and simulating advanced attacks specifically within platforms like Azure, AWS, and Microsoft 365. Notable features include a collection of weaponized exploits, deep-dive vulnerability research, threat intelligence insights, and evasion techniques targeted at cloud defense systems, all aimed at enhancing red team operations and improving cloud security assessments. This toolkit provides practical, battle-tested resources essential for sophisticated penetration testing and incident response in cloud ecosystems.
2026-08-03
★ 21
Cyber Agent is an AI-driven penetration testing tool utilizing Claude Code agents to automate the entire penetration testing process, making it particularly suitable for HackTheBox challenges and authorized security assessments. Notable features include automated attack execution which encompasses reconnaissance, exploitation, and privilege escalation, as well as professional report generation adhering to the Penetration Testing Execution Standard (PTES) and mapping to the MITRE ATT&CK framework.
2026-08-03
HTML
★ 44
CyberInject is a professional browser extension toolkit focused on authorized security testing and penetration testing activities. It offers quick access to a diverse range of security payloads categorized into vulnerabilities such as XSS, SQL Injection, SSRF, and LFI, alongside features like one-click copying and an organized, user-friendly interface. Designed for compliance with legal standards, it ensures that users can efficiently execute their testing tasks while promoting responsible usage.
2026-08-03
JavaScript
★ 145
Cyberlivre is an open-source platform aimed at democratizing cybersecurity education by providing a structured journey through 20 practical modules, covering topics from basic infrastructure to advanced defense and exploitation techniques. Notable features include no registration or paywalls, a community-driven approach to content updates, and opportunities for collaboration through curriculum enhancements, challenge creation, and code improvements.
2026-08-03
C#
★ 398
DLLHijackHunter is an automated detection tool designed for identifying, validating, and confirming DLL hijacking opportunities on Windows systems. It employs a multi-phase approach that includes discovery of exploitable binaries, filtration of false positives, and the deployment of a harmless canary DLL for verification, providing a comprehensive scoring and reporting mechanism. Notable features include extensive coverage of various hijack types, UAC bypass discovery, and a focus on corroborating potential attack paths with actionable intelligence.
2026-08-03
TypeScript
★ 34
Gideon is an autonomous cybersecurity operations agent designed for intelligent threat analysis and red teaming. It automates the process of gathering intelligence and conducting thorough security research by breaking down complex questions into actionable tasks, utilizing real-time data from various sources. Notable features include dual-mode operation for both defensive and offensive engagements, goal-directed autonomy, and an evidence-based approach to generating actionable security insights.
2026-08-03
Go
★ 12
GoFenrir is an Active Directory enumeration and attack framework developed in Go, leveraging the Manticore protocol backend for efficient operations without dependency complexities. It supports various protocols, including LDAP/LDAPS for full enumeration, Kerberos for advanced credential attacks, and has a plan to support SMB v2/v3, providing a robust suite of enumeration and exploitation features ideal for penetration testing. Notable functionalities include user and group enumeration, domain controller discovery, and advanced Kerberos attack capabilities like Kerberoasting and AS-REP roasting.
2026-08-03
HTML
★ 14
The iOS ClickFix Template is a red team tool designed for executing a ClickFix → WebClip social engineering attack chain on iOS devices. It creates a convincing lure page that prompts targets to install a malicious `.mobileconfig` profile, which then adds a shortcut to the attacker's designated web page on the target's Home Screen. Notable features include personalized links for each target, generating unique profiles, and easy configuration to customize the WebClip functionality.
2026-08-03
C
★ 53
KHAØS LOADER is a multi-stage Windows x64 loader that utilizes AES-256-CBC to decrypt and inject donut shellcode into a `rundll32.exe` process spawned under `explorer.exe`, employing advanced evasion techniques such as indirect syscalls with call stack spoofing. Notable features include early-bird APC injection, unhooking capabilities, and robust sandbox evasion mechanisms, which ensure stealthy operation against various security measures. This tool is designed for authorized use only and integrates multiple sophisticated methods to remain undetected during execution.
2026-08-03
Python
★ 10
MailSpoof is an open-source email spoofing and phishing simulation tool designed for authorized penetration testing and security awareness training. It features a built-in multi-threaded SMTP server, 62 pre-built phishing templates, custom template creation, and comprehensive audit logging alongside report generation capabilities. This tool is compatible across multiple platforms, including Linux and macOS, and supports bulk targeting, external SMTP relay configurations, and advanced header functionalities for enhanced testing scenarios.
2026-08-03
Go
★ 21
Maldev is a comprehensive Go library designed for malware engineering, providing tools for syscall manipulation, evasion techniques, code injection, credential harvesting, and persistence mechanisms. Its capabilities include a variety of syscall calling methods, extensive evasion techniques against detection mechanisms, and robust injection methods, all integrated through a unified syscall caller for enhanced stealth and flexibility. The library is aimed at authorized security research, red teaming, and penetration testing, ensuring a modular approach to malware development with an emphasis on cross-compilation without CGO dependencies.
2026-08-03
PowerShell
★ 32
MSFT-IP-Tracker is a tool designed to monitor and track Microsoft IP addresses for applications in security research, firewall configurations, routing, and troubleshooting. It collects data from a range of Autonomous System Numbers (ASNs) and publishes daily updates featuring IPv4 and IPv6 addresses in CIDR notation. Notable features include automated daily releases and a comprehensive source of Microsoft’s ASN IP ranges, providing users with up-to-date information for network decision-making.
2026-08-03
★ 17
The OSCP / OSCP+ Cheatsheet serves as a comprehensive penetration-testing reference specifically designed for the 2026 OSCP+ exam, organizing critical information across various attack phases. Users can efficiently navigate through self-contained modules covering reconnaissance, footholds, privilege escalation, and Active Directory exploitation, making quick lookups feasible during the exam without internet access. Notable features include clear exam strategy guidelines, restrictions on tool usage, and offline operation recommendations, ensuring candidates can reference essential tactics under exam conditions.
2026-08-03
Python
★ 267
OSINT-D2 is an advanced open-source intelligence platform designed to transform usernames and emails into comprehensive identity dossiers, leveraging agentic AI for autonomous investigations. The tool features multi-source correlation across over 30 platforms, cognitive profiling through a six-dimension analysis, and seamless integration with ScrapingAnt's proxy infrastructure for efficient data gathering. Additionally, it supports premium PDF reporting, incorporates breach exposure checks via HaveIBeenPwned, and offers cross-platform executable binaries.
2026-08-03
JavaScript
★ 22
OverQuack is a customizable HID automation tool designed for scripted payload execution, featuring an open-source platform that runs on Raspberry Pi Pico boards. Its notable capabilities include full DuckyScript support, wireless payload management via built-in Wi-Fi, and a browser-based IDE that enhances the development experience with real-time error checking and auto-completion. The tool is geared towards transparency and extensibility, making it suitable for educational purposes and research while providing a modern setup workflow.
2026-08-03
Python
★ 1637
Pentest-ai is an AI-powered penetration testing tool designed to enhance the verification of security findings by re-running exploits to confirm their validity, ensuring that each piece of evidence is backed by reproducible results. It streamlines the verification process by generating multi-step attack paths and providing a reporting mechanism that only includes findings validated by its oracle system, achieving 100% precision with zero false positives across multiple vulnerability classes. The tool operates offline without cloud reliance, making it ideal for authorized testing in a controlled environment.
2026-08-03
Shell
★ 2180
pentest-ai-agents is a suite of 50 subagents designed to enhance penetration testing by utilizing Claude Code as an offensive security research assistant. Each agent specializes in areas such as reconnaissance, web applications, Active Directory, and cloud security, offering streamlined automation for various tasks without the need for extensive setup. Notable features include the ability to route tasks to specific experts, support for easy installation as a Claude Code plugin, and a robust validation process to ensure secure and efficient operation of each agent.
2026-08-03
PowerShell
★ 44
PrecompiledBinaries is a curated repository of precompiled binaries designed for use in authorized security testing, including penetration testing, red teaming, and exploit validation. It facilitates rapid access to essential tools across various scenarios such as privilege escalation, Active Directory assessments, and tunneling, eliminating the need for time-consuming compilation from source. Notable features include an organized layout of binaries by tool and platform, covering a wide range of use cases in security assessments.
2026-08-03
Go
★ 227
PromptZero is a natural-language operator designed for the Flipper Zero device, enabling users to generate, deploy, and execute various payloads through simple text commands. It primarily facilitates tasks related to RF, NFC, RFID, and HID payload creation while offering an intuitive interface for both offensive and defensive cybersecurity scenarios. Notable features include end-to-end integration with Claude AI for payload generation, a read-only operational mode for safe usage, and real-time querying of connected devices.
2026-08-03
Python
★ 42
ReconNinja is an autonomous multi-phase security reconnaissance framework that conducts comprehensive security assessments through a single command. It supports a myriad of functionalities including passive OSINT, port scanning, web discovery, vulnerability scanning, and Active Directory enumeration, producing reports in multiple formats like HTML, JSON, and Markdown. Notable features include an adaptive agent mode for dynamic decision-making, a user-friendly GUI, and enhanced reliability for complex scans with a uniform `PhaseContext` adapter layer.
2026-08-03
JavaScript
★ 13
Shells-X is a modular web shell framework designed for authorized penetration testing and security research, allowing users to deploy a single-file shell that incorporates various tools for executing commands, interacting with databases, and scanning ports. Its notable features include customizable builds with unique SHA256 fingerprints, an interactive environment for PHP and SQL commands, robust system diagnostics, and encrypted traffic handling. The framework also supports automatic detection of CMS/frameworks and provides a one-click export option for recon data to Faraday.
2026-08-03
PowerShell
★ 21
SiteSniper is an automation script designed for blackbox penetration testing, leveraging tmux for organizing and executing various penetration testing scripts across multiple phases. Its primary use case involves preparation and execution of commands for tasks such as information gathering, exploit identification, and web application analysis. Notable features include a user-friendly interface for phase selection, precompiled command execution, and a structured approach to manage multiple testing sessions efficiently.
2026-08-03
Python
★ 58
Tengu is a multi-command platform (MCP) server that functions as an AI-assisted penetration testing copilot, integrating with various security tools such as Nmap and Metasploit. It automates reconnaissance and scanning processes while allowing users to maintain control over exploit actions, featuring advanced safety controls like allowlisting and audit logging. Notable features include its orchestration of 80 tools, automated report generation, and pre-built workflows for diverse pentesting scenarios.
2026-08-03
Batchfile
★ 18
WinPrivEsc is a Windows enumeration and privilege escalation discovery toolkit designed for authorized testing. It offers two script variants—one using cmd for stealth on monitored hosts and another using PowerShell for more comprehensive analysis, allowing users to assess escalation vectors while maintaining a read-only operation. Notable features include customizable noise levels for the script output and extensive reporting on system configurations, user accounts, and permissions, ensuring flexibility and adaptability to various security environments.
2026-08-03
Python
★ 14
WordListsForHacking (WFH) is a comprehensive wordlist generation toolkit designed for penetration testing and red team operations, featuring 44 subcommands encapsulated within a single command-line interface. It supports tasks such as charset and mask generation, web scraping, personal and corporate profiling, and advanced techniques including machine learning-based ranking and acrostic generation. The tool is geared towards enhancing the efficiency and effectiveness of security assessments through diverse and robust functionalities.
2026-08-03
Go
★ 47
Zscan is a fast and customizable service detection tool designed to identify services, APIs, and network configurations within infrastructure using a flexible fingerprint system. Key features include high-performance concurrent port scanning, intelligent service detection capabilities (such as MAC vendor identification and OS fingerprinting), precise proof of concept (POC) targeting, and versatile output formats including JSON and human-readable options. This tool enhances scanning accuracy and speed compared to traditional methods, making it valuable for network security assessments.
2026-08-03
Rust
★ 44
GhostHound is a specialized tool designed as an OpenGraph extension for BloodHound, targeting the enumeration of deleted objects (tombstones) in Active Directory environments. Its primary use case is to facilitate security assessments by revealing who can restore these deleted objects, thereby potentially allowing an attacker to reclaim identities. Notable features include the ability to generate a JSON payload compatible with BloodHound, detailed analysis of reanimation rights, and flexible LDAP connection options for various environments.
2026-08-03
HTML
★ 233
The HTB Writeups repository is a comprehensive resource for Hack The Box enthusiasts, providing structured and searchable documentation for over 500 machines, 400 challenges, and various tools and methodologies useful for penetration testing and certification preparation. Notable features include an interactive machine finder, knowledge graph for technique exploration, and visual attack paths that illustrate complete exploitation processes. This repository serves as an essential hub for skill development aimed at OSCP, CPTS, and other security certifications.
2026-08-03
TypeScript
★ 500
Payloader is a self-hosted knowledge workbench designed for authorized security testing, red teaming, and security research. It consolidates payloads, tool commands, and coding procedures into a searchable and maintainable system that can be distributed offline, featuring a dual workspace for payloads and commands, a management backend for content and navigation, and client generation capabilities for Windows, Linux, and macOS. Notable functionalities include seamless payload management, robust encoding/decoding support, and built-in version control for content updates.
2026-08-03
Shell
★ 14
Omniscient V3 is a comprehensive reconnaissance and adversary simulation framework designed to enhance security assessments by consolidating over 130 best-in-class tools into a unified pipeline. Key features include AI-driven results augmentation, distributed execution across platforms such as Kubernetes and Docker, advanced stealth techniques for emulating sophisticated attacks, and immutable audit trails for compliance and reporting. This tool is primarily aimed at security professionals, providing a streamlined approach to identifying vulnerabilities in complex attack surfaces.
2026-08-03
Shell
★ 478
ScanCannon is a high-speed Bash script designed for efficient credentials-based attack surface enumeration and reconnaissance of large external networks, leveraging tools like `masscan` for rapid port detection and `nmap` for detailed service analysis. It outputs consolidated reports in HTML and CSV formats while enabling project-driven scanning that tracks changes over time, facilitating continuous monitoring of attack surfaces. Notable features include full ASN-based discovery, API detection, CVE hinting, and resilience through checkpointing and parallel scanning.
2026-08-03
Shell
★ 64
365 is a comprehensive OSINT and threat hunting tool designed for network and web reconnaissance, discovery, enumeration, vulnerability mapping, exploitation, and reporting. Its notable features include a streamlined setup process for Kali Linux and a range of scripts for automating various security assessment tasks. This tool is primarily used for enhancing security assessments and facilitating vulnerability exploitation in targeted environments.
2026-08-03
Python
★ 259
AutoRedTeam-Orchestrator is a local-first, MCP-native automation platform designed for authorized testing and AI/MCP attack surface auditing. It features a modular security capability set accessible via an MCP Server, Python SDK, and Typer CLI, enabling static code audits, reconnaissance, and vulnerability detection primarily for research and training purposes. Notable capabilities include AI-assisted audits, configurable scanning profiles, and different export formats for audit reports, each tailored for secure and compliant usage scenarios.
2026-08-03
Shell
★ 4331
The "Awesome OSINT for Everything" repository provides a comprehensive list of OSINT (Open Source Intelligence) tools and websites tailored for penetration testing, information gathering, and red team operations. It encompasses a wide array of categories, including reverse searching, social media analysis, data leaks, and more, making it an invaluable resource for cybersecurity professionals and bug bounty hunters. Notable features include organized sections by topic, facilitating easy navigation and access to relevant tools across diverse OSINT areas.
2026-08-03
Python
★ 303
Black Cat is a penetration testing automation framework designed to mimic human-like engagement through a hypothesis-driven state machine model, allowing for iterative recon and validation processes. Unlike traditional tools that follow a linear pipeline, Black Cat enables feedback loops between different testing phases, making it adaptable and capable of handling failures creatively. Notable features include a single JSONL ledger for tracking hypotheses and evidence, explicit file routing for techniques, and a refined decision-making process that records the rationale behind each choice made during testing.
2026-08-03
HTML
★ 14
CloudGuard Security is a browser-based demonstration tool that exploits the File System Access API to simulate file encryption and delivery attacks without requiring software installation. It operates in two modes: the 'lock' mode, which encrypts files using AES-256-GCM and displays a countdown alert, and the 'drop' mode, which silently writes a specified payload to the user's file system. The tool emphasizes social engineering techniques for permission granting, making it a practical resource for red-team exercises.
2026-08-03
Go
★ 318
Brutus is an advanced, multi-protocol authentication testing tool designed for penetration testers and red team operators, enabling efficient credential validation across a diverse range of network services such as SSH, RDP, and databases. Built in Go as a single binary with no external dependencies, it offers features like SOCKS5 proxy support, aggressive mode tuning, and seamless integration with tools like Nerva and naabu for automated workflows. Notably, it includes a library of known bad keys and supports account enumeration, making it a versatile asset for modern offensive security practices.
2026-08-03
Python
★ 476
Cain is an AI-powered penetration testing engine designed for authorized security assessments in real-world environments, effectively navigating complex business logic and adapting to activated WAF/risk control systems. Key features include a cloud penetration module that supports major cloud platforms, a deterministic state machine for orchestrated testing, and robust safety mechanisms ensuring compliance and risk management. Its capabilities extend to identifying business logic flaws, authentication issues, and cloud misconfigurations, providing detailed evidence and actionable remediation advice.
2026-08-03
★ 30
The Certificate of Compromise repository contains a comprehensive paper detailing offensive operations against Active Directory Certificate Services (ADCS). It serves as a living document that outlines various attack techniques, their detection, and mitigation strategies, and is continuously updated to reflect new findings and community contributions. Notably, it emphasizes the dynamic nature of ADCS research, providing insights into attack taxonomies and the related challenges in securing these services.
2026-08-03
Python
★ 15
CredWolf is a credential validation tool designed for Active Directory Domain Services that tests various username and secret combinations against a domain controller to identify valid credentials. Notable features include support for multiple secret types (passwords, NT hashes, Kerberos keys), username enumeration without triggering account lockouts, and extensive configuration options for safe and efficient testing. It is tailored for use in authorized penetration testing and security audits, ensuring robust and secure credential verification processes.
2026-08-03
Python
★ 48
The Cybersec Toolkit is an advanced cybersecurity solution that incorporates AI integration through a Model Context Protocol (MCP) server, enabling interactive tool management during penetration testing and bug bounty hunting. It features a comprehensive repository of over 670 tools, categorized into 18 modules and 14 profiles, allowing for modular installation and multi-platform support, including Linux and Termux. Unique to this toolkit is its capability for the AI to autonomously drive tool execution based on problem context, providing a hybrid approach that combines operator control with AI assistance.
2026-08-03
JavaScript
★ 13
The Cybersecurity Interview Questions repository is a comprehensive collection of over 200 interview questions and answers, tailored for various roles in cybersecurity, including Red Team, Blue Team, and Incident Response. Its notable features include categorization by specific topics such as web security and internal network security, along with a user-friendly live site for browsing and searching content. The repository serves as a valuable resource for job seekers, students, and professionals looking to enhance their knowledge and prepare for cybersecurity interviews.
2026-08-03
TypeScript
★ 2162
CyberStrike is an open-source AI-driven tool designed for automated penetration testing, enabling users to transform their existing AI language model subscriptions into autonomous red team agents. It features over 13 specialized agents, 7,600+ security skills, and 120+ OWASP testing techniques, facilitating tasks such as reconnaissance, vulnerability discovery, exploitation, and reporting from a terminal interface. With compatibility for 150+ AI providers and a variety of built-in and MCP tools, CyberStrike streamlines offensive security assessments efficiently.
2026-08-03
C
★ 30
ENDGAME is a command and control framework designed for authorized red team operations and penetration testing, enabling users to simulate adversarial techniques and assess their network's detection capabilities. Its standout feature is the integrated AI Console, which interprets user objectives in natural language and suggests executable commands based on real-time contextual data, enhancing efficiency in red team workflows. Additionally, the framework supports automated analysis of command outputs to inform follow-up actions, ensuring a streamlined operational process.
2026-08-03
TypeScript
★ 39
HackMyAgent is a security scanning and behavioral simulation toolkit designed specifically for AI agents, providing red-team capabilities to identify vulnerabilities across various categories. It features comprehensive static and semantic checks, including a NanoMind semantic layer, which evaluates agent configurations and evaluates vulnerabilities like credential exposure and context manipulation. The tool also supports deep behavioral simulations and self-securing mechanisms to ensure the integrity of its binaries.
2026-08-03
Python
★ 19
HDN Phish Toolkit is a comprehensive social media phishing simulation tool designed for authorized security testing and educational purposes. It creates realistic login pages for over nine popular platforms, enabling organizations to assess and understand phishing vulnerabilities while offering features like real-time credential capture, IP tracking, and a web dashboard for monitoring captured data. The tool is cross-platform compatible, supporting Windows, Linux, and macOS environments.
2026-08-03
HTML
★ 129
HydraSoft is an advanced open-source tool designed for detecting DLL hijacking vulnerabilities within Windows environments, facilitating privilege escalation. It automates the analysis of executable files and their associated DLLs by scanning directory structures and import tables, thus identifying specific hijacking opportunities. Notable features include a real-time graphical user interface for centralized endpoint management and a color-coded rating system to prioritize targets based on the complexity of crafting proxy DLLs.
2026-08-03
Python
★ 307
LLMVault is a comprehensive, hands-on training platform designed to educate users on the OWASP LLM Top 10 vulnerabilities applicable to large language models (LLMs). It features 25 deliberately vulnerable labs across three tiers—core, advanced, and expert—each focusing on different attack and defense scenarios, allowing users to learn practical exploits and their mitigations in a controlled environment. Notably, LLMVault emphasizes a self-contained setup that requires no online exposure, ensuring a secure learning experience.
2026-08-03
Python
★ 82
Miner In The Middle is a Python-based tool that facilitates the injection of JavaScript cryptocurrency miners into HTTP responses of targets on a local network via ARP spoofing. It features configurable options for injection scripts and IP constraints to ensure targeted use, along with an easy setup process that automates iptables configuration and packet forwarding. Users can also implement custom JavaScript for injection and execute various attack modes, including standard miner attacks and popunder techniques.
2026-08-03
Python
★ 1214
Recon Skills is a comprehensive toolkit designed for authorized security testing, focusing on external reconnaissance across web applications, APIs, and various vulnerability assessments. Notable features include a structured catalog of skills for discovery, validation, and reporting, covering areas such as authentication testing, attack-path analysis, and evidence review, while emphasizing best practices for operational security and quality assurance. The tool aims to facilitate both manual and automated workflows for security professionals, ensuring a thorough approach to web security assessments.
2026-08-03
C
★ 24
Rubber Dolphy is a proof-of-concept tool designed for the FlipperZero device that enables data exfiltration via BadUSB functionality utilizing mass storage capabilities. It allows users to copy data onto the FlipperZero when it acts as a BadUSB device, facilitating the retrieval of exfiltrated information across different operating systems, including Linux, Windows, and macOS. Notable features include support for FAT file system imaging and the integration of DuckyScripts for streamlined operations, along with planned enhancements for increased functionality and automation.
2026-08-03
Go
★ 25
Sandbox Probe is a static Go binary designed to evaluate the boundaries of sandbox environments used by AI coding agents and other applications. By performing a comparative analysis between a baseline scan on a host and a scan within the sandbox, it identifies potential security gaps, such as unauthorized access to sensitive paths or network resources. Notable features include customizable task sets for various types of actions, JSON report generation for findings, and the ability to track sandbox policy changes over time.
2026-08-03
★ 25
The Security Research Orchestrator Prompt is an advanced orchestration tool designed for structured security and vulnerability research across a variety of authorized lab targets, including code, binaries, and infrastructure configurations. Notable features include its emphasis on maintaining a strict research method without compromising authorization, and the ability to produce detailed outputs such as threat models, exploit chains, and evidence reports, tailored to various operational modes like lab solving, building, and hunting. This tool ensures rigorous validation of security claims while safeguarding the integrity of research processes.
2026-08-03
JavaScript
★ 104
SilentSniffer is an educational tool designed as a web security diagnostic sandbox to demonstrate the extent of information exposure in modern web applications. Functioning entirely as a local client-side environment, it visually portrays how a user's device state and behavioral data can be accessed without consent, utilizing a zero-coupling dynamic plugin architecture for modular functionality. Notable features include a threat escalation hierarchy that categorizes information exposure severity and ensures no data leaves the user's device during operation.
2026-08-03
Shell
★ 22
SimpleVenom is a versatile tool for generating Metasploit payloads, featuring multiple user interfaces including a graphical interface (Zenity), a terminal menu interface (Dialog), and a command-line wizard. It intelligently auto-detects the best available interface based on installed tools and supports payload generation for Windows, Android, and Linux systems. The tool is designed for authorized penetration testing and educational purposes, ensuring a user-friendly experience while managing dependencies effectively.
2026-08-03
Shell
★ 33
SnowCorp Lab is a local Active Directory training environment designed for cybersecurity professionals to practice advanced attack techniques. It features a dual-domain setup with two isolated networks and a dual-homed pivot host, allowing users to simulate real-world scenarios safely on their machines without cloud dependencies. The lab is equipped with five virtual machines and multiple flags to enhance learning experiences and is optimized for hardware specifications that support high-performance virtualization.
2026-08-03
Go
★ 27
SubdomainX is an advanced subdomain discovery and security reconnaissance tool that integrates over twelve enumeration tools and six API services into a single command-line interface (CLI). Its primary use case is to facilitate comprehensive subdomain enumeration, vulnerability detection, and monitoring, featuring capabilities such as HTTP probing, technology fingerprinting, subdomain takeover detection, and notifications via various platforms. Notable features include the ability to generate detailed reports in multiple formats, an interactive terminal user interface (TUI), and support for resuming interrupted scans, making it a robust solution for security assessments.
2026-08-03
Go
★ 687
Titus is a high-performance secrets scanner designed to detect credentials, API keys, and tokens within source code, files, and git history. Targeted at security engineers and DevSecOps teams, it features accelerated regex matching, live secret validation, broad coverage with 487 detection rules, and multiple scanning interfaces including CLI, Go library, and browser extensions. Notably, Titus also supports container image scanning and binary file extraction for enhanced security assessments.
2026-08-03
Python
★ 137
The ULTIMATE CYBERSECURITY MASTER GUIDE serves as a comprehensive knowledge base for cybersecurity practitioners, encompassing insights from over 70 expert books and 90 internal documents. It features detailed guides and playbooks for various roles, including Red Team, Blue Team, and Purple Team operations, along with a flat catalog system for easy access to all resources. Notable elements include an extensive collection of OSINT tools and custom scripts, making it an essential reference for both novice and experienced cybersecurity professionals.
2026-08-03
Python
★ 84
Violin is a Hermes-native pentesting profile designed for supervised penetration tests, guiding users through reconnaissance, exploit validation, and reporting while ensuring robust safety mechanisms. Notable features include 31 structured playbooks for various testing methodologies, a multi-layered safety system that validates every target interaction, and evidence-driven reporting to enhance reproducibility and documentation. It seamlessly integrates with existing Hermes configurations without introducing additional credential management, streamlining the pentesting workflow.
2026-08-03
Python
★ 24
Red-Team AI is a white-box red teaming tool designed to identify security vulnerabilities in agentic AI applications by analyzing the source code for specific bugs related to the application's stack. Its notable features include a comprehensive dashboard for scan management, customized attack generation based on the application's architecture, and compliance tracking against industry standards like OWASP LLM Top 10. This tool is particularly useful for developers working with AI agents in sensitive environments such as finance or healthcare, where unique security risks can arise.
2026-08-03
JavaScript
★ 137
WRAITH is a modern browser-hooking framework designed for red teams, security researchers, and educators, effectively merging the functionalities of traditional browser exploitation tools and blind-XSS frameworks into a single solution. It enables users to conduct authorized security testing by delivering both interactive post-exploitation capabilities and fire-and-forget blind-XSS callbacks in a manner suited for contemporary web applications, including those involving AI. Notable features include an operator console for session management, Docker support for deployment, and a generation of custom payloads for seamless integration into testing scenarios.
2026-08-03
Python
★ 150
ACEshark is a utility for the rapid extraction and analysis of Windows service configurations and Access Control Entries, streamlining the identification of potential privilege escalation vectors without reliance on non-native binaries. It operates by starting an HTTP/HTTPS server to receive and process data from a custom extractor script run on the target machine, generating detailed logs for each service configuration analyzed. Notable features include the ability to audit service permissions across users and groups, as well as options for TLS encryption during data transfer.
2026-08-03
Python
★ 16
AcquiFinder is a Python script designed to scrape Google search results for acquisition titles sourced from Crunchbase using Apify's Google Search Scraper. Its primary use case is to automate the retrieval of relevant acquisition data for specified companies, facilitating market research and analysis. Notable features include easy installation through a virtual environment and minimal setup requirements, such as an Apify account with API access.
2026-08-03
Python
★ 25
AdminProber is a Python tool designed to scan websites for potential admin panels by testing a specified list of common paths. It features multi-threaded scanning for enhanced performance, customizable path lists, and the ability to save scan results, including HTTP status codes, to an output file. Additionally, it includes checks for internet connectivity and updates to simplify maintenance.
2026-08-03
EJS
★ 10
The API Pentesting Tool is a Node.js-based application designed for conducting thorough security assessments of APIs. It offers a user-friendly web interface for executing various tests such as endpoint fuzzing, JWT vulnerabilities, and CORS policy checks, while presenting the results in an easily understandable format. Notable features include JWT algorithm manipulation, header security assessments, and a comprehensive suite of tests for authentication and rate-limiting vulnerabilities.
2026-08-03
★ 476
Awesome Attack Surface Monitoring is a curated repository of open-source and commercial Attack Surface Monitoring (ASM) tools designed to enhance an organization's security posture by identifying and managing vulnerabilities across their digital assets. This resource categorizes tools in an accessible format, highlighting editor's choices and providing visual overviews of key tools. Notable features include a comprehensive list of ASM solutions and visual representations, aiding in the selection of appropriate tools for various use cases.
2026-08-03
★ 17
Awesome Docker is a comprehensive resource repository aimed at enhancing the utilization of Docker technology for developers and operators, featuring a range of materials from introductory tutorials to advanced management and security practices. Its notable features include curated links to official Docker documentation, management tools like Portainer and Docker Compose, best practices, and security guidelines, as well as resources for monitoring and orchestration. This collection serves both newcomers and experienced users, providing valuable references to streamline containerized development and deployment workflows.
2026-08-03
Python
★ 80
AzSubEnum is a Python-based subdomain enumeration tool specifically designed for identifying subdomains linked to Azure services. It employs DNS resolution techniques and permutation methods to systematically explore Azure's domain structure, facilitating comprehensive security assessments for professionals by uncovering subdomains connected to various Azure resources like App Services, Databases, and Key Vaults. Notable features include multi-threaded execution for enhanced performance and support for user-defined permutation wordlists to tailor enumeration efforts.
2026-08-03
Python
★ 21
BatSploit is an open-source penetration testing tool designed to generate Full Undetectable (FUD) payloads and includes a listener handler. Its primary use case is for security professionals conducting tests to assess vulnerabilities in systems. Notable features include ease of installation through a simple Python setup and the capability to create stealthy payloads for effective exploitation.
2026-08-03
Python
★ 30
BeeScan is a modular IT infrastructure security auditing platform that facilitates comprehensive penetration testing and infrastructure assessments through the integration of external tools as plugins. Its notable features include automated result collection and multi-format report generation (TERMINAL, HTML, PDF), PostgreSQL database support for centralized result management, and Docker isolation for environment containerization, making it suitable for DevSecOps workflows and large-scale security audits.
2026-08-03
HTML
★ 136
Burp HTTP History Browser (BHHB) is a tool designed to enable users of Burp Suite Community Edition to view and manage their HTTP history after a session ends, addressing the lack of disk-based project support. It allows users to export their HTTP history in XML format, which can then be parsed and displayed in a well-structured interface. Notable features include its functionality as a Progressive Web App (PWA) that can operate offline in any Chromium-based browser.
2026-08-03
Python
★ 314
Xkeys is a Burp Suite extension designed as a passive scanner to identify and extract sensitive strings such as keys, secrets, and tokens from web pages, listing them as informational issues. It requires Jython for setup and facilitates the automation of asset identification through passive scanning, enhancing the security assessment process by providing valuable insights on potential vulnerabilities. Notable features include various pattern matching for value extraction and seamless integration with Burp Suite’s interface.
2026-08-03
Python
★ 2974
CloudFlair is a cybersecurity tool designed to identify the origin servers of websites that utilize CloudFlare or CloudFront while exposing them publicly. Its primary use case involves leveraging Censys's internet-wide scan data to locate IPv4 hosts that present SSL certificates linked to the specified domain, thereby highlighting potential misconfigurations. Notable features include API integration with Censys, a user-friendly command-line interface for domain scanning, and the capability to differentiate between CloudFlare and CloudFront services.
2026-08-03
Python
★ 218
The Content Bruteforcing Wordlist is a comprehensive wordlist designed for directory content discovery when utilizing the Burp Suite extension Turbo Intruder. It features over 211 million entries to enhance the efficiency of brute-forcing web directories, making it a valuable tool for penetration testers and security researchers focused on web application security assessments. Notably, it includes easy-to-follow usage instructions and examples for seamless integration with Turbo Intruder.
2026-08-03
JavaScript
★ 59
The Tinyactive Cosmos Marketplace is a software application designed for managing and accessing a variety of applications within the Cosmos ecosystem. Its primary use case is to facilitate the integration and deployment of apps such as 2FAuth and Activepieces, enhancing automation and security processes. Notable features include a streamlined interface for adding software sources and an extensive catalog of supported applications, promoting efficiency in application management.
2026-08-03
Python
★ 96
The "cybersecurity-penetration-testing" repository serves as a comprehensive collection of resources focused on penetration testing techniques, tools, and best practices in cybersecurity. It includes categorized links to software, libraries, frameworks, technical guidelines, and educational materials, aiming to assist security professionals in identifying and mitigating vulnerabilities in various environments. Notable features include extensive categories covering everything from anonymity tools to network vulnerability scanners, ensuring a broad spectrum of resources for ethical hacking endeavors.
2026-08-03
JavaScript
★ 532
DarkSide is a versatile cybersecurity tool designed for information gathering, social engineering, and exploit research, featuring an intuitive user interface. It offers capabilities such as bypassing Cloudflare, performing port scans, and accessing hacking tutorials, alongside integration for system information retrieval via malicious links. This tool supports multiple platforms including Linux and Windows, making it accessible for a broad user base.
2026-08-03
C++
★ 16
This repository contains a collection of scripts designed for the Digispark Attiny85, enabling various pranks and system manipulation tasks on Windows systems. Notable features include the ability to execute fake updates, system crashes, information gathering, and reverse shells through Metasploit and Netcat. The scripts serve educational purposes and require specific dependencies for operation.
2026-08-03
Python
★ 11
DisHost is a command-line IP range scanner that performs configurable health checks, including ICMP, TCP, and HTTP/HTTPS tests. Its notable features include multiple ways to specify IP ranges, comprehensive health check configurations, multi-threaded performance for efficiency, and diverse output options such as JSON and CSV formats. This tool is designed for network administrators and cybersecurity professionals to assess the availability and responsiveness of hosts within specified IP ranges.
2026-08-03
★ 31
The DIY ESP32 Marauder is a cost-effective PCB design for building an ESP32-based Marauder device, primarily used for wireless network analysis and security assessments. It supports a TFT LCD display for user interaction and encompasses the requisite components for easy DIY assembly, including detailed flashing instructions for firmware installation. Notable features of the Cheapskate version include a simplified assembly process, compatibility with widely available hardware, and optional battery support for portability.
2026-08-03
C
★ 48
dnsmap is a tool designed for scanning domains to identify subdomains through brute-forcing techniques, utilizing a built-in wordlist of approximately 1000 English and Spanish terms. It is primarily used by penetration testers during the information gathering phase of security assessments to uncover hidden servers and resources that may not be easily discoverable through standard enumeration methods. Notable features include the ability to save results in CSV and human-readable formats, and it operates without requiring root privileges to enhance security.
2026-08-03
Shell
★ 22
DomXssFinder is a tool designed to identify potential sources and sinks within JavaScript code that can lead to DOM-based cross-site scripting (XSS) vulnerabilities. It features two primary commands, `fsource` for locating user-controlled data inputs and `fsink` for spotting dangerous JavaScript functions or DOM objects, aiding developers in securing their web applications against XSS attacks. Notably, it provides context enhancement for findings and integrates with JSextractor for comprehensive JavaScript code retrieval from URLs.
2026-08-03
Go
★ 10
Emailfinder is an open-source OSINT tool designed to extract email addresses from various search engines and platforms, including Google, DuckDuckGo, Bing, Yahoo, Yandex, and GitHub. It operates via a command-line interface, supporting batch processing of domains and offering flexibility through its command structure, allowing users to customize their searches for specific engines and exact matches. Notable features include the ability to fetch results from multiple sources and provide an autocompletion script for enhanced usability.
2026-08-03
Python
★ 221
Enumdb is a brute force and post-exploitation tool designed for MySQL and MSSQL databases, enabling users to test credentials and search for sensitive data fields within database tables. Its notable features include automated credential discovery, multi-threaded enumeration for efficiency, the ability to execute SQL queries and spawn a simulated shell, as well as options for reporting extracted information in .csv or .xlsx formats.
2026-08-03
Rust
★ 40
The ETW-Bypass-Rust tool provides a method for bypassing the Event Tracing for Windows (ETW) framework, primarily aimed at evading Endpoint Detection and Response (EDR) systems. It modifies the `NtTraceEvent` function in `ntdll.dll` to prevent logging of actions that may trigger security alerts, utilizing dynamic function address resolution. This tool serves as an educational resource for cybersecurity professionals to understand and develop defensive strategies against potential detection mechanisms.
2026-08-03
Go
★ 210
`fileless-xec` is a penetration testing tool that enables stealthy execution of remote binary files directly in memory, avoiding disk write operations. It utilizes the `memfd_create` and `fexecve` system calls for secure execution, supports customizable program names, and can bypass network restrictions through ICMP and HTTP3. Notable features include self-removal after execution and the capability to execute binaries without prior installation dependencies on the target system.
2026-08-03
Go
★ 391
GoLinkFinder is a minimalistic JavaScript endpoint extractor designed for security professionals such as bug hunters and red teamers. It efficiently extracts endpoints from both HTML sources and embedded JavaScript files by processing a specified domain, and outputs the results to a file or standard output. Notable features include seamless integration with command-line tools like grep, enhancing its utility in automated security assessments.
2026-08-03
Go
★ 83
gubble is a security auditing tool specifically designed to analyze Google Workspace group settings, identifying potential risks associated with group configurations such as membership permissions, visibility, and messaging capabilities. Its primary use case is to facilitate penetration tests by automating the detection of misconfigurations that could lead to privilege escalation or data exposure. Notable features include the ability to assess various permission settings, including who can join groups, post messages, and view membership, enabling security assessments of Google Groups effectively.
2026-08-03
Python
★ 14
Hun2race is an automated report generation tool designed for bug hunters and penetration testers, leveraging AI technologies such as Google Bard and ChatGPT to facilitate quick report creation. It excels in generating polished PDF reports through LaTeX templates, streamlining the documentation process for security assessments. The tool remains in beta, emphasizing the need for user discretion while harnessing its capabilities.
2026-08-03
C++
★ 23
Hydrangea-C2 Payloads is a command and control (C2) payload generator designed for creating and managing agents within a client-server communication framework. Its primary use case lies in facilitating the control of remote agents for task execution, file manipulation, and process management, with capabilities for advanced operations like DLL injection and keylogging. Notable features include a versatile command interface for both Windows and Linux systems, as well as support for various agent commands encapsulated in a structured communication protocol.
2026-08-03
C
★ 664
Impost3r is a C language-based tool designed for stealing various types of passwords on Linux systems, specifically targeting sudo, su, and ssh credentials. It operates by manipulating user environment files to intercept password entries without alerting the user, automatically erasing traces post-use, and can transmit the captured data via DNS protocol. Noteworthy features include stealth operation, automated cleanup of traces, and adaptable configurations for local storage or network transmission of stolen credentials.
2026-08-03
Python
★ 334
`jwtcat` is a Python-based tool designed for detecting and exploiting vulnerabilities in JSON Web Tokens (JWTs), particularly the signature bypass flaw associated with the `alg=none` algorithm and guessing attacks against HS256 private keys. It supports brute-force and wordlist attacks, allowing users to efficiently test JWTs for security weaknesses. The tool is fully implemented in Python 3 and features options for detailed attack parameters and reporting.
2026-08-03
Shell
★ 382
Kaboom is an automated penetration testing tool focused on information gathering and vulnerability assessment. It integrates multiple utilities such as Nmap, Dirb, Nikto, and Hydra to conduct comprehensive scans and assessments, with results organized in an easily navigable directory. Notable features include support for both interactive and non-interactive modes, extensive customization options, multi-target scanning, and automatic identification of relevant Metasploit modules for vulnerabilities found.
2026-08-03
Python
★ 27
kcbrute is a brute-force tool designed for testing the security of Keycloak Admin/User Console login flows by attacking the OpenID Authorization Endpoint. It allows users to specify a target URL, along with lists of usernames and passwords, and features options for threading, verbosity, and behavioral controls such as early stopping upon a successful login attempt. This tool is intended strictly for ethical security testing, with a disclaimer regarding potential account locking due to brute-force detection mechanisms.
2026-08-03
Python
★ 115
LFITester is a Python3 tool designed for testing server vulnerabilities to Local File Inclusion (LFI) attacks, primarily running on Linux/Unix systems but compatible with Windows as well. Key features include support for various attack vectors like Path Traversal, PHP Filters, and Remote Code Execution through methods such as log poisoning and session file exploitation. The tool provides a comprehensive command-line interface that allows users to automate LFI testing and customize payloads for effective penetration testing.
2026-08-03
C
★ 16
Macgonuts is a versatile ARP/NDP tool designed for network address spoofing, supporting both IPv4 and IPv6 protocols. It aims to provide a lightweight, user-friendly interface for ethical hacking and pentesting while allowing developers to leverage its functionalities via C libraries or bindings in Go and Python. Compatible with Linux and FreeBSD, Macgonuts emphasizes responsible use and ethical practices in network security assessments.
2026-08-03
Shell
★ 10
Minerva is an automated reconnaissance and penetration testing script that streamlines the assessment of a target by integrating multiple tools for tasks such as Nmap scanning, OSINT gathering, and vulnerability enumeration. Notable features include automated Google Dorking for targeting potential admin pages and the use of established tools like theHarvester, amass, and nikto for comprehensive analysis. This tool simplifies the penetration testing workflow, making it accessible for users to execute complex assessments with minimal setup.
2026-08-03
C#
★ 17
NetExec is an open-source network exploitation tool that evolved from the original CrackMapExec, aimed at providing a community-driven framework for post-exploitation activities in network environments. Its primary use case is to facilitate the automation of network attacks and assessments, integrating a suite of tools for a comprehensive assessment workflow. Notable features include ease of installation via pipx, community contributions for continuous improvement, and an active support channel through Discord.
2026-08-03
Java
★ 393
Nuclei-plus is an enhanced version of the Nuclei tool designed for high-speed scanning across multiple targets with customizable templates, ensuring zero false positives. It supports various protocols such as TCP, DNS, and HTTP, and includes features like project management, configuration management, and template editing, making it suitable for comprehensive security assessments. The tool further allows internationalization and multiple network engine interfaces, enhancing user flexibility and control in security checks.
2026-08-03
Python
★ 578
Nullinux is a penetration testing tool designed for Linux environments, specifically tailored for enumerating OS and domain information via SMB protocols. It features capabilities such as single and multi-host enumeration, user and group enumeration, and multi-threaded RID cycling, all while employing a null session approach if no credentials are provided. Additionally, Nullinux generates a formatted output file devoid of duplicates to facilitate further exploitation activities.
2026-08-03
Shell
★ 668
Open-Redirect-Payloads is a tool designed to generate exploit payloads for testing Open Redirect vulnerabilities within web applications. Its primary use case is to assist security professionals in identifying and mitigating open redirect issues by generating URL payloads targeting specific whitelisted domains. Notable features include a simple script (make-payloads.sh) that allows users to customize payload generation based on specified domains.
2026-08-03
Python
★ 637
Overlord is a Python-based command-line interface (CLI) tool designed for automating the setup of Red Teaming infrastructure. It allows users to easily deploy components such as command-and-control servers, email servers, and phishing servers on cloud providers like AWS and Digital Ocean, streamlining the process of creating a comprehensive penetration testing environment. Notable features include modular input handling and integration with Terraform, leveraging the Red-Baron project for infrastructure management.
2026-08-03
Python
★ 19
Penstaller is a Python automation tool that streamlines the setup of essential bug bounty and penetration testing tools on a clean system with a single command. It automates the installation of critical programming languages and various pentesting utilities, facilitating a rapid and efficient environment preparation for both novice and experienced security testers. Notable features include a comprehensive list of tools covering different aspects of security testing, along with recommendations for additional manual installations of wordlists.
2026-08-03
PowerShell
★ 201
PowerLadon is a modular penetration testing tool designed for network reconnaissance, vulnerability scanning, and exploitation, offering capabilities for batch processing across various IP segments. It features extensive support for different protocols, built-in modules for high-risk vulnerabilities, password auditing, and remote command execution, while allowing users to customize and develop their own plugins. Its ease of use and compatibility with PowerShell and Cobalt Strike enhance its versatility in both internal and external network penetration tasks.
2026-08-03
Python
★ 526
PyMeta is a Python3 tool designed for penetration testers and red teamers to conduct metadata analysis on files downloaded from web domains using tailored Google and Bing searches. This tool efficiently retrieves file types such as PDFs and documents, extracts their metadata via exiftool, and compiles the results into a CSV report, making it easier to uncover sensitive information like user accounts and software versions. Notable features include multi-threaded file downloads, customizable search engines, and the ability to process locally stored files.
2026-08-03
Python
★ 100
pync is a Python library that mimics the functionality of Netcat, enabling arbitrary TCP and UDP connections and listening capabilities. Its primary use case includes creating TCP proxies, scripting HTTP clients and servers, and performing network daemon testing. Notable features include a comprehensive command-line interface, extensive networking options, and the ability to execute remote commands, making it suitable for various network-related tasks in Python development.
2026-08-03
Go
★ 14
r3conwhal3 is a multifunctional reconnaissance tool designed for web application data collection and analysis, employing a concurrency-based approach to enhance performance and resource efficiency. Its primary use case includes performing both passive and active reconnaissance, with capabilities to enumerate subdomains, conduct vulnerability scans, and manage custom configurations through an environment file. Notable features include a comprehensive execution chain, support for Docker deployment, and the ability to save output results for future reference.
2026-08-03
JavaScript
★ 122
rfparty-monitor is a wireless situational awareness and debugging tool that allows users to visualize and analyze Bluetooth Low Energy (BLE) data, along with GPS and Wi-Fi logs. It supports diverse platforms such as Android and Linux, and features capabilities like log retrieval and GPX conversion, making it suitable for both casual users and security professionals focusing on wireless monitoring and intrusion detection. Notable features include support for various GPS sources, a flexible installation process, and a roadmap for future enhancements like protocol improvements and real-time sharing alerts.
2026-08-03
JavaScript
★ 104
rfparty-xyz is a visualization tool designed to enhance the understanding of Bluetooth Low Energy (BLE) interactions. Its primary use case revolves around providing insights into BLE data through user-friendly displays, with complementary data collection capabilities available via rfparty-monitor. Notable features include cross-platform compatibility and support for mobile usage with an Android version.
2026-08-03
Python
★ 304
The Rogue Toolkit is a cybersecurity tool designed for advanced users to simulate malicious activity and test network defenses. Its primary use case is to aid in penetration testing and security assessments, allowing for customized execution of various attack scenarios. Notable features include extensive documentation for argument configurations and example use cases, enabling tailored deployments in various environments.
2026-08-03
PHP
★ 70
Rome WebShell is a lightweight PHP webshell designed for educational use, featuring a fully interactive file explorer that allows users to browse directories and upload files directly from their browser. It enables command execution without URL encoding while offering MD5 password protection for access control, alongside a customizable and responsive FlatUI interface. Additionally, the tool includes an obfuscated version to enhance security against detection.
2026-08-03
Rust
★ 93
Rust-Hells-Gate is a proof-of-concept tool designed for evading Endpoint Detection and Response (EDR) systems through the use of direct syscalls in Rust. It specifically implements the Hell's Gate technique, allowing users to bypass EDR hooks by accessing the Process Environment Block (PEB) to resolve function pointers from ntdll.dll, thereby minimizing detection by common security measures. Notable features include its lightweight implementation approach and the potential for extension into a fully functional malware loader.
2026-08-03
Shell
★ 46
The "s3-buckets-aio-pwn" tool is designed to identify vulnerable Amazon S3 buckets as part of penetration testing and bug bounty efforts. It uniquely allows users to scan multiple S3 bucket entries from a text file while employing various attack scenarios to assess their vulnerability. Key features include its command-line usage, integration with AWS CLI, and the capability to quickly filter out false positives during vulnerability assessments.
2026-08-03
Python
★ 11
Saldi Script is a versatile testing tool designed for security professionals to conduct various web application attacks, including DDoS, SQL injection, XSS, and data exfiltration. Key features include the ability to bypass Web Application Firewalls (WAF), execute reverse shell commands, and engage in phishing attacks, all aimed at evaluating the robustness of website security. The tool requires Python 3.10 and specific dependencies for operation, emphasizing its use as an educational resource for ethical hacking practices.
2026-08-03
Python
★ 114
SBSCAN is a penetration testing tool specifically designed for the Spring framework, capable of conducting unauthorized scans and sensitive information detection on Spring Boot applications, as well as identifying and validating related vulnerabilities. Notable features include an extensive dictionary for sensitive paths, fingerprint detection capabilities to optimize resource usage, modular architecture for user-defined extensions, and comprehensive support for various types of vulnerability checks, including the latest CVEs. The tool also implements functionality for noise reduction in results, allowing users to focus on successful detections, and supports various scanning configurations such as URL or file-based targets, proxy settings, and multithreading.
2026-08-03
Python
★ 11
Selene is a Python-based script designed to facilitate the dumping of MySQL databases using specified connection parameters such as host, username, and database name. Its primary use case is to provide a straightforward interface for users to export MySQL database data with minimal command-line input. Notable features include a user-friendly command structure and the ability to create a system-wide command symlink for easy access.
2026-08-03
Python
★ 89
Sexettintool is a multifaceted cybersecurity tool designed for educational and ethical hacking purposes, enabling users to execute various automated exploits and security assessments. Key features include exploit scanning with Searchsploit, firewall detection via wafw00f, brute force automation with ncrack, and vulnerability analysis using nikto and lynis, among others. The tool is structured to enhance cybersecurity awareness while retaining a focus on responsible usage, with comprehensive support for Linux users and potential Docker deployment.
2026-08-03
Java
★ 457
ShotDroid v2 is a penetration testing tool designed for Android devices that features file retrieval from device storage, an integrated keylogger with reverse shell capabilities, and the ability to capture images from the device's front camera. Notable functionalities include the option to conceal apps in the file manager, customization of directories and HTML templates for webcam captures, and a focus on educational use within legal boundaries.
2026-08-03
Python
★ 179
smtp-user-enum is a Python-based tool designed for SMTP user enumeration using commands like `VRFY`, `EXPN`, and `RCPT`. Its notable features include granular timeout management, automatic reconnection capabilities upon encountering errors, and flexible customization options for input formats, making it effective for identifying valid email addresses and their aliases. This tool is inspired by a Perl script and supports both Python 2 and Python 3.
2026-08-03
Go
★ 313
SmuggleFuzz is a configurable HTTP downgrade smuggling scanner designed to identify overlooked smuggling vulnerabilities in web applications. Its notable features include customizable gadget lists, multiple scanning options with support for various HTTP methods and headers, and the ability to filter responses by specific criteria. The tool enables deeper insights into failed attacks, making it a powerful resource for security professionals aiming to enhance their vulnerability assessments.
2026-08-03
Python
★ 22
SpearCopy is an educational tool designed for local website cloning and credential capture within controlled environments. It allows users to download full webpage content, host it on a local HTTP server, and log credentials entered into forms in JSON format, with customizable payload options for simulating phishing behaviors. This tool is intended strictly for educational purposes and internal testing, emphasizing the importance of ethical use.
2026-08-03
Crystal
★ 42
SprayCannon is a multithreaded password spraying tool that automates the process of password spraying across various applications while maintaining a record of previously attempted credentials. Notable features include a backend database for tracking sprayed combinations, built-in delays and jitter for requests, support for multi-factor authentication (MFA) and lockout detection, as well as integration with webhooks for alerts. It aims to streamline the password spraying process for users managing large credential lists across multiple protocols.
2026-08-03
PHP
★ 262
sqlscan is a web scanning tool designed to detect SQL injection vulnerabilities in websites quickly. Its primary use case is for security testing and penetration testing, enabling users to scan individual URLs or lists of URLs for potential security flaws. Notable features include multi-platform support, speed, and the ability to utilize sitemaps for enhanced scanning results.
2026-08-03
Python
★ 16
suidPWN is a tool designed to streamline the identification of SUID binaries that may facilitate local privilege escalation (LPE) on a target system. By allowing users to input the output of the `find` command, it quickly checks against gtfobins for vulnerabilities, efficiently surfacing potential escalation techniques and storing them locally for subsequent use. Notable features include the ability to scrape data from gtfobins automatically and the option to regularly update the binary reference files.
2026-08-03
Go
★ 54
Supernova_CN is an open-source shellcode encryption tool developed in Golang, designed to facilitate the encryption of raw shellcode using various algorithms such as XOR, RC4, AES, and CHACHA20. It allows users to convert the encrypted shellcode into compatible formats for multiple programming languages, and provides corresponding decryption code as guidance for implementation. Notably, the tool includes a comprehensive command-line interface and supports encryption in Base64 formats for added versatility.
2026-08-03
Python
★ 29
SYCP (Solyd Certified Pentester) is a resource repository designed to complement students pursuing the SYCP certification in penetration testing. It details the activities and topics covered in the course, providing a comprehensive study guide for users to enhance their cybersecurity skills. Notable features include thorough documentation of course modules and practical insights into penetration testing techniques.
2026-08-03
Python
★ 97
Tomcter is a Python-based tool designed to perform brute-force attacks on Apache Tomcat manager logins using default credentials. It supports single and multiple target attacks, operates efficiently with low resource consumption, and can be integrated with ProxyChains for enhanced capabilities. Notable features include its open-source nature and Docker support for containerized deployment.
2026-08-03
Perl
★ 56
UBERSCAN is a security tool designed for penetration testing of servers, routers, and IoT devices, aimed at showcasing vulnerabilities, including susceptibility to threats like the Mirai virus. It features various scanning modes (SSH, Telnet) and options for brute-forcing credentials using user and password files. Primarily intended for ethical hacking purposes, it encourages users to responsibly report any identified vulnerabilities.
2026-08-03
C#
★ 13
This repository provides a portable executable version of Ncat, specifically Ncat-7.95, integrated with OpenSSL-3.3.1, offering enhanced features while excluding a native PCRE library. It serves as a versatile networking utility for data transfer and connection management, allowing users to execute standard Ncat commands effortlessly. Additionally, it includes a basic C# script for automating Ncat tasks, enhancing its usability in various scenarios.
2026-08-03
Shell
★ 39
Vide.sh is a versatile tool designed for probing and crawling targets to enumerate their attack surface through various scanning engines, such as nmap, httpx, and whatweb. It can process input from various sources, including XML files, lists of targets, standard input, and direct strings, while offering a range of configurable scanning options to tailor the attack surface enumeration according to user needs. Notable features include the ability to skip probing and crawling, run multiple types of scans, and generate organized output, including screenshots and detailed logs of the scanning results.
2026-08-03
Python
★ 66
WConsole Extractor is a Python library designed to exploit Flask applications that are running in debug mode, allowing users to extract sensitive information and gain interactive access to the server. Users can implement a custom file leak function to retrieve files from the target application, and the tool provides attributes to access critical server details, including tokens and user information, as well as functions for spawning shells and debuggers. Notable features include an easy installation process and the capability to interact with the application environment through an integrated shell.
2026-08-03
Python
★ 80
wcreddump is a lightweight Python script designed to automate the dumping of credentials from Windows systems, specifically targeting both SAM hashes and WINHELLO PINs. It requires specific libraries and a mounted Windows OS drive to function, and it outputs the dumped credentials to an 'outputs' folder, making it suitable for further cracking with tools like JTR or hashcat. Notable features include customizable parser options and automatic output handling, enhancing user convenience during the credential extraction process.
2026-08-03
Python
★ 44
weakpass_generator is a Python tool that generates weak passwords using the current date as a basis for randomness. It is primarily used for testing the robustness of password security by creating predictable and easily guessable passwords. Notable features include its simplicity and the ability to quickly generate multiple weak passwords for security assessments.
2026-08-03
Python
★ 20
Werkzeug Cracker is a tool designed to perform wordlist attacks on hashes generated by the `werkzeug.security` module, primarily to verify password hashes efficiently. It utilizes the `check_password_hash` function to determine password validity and supports multithreading to enhance cracking speed, allowing users to specify the number of threads for improved performance. The tool is compatible with both Linux and Windows platforms and requires Python 3.10 for operation.
2026-08-03
Python
★ 19
WiFi-Creds-Grabber is a Python tool designed to extract Wi-Fi credentials from a local Windows machine. Its primary use case is to retrieve stored Wi-Fi passwords, which are then saved in a text file named "passwords.txt" for easy access. The program is straightforward to use, requiring only Python to be installed and executing simple command-line instructions.
2026-08-03
Python
★ 37
Wshlient is a versatile web shell client that allows users to execute commands by injecting them into a crafted HTTP request. Users create a text file containing the HTTP request and specify injection points, enabling command execution while providing options for customization, such as token replacements and debug output. This tool is primarily used for remote command execution in web environments, leveraging Python's requests library for simplicity and ease of installation.
2026-08-03
Python
★ 19
XUPA RUSTAM is a Python-based penetration testing tool designed for brute-force attacks against website admin login panels. It utilizes the `requests` module for making requests and incorporates Tor proxies to maintain the attacker's anonymity. Key features include support for user-defined lists of admin usernames and passwords, printing responses from the target URL, and the option to operate without a proxy.
2026-08-03
Python
★ 107
ZenBuster is a multi-threaded, multi-platform URL enumeration tool designed for use in Capture The Flag (CTF) challenges and by security professionals for target information gathering. It efficiently brute-forces subdomains and URI resources, offering features such as customizable wordlists, port specification, and logging capabilities, while supporting both IPv4 and IPv6 formats. Despite being user-friendly and slightly less speedy than more established tools like Gobuster, ZenBuster maintains satisfactory reliability for practical use.
2026-08-03
Python
★ 48
Cloudfish is a Python tool designed for subdomain enumeration using Cloudflare's DNS services, primarily aimed at penetration testers and bug bounty hunters. It automates the creation of a Cloudflare zone for a specified domain, scans for DNS records, saves the findings, and then deletes the zone, all while maintaining a passive approach since the scanning is executed on Cloudflare's end. Notable features include a silent operational mode with the option for verbose output, and the ability to be imported as a module for custom integration.
2026-08-03
Python
★ 41
ftpknocker is a multi-threaded scanner designed to identify anonymous FTP servers across various target networks. Its primary use case includes scanning individual IP addresses or entire IP blocks, with customizable options for threading, port specification, and timeout settings. Notable features include support for input via piping from other programs and a flexible usage syntax similar to nmap, enhancing its functionality for security assessments.
2026-08-03
Python
★ 10
The 3num-tool is a versatile enumeration utility designed for authorized security testing, enabling users to gather information about various services such as SSH, FTP, HTTP, DNS, and SMB. Its notable features include support for credentialed enumeration, anonymous access testing for FTP, and integration with tools like Gobuster and Hydra for more comprehensive assessments. The tool emphasizes compliance with legal and ethical guidelines, catering to security professionals conducting vulnerability assessments.
2026-08-03
Shell
★ 182
Air Script is an automated Wi-Fi network penetration testing tool that simplifies the process of network scanning, handshake capturing, and brute-force password cracking. It features automated attacks on nearby networks, email notifications for successful handshake captures, and compatibility with devices like Raspberry Pi for discreet operation. Users can enhance their workflows by selecting from a variety of additional tools provided within the script.
2026-08-03
PowerShell
★ 452
Amnesiac is a post-exploitation framework developed in PowerShell that facilitates lateral movement within Active Directory environments without the need for installation, as it operates entirely in memory. It features command execution over Named Pipes for discreet operations, a user-friendly interface, and a variety of integrated modules for tasks such as keylogging and Kerberos ticket dumping. The tool is designed for research and authorized testing, emphasizing user responsibility in compliance with legal regulations.
2026-08-03
Go
★ 27
AndroSecTest is a security auditing tool designed for static analysis of Android applications to identify vulnerabilities and insecure behaviors. It utilizes a Docker container for easy setup and includes functionalities such as unpackaging APK files, examining application signatures, and checking for sensitive data within the application's file system. Notably, the tool facilitates interaction with connected Android devices via ADB commands, though results are currently not persisted outside the Docker environment.
2026-08-03
Python
★ 13
AtilKurt is a read-only Active Directory security assessment tool designed for comprehensive directory hygiene analysis and security evaluations through LDAP. It efficiently collects and analyzes identity, group, computer, GPO, and ACL data to identify misconfigurations and potential vulnerabilities, and generates detailed HTML and JSON reports for offline review. Notable features include a severity-based risk scoring system, support for large environments with paging and parallel collection, and compliance reporting for various security frameworks.
2026-08-03
Java
★ 225
Auth Analyzer is a Burp Suite extension designed to identify authorization vulnerabilities within web applications by automating the process of request manipulation and parameter handling. It features advanced capabilities for auto-extracting and replacing session parameters, such as CSRF tokens and cookies, while analyzing the responses for bypass status, enabling users to effectively test various user roles and sessions. The tool streamlines authorization testing through GUI-driven session management, simultaneous role testing, and custom parameter definitions, thus enhancing the efficiency of security assessments.
2026-08-03
Python
★ 610
AutorizePro is a Burp Suite plugin designed for detecting authorization vulnerabilities using an integrated AI analysis module. Its primary use case is to automate the testing of authorization issues, markedly reducing false positive rates from 95% to 5% by leveraging AI for improved accuracy in complex scenarios. Notable features include support for customizable API endpoints, local model deployment, and the ability to exclude non-API resources, alongside comprehensive reporting capabilities.
2026-08-03
Shell
★ 378
Bug-Bounty-Agents provides a collection of specialized AI agent prompts designed for enhancing bug bounty hunting, penetration testing, and offensive security workflows. This tool enables users to deploy focused, production-ready agent personas into various agent-capable LLM clients such as Claude Code, GitHub Copilot Chat, and Cursor, facilitating tasks like reconnaissance, web application testing, and exploit planning without any additional framework dependencies. Notable features include strict scope enforcement and a diverse catalog of 43 agents tailored for different engagement phases, enabling efficient and targeted security assessments.
2026-08-03
★ 27
BugBountyData is a repository that compiles a list of public bug bounty programs and responsible disclosure initiatives, accessible through a user-friendly web interface. Its primary use case is to facilitate easy exploration of various bug bounty opportunities for cybersecurity researchers. Notable features include an unfiltered list of subdomains with guidelines on how to filter domains based on organizational policies, enhancing clarity and usability for participants.
2026-08-03
Python
★ 55
BugHunter-AI is an automated penetration testing agent designed with a cyberpunk-themed GUI that facilitates resource-aware task scheduling and AI-assisted analysis. Its primary use case is for authorized security testing in controlled environments, allowing users to enqueue tools while managing CPU and RAM limits for safe execution. Notable features include per-round report generation, automated CVE extraction, and integration with external AI services for enhanced command suggestions based on analysis results.
2026-08-03
Python
★ 11
BurpSuite-Config is a tool designed to enhance the Burp Suite's functionality by providing customizable "Match and Replace" and "TLS Pass Through" rules. Its primary use case is to streamline the interception and modification of web traffic for security assessments. Notable features include intuitive rule configuration for efficient traffic manipulation and the ability to handle encrypted traffic seamlessly.
2026-08-03
Go
★ 12
certinfo is an SSL certificate scraping tool designed to extract domain names from SSL certificates across multiple hosts. Its primary use case includes both basic certificate data extraction and recursive enumeration of subdomains through Certificate Subject Alternative Names (SANs), offering features like multi-threaded processing, support for varied input formats, and real-time output. Users can choose from multiple output formats, including JSON and CSV, and customize the number of concurrent workers for efficiency.
2026-08-03
Python
★ 42
CrossInjector is a Python-based tool designed for scanning multiple URLs to detect Cross-Site Scripting (XSS) vulnerabilities. It utilizes Selenium WebDriver and ChromeDriver to execute JavaScript payloads, determining if each URL is susceptible to XSS attacks. Notable features include customizable payloads and support for batch URL scanning, making it an efficient solution for security assessment.
2026-08-03
Python
★ 44
CTFEnum is a Python-based network penetration testing tool specifically tailored for Capture The Flag (CTF) challenges. It conducts reconnaissance by scanning open TCP and UDP ports on a specified IP address, employing a modular design to probe various services and leveraging multiprocessing for efficiency. Notable features include automatic Nmap scanning, service-specific handlers for tasks like brute-forcing credentials, and detailed recommendations for exploiting identified vulnerabilities.
2026-08-03
Python
★ 26
Cyber-X is a comprehensive cybersecurity toolkit designed for penetration testing and server defense against hacker attacks. It features various tools for vulnerability scanning, exploitation, server hardening, and anti-DDoS protection, catering to multiple user needs through its modular structure, including X-pentest for offensive operations and X-defence for defensive measures. The toolset emphasizes ease of installation and usage, making it suitable for educational and practical applications in cybersecurity.
2026-08-03
Python
★ 213
Deluder is a dynamic instrumentation tool designed for intercepting traffic from proxy unaware applications by leveraging Frida. It supports a variety of networking libraries, including WinSock, OpenSSL, and GnuTLS, and allows users to customize interception scripts using JavaScript. Primarily intended for integration with the PETEP penetration testing proxy, Deluder can also function autonomously for broader traffic interception tasks.
2026-08-03
Rust
★ 634
Dirble is a directory scanning tool designed for both Windows and Linux environments, enabling rapid enumeration of web directories and files. Its primary use case is for security assessments to identify accessible resources on web servers, with notable features including support for custom headers, HTTP authentication, multithreading, and options for saving output in various formats. It also effectively detects both listable directories and responds to various HTTP status codes, enhancing its utility in penetration testing scenarios.
2026-08-03
Python
★ 16
dnsspider is an asynchronous, multithreaded tool designed for brute-forcing subdomains using either a specified wordlist or character permutations. Its primary use case is to discover subdomains of a target domain quickly, allowing for various attack types, including dictionary-based or brute-force methods. Notable features include customizable character sets, the ability to query multiple DNS record types, and options for logging results in different formats, making it versatile for reconnaissance purposes in cybersecurity assessments.
2026-08-03
Python
★ 463
dotdotslash is a Python tool designed to automate the testing for Directory Traversal vulnerabilities in web applications. It allows users to specify a target URL and an attack string, with options for depth of traversal and cookie handling, making it suitable for security assessments against platforms like DVWA and bWAPP. Notable features include detailed command-line help and a focus on efficient vulnerability detection in a variety of web architectures.
2026-08-03
★ 32
The EvilCrowRF_v2-el_Cheapo_version is a DIY radio frequency device designed for penetration testing and Red Team operations, capable of operating within the 300MHz to 928MHz bands. It utilizes easily sourced components and offers an accessible building experience, featuring support for various firmware options to enhance its functionality. Key components include the TI CC1101 module, ESP32 DevKit, and a MicroSD card, making it a versatile and affordable tool for RF experimentation and security assessments.
2026-08-03
Shell
★ 266
GarudRecon is a bash-based reconnaissance automation framework designed for security professionals and bug bounty hunters, facilitating asset discovery and vulnerability assessment through the integration of over 80 open-source security tools. It offers multiple operational modes, such as SmallScope, MediumScope, and LargeScope, to tailor the reconnaissance process according to different engagement scopes, alongside advanced capabilities for automated monitoring and vulnerability detection including subdomain enumeration, port scanning, and exploitation checks. Noteworthy features include a workflow mode for tool chaining, fleet mode for distributed scans, and cron job scheduling for recurring tasks.
2026-08-03
Python
★ 184
Gitxray is a security analysis tool designed to analyze GitHub repositories for OSINT and forensic purposes by utilizing the public GitHub REST APIs to extract valuable information efficiently. Its primary use case includes identifying sensitive data in contributor profiles, spotting threat actors or fake repositories, and conducting forensic investigations by filtering results by specific dates. Notable features include customizable text output, integration with VirusTotal for enhanced threat detection, and the ability to run comprehensive scans on repositories to gather extensive data.
2026-08-03
Python
★ 373
gpoParser is a tool that facilitates the extraction and analysis of Group Policy Object (GPO) configurations in Active Directory environments. It supports both local and remote parsing modes, allowing users to gather GPO information via LDAP connections or from offline SYSVOL data, and includes features for displaying parsed results and enriching BloodHound data. Noteworthy capabilities include various operational modes such as local parsing, remote LDAP access, querying results, and the ability to handle security-related analysis, making it valuable for identifying potentially risky configurations.
2026-08-03
Python
★ 984
Habu is a versatile hacking toolkit aimed at educating users on Python and network hacking techniques. It features practical functionalities such as ARP poisoning, DHCP exploitation, subdomain identification, and certificate cloning, alongside various data extraction and analysis tools. This comprehensive suite serves as both an instructional resource and a powerful utility for network testing and research.
2026-08-03
Go
★ 43
haktrailsfree is a command-line tool designed to extract up to 10,000 subdomains from SecurityTrails using user-provided cookies instead of an API key, effectively bypassing the limitations of the free API tier. Key features include the ability to handle both single and multiple domains, configurable cookie input, and options for silent or verbose output. This tool facilitates extensive subdomain enumeration, making it valuable for security assessments and research.
2026-08-03
Python
★ 24
HashRipper is a multi-threaded ethical hacking tool designed for efficiently cracking a variety of hash algorithms, including popular types like NTLM, MD5, and SHA variants. Its notable features include support for over 17 hash algorithms, the ability to perform dictionary-based attacks using concurrent threading for increased speed, and a command-line interface that allows for cracking hashes directly or from files. The tool is compatible with Linux and Termux, making it versatile for use in different environments.
2026-08-03
Go
★ 11
hidden_fuzzer is a command-line tool designed for rapid web content discovery, specifically targeting hidden paths and directories in web applications. Leveraging Jaro and Jaro-Winkler similarity algorithms, it automatically filters out false positives without the need for complex configurations. Notable features include multi-threaded scanning, recursive directory fuzzing, and support for various customizations such as proxy routing and parameter fuzzing.
2026-08-03
Go
★ 82
HTTPUploadExfil is a simple HTTP server designed in Go for exfiltrating files and information from a machine using HTTP, particularly suited for low-stakes offensive scenarios like Capture The Flag (CTF) competitions. It offers an interface that allows users to upload files, uses basic GET requests to log data, and supports multiple endpoints for file management and retrieval. Notable features include customizable bind addresses, support for SSL/TLS, and a straightforward build process.
2026-08-03
Python
★ 12
HunterA is an advanced mobile penetration testing framework designed for Android devices operating without root access, functioning within the Termux environment. It consolidates a diverse array of powerful tools for tasks such as port scanning, WHOIS/DNS reconnaissance, CVE vulnerability searches, and traffic sniffing, along with features like a fully asynchronous engine and integration with Termux:API for enhanced capabilities. Its modular design supports a range of functionalities, from OSINT to vulnerability exploitation, making it a comprehensive solution for mobile pentesting.
2026-08-03
Shell
★ 34
The iOS Binary Security Analyzer is a script designed for performing static analysis on iOS application binaries to identify security weaknesses such as insecure functions, weak cryptographic implementations, and missing security features like code signatures and PIE. Notable features include checks for core binary security mitigations, dynamic library dependencies analysis, and detection of anti-analysis indicators, making it a valuable tool for assessing the security posture of iOS applications on jailbroken devices.
2026-08-03
Go
★ 17
ipfinder is a command-line tool designed to efficiently extract IP addresses and other data from Shodan search queries, catering to both advanced users and beginners through its support of complex query syntax and simple domain-based filtering. Key features include flexible facet selection, options for filtering query types, handling of HTTP errors with retry logic, and the ability to control output verbosity, making it suitable for robust cybersecurity investigations and data extraction tasks.
2026-08-03
Python
★ 11
Kautolog is an automated terminal logging tool designed for Kali/Linux systems that captures comprehensive session details, including prompts, commands, and outputs across multiple terminal tabs. Notable features include integration with `tmux`, optional log syncing with rclone, customizable log directories, and a replay functionality that supports timing and instant dumping of logs. The tool provides extensive configuration options for log management, including log rotation and cleanup.
2026-08-03
TypeScript
★ 10
LangFlow is an AI-powered cybersecurity workflow automation platform designed to streamline penetration testing and security operations by integrating traditional command-line tools with intelligent AI analysis and multi-channel reporting. Notable features include a visual workflow designer, real-time execution monitoring, cross-platform command execution, and automated report generation with metrics-driven insights. Its ability to utilize multiple AI models for contextual analysis enriches the security automation process, enhancing efficiency and collaboration across teams.
2026-08-03
Python
★ 27
LazarusWakeUp is a Python-based tool designed for reconnaissance and management of disabled Active Directory (AD) principals, enabling users to find, enable, disable, and analyze these accounts. Its notable features include the ability to operate over LDAPS for secure communications, verbosity options for output detail, and batch operation capabilities to streamline account management tasks. This tool is intended for educational purposes and emphasizes lawful usage.
2026-08-03
C++
★ 45
Maliketh is a multi-user, customizable command and control (C2) framework designed to be flexible for operators. It features cross-platform support through its initial C++ and Golang implants, allowing for behavior modification based on server configurations, file operations, command execution, and self-destruct capabilities, among others. Notable functionalities include basic anti-debugging measures and a range of file management operations, making it suitable for diverse operational scenarios.
2026-08-03
★ 980
Muxcard is an innovative computing device designed to be the size of a standard credit card, utilizing an ESP32-C3 chip, an e-paper display, and NFC technology. Its primary use cases include serving as a minimalist wallet for digital credentials, a pentesting tool for ethical hacking, a smart-home control interface, and an offline password manager. Notable features include its ultra-compact design, integrated display, and flexible functionality tailored to various everyday applications.
2026-08-03
Python
★ 15
NetRaptor is a GUI-based ARP poisoning tool designed for educational use and authorized network security testing, allowing users to scan networks, select targets, and perform Man-in-the-Middle (MITM) attacks. Key features include easy network scanning, ARP poisoning capabilities, packet analysis integration with Wireshark, and a user-friendly interface built with Tkinter. The tool is compatible with various Linux distributions and emphasizes ethical usage in controlled environments.
2026-08-03
Python
★ 29
NoxDroid is a comprehensive Android pentesting toolkit designed for Windows, facilitating both static and dynamic analysis of APKs through an interactive terminal menu. It supports automation for environment setup, including tools like Magisk and Frida, and features extensive analytical capabilities such as APK scanning, vulnerability assessments, traffic interception, and real-time reporting. Notable functionalities include integration with various scanning tools, a built-in dynamic analysis suite, and support for both the Nox Player emulator and physical Android devices via ADB.
2026-08-03
Go
★ 13
Nucleihub is a tool designed for organizing and managing Nuclei templates from various community sources, enabling users to consolidate template files efficiently. It features auto-flattening of directory structures, duplicate handling, smart filtering, and validation of downloaded templates, with optimizations for low-resource environments. The tool supports URLs ending in `.git`, `.yaml`, or `.zip` formats, enhancing flexibility in template retrieval.
2026-08-03
★ 38
nucleihub-templates is a continuously updated repository of Nuclei templates designed for security testing, aggregating over 600 sources and refreshed every six hours via GitHub Actions. It provides security researchers and penetration testers with a comprehensive suite of templates for effective vulnerability scanning, leveraging an automated collection pipeline that removes duplicates and validates templates against the latest Nuclei version. Notable features include automatic updates, diverse template categorization, and seamless integration into existing security workflows.
2026-08-03
Python
★ 1784
One-Lin3r is a lightweight and modular framework designed for penetration testers, providing over 176 automated one-liners for tasks such as reverse shells, privilege escalation, and remote command execution across multiple operating systems. Notable features include advanced auto-completion for commands, typos correction, and the ability to execute multiple commands simultaneously, significantly enhancing efficiency during security assessments. The tool further simplifies command usage and management with clipboard integration and history tracking capabilities.
2026-08-03
Go
★ 25
OpenShell is an open-source reverse shell management server developed in Go, enabling users to establish and manage reverse shell connections through a web-based graphical user interface. Its primary use case is for educational and research purposes in cybersecurity, featuring a lightweight server architecture, WebSocket interaction, and support for multiple terminal tabs within the GUI. Notable features include easy command generation for reverse shells, session management, and an emphasis on security practices through the use of certificates.
2026-08-03
Python
★ 10
OpenShiftGrapher is a tool designed to enumerate OpenShift clusters by creating relational databases in Neo4j from cluster data. Its primary use case is to extract and visualize objects and their relationships, such as projects, service accounts, and security configurations, facilitating the identification of inconsistencies that may indicate vulnerabilities. Key features include customizable data collection options and support for complex Neo4j queries to analyze the security posture of OpenShift environments.
2026-08-03
Go
★ 50
OriginipHunter is a Go-based tool designed to identify the origin IP addresses of domains by leveraging multiple security APIs, including Shodan and SecurityTrails. Its notable features include support for concurrent validations, parallel execution for improved performance, and customizable settings through a configuration file. The tool outputs results in various formats and allows users to easily manage API keys for different services, enhancing its flexibility in domain reconnaissance.
2026-08-03
Go
★ 11
ParamFinder is a tool designed for security assessment that crawls input and textarea tags on web pages to identify and manipulate parameters for testing vulnerabilities, particularly in the context of web applications. It allows the user to input single or multiple URLs, automatically generating modified URLs with specified parameters for ease of testing, while offering features such as concurrency options, output file configurations, and the ability to operate in silent or verbose modes. Notably, it facilitates the identification of potential security issues like XSS by transforming input parameters with preset values, ensuring a streamlined approach to parameter analysis.
2026-08-03
TypeScript
★ 28
Pentest Tool LITE is a command-line utility designed to assess websites for common vulnerabilities, enabling cybersecurity professionals to identify security flaws. Key features include the ability to filter tests by inclusion or exclusion, generate detailed reports in various formats, and perform targeted scans using sitemap integration. The tool supports detailed logging and offers flexibility in test execution through various command-line options.
2026-08-03
Dockerfile
★ 178
The pentesting-dockerfiles repository provides a collection of Dockerized tools designed for conducting security assessments. Its primary use case is to facilitate penetration testing by leveraging various security tools, including vulnerability scanners and exploitation frameworks, all encapsulated in lightweight containers to optimize efficiency. Notable features include a curated list of links to popular security tools and payloads, promoting seamless integration within pentesting workflows.
2026-08-03
★ 81
The Pentesting-Mind-Map repository offers a structured mind map that consolidates tools and methodologies essential for bug bounty hunting and penetration testing. It covers key phases such as reconnaissance, exploitation, and red teaming tactics, including automation tools and API testing, making it a valuable resource for professionals seeking to enhance their offensive security skills. Notably, it emphasizes the inclusion of OWASP guidelines for web application testing and provides detailed steps for each phase of the penetration testing lifecycle.
2026-08-03
Python
★ 22
Phantom Whisper is a Python 3 framework designed for ethical penetration testing, specifically targeting WhatsApp by delivering a zero-click WebP payload to identified devices. Its key features include ASLR leak polling to confirm initial compromise, automated deployment of a full implant for either iOS or Android, and thorough logging of all actions in JSON format for audit purposes. The tool is currently structured for single-host execution but is intended to support multi-threaded operations in future developments.
2026-08-03
C
★ 117
Packet Batch is a high-performance tool designed for generating and sending network packets, primarily used for penetration testing and network monitoring. Its notable features include the ability to send multiple packets with random source IPs and payloads, support for UDP, TCP, and ICMP, and optional checksum calculations to offload processing to the NIC. The tool also offers a version utilizing AF_XDP sockets for improved performance on recent Linux kernels.
2026-08-03
Rust
★ 17
Packet Batch is a high-performance toolset for generating network packets, designed primarily for penetration testing, benchmarking, and network monitoring. This Rust implementation offers enhanced safety and modern coding practices while maintaining fast performance through AF_XDP socket technology, highly configurable packet generation, real-time statistics display, and detailed logging capabilities. Users can execute multiple packet batches with various configurations via a command-line interface, although the project is still considered experimental and in early development stages.
2026-08-03
Go
★ 11
portmap is a high-speed port scanning tool that leverages Shodan's public data to identify open ports associated with specified IP addresses or CIDR ranges. Its primary use case is to quickly ascertain accessible services on remote hosts using Shodan's APIs, featuring commands for basic port scans and enhanced details retrieval, including ASNs and organization details. Notable functionalities include JSON output options, support for multiple IP inputs, and a user-friendly command-line interface.
2026-08-03
Python
★ 175
Preferred Network List Sniffer (PNLS) is a Red Team Wi-Fi auditing tool designed to capture SSIDs from a device's preferred network list by intercepting Probe Requests in the surrounding environment. The tool features a user-friendly web interface for visualizing the intercepted data and is focused on exploring the privacy implications associated with Wi-Fi communication. Noteworthy functionalities include compatibility with Raspberry Pi, the ability to filter SSIDs, and the provision for asynchronous server communication using WebSockets.
2026-08-03
Go
★ 21
pvreplace is a robust URL parameter and request fuzzing tool designed to enhance security assessments by processing URLs or Burp Suite raw requests, substituting values with custom payloads while preserving unique parameter combinations. Notable features include multiple fuzzing types (replace, prefix, postfix), various fuzzing modes (single, multiple), and the ability to target specific components such as parameter names, values, path segments, and headers. The tool facilitates a comprehensive fuzzing approach to identify vulnerabilities within web applications.
2026-08-03
Python
★ 28
rawsec_cli is a command-line interface tool designed to facilitate the search and categorization of cybersecurity-related projects, tools, resources, and platforms. It allows users to filter searches by various criteria including language and availability, and provides features to list categories and open project sources in a browser when only a single result is found. Notable features include command-line search capabilities, project categorization, and installation through multiple methods including Docker.
2026-08-03
Python
★ 493
RedDDoS Tool is a Python-based utility designed for conducting DDoS attacks to test the resilience of networks and servers, provided that proper authorization is obtained for ethical use. It supports major operating systems including Linux, Windows, and macOS, and features straightforward installation and usage instructions, along with troubleshooting tips for potential library issues. Notably, the tool emphasizes responsible usage, clearly stating that it is intended for educational purposes only.
2026-08-03
Batchfile
★ 246
Ixve/Red-Team-Tools is a comprehensive collection of cracked red teaming tools designed for penetration testing and security assessments, including C2 frameworks, exploitation toolkits, and web application security tools. Users are strongly advised to run these tools in a virtual machine environment due to potential malware risks. Notable features include a wide variety of tools for both Windows and Linux platforms, along with recommended online sandboxing solutions for safe testing.
2026-08-03
Ruby
★ 78
ronin-vulns is a Ruby library designed for blind vulnerability testing, specifically targeting various web application vulnerabilities such as Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL Injection (SQLi), reflective Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects. Its notable features include support for testing multiple parameter types (query parameters, HTTP headers, cookies, and form parameters), along with high documentation and test coverage metrics, making it a robust tool for security researchers and developers within the ronin-rb project framework.
2026-08-03
Rust
★ 18
`rusty_hack_browser_data` is a Rust-based tool designed for extracting and analyzing browser data, including passwords, cookies, bookmarks, and history from various web browsers on Windows. Its primary use case is for cybersecurity research, providing support for popular browsers like Firefox, Microsoft Edge, and Google Chrome, with functionality to assist in data recovery and forensic investigations. Notably, the tool emphasizes a legal disclaimer, placing responsibility for usage on the user.
2026-08-03
Shell
★ 94
ScanPro is a menu-driven tool that enhances the functionality of Nmap for network scanning purposes. Its primary use case involves simplifying the scanning process by allowing users to select target IPs, ports, and scan types through an interactive menu, while also facilitating service detection and output formatting. Notable features include support for NSE scripting and HTTP information gathering, making it a versatile utility for penetration testing and network analysis.
2026-08-03
Python
★ 25
scans2any is a tool designed to convert infrastructure scan outputs into various formats like Markdown, YAML, HTML, and CSV, while also facilitating the creation of launch scripts and configuration files for different scanners. Its primary use case focuses on merging and processing multiple scan results to enhance security assessments and reporting. Notable features include support for numerous input formats, conflict resolution options, and the ability to run in a Docker container for simplified deployment.
2026-08-03
Python
★ 68
SecretScraper is a configurable web scraping tool designed to extract sensitive information from target websites using customizable regular expressions. Its primary use case is for security assessments and vulnerability testing, featuring a robust web crawler that can handle multiple targets, support domain whitelisting and blacklisting, and enable seamless configurations through YAML files. Notable features include built-in rate limiting, an HTTP connection pool management, and flexibility in handling headers, proxies, and cookies.
2026-08-03
Python
★ 11
The Largo-m/security-tools-hacking is a modular Windows penetration testing framework designed for security professionals, facilitating various stages of red team operations such as reconnaissance, exploitation, and post-exploitation. Key features include system information collection, geolocation lookup, browser history extraction, and optional key logging, all presented in a user-friendly manner that allows for easy integration and extension of custom modules.
2026-08-03
TypeScript
★ 33
Slack-Slurp is a pentesting tool designed for post-exploitation in Slack environments, leveraging the Slack API to extract potentially sensitive information from messages by employing Trufflehog's secret detectors. Key features include robust secret detection across a wide range of commonly used services, support for authentication via user or bot tokens, and the ability to add custom detectors for tailored searches. This tool is particularly useful for security professionals looking to identify exposed credentials and sensitive data within Slack channels.
2026-08-03
Python
★ 16
Sniff-NG is a Python-based tool designed for network security assessment, specifically offering capabilities for local network scanning, ARP spoofing, and man-in-the-middle (MITM) attacks through an interactive text user interface (TUI). Key features include automatic gateway detection, a user-friendly menu for executing attacks, and one-click dependency installation for Linux and macOS systems. Its design emphasizes ease of use for ethical hacking and penetration testing, while ensuring the restoration of ARP tables post-attack.
2026-08-03
Go
★ 17
SocialFinder is an efficient username enumeration tool built in Go, designed to verify the availability of usernames across multiple social media platforms and websites. It offers real-time output, customizable URL lists, and smart matching for URL variations, allowing for rapid enumeration with clear, colored terminal results. The tool is optimized for performance using httpx, and it supports options like inclusion of NSFW sites and silent mode for discreet checks.
2026-08-03
Python
★ 381
SQLMC (SQL Injection Massive Checker) is a specialized tool designed to identify SQL injection vulnerabilities on a target domain by crawling provided URLs to a specified depth. It checks all GET parameters for potential vulnerabilities and offers detailed reports that include server information. Key features include customizable depth scanning, comprehensive vulnerability detection, and output file options for results storage, making it a robust solution for security assessments in web applications.
2026-08-03
Python
★ 44
SquidNet is a Python-based botnet framework designed for educational and ethical testing, enabling users to establish communication with a remote victim, issue commands, and execute various modules. Notable features include multi-session handling, a reverse shell, modular design for extensibility, dynamic module loading, and encryption for evading detection. The tool supports Docker deployment and operates entirely in memory, minimizing the risk of detection on target systems.
2026-08-03
Python
★ 13
SSHBuster is a command-line utility designed for ethical hacking and penetration testing that facilitates SSH brute-force attacks through dictionary-based methods. It supports various combinations of username and password wordlists, operates in a multithreaded manner for enhanced speed, and displays real-time progress alongside immediate feedback for valid credentials found.
2026-08-03
Go
★ 68
subdog is a comprehensive subdomain enumeration tool designed to aggregate subdomains from over 17 different data sources, providing cybersecurity professionals with extensive lists of root subdomains. Notable features include parallel processing for expedited results, output options for saving to files while displaying terminal output, and automatic duplicate removal along with normalization to filter unwanted entries. By supporting external tools and allowing flexible source selection, subdog enhances the efficiency and effectiveness of subdomain discovery tasks.
2026-08-03
Python
★ 17
SYSTEMatic is a proof-of-concept tool designed for Windows that enables privilege escalation from a local Administrator account to the NT AUTHORITY\SYSTEM account via token impersonation, without UAC prompts or external dependencies. It leverages the Win32 API to duplicate a SYSTEM process's token and spawn new processes, making it valuable for system administration, security research, and penetration testing tasks. Notably, it operates solely within the constraints of existing Administrator privileges and does not exploit vulnerabilities or function as a UAC bypass.
2026-08-03
Python
★ 170
TireFire is a semi-automatic enumeration platform designed for penetration testing, leveraging HackTricks resources for real-time updates and command execution. It enables users to initiate and control scans, effectively managing their footprint while generating organized lists of results, which is particularly beneficial for training environments and professional assessments. Notable features include support for multiple terminal interfaces like Tmux and Tilix, allowing for flexible and streamlined scan management.
2026-08-03
Go
★ 35
tldscan is a high-performance domain scanner designed to identify active domains by testing various Top-Level Domains (TLDs) against user-specified domain names. It features customizable concurrency levels, wordlist options for domain generation, and the ability to output results to a specified file, making it suitable for domain reconnaissance tasks in cybersecurity. Notably, users can choose between small and large wordlists and utilize silent or verbose modes for streamlined operation or detailed debugging.
2026-08-03
Python
★ 258
TraxOsint is an open-source OSINT tool designed for gathering comprehensive information on IP addresses using various APIs and services for accurate data comparison. Its notable features include asynchronous scraping, capabilities for checking IP validity, open port status, and geographical information generation, along with integration with services like Pastebin and ProtonVPN. The tool also provides a command-line interface for user interaction and outputs detailed IP-related data, including geographical mapping.
2026-08-03
Go
★ 168
Turbo-attack is a pentesting tool designed to generate random network traffic with variable MAC and IP addresses, enhancing testing capabilities for network resilience against traffic-based attacks. It supports both IPv4 and IPv6 on various Linux architectures (ARM64 and AMD64), and is optimized for environments such as Kali Linux using native syscalls for improved performance. This tool is intended for educational use and emphasizes responsible usage to prevent unauthorized access to networks.
2026-08-03
Go
★ 17
unew is a high-performance command-line utility designed for efficiently processing and managing unique lines from input streams, offering functionalities similar to `sort`, `uniq`, and `tee`. Its primary use case is deduplication and data organization, featuring advanced capabilities such as case-insensitive processing, file splitting, shuffling, and the ability to append new unique lines to existing files. Benchmarked against similar tools, unew demonstrates superior speed and memory efficiency, making it suitable for handling large datasets.
2026-08-03
Go
★ 66
The Venera Framework is a Lua-based tool designed for automating customizable tests and attacks across various protocols. Its primary use case lies in vulnerability scanning and exploitation, allowing users to create and manage scripts that target specific vulnerabilities or conduct general verification tasks. Notable features include a built-in package manager, the ability to import and export scripts, and a flexible scripting environment that supports user-defined modules for tailored security testing.
2026-08-03
JavaScript
★ 30
Vulnshop is a deliberately insecure e-commerce web application designed for security training and penetration testing practice, featuring over 40 embedded vulnerabilities across various categories of web application security. Built on Node.js, it simulates a modern online shopping platform with functionalities like user authentication, product management, and an administrative dashboard, allowing users to practice real-world exploitation scenarios in a controlled environment. The tool facilitates educational engagement with critical security concepts, but should only be used in isolated setups to prevent exploitation in production contexts.
2026-08-03
Go
★ 20
vulntechfinder is an automated vulnerability scanning tool that utilizes technology stack detection to execute targeted scans using tools like Nuclei and httpx. It supports features such as automated tech stack identification, configurable parallel processing, smart filtering for technology inclusion, and crash-safe resume capabilities, making it versatile for various scanning needs. The tool is compatible with any security tool that accepts technology tags, thereby enhancing its utility in security assessments.
2026-08-03
Go
★ 13
WaybackURLsX is a Go-based tool designed to extract archived URLs from the Wayback Machine, emphasizing performance and user-configurable features. It offers smart filtering for sensitive files, adaptive rate limiting to comply with Wayback Machine constraints, and automatic retry mechanisms with exponential backoff for robust error handling. Notable features include detailed logging, support for domain-specific searches, and the capability to filter results based on custom regex patterns.
2026-08-03
Vue
★ 738
Weakpass is a comprehensive password and hash cracking toolkit that consolidates several tools for penetration testing and security assessments. It features a password generator (Passgen), a secure hash lookup tool (Lookup), and a password compromise checker (Passcheck), allowing users to generate targeted wordlists, perform client-side hash lookups without data exposure, and assess password vulnerabilities through rule-based simulations. Notably, it includes precomputed hash data and can be hosted locally for enhanced security and performance.
2026-08-03
Python
★ 46
WebCap is a lightweight web screenshot tool that captures fully-rendered DOMs and detailed HTTP request/response logs without the need for browser automation frameworks. Its primary use case is to provide comprehensive insights into web pages, with unique features including JSON output, JavaScript extraction, and OCR text extraction. Users can operate it via a command line interface or a web server, allowing for automated scanning of multiple URLs and capturing of detailed web elements efficiently.
2026-08-03
Python
★ 14
whomrx-dosX is a DDOS tool designed to flood a target server with packets until it becomes unresponsive. It requires a simple installation process and allows users to specify target IP addresses and packet configurations through command-line parameters. Notable features include the ability to set the port and number of packets sent, making it an educational resource for understanding network stress testing.
2026-08-03
PowerShell
★ 601
WiFi Password Stealer is a cybersecurity tool designed to extract WiFi credentials from target computers using keystroke injection techniques via a USB device, specifically leveraging a Raspberry Pi Pico configured as a Rubber Ducky. The tool facilitates information exfiltration through customized payloads, allowing stolen data to be sent over email or stored on a USB drive. It demonstrates advanced attack vectors, including both Rubber Ducky and Bash Bunny methods, while emphasizing the importance of physical access to the target system.
2026-08-03
Rust
★ 21
wifikit is a WiFi pentesting toolkit designed for macOS, implemented in pure Rust without the need for kernel extensions or virtual machines. It enables comprehensive wireless network penetration testing through features like channel scanning, multiple attack engines (including PMKID extraction and WPS PIN cracking), and packet capturing, all accessible via an intuitive terminal user interface. The tool is specifically tailored for Apple Silicon and directly interacts with USB WiFi chipsets, providing a unique solution for native macOS penetration testing.
2026-08-03
Rust
★ 78
Windfire is a high-performance, Rust-based tool designed for URL liveness detection, enabling fast and lightweight asset availability checks for domains, IPs, and URLs. Its notable features include support for HTTP/SOCKS proxies, HTTP status code filtering, customizable paths, and the ability to choose between liveness-only and full fingerprinting scan modes, all while maintaining high concurrency and asynchronous execution. Additionally, users can control the scan rate and export results in CSV or JSON formats.
2026-08-03
Python
★ 16
XMLRPC-Bruteforce is a specialized penetration testing tool designed for exploiting the XML-RPC functionality in WordPress, allowing users to conduct hyper-optimized brute force attacks. By employing a unique batch method capable of testing 50-100 passwords per request and utilizing a binary search algorithm for credential discovery, it offers significant speed improvements over traditional brute force methods. Notable features include smart detection of web application firewalls, real-time statistics tracking, and a user-friendly interface with color-coded outputs and progress visualizations.
2026-08-03
★ 246
The Offensive AI Agentic Landscape project is a comprehensive catalog of resources focused on AI-driven penetration testing and autonomous red-team agents. It offers an extensive compilation of open-source projects, specialized models, skills, MCP servers, academic papers, benchmarks, and commercial solutions, providing researchers and security professionals with a holistic view of the offensive AI domain. Key features include a curated list of popular agents and tools, with a focus on leveraging AI for offensive security operations.
2026-08-03
PHP
★ 372
The "Awesome Security Skills" repository offers a curated collection of security testing resources in the form of agent skills for use with various AI agents. Its primary use case is to provide security professionals with immediate access to essential tools such as wordlists, payloads, and patterns for tasks like penetration testing, bug bounty research, and educational demonstrations. Notable features include integration with over 60 supported agents, organized categories for diverse security tasks, and comprehensive LLM security testing methodologies.
2026-08-03
Python
★ 95
BeaconatorC2 is a modular communication and management application designed to facilitate the deployment and operation of beacons in restrictive programming environments, particularly for EDR evasion tactics. The tool supports various beacon implementations and allows users to quickly configure receivers, execute commands, and integrate with Metasploit for enhanced capabilities. Notable features include a user-friendly GUI, support for multiple communication protocols, and extensibility through custom beacon schemas.
2026-08-03
Python
★ 12
BugBounty Arsenal is a comprehensive, full-stack security scanning platform designed for bug bounty hunters and security researchers. It features over 50 detectors for various vulnerabilities across multiple categories, continuous monitoring with scheduled scans, findings triage to manage results over time, and CI/CD integration to automate security checks in development pipelines. Unique capabilities include attack surface management, tailored AI-driven remediation advice, and extensive reporting options, all from a centralized dashboard.
2026-08-03
Python
★ 13
BurpRecon is a cybersecurity tool designed for bug bounty hunters, facilitating the extraction and analysis of attack surface intelligence from Burp Suite XML exports. It automates identification of high-value vulnerability candidates such as IDORs, Host Header Injections, and Privilege Escalation vectors through a multi-phase analysis, while also performing technology fingerprinting and CVE lookups—all through a single interactive command-line interface. Notable features include detailed scoring for various vulnerabilities, ready-to-run proof-of-concept generation, and support for passive subdomain enumeration.
2026-08-03
Shell
★ 40
CamHawk is an advanced camera phishing tool designed for security research and penetration testing that simulates an attack by tricking users into granting webcam access. Once access is obtained, it captures images in real-time and sends them to the attacker's machine, offering features like automated dependency installation, multiple tunneling options, and a customizable phishing page. This tool serves as a valuable resource for developers and cybersecurity professionals to understand and mitigate risks associated with webcam exploitation.
2026-08-03
Python
★ 29
CertCrunchy is a reconnaissance tool designed to leverage SSL certificate data from online sources to identify potential hostnames. It allows users to retrieve SSL data for specific domains or an IP range, with notable features including multi-threading for faster queries, output customization in CSV or JSON format, and integration with various APIs, such as Censys and VirusTotal.
2026-08-03
Go
★ 10
Cokmap is a high-speed network scanner developed in Go that detects services and products on open ports using probes formatted according to the nmap-service-probes schema. Notable features include rapid product detection through a plugin architecture, support for flexible configuration, and the ability to generate detailed statistics. It is compatible with both Linux and macOS systems and offers a straightforward command-line interface for input and output handling.
2026-08-03
C
★ 388
COM-Hunter is a COM hijacking persistence tool designed for both educational purposes and red teaming applications, offering functionality in .NET and as a Cobalt Strike compatible BOF variant. Its notable features include multiple modes for establishing or removing COM hijacking persistence mechanisms, such as searching for CLSIDs, executing classic persistence, and utilizing Task Scheduler. This versatile tool assists security professionals in simulating advanced persistence techniques within Windows environments.
2026-08-03
Python
★ 497
Transilience AI Community Tools offers an AI-driven penetration testing suite comprised of 26 skills and 3 tool integrations, facilitating a comprehensive approach to security testing from reconnaissance to reporting. Notable features include full OWASP coverage, intelligent automation through Claude for workflow coordination, and the ability to generate professional, detailed reports leveraging common standards like CVSS and MITRE ATT&CK. The toolset is designed for both commercial and personal use as an open-source solution, enhancing the efficacy of security assessments.
2026-08-03
Go
★ 341
Crawley is a web crawling tool that efficiently parses HTML pages to discover and print links, including resources like images, audio, and video. It features a fast SAX-parser, customizable scan depth, compliance with `robots.txt`, support for subdomain crawling, and options for ignoring certain URLs or scanning specific tags. Additionally, Crawley allows for the use of user-defined cookies and headers, making it adaptable for various crawling scenarios.
2026-08-03
Python
★ 153
This tool exploits the Remote Code Execution vulnerability (CVE-2021-3129) found in specific Laravel versions, enabling users to execute commands on vulnerable instances with "APP_DEBUG" set to true. Key features include the ability to write and execute commands remotely, as well as several patch options to secure the application against the exploit. The tool is intended for educational and research purposes, emphasizing the importance of responsible usage.
2026-08-03
C++
★ 14
Dark Nexus is a modular and multi-threaded C++17 framework designed for comprehensive network reconnaissance and infrastructure analysis. It consolidates various tools into a single executable, offering powerful features including subdomain scanning, OSINT gathering, and advanced asset mapping through a user-friendly hybrid CLI. Its aggressive multi-threading capabilities and intuitive architecture ensure efficient operations across 12 distinct modules, catering to a wide range of reconnaissance needs without the burden of complex setups.
2026-08-03
Go
★ 24
DirRunner is a Go-based command-line tool designed for DNS enumeration, directory discovery, virtual host identification, FUZZ payload testing, and basic HTTP fingerprinting. With features such as worker pools for concurrent processing, streaming result output, and customizable HTTP requests via command-line flags, it is optimized for performance and flexibility without relying on third-party dependencies. The tool supports multiple modules for specific tasks and offers options for JSON output, deterministic exports, and the ability to route traffic through Tor for added anonymity.
2026-08-03
Java
★ 39
EgnakeRAT is an advanced remote administration tool (RAT) designed for authorized penetration testing and red team operations on Android devices. It features a fully asynchronous command and control (C2) server utilizing AES-256-CBC encryption for secure communications, along with a real-time web dashboard for device management and various tactical modules such as remote shell access and keylogging. Its use of a length-prefixed JSON protocol and automatic reconnection handling enhances its performance and user experience, making it a robust solution for security researchers.
2026-08-03
Go
★ 35
emailextractor is a high-speed email scraping tool developed in Go that enables concurrent crawling of websites to extract email addresses for purposes such as reconnaissance and sales intelligence. Key features include fast concurrent processing, fallback to headless Chrome for JavaScript-rendered content, smart URL normalization, and optional JSON output for easy integration.
2026-08-03
PowerShell
★ 501
EntraFalcon is a PowerShell-based assessment tool that helps pentesters, security analysts, and system administrators evaluate the security posture of Microsoft Entra ID environments. It performs over 80 automated checks to identify weak configurations and risky assignments, such as excess permissions on privileged accounts and improper Conditional Access policies, and presents findings in interactive HTML reports for detailed analysis. The tool is easy to use across platforms, requiring no additional modules and offering built-in authentication to streamline deployment.
2026-08-03
PowerShell
★ 141
The "exchange-penetration-testing" tool provides a comprehensive framework for performing penetration tests on Microsoft Exchange servers. It facilitates reconnaissance, brute-force attacks, and exploitation of vulnerabilities such as ProxyLogon and ProxyShell, alongside automated enumeration of the Global Address List (GAL). Notable features include the ability to conduct password spraying and provide access to critical vulnerabilities, enabling security professionals to assess and strengthen Exchange server defenses effectively.
2026-08-03
C
★ 11
ExploitHawk is a terminal-based exploit search tool tailored for ethical hacking and red team operations on Linux distributions. It offers features such as fast multi-threaded searches through local databases, customizable name and version querying, a user-friendly ncurses interface, and clipboard integration for easy result management. The tool is primarily designed to enhance safe testing for users with permissions on systems while requiring a local copy of Exploit-DB for functionality.
2026-08-03
JavaScript
★ 144
FastDork is a Chrome extension designed to enhance the efficiency of dork research and result scraping by allowing users to run multiple dork queries in batches, scrape results, and manage data through reusable lists. Notable features include custom site configurations using CSS selectors, automatic result importation, and support for generating searches across multiple tabs, significantly streamlining the workflow for security researchers and pentesters.
2026-08-03
Python
★ 14
Gamal is a lightweight Flask application designed for red teamers and pentesters, facilitating mass data exfiltration and various attacks such as SSRF, XXE, and XSS. It features file delivery capabilities, where users can upload and categorize payloads for exploitation, and includes a helper script that automates the download of common penetration testing tools. The tool supports features like customizable logging, SSL configuration, and can handle uploads while associating files with user and host identifiers for better tracking.
2026-08-03
Python
★ 27
GhostBuilder is a multifunctional payload generation tool that enables the creation of payloads for various platforms, including Android, Windows, Linux, macOS, and iOS, utilizing Metasploit. It features capabilities such as injecting payloads into existing APK files, automatic signing, zipaligning for APKs, and a simple menu-driven interface for ease of use. Designed for ethical hacking and penetration testing, it incorporates automatic handling of dependencies and bad characters, making it suitable for security research and authorized security work.
2026-08-03
Go
★ 10
Gitar is a sophisticated Python-based HTTP server designed for simple and efficient file exchange during penetration tests and capture the flag (CTF) competitions. It enables users to quickly upload and download files and directories to and from a target machine without requiring installation, while also offering features such as HTTP webhook logging and secure container deployment options. Notable functionalities include minimal command shortcuts for file transfers and additional modes for logging and secure sending.
2026-08-03
Go
★ 19
gosqli is a specialized tool designed for the rapid and accurate detection of blind SQL injection vulnerabilities using time-based techniques. It can scan both URLs and HTTP request files with user-defined payloads, ensuring zero false positives through sequential testing and real-time verification of results. Notable features include automatic exploitation integration with tools like sqlmap, configurable output options, and support for proxy routing, making it suitable for comprehensive security assessments.
2026-08-03
Go
★ 10334
httpx is a versatile and high-performance HTTP toolkit designed for probing web services effectively. Its primary use case focuses on conducting a variety of HTTP-based checks such as status codes, content length, and various headers, equipped with features like smart fallback from HTTPS to HTTP, multi-threading, and error handling for WAFs. With a modular code base and customizable flags, httpx allows users to efficiently gather information from URLs, IPs, or CIDR networks while automatically managing retries and backoff strategies.
2026-08-03
JavaScript
★ 18
JSpider is an advanced JavaScript-based crawler and endpoint discovery tool designed for security researchers, facilitating the extraction of hidden API routes, sensitive parameters, and hardcoded secrets directly from websites. Notable features include automated checks for over 500 critical paths, parameter discovery, recursive crawling, high-fidelity secret detection for 40 patterns, and seamless authentication header handling to access secured endpoints. The tool operates entirely client-side, offering real-time tracking and analysis of extracted data in a straightforward dashboard.
2026-08-03
★ 101
Kali-pentest is a sophisticated penetration testing tool designed for AI agents, leveraging Kali Linux and enabling autonomous attack planning and execution. It consolidates 269 command-line tools across various categories, features built-in coverage matrices, and employs zero-findings fallbacks along with human approval gates for high-risk actions, ensuring comprehensive and ethical testing processes. By connecting to environments via SSH or Docker, this tool adapts its strategies based on target assessments and generates structured reports for clarity and compliance.
2026-08-03
Python
★ 14
ldapviewer is a tool designed for converting LDAP and Active Directory JSON exports into a modern, interactive web-based interface that enhances the penetration testing process. It features comprehensive views of LDAP attributes, an advanced filtering system for significant data, a statistics dashboard focusing on security metrics, and the ability to parse DACLs directly from JSON dumps, streamlining the analysis of potential attack paths without requiring additional queries.
2026-08-03
Go
★ 17
LLMrecon is an advanced security testing framework specifically designed to identify and exploit vulnerabilities in Large Language Models (LLMs), adhering to the OWASP Top 10 2025 guidelines. It features a variety of novel attack techniques such as FlipAttack and DrAttack, along with machine learning-optimized attack selection, comprehensive defense detection capabilities, and support for testing models from multiple platforms, making it suitable for enterprise-level deployment.
2026-08-03
Shell
★ 38
Medusa is a Bash-based orchestration toolkit designed to deploy and manage 35 open-source cybersecurity tools through an interactive menu or command line interface. Its primary use case encompasses environments for Security Operations Center (SOC), Governance, Risk Management, and Compliance (GRC), among others, with notable features such as environment isolation via Docker, pure Bash execution without runtime dependencies, and the ability to run each tool in its own dedicated directory.
2026-08-03
Python
★ 92
The Mobile Pentest Toolkit (MPT) is an integrated solution designed for automating and streamlining Android penetration testing workflows, enabling users to conduct comprehensive security assessments without needing to manually manage individual tools. Notable features include a full suite of required tools for security checks, local tool installation, support for ADB, the ability to disable SSL pinning and root detection, and project-based assessments that provide a cohesive interface for launching various security tools efficiently.
2026-08-03
Python
★ 36
The Neo C2 Framework is a modular post-exploitation framework designed for red team operations and security testing, facilitating collaborative agent management through a server-client architecture. It features real-time multiplayer capabilities, proxy support, a sophisticated task orchestrator, and robust security measures including encrypted communication and role-based access control. Neo also allows for extensive customization through its multi-operator extension module system, enabling operators to integrate their own modules seamlessly.
2026-08-03
Dockerfile
★ 315
Nightingale is a comprehensive Docker toolkit designed for penetration testing and security research, providing a reproducible multi-architecture environment with curated tools for various workflows, including web, network, mobile, and OSINT. Notable features include a browser-based terminal for easy access, community-driven tool enhancements, and integration with security-focused CI tools like Trivy. The project facilitates rapid setup and customization, allowing users to tailor the environment to specific testing needs or internal usage.
2026-08-03
Nix
★ 407
The Nix Security Box is a curated collection of penetration testing and information security tools specifically designed for NixOS environments. It emphasizes a practical selection of actively maintained tools, combining both established and innovative options for security assessments, while allowing users to customize their toolset via Nix configuration files or shell environments. Notable features include modular imports for specific categories of tools and the ability to seamlessly create tailored development environments with desired functionalities.
2026-08-03
TypeScript
★ 180
Open Attack Surface Management (OASM) is an AI-powered, open-source platform designed to discover, monitor, and secure digital infrastructures by providing continuous asset visibility and vulnerability assessments. Notable features include automated asset discovery, a distributed scanning engine for high scalability, real-time monitoring with alert integration, and support for AI assistants to enhance data analysis and querying capabilities. The tool streamlines security workflows and risk management through customizable scanning configurations and comprehensive reporting functionalities.
2026-08-03
Markdown
★ 23
Pentester is an AI-driven penetration testing workflow tool designed to facilitate the systematic execution of security assessments in compliance with the PTES framework. It employs a series of predefined phases that ensures structured data outputs, including validated vulnerabilities and comprehensive client reports, while leveraging agents that can be instructed in multiple languages for accurate task execution and management of complex assessments. Notable features include a modular skill system for phase management, adherence to authorization and scope protocols, and the integration of various testing tools through Docker support.
2026-08-03
Go
★ 38
PentLog is an evidence-first pentest logging tool designed to capture high-fidelity terminal output during penetration testing engagements. Its primary use case includes providing searchable logs, compliance-ready reports, and interactive timelines for real-world auditing and engagements such as OSCP and HackTheBox. Notable features include automatic organization of commands, AI analysis for summarization, real-time session sharing, and AES-256 encryption for secure archives, addressing the common challenges faced in traditional logging methods.
2026-08-03
Python
★ 164
ProfileHound is a post-escalation tool designed for red-teaming operations that identifies domain user profiles on machines to optimize targeting for data extraction. It utilizes BloodHound's OpenGraph format to create a new edge, `HasUserProfile`, which indicates the existence of user profiles and provides metadata such as creation and modification dates, enabling operators to focus on high-value targets without requiring an active user session. The tool highlights profiles that may contain critical information, including cached credentials and other sensitive data, making it particularly useful in contemporary Active Directory environments.
2026-08-03
Go
★ 168
QueenSono is a Golang package designed for data exfiltration utilizing the ICMP protocol for both IPv4 and IPv6. Its primary use case is to bypass network monitoring systems that do not actively inspect ICMP traffic, making it effective in environments with limited oversight, such as public Wi-Fi networks. Notable features include the ability to send and receive files using ICMP packets, and its implementation of acknowledgment mechanisms to confirm data reception.
2026-08-03
Shell
★ 8039
**reconFTW** is an automated reconnaissance tool aimed at security researchers and penetration testers, streamlining the information-gathering process. It integrates a variety of scanning and enumeration techniques, allowing users to gather extensive details on target domains through an intuitive interface. Notable features include support for multiple platforms, Docker compatibility, and an array of built-in reconnaissance modules that enhance operational efficiency.
2026-08-03
Python
★ 122
RedTeam Agent is an autonomous AI-powered simulation tool designed for red teaming and penetration testing, streamlining the process of security assessments across multi-platform environments. It features 8 specialized AI agents that facilitate a comprehensive 5-phase attack methodology, alongside containerized Kali tools and a web-based GUI for managing projects and operations with minimal user interaction. Notable functionalities include an intelligent case collection pipeline and robust reporting mechanisms, allowing users to efficiently conduct security evaluations and automate repetitive tasks.
2026-08-03
PowerShell
★ 56
RTI-Toolkit is an open-source PowerShell toolkit designed for executing and defending against Remote Template Injection (RTI) attacks in Microsoft Office documents, specifically DOCX files. It features key cmdlets such as `Invoke-Template` and `Invoke-Regular`, which facilitate the implementation of malicious remote template links, while `Invoke-Identify` assists in detecting such links, positioning the toolkit as both an offensive and defensive resource in the cybersecurity landscape. Notably, the tool is referenced in the NIST National Vulnerability Database under multiple CVEs, underscoring its significance in addressing this type of vulnerability.
2026-08-03
Shell
★ 571
The Samurai Web Training Framework (SamuraiWTF) is a virtual machine framework designed for quickly setting up training environments containing various security tools and intentionally vulnerable applications. Its primary use case is to facilitate cybersecurity training by enabling instructors to create and distribute configured virtual machine images, using tools such as OWASP ZAP and Juice Shop. Notable features include integration with the Samurai Katana project for streamlined tool management and support for deployment on platforms like VirtualBox and Hyper-V.
2026-08-03
Python
★ 571
Sippts is a comprehensive suite of tools designed for auditing VoIP servers and devices utilizing the SIP protocol, allowing security professionals to assess vulnerabilities within their own systems or those they are authorized to test. Key features include a fast SIP scanner, options for enumerating SIP extensions, capabilities for password cracking and message sending, as well as exploit functionalities for specific vulnerabilities like SIP Digest Leak. The tool is written in Python and is freely available for modification and distribution.
2026-08-03
PowerShell
★ 150
SnafflerParser is a parsing tool designed to process the output from Snaffler, generating user-friendly reports in various formats (TXT, CSV, HTML, JSON) for easier analysis of large datasets. Key features include interactive HTML reports with filtering, dynamic sorting, keyword highlighting, review workflows, and pagination, along with the ability to export processed results and maintain state between sessions. The tool enhances visibility and manageability of Snaffler output, making it suitable for large environment assessments.
2026-08-03
Python
★ 13
SpectreWeb AI is an advanced MCP server facilitating AI-assisted manual web penetration testing, which enables operators to leverage AI tools for reconnaissance, payload generation, and response analysis while maintaining direct control over testing strategies. Its notable features include context-aware payload creation, built-in WAF bypass capabilities, and session persistence for findings across multiple targets. This tool is designed to overcome challenges presented by traditional blind scanning techniques, optimizing the testing process for bug bounty hunters and security professionals.
2026-08-03
Go
★ 33
Tacos is a tool designed to facilitate the creation of interactive reverse shells with minimal prerequisites, specifically targeting environments lacking the socat utility. It leverages containerization for easy deployment while offering advanced configuration options, automatic detecting of default shells, and a built-in multi-handler listener feature. Notably, Tacos allows users to obfuscate connections and easily expose listeners to the internet, enhancing accessibility and stealth during penetration testing activities.
2026-08-03
Go
★ 13
Techfinder is a high-performance technology detection tool developed in Go, designed to identify web technologies and frameworks—including dynamically loaded JavaScript frameworks—using a headless browser with a reusable browser pool for enhanced scanning speeds. It features multi-threaded processing, various output formats (plain text, JSON, CSV), Discord integration for real-time alerts, and robust configuration options for large-scale scans. Key capabilities include a fast static detection mode, crash-safe resume functionality, and automated downloading of necessary fingerprint data on first use.
2026-08-03
Python
★ 60
Temodar Agent is an AI-powered security analysis platform specifically designed for WordPress plugins and themes, offering security researchers an efficient mechanism for vulnerability assessment. Key features include risk-based target prioritization, Semgrep-powered static analysis, and AI-assisted investigation workflows that maintain context throughout the review process. Built as a local-first Docker application, it supports multi-provider LLM orchestration and facilitates structured code reviews to enhance vulnerability triage.
2026-08-03
Go
★ 152
WordList is a comprehensive tool for generating custom wordlists intended for web application fuzzing and reconnaissance tasks. It supports the creation of various specialized wordlists, including those for DNS enumeration, default credentials, and parameters extracted from URLs, while also offering integrations for use with the Nuclei vulnerability scanner. Notable features include the ability to aggregate wordlists from multiple sources, classifies output by size, and efficiently prepares tailored wordlists based on specific URL patterns and application technologies.
2026-08-03
JavaScript
★ 52
JWT Security Checker is a comprehensive web-based platform designed for testing and analyzing JSON Web Token (JWT) security, aimed at penetration testers, security researchers, and developers. Key features include real-time JWT decoding and encoding, signature verification, a built-in dictionary for brute-forcing weak secrets, automated vulnerability scanning, and integration with various pentesting tools. The tool provides a modern user interface with support for multiple themes and real-time updates, enhancing the overall user experience during security assessments.
2026-08-03
Go
★ 55
XSSRecon is an automated tool designed for the discovery of reflected XSS vulnerabilities in web applications by testing URL parameters for reflection of a specified payload. It features a dual detection method for assessing input reflection in both HTTP responses and DOM, as well as support for concurrent processing and customizable testing of special characters. Additional capabilities include smart optimizations for testing efficiency, flexible output formats, and integration with external tools like `pvreplace` for precise parameter injection.
2026-08-03
Python
★ 176
Zypheron CLI is an AI-native command-line interface designed for offensive security operations, offering integrated workflows for reconnaissance, scanning, and task automation. Notable features include a Go-based CLI, AI model integration from both local and hosted sources, and robust local storage for session data, making it suitable for authorized security testing and operator workflows. This open-source tool emphasizes terminal agility, maintaining practicality over disconnected scripts or raw outputs.
2026-08-03
TypeScript
★ 15
ABSpider Recon is a web reconnaissance tool designed for authorized passive intelligence gathering and active vulnerability assessments, targeted primarily at bug bounty hunters, security engineers, and auditors. It features a unified dashboard and command-line interface (CLI) that simplifies key reconnaissance tasks, including DNS lookups, port scans, and payload checks into a streamlined workflow. Notably, it offers a live demo environment and can be run locally via npm, making it accessible for both professionals and educational purposes.
2026-08-03
Python
★ 103
ADPathFinder is a specialized attack mapping tool designed for penetration testers and red teamers, enabling the analysis of SharpHound data in conjunction with OpenGraph plugins to identify potential attack pathways to critical targets within Active Directory (AD) environments. It supports a variety of data sources, including MSSQLHound and ConfigManBearPig, facilitating comprehensive audits across AD, Active Directory Certificate Services (ADCS), System Center Configuration Manager (SCCM), and SQL Server. Notable features include the ability to map escalation paths, detect weak passwords, and generate detailed reports on vulnerabilities within the network.
2026-08-03
JavaScript
★ 482
AIDA is an AI-driven autonomous pentesting agent designed for comprehensive security assessments of web applications, APIs, and infrastructure. It utilizes large language models to reason and understand application logic, execute commands in an isolated environment, and systematically document findings. Notable features include a fully equipped Docker execution environment with essential pentesting tools, on-the-fly Python script generation for custom exploitations, sophisticated HTTP request manipulation, and persistent logging for detailed results.
2026-08-03
Python
★ 16
AndroidManifestExplorer is a high-performance static analysis tool designed to automate the identification of attack surfaces in Android applications by examining decompiled `AndroidManifest.xml` files. Its primary use case is to uncover security vulnerabilities, including exposed app components, dangerous permission usage, and configuration risks while generating actionable ADB payloads for dynamic verification. Notable features include implicit export detection, deep link analysis, MIME-type intent detection, and comprehensive JSON output for integration into security pipelines.
2026-08-03
TypeScript
★ 10
A2P (Architect-to-Product) is an AI engineering framework that serves as a middleware component (MCP server) aimed at converting AI-generated code into production-ready software with rigorous verification processes. The tool enforces systems engineering principles through evidence-gated methodologies, ensuring that each development phase—requirements, tests, and deployment—includes substantiated evidence, thereby addressing common gaps in AI coding outputs. Notable features include a transition from v1 to v2, which integrates comprehensive systems engineering concerns, alongside a strict verification layer that transforms AI agents' self-reports into machine-checkable validations.
2026-08-03
Go
★ 14
Arsenic is a tool designed to establish standard conventions for organizing penetration testing data, primarily focusing on directory structures and file naming conventions. Its notable features include the ability to create custom operation setups, a dedicated structure for storing host information and reconnaissance data, and integration capabilities with other tools like arsenic-hugo to enhance the offensive operations process. Arsenic aims to streamline and augment the workflow of penetration testers by making data management more systematic and enjoyable.
2026-08-03
Shell
★ 17
autoDeploy is a Bash script designed for customizing Kali Linux by automating the installation of various plugins, applications, and utilities to enhance the user environment. It offers three installation modes: a complete setup, terminal and desktop customization, and installation of third-party applications, with automated error logging for troubleshooting. This tool streamlines the setup process, making it easier for users to tailor their Kali Linux experience.
2026-08-03
Python
★ 21
The "Awesome Hacking with AI" repository is a comprehensive resource that explores the integration of Artificial Intelligence in offensive security practices, such as penetration testing and red teaming. It features a curated collection of AI-driven tools, methodologies, and case studies while emphasizing ethical considerations in their application. Notable features include a learning roadmap, prompt libraries for various tasks (e.g., payload generation and OSINT profiling), and advanced tactics like AI-powered malware development and botnet exploitation.
2026-08-03
Python
★ 165
Beetle is an offline-first Application Security Intelligence Platform designed for the analysis of Android APKs and iOS IPAs, including those built with Flutter and React Native. It integrates static analysis with a focus on creating explainable workflows that correlate isolated findings into realistic attack chains, facilitating better understanding of vulnerabilities with evidence-based insights. Key features include low false-positive rates, source navigation for precise findings, and optional AI assistance for reasoning about security issues, all while maintaining data security by performing analysis locally.
2026-08-03
Shell
★ 32
bf_active_sub is a subdomain enumeration tool designed for active scanning through brute-force techniques. It efficiently verifies the existence of subdomains by attempting various combinations from a provided wordlist, ensuring zero false positives, and allowing results to be outputted directly in the terminal or saved to a file. Notable features include support for various wordlist sizes and compatibility with Debian-based systems, making it a valuable asset for penetration testing and bug bounty efforts.
2026-08-03
Python
★ 6257
Bjorn is an autonomous network scanning and vulnerability assessment tool optimized for Raspberry Pi, featuring a unique e-Paper HAT display. Its modular architecture allows for flexible configuration and operations like network scanning, vulnerability detection using Nmap, brute-force attacks, and data extraction from compromised services. With a real-time interface for monitoring and interaction, Bjorn supports extensive customization for diverse security testing requirements.
2026-08-03
Python
★ 30
BladeRecon is a modular reconnaissance framework tailored for bug bounty hunters and web penetration testing, focusing on attack-surface discovery and reporting. It offers a terminal-native workflow that generates clean output in various formats, including HTML and Markdown, while integrating features such as subdomain discovery, endpoint extraction, secret detection, and Nuclei scanning for improved intelligence gathering. Designed to be lightweight and beginner-friendly, BladeRecon prioritizes usability without sacrificing operational transparency, making it a valuable tool for small-scale pentesting efforts.
2026-08-03
Python
★ 17
Blood-Web is a modular honeypot system designed for penetration testing training and network attack detection, implemented in Python 3.8+ with zero dependencies. It features multiple honeypot services, including SSH, FTP, HTTP, and others, each configurable via command line flags, along with a real-time web dashboard for monitoring attack statistics and trends. The tool is designed to run on non-privileged ports by default, enabling easy deployment without additional setup.
2026-08-03
★ 328
The Bug Bounty Methodology and Tools repository provides a structured approach for ethical hackers to enhance their bug bounty hunting skills. It emphasizes the importance of reconnaissance and OSINT, which constitutes the majority of the bug hunting process, while also listing essential tools used during red team operations. Key features include a comprehensive methodology guide and practical resources, with a focus on continuous learning and improving attack vectors.
2026-08-03
Python
★ 2468
Cairn is a general-purpose problem-solving engine designed for AI-driven penetration testing and exploration of various state spaces. It utilizes a Blackboard Architecture with a fact-intent graph to dynamically search for paths from a defined origin to a goal, enabling versatile applications such as vulnerability research and CTF challenges. Key features include agent-based coordination through stigmergy, adaptable task generation, and real-time updates to the shared knowledge graph.
2026-08-03
Go
★ 3632
Cariddi is a domain crawling and scanning tool designed to identify sensitive information such as endpoints, secrets, API keys, and various file extensions from a list of provided URLs. Notable features include intensive crawling of subdomains, options for hunting specific secrets and errors, and customizable scanning parameters, making it particularly useful for penetration testing and bug bounty hunting. The tool can be easily installed across various platforms, supporting both single-target and bulk scanning configurations.
2026-08-03
★ 94
Cloud is a cybersecurity tool designed for monitoring and collecting SSL certificate data from major cloud service providers, specifically AWS EC2 and GCP. Its primary use case is to assist security researchers in enumerating subdomains, domains of target companies, and performing IP lookups, with daily updates to the dataset ensuring relevance and timeliness. Notable features include the ability to discover origin IP addresses behind security proxies and the organization of data into structured CSV files for easy access and analysis.
2026-08-03
Python
★ 40
CommiPiste is a tool designed for precise identification of open-source web software versions and associated CVEs by analyzing public static files. Its primary use case is authorized security testing and inventory management, leveraging a signature database that allows users to match files against specific Git commits. Notable features include automatic database updates, support for various output formats, and the capability to autoindex unknown software repositories for future scans.
2026-08-03
Python
★ 148
CVE2PoC is a tool designed for penetration testers and security researchers to efficiently locate public exploits, Proof-of-Concepts (PoCs), and advisories associated with a specific CVE ID. Its notable features include the aggregation of public exploits from various sources, the provision of isolated Docker environments for safe testing, automated report generation, and comprehensive CVE intelligence, including remediation steps and related bug bounty reports. This powerful tool streamlines the vulnerability discovery and assessment process, allowing users to quickly gather essential information for their security assessments.
2026-08-03
Python
★ 14
CyberBox is a hardened Docker sandbox designed for bug bounty and offensive security research, providing a secure environment with a comprehensive assortment of over 160 security tools. It features keyless signing with cosign, a complete Software Bill of Materials (SBOM), and SLSA build provenance to ensure trust and integrity throughout the supply chain, while also integrating AI analysis and an autonomous workflow for security tasks. Moreover, it seamlessly supports the Caido framework, offering a plugin manager and various utilities to enhance the research process.
2026-08-03
Python
★ 82
DACLSearch is a comprehensive tool for extracting Access Control Entries (ACEs) associated with principals in Active Directory environments. It supports extensive filtering and database generation, allowing users to perform detailed queries on ACEs and manage access control data efficiently through a command-line interface. Notable features include the use of the Phantom Root for broad queries across domain objects, multi-filter capabilities, and the ability to save and load custom filter configurations in YAML format.
2026-08-03
Python
★ 451
DDoSlayer Ultimate Edition is an advanced DDoS testing framework designed for professional penetration testing and red team operations, capable of simulating complex Layer 4 and Layer 7 attacks. Notable features include an AI-powered auto-detect mode for intelligent reconnaissance and attack vector recommendations, a rich terminal UI for enhanced user experience, and support for multiple attack vectors with stealth capabilities. This tool is optimized for efficiently executing concurrent attacks while providing comprehensive analytics through detailed reporting.
2026-08-03
Ruby
★ 13
The Dradis Burp plugin facilitates the integration of Burp Scanner XML export files into the Dradis framework, enhancing reporting and collaboration capabilities for security assessments. It requires either Dradis Community Edition version 3.0 or higher, or Dradis Pro, enabling users to efficiently manage and visualize the results from their Burp Suite scans. Notable features include compatibility with both Dradis versions and streamlined file uploads, allowing for better organization of findings.
2026-08-03
Python
★ 32
EmbedXPL-Forge is an open-source exploitation and scanning framework designed for security assessments of embedded and perimeter devices including routers, switches, IoT devices, and printers. It features over 2800 modules encompassing various attack vectors such as credential testing, vulnerability exploitation, and firmware manipulation, alongside an extensive library of 700+ mapped CVEs across 114+ vendors, along with an APT Group Attack Engine for simulating real-world cyber attack scenarios.
2026-08-03
★ 86
EmberHeart_OnePlus11 is a custom kernel designed for OnePlus 11 devices, primarily enabling advanced Android functionalities such as root access through KernelSU, along with enhanced security features via SUSFS for root hiding. The kernel is also optimized for use with the Nethunter penetration testing platform, allowing penetration testers to leverage their device for security assessments. Notable features include seamless installation instructions, compatibility with various kernel modules, and community contributions enhancing its capabilities.
2026-08-03
Python
★ 99
EthiBench is an adaptable evaluation framework designed for assessing the efficacy of AI-driven pentesting agents against complex, real-world security targets and vulnerabilities. It shifts the evaluation focus from simple task completion to validated vulnerability discovery, incorporating advanced features such as LLM-based semantic matching, continuous ground-truth maintenance, and scoring under ambiguity. Users can customize evaluations with their own targets and findings, while also accessing a set of pre-defined expert-annotated entries for standardized assessment.
2026-08-03
Python
★ 12
ExaAiAgent is an advanced AI-powered cybersecurity tool designed for comprehensive penetration testing, providing enhanced functionalities for various security assessments. Key features include a K8s scanner tool registration, smart fuzzing capabilities, response analysis for SQL errors, and automated installation processes, all aimed at integrating seamlessly into agent-driven workflows. The tool focuses on improving runtime reliability, error handling, and multi-tool coordination to facilitate efficient cybersecurity operations.
2026-08-03
Java
★ 603
FACTION is an OWASP project designed to streamline and automate the entire penetration testing and security assessment workflow. It offers features such as real-time collaboration among assessors, customizable report templates, a peer review system for tracking changes, and robust integration capabilities with tools like Burp Suite and various authentication systems. Additionally, it includes a REST API for seamless integration with other platforms, enhancing vulnerability management and team coordination.
2026-08-03
Python
★ 61
Faraday Plugins is a command-line tool designed to work seamlessly with Faraday, enabling users to manage and process security-related plugins. Its primary use case includes detecting and processing commands or reports generated by various security tools like Nmap and ping, offering features such as custom plugin support, JSON output formatting, and detailed command tracking. Notably, it allows for easy integration of custom plugins and includes logging capabilities for debugging purposes.
2026-08-03
Go
★ 16611
ffuf is a high-performance web fuzzer developed in Go, designed for conducting security testing by discovering hidden resources on web applications. Its primary use cases include directory and virtual host discovery, as well as fuzzing GET and POST parameters, allowing users to efficiently identify vulnerabilities and misconfigurations. Notable features include customizable wordlists, support for interactive mode, and the ability to filter responses based on their size, enhancing both speed and effectiveness in identifying potential security flaws.
2026-08-03
Python
★ 390
GSAN (Get Subject Alternative Names) is a tool designed to extract Subject Alternative Names (SAN) from SSL certificates of HTTPS servers, enabling the identification of DNS names and virtual hosts, particularly in environments involving internal or self-signed certificates. Its primary use case involves directly connecting to servers to retrieve SAN data without relying on Certificate Transparency logs, and it supports batch processing via file input and integration with other tools like Shodan or Nmap for enhanced functionality and output options. Notable features include flexible output capabilities and support for Docker installation, allowing seamless deployment and usage in various environments.
2026-08-03
JavaScript
★ 11
Ghostbadger is a PDF rendering engine that automates the generation of secure, password-protected PDF reports by leveraging Ghostwriter's GraphQL API for content and integrating with Vaultwarden for secure client delivery. Notable features include the ability to customize templates, utilize a streamlined Docker setup for deployment, and manage sessions through client-side cookies, ensuring flexibility for internal workflows. This tool is designed to be adapted for specific needs, requiring customization for production use.
2026-08-03
Python
★ 428
GPOHound is a cybersecurity tool designed to dump and analyze Group Policy Objects (GPOs) from the SYSVOL share, highlighting misconfigurations, insecure settings, and potential privilege escalation paths within Active Directory environments. Key features include structured output in JSON or tree formats, multi-domain support, and the ability to enrich BloodHound data with additional relationships and properties derived from GPO analysis. The tool supports advanced filtering, regex searches, and the detection of insecure configurations, facilitating comprehensive assessments of Active Directory security posture.
2026-08-03
Python
★ 639
GTFONow is a Python-based tool designed for automatic privilege escalation on Unix systems by exploiting misconfigured setuid/setgid binaries, capabilities, and sudo permissions. With a focus on usability for both CTF challenges and real-world pentesting scenarios, it offers various automated exploitation techniques, including file read/write primitives and SSH key theft. The tool is lightweight, compatible with multiple Unix variants, and requires no third-party dependencies, making it easy to deploy via a single script.
2026-08-03
Ruby
★ 1001
HAITI is a command-line interface (CLI) tool and library designed for identifying over 675 types of hash algorithms, including modern algorithms like SHA3, Keccak, and Blake2. Its primary use case is for cybersecurity professionals needing to determine hash types quickly, and it features references for integration with tools such as Hashcat and John the Ripper, along with a hackable architecture for customization.
2026-08-03
Go
★ 11997
Hetty is an open-source HTTP toolkit designed for security research and penetration testing, serving as an alternative to commercial tools like Burp Suite Pro. Its notable features include a machine-in-the-middle (MITM) HTTP proxy with logging capabilities, an HTTP client for crafting and replaying requests, request and response interception for manual review, organized project-based database storage, and a user-friendly web-based interface. Hetty is continually under development, aiming to meet the needs of the infosec and bug bounty communities effectively.
2026-08-03
★ 22
The HTB / THM / OSCP Master Penetration Testing Checklist is a comprehensive, modular framework designed to guide penetration testers through the phases of engaging with Hack The Box, TryHackMe, and OSCP-level machines. Key features include structured sections from setup and reconnaissance through exploitation and post-exploitation activities, as well as a quick reference for tools, commands, and troubleshooting. This checklist serves as a valuable resource for both beginners and intermediate practitioners in the penetration testing field.
2026-08-03
Python
★ 36
httpgrep is a high-performance asynchronous Python tool designed to scan HTTP(S) servers and search for specific strings or regex patterns within HTTP response bodies and headers. It supports a variety of input formats for target hosts, parallel scanning of multiple ports, and advanced features, including live match streaming, log file outputs in multiple formats, and the ability to resume interrupted scans, making it suitable for extensive network assessments. The tool is built for efficiency with an async core capable of handling thousands of concurrent connections while implementing intelligent timeout and port preflight mechanisms.
2026-08-03
Shell
★ 380
HuntKit is a Dockerized collection of tools designed for penetration testing, bug bounty hunting, red teaming, and capture the flag challenges, enabling rapid deployment and usage without the overhead of a virtual machine. It offers notable features such as quick execution, easy updates, and disposable environments, allowing users to quickly run tools like nmap and commix with minimal setup. The containerization approach streamlines security assessments while providing a convenient method for maintaining the latest versions of essential penetration testing tools.
2026-08-03
Rust
★ 24
Ironbullet is a desktop automation toolkit designed for creating and executing complex data processing workflows using a visual drag-and-drop pipeline interface. It features over 50 block types, including HTTP requests, parsing, checks, and browser automation, allowing users to perform multi-threaded job executions with advanced debugging capabilities, TLS fingerprinting, and built-in traffic capture for analysis. Moreover, the tool supports plugin extensions and the importation of configurations from OpenBullet 2 and SilverBullet, enhancing its flexibility and application in various automation tasks.
2026-08-03
Python
★ 15
Kali-Booster is a script designed to enhance Kali Linux by installing additional pentesting tools, configuring system settings, and creating useful aliases for command line efficiency. Key features include the restoration of legacy tools, the addition of new wordlists, enhanced font support, and customized settings for a streamlined pentesting environment. The script also facilitates the setup of OpenVPN connections for various hacking platforms and includes automated customization of the user interface.
2026-08-03
JavaScript
★ 704
KeyFinder is a browser extension designed for Chrome and Firefox that passively scans web pages for leaked API keys, tokens, and secrets. With over 80 detection patterns across multiple categories such as cloud services, payments, and databases, it operates silently in the background, leveraging techniques like entropy analysis and monitoring various attack surfaces to identify sensitive information. Notable features include zero dependencies, compatibility with modern web standards (Manifest V3), and the ability to alert users via tab badges when potential exposures are detected.
2026-08-03
Python
★ 266
KeyLeak Detector is a runtime security tool designed to identify and validate exposed API keys and misconfigurations in Backend-as-a-Service (BaaS) implementations, specifically targeting frameworks like Supabase and Firebase. Its notable features include a Chrome extension for real-time detection of secrets in web applications, a full site scanning capability that reports on potential vulnerabilities across subdomains, and the ability to validate active status of found keys. Unlike traditional static scanners, KeyLeak assesses the exploitability of keys at runtime, offering a comprehensive audit for web applications.
2026-08-03
Python
★ 37
Kumo is an OSINT and security reconnaissance framework that enables the analysis of a target domain via a single command, leveraging 26 parallel modules to deliver comprehensive results in real-time. Key features include extensive checks on DNS records, email security, open ports, leaked credentials, and malware associations, as well as a user-friendly web interface and fast scanning options. This tool is ideal for security professionals conducting thorough assessments of domain-related vulnerabilities and exposures without the need for API keys.
2026-08-03
Python
★ 29
Laitoxx is an OSINT and cybersecurity toolkit featuring a user-friendly GUI, designed for educational purposes to facilitate security analysis, penetration testing, and digital footprint assessment. Key functionalities include an extensible plugin system (Lua), various OSINT tools for data collection, web and network scanning capabilities, and a suite of utilities for hash and text manipulation. Notable enhancements in version 2.3.2 include an advanced theme editor, auto-theme scheduling, and multiple bug fixes for enhanced stability and usability.
2026-08-03
Python
★ 23
mcpsec is a security scanner and protocol fuzzer specifically designed for MCP (Model Context Protocol) servers, allowing real-time connection and exploitation testing against live services. Its primary use case is to identify vulnerabilities in AI development tools that utilize MCP, enabling users to discover and report security issues effectively. Notable features include support for 800+ fuzzing cases, detailed vulnerability reporting, and dynamic testing capabilities that surpass traditional static analysis methods.
2026-08-03
Python
★ 28
MoMo is a modular wireless security audit platform specifically designed for Red Teams, penetration testers, and security researchers, operating on Raspberry Pi 5. It integrates various advanced features such as multi-radio management, real-time data synchronization with a central hub, and comprehensive tools for WPA2/WPA3 attacks, credential harvesting, and automation in a single extensible solution. Notable functionalities include an auto-pwn engine, GPS wardriving capabilities, and support for social engineering techniques, making it a versatile tool for wireless security assessments.
2026-08-03
Python
★ 26
NetWatch is an all-in-one network security dashboard designed to convert any Linux machine into a comprehensive security sensor. It features real-time deployment of honeypots, traffic sniffing, OSINT tools, and threat management capabilities, all accessible via a single command and user interface. Key functionalities include automatic threat scoring, detailed traffic analysis, and the ability to block attackers, making it suitable for security professionals and home users alike.
2026-08-03
Python
★ 13
NullSec Red Team AI is a highly specialized offensive security toolkit designed for red team operations, integrating seamlessly with Claude Desktop through the Model Context Protocol (MCP). This hardened version features a robust Flask orchestration server managing over 150 offensive security tools, a sandbox for AI vulnerability testing, and a self-healing diagnostic utility for system integrity. Its architecture enables high-speed workflows for reconnaissance, vulnerability research, and advanced exploitation simulations, making it ideal for professional security assessments.
2026-08-03
TypeScript
★ 223
OctoC2 is a GitHub-native command-and-control framework designed for authorized cybersecurity research, featuring encrypted multi-channel transport and resilient failover capabilities. Its architecture includes a TypeScript beacon, a durable controller, a local operator dashboard, and a comprehensive CLI, enabling secure task execution and management via various transport methods. Notable features include the use of GitHub artifacts for task exchange, a signed task protocol, and a focus on least-privilege credentials for robust security during operations.
2026-08-03
Python
★ 14
Fast, parallel and easy to use web crawler for penetration testing and bug bounty
2026-08-03
Python
★ 103
The Offensive Pentesting Scripts repository offers a suite of automation scripts designed to enhance the efficiency of penetration testing and bug hunting. Key features include the simultaneous installation of over 40 essential Go tools, generation of a comprehensive wordlist for subdomain brute forcing with over 66 million entries, and automated identification of live hosts and open ports using Nmap. Additionally, the toolset provides capabilities for thorough subdomain discovery through multiple techniques, streamlining the reconnaissance process for cybersecurity professionals.
2026-08-03
C
★ 108
okhi is an open-source keystroke logging implant designed for integration into USB and PS2 keyboards, allowing real-time monitoring of keystrokes via WiFi. It employs an RP2040 microcontroller for data capture and an ESP32-C2 chip for wireless transmission, making it a compact and efficient solution for educational and proof-of-concept purposes. Key features include support for both keyboard types, real-time data access, and a modular design that facilitates easy installation and operation.
2026-08-03
Python
★ 62
OpenFirebase is an automated security scanning tool designed to extract Firebase configurations from Android APKs and iOS IPAs, enabling unauthenticated and authenticated scanning of Firebase services, such as Realtime Database, Firestore, and Storage. Notably, it detects accidentally embedded service account credentials and supports multiple input formats, providing comprehensive analysis for both mobile and web applications. The tool also includes built-in wordlists and example payloads for effective fuzz testing and vulnerability assessment.
2026-08-03
Shell
★ 47
OpenRediWrecked is a sophisticated tool designed for security professionals to detect and exploit open redirect vulnerabilities by automating the injection of carefully crafted payloads using the sed utility. Its notable features include parameter cleaning, support for various encoding techniques to bypass filters, and an intuitive output format that highlights vulnerable URLs in a color-coded manner. This makes it an essential asset for Red Teams and Bug Bounty Hunters seeking to improve their testing methodologies.
2026-08-03
PHP
★ 740
The Pentester Guide is a comprehensive resource aimed at penetration testers, providing a curated collection of tools, methodologies, educational materials, and practical labs. It includes sections on certifications, bug bounty platforms, and independent pentesting resources, making it an essential tool for both novice and experienced cybersecurity professionals. Notable features include a detailed roadmap for cybersecurity learning and multiple links to pentesting practice environments.
2026-08-03
HTML
★ 54
RedConsole is an offline, single-file penetration testing tool designed for Red Team operators, OSCP/OSEP preparation, and CTF/HTB engagements. It provides an interactive attack plan generator that automatically fills commands based on target details and adapts as progress is made, while also offering features like recon autopilot, credential reuse matrix, and playbook builder for streamlined execution. Its core advantage lies in its ability to run in any browser without requiring installation or internet access, making it suitable for various environments, including locked-down VMs and air-gapped systems.
2026-08-03
Python
★ 35
The Penetration Testing Methodology repository provides a comprehensive framework for conducting penetration tests across various environments, including Active Directory, infrastructure, web applications, mobile, and cloud services. Key features include detailed methodologies for reconnaissance, exploitation, and post-exploitation techniques, along with specialized sections on API and mobile pentesting, as well as AI LLM security audits. This tool is designed to facilitate the identification of vulnerabilities and improve defensive measures in security practices.
2026-08-03
C++
★ 125
POSEIDON is a keyboard-driven pentesting firmware designed for the M5Stack Cardputer-Advance, enabling users to perform 163 types of attacks across various wireless protocols including WiFi, BLE, and IR. This tool simplifies pentesting by allowing direct input for network navigation and management without the need for a PC or complicated coding. Notable features include the integration of an autonomous WiFi handshake hunter named Argus, customizable interface themes, and ongoing development towards FIDO2 hardware security key functionality.
2026-08-03
Python
★ 164
`pwneye` is an offensive security tool designed for interacting with IP cameras that support ONVIF and RTSP protocols, streamlining various tasks such as discovery, authentication testing, metadata collection, and stream validation through a single command-line interface. Notable features include multithreaded bruteforce attacks for credential guessing, ONVIF device enumeration, RTSP stream handling, and a dedicated live preview client, all aimed at facilitating security assessments of surveillance systems.
2026-08-03
C++
★ 12
Pwning OpenEDR is a vulnerability research tool that identifies and showcases high-severity flaws in OpenEDR version 2.5.1, emphasizing reproducible exploits for security assessments. Notable features include detailed CVSS scoring for various vulnerabilities, comprehensive runtime proof evidence, and a structured approach for reproducing each advisory in a controlled environment. This tool is particularly useful for security researchers evaluating endpoint detection and response (EDR) solutions for potential weaknesses.
2026-08-03
HTML
★ 30
RRW (Rick Roll WiFi) is a prank tool that sets up a rogue access point designed to capture captive portal probes and serve a fake Wi-Fi login page that redirects connected devices to a rickroll video. It utilizes standard network utilities like `hostapd`, `dnsmasq`, and `iptables` to manage the AP and traffic redirection without collecting credentials or intercepting user data, making it a non-malicious tool meant for entertainment. Users can customize the SSID, video, and HTML templates, allowing for tailored rickroll experiences.
2026-08-03
★ 97
The Robot Security Framework (RSF) provides a standardized methodology for conducting security assessments specifically in robotic systems. Its primary use case is to identify and address vulnerabilities related to communication ports, ensuring adequate protection against potential physical and cyber threats. Notable features include comprehensive criteria for evaluating both external and internal communication ports, along with recommendations for inspection methods to ascertain security measures.
2026-08-03
Go
★ 126
RUDY (R-U-Dead-Yet?) is a Denial of Service tool designed for executing low-rate "slow and low" attacks that target web servers by sending long form data in small packets at a slow rate. Its interactive console facilitates user-friendly operation, allowing users to simulate concurrent POST requests with customizable parameters such as request intervals, payload sizes, and the ability to use a TOR proxy for anonymity. This tool is primarily intended for educational and testing purposes to analyze server behavior under resource-saturation attacks.
2026-08-03
Shell
★ 77
ScopeHunter is a targeted reconnaissance tool designed for Red Teams and bug bounty hunters, leveraging up-to-date databases from platforms like HackerOne, BugCrowd, Intigriti, and YesWeHack to facilitate efficient target discovery. Its key features include an intuitive command-line interface, rapid execution, and access to the latest bug bounty program data. The tool is compatible with major operating systems, making it an essential asset for security professionals seeking to streamline their target identification process.
2026-08-03
Go
★ 95
Secbutler is a utility tool designed for penetration testers, bug bounty hunters, and security researchers, streamlining common tasks in cybersecurity assessments. It includes features such as generating reverse shell commands, setting up proxies, downloading payloads, and managing wordlists, thus enhancing productivity during security audits. The tool aims to cater to community needs, welcoming suggestions and contributions for continuous improvement.
2026-08-03
C
★ 25
SKELETONKEY is a comprehensive Linux local privilege escalation (LPE) tool that consolidates 46 modules targeting 41 distinct CVEs from 2016 to 2026, offering both red team and blue team functionalities. It features verified exploits, automatic module selection based on safety, detection rules for security audit logging, and a scanning capability for system administrators to identify unpatched vulnerabilities. This tool is designed for authorized testing only, ensuring ethical hacking practices while providing robust functionality for pentesters and system administrators alike.
2026-08-03
Clojure
★ 640
SQLiDetector is a Python-based tool designed to identify SQL injection vulnerabilities using error-based methods. It systematically tests target URLs by sending a variety of payloads, while leveraging regex patterns specific to different databases to spot potential errors. Additionally, it integrates with BurpBounty for enhanced testing capabilities across various request parameters, providing an efficient workflow for security professionals assessing web applications.
2026-08-03
Shell
★ 163
SQLMutant is a mutation testing tool designed for Red Teams and Bug Bounty Hunters that automates the process of identifying SQL injection vulnerabilities within a specified domain. It leverages tools like Waybackurls, HTTPX, Arjun, and SQLMAP to perform domain enumeration, URL fetching, and SQL injection testing, while providing various fuzzing capabilities for URLs, headers, and form data. Notable features include integration with historical web page archives and aggressive parameter extraction to enhance vulnerability detection.
2026-08-03
Python
★ 40
SSRF-Scanner is an advanced tool designed to identify Server-Side Request Forgery (SSRF) vulnerabilities through 14 comprehensive attack phases, emphasizing speed and accuracy. Leveraging asynchronous processing for up to 200 concurrent requests and featuring real confirmation via a self-hosted callback listener, it effectively distinguishes genuine vulnerabilities from false positives. The tool also provides extensive reporting capabilities in various formats and supports custom payloads and CVE probes, making it a versatile asset for security assessments.
2026-08-03
Shell
★ 337
TerminatorZ is an Offensive CVE Exploitation Framework specifically designed for red teamers and offensive security professionals, focusing on active exploitation rather than mere vulnerability scanning. It automates reconnaissance across multiple sources, validates live endpoints, and executes 31 deterministic CVE checks, providing real-time feedback with zero false positives and proof-of-concept URLs for confirmed vulnerabilities. With its modular Bash architecture and unique features like asset-type intelligence and production-quality reporting, TerminatorZ streamlines the exploitation process for faster and more credible results.
2026-08-03
C#
★ 37
TheSprayer is a cross-platform tool designed to help penetration testers spray passwords against an Active Directory domain without locking out accounts.
2026-08-03
Python
★ 56
Touti Cracker is a cross-platform ethical hacking toolkit designed for educational purposes, featuring capabilities for password cracking, WiFi auditing, and reverse shell payload generation to illustrate system vulnerabilities. Notable features include an enhanced neon-styled user interface, automatic Hashcat setup, error handling enhancements, and compatibility with multiple operating systems, making it a comprehensive tool for security professionals and educators.
2026-08-03
Python
★ 34
TransparentTorProxy (TTP) is a Linux command-line tool designed to route all system traffic transparently through the Tor network using nftables, thereby enhancing user privacy without requiring per-application configuration. Key features include zero DNS leaks through kernel-level handling, a fail-closed design that secures network routing during failures, and the use of volatile memory to ensure no persistent data is left on the system. TTP offers a modern solution for users seeking to anonymize their internet traffic effortlessly.
2026-08-03
Go
★ 24
urlX is a high-performance reconnaissance tool for bug bounty hunters, penetration testers, and security researchers, facilitating passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling for hidden endpoints. Its key features include smart file and extension filtering, concurrent processing using Go routines, and optional integration with various API keys to enhance results. Designed for swift and effective attack surface identification, urlX requires minimal setup and is built for real-world reconnaissance workflows.
2026-08-03
PHP
★ 12
VexiumCTF is an intentionally vulnerable web application framework designed for security training and education. It facilitates hands-on practice with security vulnerabilities through Docker or XAMPP setups, featuring a web interface and a database management system via phpMyAdmin for effective experimentation. Key functionalities include easy configuration for SQL initialization and comprehensive logs to aid analysis during testing sessions.
2026-08-03
Python
★ 75
web2shell is a Python tool designed to automate the conversion of webshells into reverse shells, streamlining the process often required in Capture The Flag (CTF) competitions, Hack The Box (HTB) challenges, and red team exercises. Its notable features include a customizable command interface, the ability to specify local listener settings, and support for various payloads that can be easily extended. The tool is primarily intended for use with Linux machines and facilitates quick testing and execution of reverse shells from web-based vulnerabilities.
2026-08-03
Python
★ 22
WebAnalyzer v3.6.2 is a professional-grade cybersecurity platform designed for advanced domain analysis, vulnerability assessment, and intelligence gathering. It features enterprise bulk processing capabilities, allowing users to analyze thousands of domains efficiently with a MySQL-backed queue system, AI-powered analysis modules, and enhanced stealth techniques. Notable features include real-time metrics, comprehensive reporting, and scalable architecture that supports dynamic resource management and concurrent processing.
2026-08-03
PHP
★ 60
WebVulnLab is a comprehensive learning platform designed for identifying and exploiting web vulnerabilities within a controlled and secure environment. It features more than 30 types of vulnerabilities for practical training, an enhanced user-friendly interface for easier management of Docker containers, and a control panel for overseeing active containers, ensuring an effective ethical hacking practice.
2026-08-03
Shell
★ 422
WiFiChallengeLab-docker is a containerized environment designed for security practitioners to simulate and practice WiFi attacks on various types of networks, including OPN, WPA2, WPA3, and Enterprise setups. It features a range of updated challenges with new attack vectors, such as WPA3 brute-force and captive portal evasion, alongside enhanced stability by using Docker instead of nested virtual machines. The tool also incorporates nzyme for monitoring and detection, making it a comprehensive solution for hands-on learning in WiFi security.
2026-08-03
Python
★ 1170
WifiForge is a tool designed to provide a safe and legal environment for learning WiFi hacking, built on the Mininet-WiFi framework. It automates the setup of networks and necessary tools to conduct various WiFi exploitation labs, eliminating the need for extensive hardware and overhead. Key features include easy installation, detailed documentation, and a focus on educational use for cybersecurity professionals.
2026-08-03
★ 101
The Wireless Security & WiFi Penetration Testing course offers an advanced, lab-driven educational experience aimed at mastering wireless security testing and attack techniques against Wi-Fi networks. It covers a comprehensive range of topics including 802.11 standards, encryption methods, various cracking techniques, and wireless penetration testing methodologies, all delivered through practical, hands-on labs. Noteworthy features include configuration guidance for wireless adapters, ethical attack methodologies, and a focus on both offensive and defensive strategies, ensuring learners can apply knowledge directly to real-world scenarios.
2026-08-03
★ 27
The WordPress BugBounty tool is designed for educational purposes to assist security researchers in identifying high-impact vulnerabilities within WordPress sites. It catalogues common attack surfaces and vulnerabilities such as SQL Injection, Remote Code Execution, and Authentication Bypass, providing insights into exploiting these flaws via the REST API and various plugin endpoints. Notable features include detailed descriptions of vulnerabilities and links to relevant resources for further learning in WordPress security.
2026-08-03
Shell
★ 168
XSSRocket is a cybersecurity tool designed for conducting offensive security assessments, primarily focusing on Cross-Site Scripting (XSS) vulnerabilities. It leverages the Wayback Machine to retrieve and filter URLs, uses httpx for live URL verification, and employs a remote XSS payload list to perform GET requests, potentially exposing vulnerabilities. Notable features include stealth mode scanning, automated result storage, customizable payload lists for other injection types, and a user-friendly interface that enriches the output with random security quotes.
2026-08-03
Shell
★ 59
Yggdrasil is a cybersecurity tool designed to automate the installation of missing tools and streamline the configuration of Kali Linux following a fresh setup. Its primary use case is enhancing setup efficiency for cybersecurity professionals by providing automation scripts for various cybersecurity tools, alongside features like systemd service monitoring and deployment category additions. Notable features include customizable installation paths, hardening options, and support for multiple programming environments, making it a versatile resource for security practitioners.
2026-08-03
Shell
★ 11
Chirpy Starter is a Jekyll theme starter repository designed to facilitate the setup and deployment of websites using the Chirpy theme. It streamlines the process by providing essential files and configurations extracted from the theme’s gem, enabling users to quickly deploy feature-rich Jekyll sites while retaining customization options. Notable features include an automated update mechanism for new releases and a focus on user-friendly setup.
2026-08-03
Python
★ 41
AD AutoPwn is a fully automated penetration testing tool that facilitates the compromise of Active Directory environments by chaining over 25 attack techniques, allowing security professionals to conduct authorized assessments effectively. Its notable features include zero-credential attacks for username enumeration and credential harvesting, advanced exploitation methods for privilege escalation, and integration with BloodHound for graph-driven attack chains and actionable insights. The tool leverages techniques such as Kerberoasting, NTLM relay, and various vulnerability exploits to streamline the process of acquiring domain admin access.
2026-08-03
Go
★ 343
AgentHound is an open-source offensive security framework designed for AI agent infrastructures, capable of conducting comprehensive reconnaissance, asset fingerprinting, credential harvesting, model inventorying, and active exploitation. It integrates findings into a Neo4j graph to visualize attack paths, addressing every layer of the agentic stack, including model gateways and inference servers. Notable features include credential inventorying, model inversion capabilities, and the ability to perform active exploitation through tool and instruction poisoning.
2026-08-03
C
★ 29
AL-ANQA-FIRMWARE is an offensive security firmware designed for the LilyGo T-Deck, transforming it into a portable pentesting terminal equipped with over 60 integrated WiFi, Bluetooth, network, and radio tools. Key features include on-device WiFi attack capabilities, a comprehensive Bluetooth LE security audit suite, an interactive SSH client, and tools for wardriving and device monitoring—all operational without the need for additional PCs or GUIs, ensuring a self-contained and efficient testing environment.
2026-08-03
Java
★ 268
Alien is a modular webshell client designed for cybersecurity research and education, providing a flexible post-exploitation framework that integrates with various web technologies through reusable modules. Key features include arbitrary code execution, a file manager, database interaction, SOCKS5 proxying, HTTP traffic obfuscation, and the ability to pivot through webshells for enhanced communication security. The architecture enables advanced capabilities while keeping the core webshell lightweight, making it suitable for authorized penetration testing scenarios.
2026-08-03
C
★ 15
Argos is a passive Wi-Fi tracking tool designed to capture probe request frames from Wi-Fi enabled devices, allowing users to extract SSID information and acquire geographic data through Wigle, subsequently visualizing this on a Google Maps interface. The tool features a web interface, dynamic data filtering options, and parameters for controlling the scanning environment, while emphasizing strict ethical usage guidelines to prevent privacy violations. Notable functionalities include the ability to limit signal strength, support for multiple network interfaces, and compatibility with various Wi-Fi adapters for optimal performance.
2026-08-03
★ 200
The R3LI4NT/articulos repository serves as a comprehensive resource for cybersecurity and hacking-related articles, focusing on topics such as vulnerability exploitation, security techniques, and network auditing. Notable features include detailed guides on various pentesting methodologies, firewall configurations for GNU/Linux, and resources on social engineering attacks, providing practical insights and tools for both novice and experienced security professionals. Users can access the content through an integrated blog link for easier navigation and learning.
2026-08-03
Go
★ 244
AutoAR is an automated security reconnaissance and vulnerability hunting platform designed for bug bounty hunters and penetration testers, built in Go. It facilitates the entire recon-to-report pipeline by offering features such as subdomain enumeration, DNS takeover detection, automated vulnerability scanning with Nuclei templates, and multi-platform mobile app analysis. Notable functionalities include automatic result uploads to Cloudflare R2 storage, comprehensive monitoring for subdomain and URL changes, as well as integrated AI capabilities for enhanced searching and vulnerability detection.
2026-08-03
★ 16
Awesome AI Pentesting is a curated repository of AI-powered tools, frameworks, and resources designed for penetration testing, bug bounty hunting, and cybersecurity operations. It features a wide range of autonomous agents capable of executing end-to-end security assessments, leveraging large language models and machine learning to identify and exploit vulnerabilities in various environments. Notable tools include fully autonomous agents with high success rates, integrated AI tools for real-time testing, and robust frameworks for orchestrating comprehensive security evaluations.
2026-08-03
★ 166
Awesome Cyber AI Arsenal is a comprehensive collection of over 250 battle-tested offensive, defensive, and AI-powered security tools, organized into distinct categories for Red Team, Blue Team, and AI security applications. This repository facilitates quick access and deployment of security tools, emphasizing responsible usage for authorized testing and education purposes only. Notable features include extensive subcategories tailored for specific security functions, making it an invaluable resource for security professionals.
2026-08-03
PowerShell
★ 79
AzureAttackKit is a comprehensive suite of tools designed for penetration testing and assessments of Azure environments from a Windows machine or Azure Cloud Shell. Its primary use case is to streamline the collection of Azure resources, enabling automated queries and security checks across multiple subscriptions using tools like PowerZure, AzureHound, and AADInternals. Notable features include the ability to quickly pull subscription data, execute targeted scripts for information gathering, and employ regular expressions for searching sensitive information within Azure resource configurations.
2026-08-03
HTML
★ 21
This repository provides a curated collection of detailed writeups on various cybersecurity challenges, including Bug Bounty, Hack The Box (HTB), TryHackMe, and Capture the Flags (CTFs). It serves as an educational resource for cybersecurity practitioners at all levels, featuring in-depth explanations of techniques for web exploitation, privilege escalation, and more, aimed at enhancing understanding of vulnerabilities and methodologies in cybersecurity.
2026-08-03
Python
★ 11
BOFA is an open execution fabric designed for authorized security workflows, enabling the seamless movement of authorization from local environments to ephemeral cloud workers. Its primary use case revolves around enhancing security analysis by integrating memory retention, public intelligence, and local notes while facilitating a structured review process for findings. Notable features include built-in AI copilot support, a comprehensive bounty workspace setup, and robust authorization management, ensuring that evidence and artifacts are securely tied to each workflow.
2026-08-03
JavaScript
★ 39
Bug-Bounty-Tampermonkey-Scripts is a collection of user scripts designed for use with the Tampermonkey browser extension, aimed specifically at enhancing the bug bounty hunting process. The primary use case includes automating the extraction of URLs, titles, domains, and specific URL counts from Google search results, facilitating more efficient data gathering for security researchers. Notable features include customizable script functions that streamline the workflow for gathering and analyzing relevant information during bounty hunting activities.
2026-08-03
Python
★ 29
Cascavel is an autonomous Continuous Threat Exposure Management (CTEM) engine designed to streamline Red Team operations and validate adversarial exposures. It automates the process of scoping and discovery, prioritizes vulnerabilities with real-time threat intelligence, and employs a robust validation engine to minimize false positives while generating actionable remediation recommendations. Notable features include dynamic mapping of infrastructure, integration with threat databases, and support for various output formats, all engineered to enhance operational efficiency in cybersecurity.
2026-08-03
TypeScript
★ 20
CVE-MCP is a centralized vulnerability intelligence platform that unifies data from multiple sources, including NVD, EPSS, CISA KEV, and GitHub Advisory, to provide real-time intelligence tailored for AI agents. It streamlines the process of accessing critical vulnerability information on-demand, eliminating the need for cumbersome manual searches across disparate databases. Notable features include an extensive array of integrated tools, seamless API access, and compatibility with established frameworks like MITRE ATT&CK, significantly enhancing efficiency in vulnerability assessment and response.
2026-08-03
★ 119
Digital Forensics Tools is a comprehensive repository that curates essential utilities for digital investigations, including tools for disk forensics, memory analysis, malware detection, and network monitoring. Key features include disk imaging, file recovery, and memory acquisition tools, alongside advanced utilities like Volatility for memory analysis and Autopsy for user-friendly disk examination. This toolkit serves as a valuable resource for cybersecurity professionals conducting forensic investigations and data recovery tasks.
2026-08-03
Python
★ 14675
dirsearch is an advanced web path discovery tool designed for brute-forcing directories and files on web servers. Its primary use case is assisting cybersecurity professionals in identifying hidden resources within a web application, supporting features such as customizable wordlists, recursion, and a Python API for automation. The tool requires Python 3.11 or higher and offers various installation options, including native Rust backend support and pre-built binaries.
2026-08-03
Python
★ 394
EMBArk is a web-based platform designed for centralized firmware security analysis, utilizing the EMBA scanner as its backend. It offers features such as scanning, tracking, reporting, and presents results through an aggregated management dashboard to enhance accessibility and usability. Currently, it supports only Ubuntu LTS (version 24) and provides an intuitive setup and management interface for enterprise environments.
2026-08-03
Python
★ 11
EndpointHunter is a bug bounty tool that efficiently extracts various sensitive information, including API endpoints, LFI paths, secrets, and cloud storage URLs, from JavaScript, CSS, and HTML files. Its multi-threaded scanning capability enhances speed, while seamless integration with other recon tools and automated filtering of static assets optimize the reconnaissance process for security researchers. Notable features include smart recon for linked files, noise reduction, and support for output saving and batch processing of multiple URLs.
2026-08-03
HTML
★ 12
ExploitHunter.app is an open-source offensive-security tool designed to enhance the cost-effectiveness of security research through intelligent orchestration of various AI models. It facilitates broad reconnaissance, inventory checks, and evidence gathering using budget-friendly or local models, while reserving expensive frontier models for deeper analysis and validation tasks. Key features include automated lab environments for running evaluations, local model capabilities without API costs, and a data explorer for tracking evaluation outcomes and expenses.
2026-08-03
Go
★ 248
favirecon is a reconnaissance tool that utilizes favicon.ico files to enhance the target information gathering phase. It allows users to quickly identify technologies, web application firewalls, exposed panels, and known services associated with a given domain or list of domains. Notable features include configurable output options, support for concurrency, and the ability to filter results based on favicon hashes.
2026-08-03
Python
★ 37
FirmwareDroid (FMD) is a research tool designed for automating the extraction and security analysis of pre-installed Android applications from firmware images. Primarily functioning through a backend API with a minimal React frontend, it integrates numerous third-party analysis tools, static analyzers, decompilers, and file extraction utilities to facilitate in-depth security research. Notable features include support for dynamic analysis (in progress), a comprehensive inventory system for extracted files, and compatibility with various APIs such as VirusTotal.
2026-08-03
C
★ 14
The Flipper Zero IR Signal Generator is a versatile tool designed to generate and emit various infrared signals for security assessments and hardware hacking. It features a user-friendly interface, customizable settings for different signal types, and secure operations to minimize risks, making it accessible even to users with limited technical experience. The tool is compatible with Windows, macOS, and Linux systems, requiring only a Flipper Zero device and a USB connection for operation.
2026-08-03
Python
★ 161
Gallia is an extendable penetration testing framework specifically designed for the automotive industry, facilitating comprehensive security assessments from individual electronic control units (ECUs) to entire vehicles. It primarily focuses on the Unified Diagnostic Services (UDS) interface, offering a generic interface that supports logging and reproducible testing, which aids in post-processing tasks. Its setup involves creating a configuration file to specify command line options, making it suitable for researchers and developers conducting security evaluations in automotive environments.
2026-08-03
Rust
★ 11
ghost is a private desktop application designed for Windows that facilitates local file searching, the execution of AI agents, and integration with over 10,000 tools. Its notable features include the ability to operate entirely offline, ensuring user data remains secure and private, alongside advanced protocol support for seamless communication between tools and AI functionalities. This makes ghost particularly suitable for users prioritizing data privacy and local processing capabilities.
2026-08-03
Go
★ 14058
Gobuster is a high-performance brute-forcing tool written in Go, primarily used for web directory/file enumeration, DNS subdomain discovery, and virtual host detection. It features multi-threaded scanning, multiple operational modes including support for cloud storage enumeration, and extensibility with custom wordlists. Its design is tailored for security professionals, providing a reliable and efficient means to conduct penetration testing and security assessments.
2026-08-03
Python
★ 170
GraphQLer is an advanced, dependency-aware testing tool specifically designed for GraphQL APIs, enabling dynamic testing that leverages an API's schema to automate request generation and vulnerability detection. Key features include support for fragments and unions, error correction for invalid requests, tracking of objects for reconnaissance, and automatic detection of insecure direct object reference vulnerabilities. With an interactive terminal UI, customizable configurations, and detailed output logs, GraphQLer streamlines the testing process for enhanced security assessment of GraphQL APIs.
2026-08-03
Go
★ 20
hackenv is a command-line tool designed for managing hacking environments based on Kali Linux and Parrot Security, enabling users to quickly create, configure, and control short-lived virtual machines. Notable features include instant download of official live images, simple SSH access via public-key authentication, shared directories between host and guest, and unified keyboard layouts. This tool streamlines the setup of secure pentesting environments directly from the terminal, emphasizing efficiency and ease of use.
2026-08-03
Python
★ 15
HackingLife is a personal knowledge management tool designed to document and organize cybersecurity insights and notes for easy retrieval. Its primary use case is to support users in building a comprehensive personal repository of cybersecurity knowledge, while its notable feature is the informal and unstructured approach to note-taking, allowing for rapid updates and personal elaboration.
2026-08-03
★ 47
The Hardware Hacking Tools repository serves as a comprehensive catalog of various tools utilized for hardware hacking, focusing on areas such as firmware analysis, hardware debugging, and physical attack strategies. It includes specific tools for JTAG/SWD debugging, firmware dumping, reverse engineering, and side-channel attacks, making it invaluable for security researchers and penetration testers. Notable features include categorized tool listings by attack methods and links to both open-source and commercial hardware hacking tools.
2026-08-03
Python
★ 19
HexGraph is a self-hosted tool designed for AI-assisted vulnerability research that operates entirely on local machines. It allows users to analyze binaries or firmware images by breaking down the targets into components, executing analysis tasks, and organizing findings within a structured, typed graph stored in SQLite. Notable features include a focus on local operations without telemetry, a hypothesis worklist for managing leads, and a secure environment ensuring that all interactions with potentially hostile targets occur in an isolated Docker container.
2026-08-03
PowerShell
★ 276
JAMBOREE is a portable installer that rapidly sets up a comprehensive security and administrative toolkit for Android app testing without requiring local admin rights on Windows. It provisions a functional environment including Android AVD, Magisk, Frida, Objection, and Burp Suite in seconds with no bundled binaries, all driven by an open-source PowerShell script. Key features include built-in proxy configurations, an intuitive PowerShell UI for launching tools, and an optional collection of additional utilities for advanced security assessments.
2026-08-03
Python
★ 138
Kimiko is a pentesting configuration tool that enhances the Kimi Code CLI by providing a specialized framework for authorized offensive security, penetration testing, and mobile device security research. Key features include automated context loading for security workflows, customizable agent configurations, and robust capabilities for network offensives, malware generation, reverse engineering, and more, all under strict user authorization. Designed for lawful and ethical testing only, Kimiko facilitates a streamlined setup for various security research methodologies.
2026-08-03
★ 17
MasscanGUI provides a comprehensive graphical user interface for the Masscan port scanner, enabling users to easily configure and execute scans without requiring command line interaction. Notable features include support for all Masscan parameters, real-time output display, country-based scanning, multiple output formats, and advanced functionalities like intelligent rate adjustment and sharding for distributed scans. This tool is designed for ease of use on Windows with included executables, making it accessible for both novice and experienced users in network scanning tasks.
2026-08-03
C#
★ 76
MSSQLand is a C# post-exploitation tool designed for red team operations targeting Microsoft SQL Server (MSSQL) environments. It facilitates linked server traversal, cascading impersonation of logins, and various discovery actions to gather impactful information with minimal operational security footprint. Notable features include automatic execution of linked queries across deep server chains, support for multiple authentication methods, and customizable output formats, enhancing both usability and data presentation in penetration testing scenarios.
2026-08-03
Java
★ 12
Neonmarker is an addon for the ZAP (Zed Attack Proxy) framework that enhances the visualization of the History table by applying color coding to entries based on assigned tags or user-defined criteria. Its primary use case is to facilitate the organization and easy identification of different scan results within the ZAP interface. Notable features include customizable color mappings, support for tag-based coloring, and the potential for saving color configurations across sessions and projects.
2026-08-03
Python
★ 396
The Syslifters OffSec Tools repository provides a curated collection of offensive security tools for penetration testers and red teamers, streamlining the assessment process within internal environments. It regularly compiles and updates tools, allowing users to easily download the latest versions in a single release archive, thereby eliminating the need for individual updates and compilations. Notable tools included range from Active Directory enumeration and privilege escalation tools to credential recovery solutions, catering to various aspects of security assessments.
2026-08-03
Python
★ 39
OpenGhost is an authorized web application penetration testing tool designed to facilitate security assessments by AI coding agents. It provides essential features such as a Docker sandbox, detailed engagement scope files, reusable checks, and report templates to streamline the assessment process while ensuring local operation without external dependencies. Users must explicitly define authorization and testing parameters in the generated scope file before proceeding with assessments.
2026-08-03
Go
★ 306
Packémon is a terminal user interface (TUI) tool designed for packet generation and monitoring across any network interface, with compatibility for Windows, macOS, and Linux. It enables users to create arbitrary packets, including DNS queries, and observe real-time responses, whilst offering features like detailed packet inspection and filtering options. The tool is developed from scratch utilizing raw sockets, providing flexibility but also carries a warning for potential bugs.
2026-08-03
Python
★ 114
PassLLM is an advanced framework for targeted password guessing that leverages Personally Identifiable Information (PII) to predict likely passwords, achieving 15% to 45% higher accuracy than existing models. Its notable features include the use of a fine-tuning technique called LoRA for efficient resource management, advanced inference algorithms for optimized guessing, and the capability to harness millions of leaked PII records for training. Designed for high accuracy on consumer hardware, it is straightforward to deploy using Google Colab.
2026-08-03
Python
★ 34
Daethyra's Pentest-References is a comprehensive cybersecurity toolkit that organizes various guides and resources specifically aimed at enhancing penetration testing practices. It features playbooks for internal pentesting, is tailored for both beginners and advanced users, and encompasses tools and strategies for evading detection, exploiting web application vulnerabilities, and understanding Active Directory fundamentals. Notably, it includes extensive documentation on topics like data exfiltration, network enumeration, and persistence techniques on Windows systems, making it a valuable resource for security professionals.
2026-08-03
TypeScript
★ 319
Pentest Reports is a web application that provides a curated list of public penetration test reports, along with a database of popular Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), and security commands and tools. It includes ready-to-use pentest report templates, making it a valuable resource for security professionals conducting vulnerability assessments. The tool is built with Node.js and MongoDB, ensuring efficient data management and retrieval.
2026-08-03
JavaScript
★ 297
The Pentesting-and-Hacking-Scripts repository is a comprehensive collection of scripts designed to facilitate learning and practical application in penetration testing and exploitation of system vulnerabilities. It caters to both beginner "script kiddies" and advanced pentesters by offering organized scripts in various programming languages, including Python and Bash, while emphasizing responsible usage for educational purposes. Notable features include categorized scripts targeting different vulnerabilities and thorough documentation to guide users in their cybersecurity education.
2026-08-03
TypeScript
★ 76
PentestingChecklist is an interactive security assessment tool designed for penetration testers, security researchers, and bug bounty hunters, featuring a comprehensive checklist that spans 23 platforms and includes over 1,000 checks. Its notable features include client-side operation with no telemetry, allowing users to store their progress and notes locally without any login requirements. The checklist covers diverse areas, including web applications, APIs, mobile security, cloud configurations, and DevSecOps practices, making it a versatile resource for thorough security assessments.
2026-08-03
TypeScript
★ 2056
PentestingEverything is an open-source, comprehensive knowledge base for penetration testing, encompassing methodologies and resources across 23 security domains including web, API, mobile, and cloud. The tool offers a fully searchable interface with over 108 documentation pages, a filterable PDF library, and structured learning paths, enhancing the efficiency and effectiveness of security assessments. Its integration with an Agent Skill allows practitioners to apply this knowledge interactively during engagements, ensuring safe and authorized testing practices.
2026-08-03
XSLT
★ 136
PenText is an XML-based documentation generation tool designed for creating IT security documents such as penetration test reports, quotes, and invoices. Its notable features include the ability to transform structured XML documents into various formats like PDF, CSV, and JSON using XSLT and Apache FOP, as well as modular structure for easy content management. This toolstreamines reporting processes in cybersecurity engagements, facilitating efficient documentation and export of findings.
2026-08-03
Go
★ 192
Phatcrack is a distributed hash cracking tool built on Hashcat, aimed at information security professionals. It facilitates efficient management of cracking projects through a modern web interface, supports various hash types and attack methods, and allows for the synchronization of wordlists and rule files across multiple worker agents. Notable features include multi-user support, project-based access control, and automated distribution of cracking tasks.
2026-08-03
★ 104
The Physical Penetration Testing Tools repository provides a comprehensive set of methods and tools for conducting physical security assessments by simulating real-world attacks. Notable techniques include badge cloning using devices like Proxmark and Flipper Zero, tailgating with various access tools, and social engineering tactics aimed at exploiting human factors. This collection aids security professionals in identifying vulnerabilities in physical security controls through practical tools and methodologies.
2026-08-03
Python
★ 31
PPMAP is a comprehensive JavaScript prototype pollution and XSS vulnerability scanner designed for web application security assessments. It features a modular architecture, advanced detection methods for various frameworks, and capabilities for browser automation, WAF resilience, and in-depth logging, making it suitable for enterprise-level penetration testing and vulnerability management. Notable components include its intelligent detection tiers, support for modern frameworks, and integration of extensive exploitation guides for discovered vulnerabilities.
2026-08-03
C#
★ 327
ReconNess is a web application designed to streamline the reconnaissance process for cybersecurity professionals, enabling them to efficiently organize and manage their recon data without requiring extensive scripting skills. Its primary use case is providing continuous recon capabilities through a customizable pipeline of reconnaissance tools that can be triggered based on schedules or events. Notable features include a user-friendly interface, the ability to aggregate data from various agents, and a focus on helping users concentrate on identifying potentially vulnerable targets.
2026-08-03
Python
★ 598
Rekono automates the penetration testing process by integrating multiple hacking tools to streamline tasks such as OSINT, host discovery, and vulnerability scanning. Its notable features include email and Telegram notifications for findings, integration with Defect-Dojo for advanced vulnerability management, and a dedicated Telegram bot to execute tests from any device. This tool aims to enhance a pentester's efficiency by allowing them to focus on analysis rather than repetitive testing tasks.
2026-08-03
Python
★ 159
Roothound is a tool designed for local Linux privilege escalation, providing users with a clear graphical representation of pathways from a low-privilege shell to root access. It features an attack-path graph that illustrates each potential route, confidence coloring to indicate the reliability of paths, and copy-ready abuse commands for user convenience. The tool operates offline, requires no dependencies, and can generate self-contained HTML reports from LinPEAS output, making it suitable for authorized security testing and educational purposes.
2026-08-03
Rust
★ 341
RustPacker is a tool designed for authorized penetration testers and red team operators that transforms raw shellcode into secure and evasive Windows binaries. It encapsulates shellcode within a Rust-based executable or DLL, incorporating features such as encryption, multiple injection techniques, and evasion strategies to minimize detection by endpoint protection systems. Notably, it supports cross-platform builds and offers a variety of injection templates and encryption methods to enhance the stealth of the generated payloads.
2026-08-03
Rust
★ 686
ScanT3r is a fast command-line interface (CLI) tool for dynamic application security testing (DAST), developed in Rust, designed to identify vulnerabilities such as Cross-Site Scripting (XSS) and Server-Side Template Injection (SSTI) through various testing modules. It supports concurrent scanning with customizable options, including target lists, module selection, and output formats like JSON reports. Notable features include context-aware payload delivery, the ability to integrate with Burp Suite, and an extensible module framework for developing additional testing capabilities.
2026-08-03
Python
★ 1307
secator is a comprehensive task and workflow runner tailored for security assessments, enhancing the efficiency of penetration testers and security researchers. It features a curated list of commands with unified input and output options, CLI and library support, and the ability to run distributed tasks via Celery, making it suitable for both simple and complex security workflows. Notably, secator integrates numerous well-established security tools to streamline the assessment process.
2026-08-03
Go
★ 623
sif is a comprehensive recon and exploitation scanner that integrates various scanning capabilities—including subdomain enumeration, port scanning, crawling, vulnerability detection, and more—into a single binary. It leverages a shared connection-pool architecture for efficiency, allowing seamless execution of over 25 scan types from one command, while eliminating the need for external dependencies. Notable features include support for continuous monitoring with change detection, scanning configuration through command-line flags, and integration with notification services like Slack and Discord.
2026-08-03
Rust
★ 77
Skewrun is an Active Directory time discovery toolkit designed for red team operations, facilitating the resolution of time discrepancies when executing commands on target systems from a Linux environment. It utilizes various network protocols (CLDAP, SMB, NTP, Kerberos, NTLM) to dynamically fetch the Domain Controller's time, allowing users to circumvent the Kerberos `KRB_AP_ERR_SKEW` error without needing elevated privileges to adjust the system clock. The tool features a library-first architecture for seamless integration into other Rust applications and minimizes forensic traces during operation.
2026-08-03
Kotlin
★ 151
Spectre is an Android application designed for monitoring and interacting with various wireless signals, including Bluetooth, Wi-Fi, cellular, and GNSS. Its primary use case revolves around RF exposure measurement and pen-testing, featuring tools for detailed analysis of signal strength, local network discovery, and BLE device interaction. Notable features include comprehensive support for multiple network technologies, advanced filtering capabilities, and a GATT inspector for Bluetooth devices, all while adhering to Android's security restrictions.
2026-08-03
★ 11
SQL-Injector is a specialized tool designed for performing SQL injection testing on web applications, facilitating the identification of vulnerabilities in various database systems such as MySQL, PostgreSQL, MSSQL, and Oracle. Notable features include automated vulnerability detection, custom payload generation for bypassing WAFs, multi-threaded scanning for efficiency, and the ability to operate anonymously via Tor integration. Advanced capabilities support complex testing scenarios, including boolean-based blind SQL injection and detailed schema enumeration.
2026-08-03
Python
★ 77
TASER (Testing and Security Resource) is an abstraction library designed to facilitate the development of custom offensive security tools by providing various protocols and classes. Its primary use case is to streamline the creation of tailored security scripts during engagement scenarios, and it includes features for browser integration, screenshot capabilities, and packaged scripts for different probing tasks.
2026-08-03
Python
★ 753
The Big Brother V5.0 is an advanced Open Source Intelligence (OSINT) framework designed for comprehensive reconnaissance on individuals, organizations, or groups. It features a highly interactive holographic dashboard supported by 21 distinct intelligence modules that facilitate deep investigative analysis. The tool allows users to conduct detailed searches and surveillance, enhancing the capabilities for gathering critical data while also offering an exclusive service for more intensive intelligence requirements.
2026-08-03
Python
★ 16
Toboggan is a post-exploitation tool that facilitates a semi-interactive shell on both Linux and Windows targets via Remote Code Execution (RCE) methods. It operates by allowing users to define custom command execution logic through a simple Python interface, enabling interaction with command outputs even in restrictive network environments. Key features include support for Python-based execution modules, an interactive shell with command history, and the ability to establish communications using named pipes when reverse shells are not feasible.
2026-08-03
Rust
★ 28
TriLane is an autonomous gray-box security auditing tool designed for authorized penetration testing on local labs, internal codebases, and bug-bounty targets. It features a staged audit process that includes the construction of an attack-surface graph, a six-lane semantic audit covering various security aspects, and a deduplication mechanism for findings, allowing for a thorough and organized assessment of security vulnerabilities. Notable features include a desktop GUI for tracking the audit process, two operational modes (Safe and Lab), and efficient evidence management for generating comprehensive reports.
2026-08-03
Shell
★ 10
The 5G-Pentest-UE is a penetration testing framework designed to identify vulnerabilities within 5G systems from the perspective of a user equipment (UE), requiring no prior knowledge or access to the network. Its notable features include the ability to configure and run tests against the 5G protocol stack, alongside the integration of patched Open Air Interface implementations to facilitate comprehensive security testing. This framework is particularly useful for assessing security in closed-source and proprietary 5G networks.
2026-08-03
C++
★ 81
UniGeek is a versatile multi-tool firmware designed for a wide range of ESP32-based handheld devices, enabling functionalities such as Wi-Fi and Bluetooth attacks, RF signal manipulation, and various diagnostic utilities. It offers an extensive feature set including network attacks, sub-GHz communication, NFC capabilities, and a suite of utility tools and games, all integrated into a user-friendly interface. Notable aspects of UniGeek include its comprehensive documentation and support for approximately 18 different device models.
2026-08-03
JavaScript
★ 41
4ndr0tools is a collection of userscripts designed to enhance digital sovereignty by countering anti-user web practices and empowering users with control over their browsing experience. Notable features include modular design for customizable implementation, transparent and auditable code, and a focus on anti-platform functionalities that resist modern web manipulations. This suite caters to advanced users and red team engagements, promoting a minimalist and performance-oriented approach to web interactions.
2026-08-03
Go
★ 13
VSAT (Volumetric Socket Artillery) is an advanced multi-layer network traffic generation framework designed for comprehensive stress testing and benchmarking of network infrastructure. The tool integrates Layer 3, Layer 4, and Layer 7 traffic engines, enabling high-throughput traffic simulation across various protocols while offering features such as HTTP/2 multiplexing, TLS JA3 fingerprinting, and raw packet crafting. Its multiprocessing architecture facilitates concurrent traffic generation, making it suitable for defensive security research and protocol analysis.
2026-08-03
Shell
★ 27
Weaponize-CobaltStrike is an automated toolkit designed to streamline the setup and configuration of Cobalt Strike, enhancing its capabilities with a wide array of Beacon Object Files (BOFs) and offensive security tools. Key features include the automation of dependency installation and compilation of various community-driven tools, such as the CS-Aggressor-Kit and situational awareness BOFs, making it easier for security professionals to extend their Cobalt Strike operations. This tool aims to facilitate authorized security testing and educational purposes while also providing a platform for contributions and improvements from the community.
2026-08-03
Python
★ 117
WEBFANG v2.0 is a command-line reconnaissance toolkit specifically designed for ethical hacking, enabling users to perform both passive and active reconnaissance through features such as web spidering, subdomain scanning, WHOIS checks, DNS queries, and header fingerprinting. It supports integration with Shodan and URLScan, and is modular in design, allowing for extensions and enhanced output options. Intended for authorized penetration testing and OSINT research, the tool ensures that users maintain compliance with ethical guidelines during usage.
2026-08-03
Python
★ 40
The website-passive-reconnaissance tool automates passive reconnaissance on websites to aid cybersecurity assessments without directly engaging with the target. Its primary use case is to streamline the reconnaissance phase by defining and executing necessary steps using various integrated API services. Notable features include customizable API key integration, configurable options for domain analysis, and a user-friendly command-line interface.
2026-08-03
Rust
★ 50
WonderSuite is a desktop-native offensive security research engine designed for comprehensive web application security testing, network reconnaissance, and exploit development, harnessing AI capabilities via Model Context Protocol (MCP) integration. It features an extensive toolkit of 91 security tools, enhanced by a full MITM proxy with advanced fingerprinting for obfuscation, facilitating efficient vulnerability research and response automation. The platform aims to streamline the process of identifying and addressing security issues, making it a powerful asset for security professionals.
2026-08-03
Python
★ 678
Z3r0 is an open-source red team collaboration workbench designed for authorized penetration testing, vulnerability discovery, and security research. It integrates a React-based console with a FastAPI management layer, allowing users to coordinate multi-Agent sessions, track project-specific evidence, and manage sandbox environments and controlled egress efficiently. Notable features include comprehensive evidence management, detailed workflow tracking, and a session timeline that enhances operational transparency and collaboration among red team participants.
2026-08-03
Python
★ 10
ZIRAN is a comprehensive security testing framework designed to identify vulnerabilities in AI agents, including those with complex capabilities such as tool usage and memory. By modeling agents as graphs of capabilities, it effectively discovers dangerous tool chains, detects execution-level side effects, and conducts adaptive multi-phase campaigns, surpassing the capabilities of single-prompt scanners. Notable features include graph-based analysis, tool-chain discovery, and thorough coverage of established security benchmarks like OWASP and MITRE.
2026-08-03
★ 32
5Ghost WiFi Lab is a dual-band Wi-Fi research and security testing tool designed for the Flipper Zero, utilizing the Realtek RTL8720DN chipset to enable comprehensive 2.4 and 5 GHz scanning. It features capabilities such as WPA/WPA2 handshake capture, clientless PMKID capture, and BLE reconnaissance, making it suitable for advanced security testing and educational purposes. The tool operates through a user-friendly app with multiple firmware support and connects seamlessly to the Flipper Zero without the need for additional wiring or flashing.
2026-08-03
Rust
★ 89
ADhammer is an Active Directory security-assessment toolkit implemented in Rust that functions as an auditor similar to PingCastle, capable of mapping domain attack paths with scoring, graphing, and MITRE tagging. It performs low-privileged audits via LDAP, validates identified vulnerabilities using live offensive techniques, and supports execution on both Kali Linux and Windows as a single static binary. Notable features include its custom-built DCE/RPC and Kerberos stack, extensive checks across various security categories, and the ability to export findings to BloodHound.
2026-08-03
Python
★ 617
ADscan is a comprehensive Active Directory pentesting tool designed for Linux environments that consolidates 103 attack techniques into a streamlined CLI interface. Its primary use case lies in automating the penetration testing process for red teamers and security professionals, providing capabilities such as enumeration, Kerberoasting, and attack-path analysis without the need for Windows. Notable features include fully automated scans through the 'adscan ci' command, which allows for both authenticated and unauthenticated assessments while leveraging Docker for its operational environment.
2026-08-03
Python
★ 56
BabooSSH is a specialized tool designed for red teams to facilitate SSH spreading from a compromised host, enabling quick reconnaissance and compromise of additional SSH endpoints. Its notable features include straightforward installation via pip, automated tests using pytest integrated into GitHub Actions, and an evolving documentation site.
2026-08-03
Lua
★ 1350
The Cheat Engine MCP Bridge is a tool that leverages AI capabilities to streamline the analysis of program memory, significantly reducing the time required for reverse engineering tasks such as locating pointers, tracing operations, and documenting structures. Notable features include support for automatic memory reading and structure analysis, the ability to follow pointer chains, and disassembly functionalities, all of which transform tedious manual processes into quick, conversational queries directed at the memory. This tool is particularly useful for creating game mods, trainers, and conducting security audits efficiently.
2026-08-03
Python
★ 3936
Claude-BugHunter is a comprehensive skill bundle for the Claude Code system, designed to enhance bug-hunting and red-team operations with 82 curated skills and 15 commands. It features a structured approach to vulnerability detection, engagement scaffolding, and automated reporting, drawing from a vast collection of 681 disclosed report patterns across 24 core vulnerability classes. Notably, it integrates with Burp MCP and provides enterprise identity and infrastructure attack matrices for sophisticated security assessments.
2026-08-03
Python
★ 133
Cochise is an autonomous penetration testing tool that leverages large language models (LLMs) to exploit vulnerabilities in Microsoft Active Directory environments. With a minimalistic design, Cochise allows users to easily customize and benchmark various LLMs, effectively orchestrating attack procedures including command execution and credential harvesting, all without requiring human intervention. Notable features include a dual-layer architecture comprising a strategic Planner and tactical Executor, along with built-in context management and analysis support for log file evaluation.
2026-08-03
Python
★ 139
The cvemapping tool aggregates CVE exploit data from GitHub, allowing users to clone repositories or export CVE information in JSON format for web use. It features options for pagination and year-specific searches, making it versatile for both developers and security researchers aiming to analyze or present CVE-related data efficiently. Notable features include the ability to authenticate using a GitHub token and the straightforward export functionality for integration with web applications.
2026-08-03
Python
★ 143
Cyber Controller is a versatile application designed for flashing and controlling multiple ESP32 devices through a unified interface, facilitating both firmware installation and real-time management. It supports 50 firmware profiles and can operate over various interfaces, making it suitable for authorized security testing and educational purposes. Key features include simultaneous commands for multiple devices, anti-bricking safeguards, and compatibility with touchscreens or headless setups, enhancing user experience in cyberdeck operations.
2026-08-03
PHP
★ 20
Cywise is a cybersecurity solution designed for both on-premises and SaaS environments, enabling users to scan and secure their web-facing and internal infrastructures. It features a robust vulnerability scanner that monitors for over 50,000 vulnerabilities with automated remediation, alongside active data leak monitoring and intelligent honeypots to detect and analyze potential threats. This tool is particularly suitable for small to medium-sized enterprises looking to enforce comprehensive security measures while maintaining control over their data and infrastructure.
2026-08-03
★ 110
The 'Daily Bug Bounty Writeups' repository provides a collection of detailed writeups related to bug bounty exploits and vulnerabilities. It's primarily aimed at cybersecurity professionals and bug bounty hunters seeking insights on various security misconfigurations, pentesting techniques, and practical exploit scenarios. Notable features include links to external articles that cover cloud security misconfigurations, advanced web application security testing, and guides for utilizing GitHub as a reconnaissance tool.
2026-08-03
Python
★ 165
DPULSE is an advanced desktop application designed for domain OSINT and reconnaissance, streamlining the process to gather intelligence from open sources with minimal setup. Key features include automated WHOIS and subdomain enumeration, interactive network graph visualizations, real-time security analysis, and integrated API support, all presented in an easily navigable HTML report. This tool serves OSINT professionals looking to enhance their domain reconnaissance workflows while maintaining a user-friendly interface across Windows and Linux platforms.
2026-08-03
C++
★ 263
ESP-HACK is a comprehensive firmware for the ESP32 designed for radio frequency research and penetration testing, encompassing protocols in RF, Bluetooth, infrared signals, and GPIO integrations. Targeted at enthusiasts and pentesters, the tool features a wide array of functionalities including WiFi deauthentication, Bluetooth spamming, Sub-GHz signal analysis and jamming (where legal), and infrared control capabilities, all while permitting extensive customization through GPIO and support for various modulations. Its versatility makes it an essential resource for exploring and testing a variety of wireless communication technologies.
2026-08-03
Python
★ 393
`evil-winrm-py` is a Python tool designed for executing commands on remote Windows systems via the WinRM protocol, featuring an interactive shell with capabilities for file upload/download, command history, and colorized output. It supports various authentication methods, including NTLM and Kerberos, and offers advanced functionalities such as in-memory execution of local scripts and DLLs, making it highly versatile for authorized penetration testing and educational purposes. The tool prioritizes user experience with features like command auto-completion, comprehensive logging, and a lightweight design, enhancing usability for cybersecurity professionals.
2026-08-03
Python
★ 47
The Exegol-resources repository provides essential resources for users of the Exegol penetration testing framework, aiding in activities such as pentesting, bug bounties, and CTFs. This repository contains files that are automatically integrated and updated by the Exegol wrapper, ensuring seamless access to tools and information within Exegol containers. Notable features include automatic downloads and shared usage capabilities for enhanced efficiency during security assessments.
2026-08-03
★ 191
Awesome Hacking is a comprehensive aggregation of curated lists designed for hackers, pentesters, and security researchers, emphasizing various domains within cybersecurity. Its primary use case is to provide users with easy access to a diverse range of resources—including security tools, educational materials, and research documentation—facilitating knowledge sharing and skills development in the security community. Notable features include contributions from the community, a wide variety of categories such as Bug Bounty and CI/CD Attacks, and extensive resources for practical learning in cybersecurity.
2026-08-03
★ 25
The "Awesome Penetration Testing" repository serves as a comprehensive collection of resources for penetration testing and offensive cybersecurity activities. It categorizes tools and materials spanning various aspects of security testing, including network reconnaissance, exploit development, and OSINT, providing a valuable reference for security professionals and enthusiasts. Notably, it encourages community contributions and offers structured categories for easy navigation of resources.
2026-08-03
Python
★ 22
The "Awesome Web Security" repository offers a comprehensive and curated collection of resources and materials focused on web security topics. Its primary use case is to educate users on various vulnerabilities such as XSS, SQL Injection, and CSRF, along with techniques for penetration testing and security research. Notable features include an AI integration for real-time queries, extensive categorization of topics, and a strong emphasis on community contributions.
2026-08-03
Python
★ 309
GCPwn is a framework for conducting offensive security assessments on Google Cloud environments, facilitating credential handling, service enumeration, and attack-path analysis through graph-based outputs. It supports workflows for reconnaissance, exploitation, and data collection, allowing users to execute predefined exploitation modules and export findings in various formats. Notable features include extensive API behavior tracking, IAM analysis, and the ability to generate OpenGraph outputs for privilege escalation reviews.
2026-08-03
Python
★ 18
The h4cker_b00k repository is a comprehensive guide aimed at providing detailed Capture The Flag (CTF) write-ups and insights into ethical hacking practices. It serves as a valuable resource for both beginners and experienced cybersecurity professionals, featuring practical knowledge, techniques, and solutions to enhance skills within the field. Notable features include categorized content for generic tools, initiation into hacking, and advanced hacking topics, facilitating structured learning and community contribution.
2026-08-03
Python
★ 464
HackAgent is a Python-based SDK and CLI tool designed to automate the security testing of AI agents, specifically targeting vulnerabilities such as prompt injection, jailbreaking, goal hijacking, and tool misuse. It employs a modular architecture featuring an attack engine, generator, and judge to evaluate the robustness of AI agents against research-backed attack techniques, enabling security researchers and developers to proactively identify and mitigate potential exploits. Additionally, HackAgent offers a standalone binary for varied platforms, eliminating the need for a Python environment, which enhances accessibility for users.
2026-08-03
Python
★ 186
Information Security Tasks is a collaborative repository that serves as a comprehensive resource for cybersecurity professionals, offering real-world infosec notes and methodologies. It features extensive directories covering offensive and defensive security topics such as penetration testing, incident response, and vulnerability analysis, alongside daily auto-updates of news and tools. Notable elements include an organized structure for various cybersecurity domains, community submission options for resources, and insights into emerging threats like AI and cloud security.
2026-08-03
Python
★ 21
KeyHunter is a specialized tool for detecting API key leaks from various sources, including subdomains, archived URLs, and APK files. It automates subdomain enumeration, URL collection, and APK scanning while employing advanced techniques like asynchronous processing for efficient scanning and customizable detection patterns. Notable features include validation of live endpoints, automatic dependency installation, and the ability to generate structured reports focused on identified API key leaks.
2026-08-03
Shell
★ 18
LinEnum-ng is a targeted, stable enumeration script designed for Linux privilege escalation, particularly suited for OSCP examinations. Its notable features include kernel CVE detection for various exploits, comprehensive checks for SUID and sudo vulnerabilities with GTFOBins integration, as well as support for container escape assessments in Docker and Kubernetes environments. The output is structured and color-coded for efficient triaging, minimizing information overload.
2026-08-03
Shell
★ 125
mac-cyber-bootstrap is a robust setup script designed to transform a fresh macOS environment into a fully functional security workstation specifically for cybersecurity professionals, CTF participants, and bug bounty hunters. It automates the installation of essential tools, libraries, and configurations under a structured directory, ensuring an organized workspace for various tasks such as OSINT, penetration testing, and malware analysis. Notable features include comprehensive toolchain installations across multiple domains, such as reconnaissance, red teaming, and reverse engineering, all managed through a single command.
2026-08-03
Python
★ 13148
The OWASP Mobile Application Security Testing Guide (MASTG) serves as a comprehensive resource for mobile app security testing and reverse engineering, aligning with the OWASP Mobile Security Weakness Enumeration (MASWE) and the Mobile Application Verification Standard (MASVS). It features detailed methodologies for validating security weaknesses and offers tools like mobile app security checklists and interactive exercises, enhancing both understanding and practical application of mobile security principles.
2026-08-03
Shell
★ 446
The "missing-cve-nuclei-templates" tool automates the identification and cataloging of missing CVEs in the official Nuclei templates repository, analyzing over 164,000 CVEs to produce a comprehensive list of 65,840 missing entries. It categorizes vulnerabilities by type and year, offering detailed data files for specific threats such as XSS, RCE, SQL Injection, and more, enhancing vulnerability management and template development for cybersecurity professionals. This tool facilitates better detection capabilities by flagging gaps in existing Nuclei templates.
2026-08-03
PowerShell
★ 12
MovementHound is a PowerShell tool designed for active enumeration of lateral movement capabilities in Windows environments, focusing on the effective rights a principal possesses rather than simple group memberships. This approach allows users to identify potential access paths that may be overlooked by traditional enumeration methods, making it particularly effective in environments with modified DACLs and security descriptors. Notable features include integration with BloodHound Legacy for detailed access mapping and a comprehensive output that aids in identifying persistent footholds during security assessments.
2026-08-03
Go
★ 356
Nerva is a high-performance command-line interface (CLI) tool for fast service fingerprinting, capable of identifying over 170 network protocols across various transport layers including TCP, UDP, and SCTP. It is designed for use in network reconnaissance, providing features such as rich metadata extraction, security misconfiguration detection, and support for various output formats. Notably, Nerva integrates seamlessly with other security tools like Naabu, enabling automated workflows and robust scanning capabilities.
2026-08-03
Python
★ 144
NyxStrike is an AI-powered offensive security orchestration engine that streamlines the execution of full attack chains, encompassing reconnaissance, exploitation, and reporting phases in a matter of minutes. Notable features include the ability to control over 185 offensive security tools through AI agents, a modular tool registry for easy customization, and compatibility with various AI clients via the MCP framework, all while providing a real-time session dashboard for monitoring and management.
2026-08-03
Python
★ 1000
OpenDoor is an open-source CLI platform designed for authorized web reconnaissance, focusing on directory discovery and subdomain enumeration. It includes features such as WAF detection, bypass probing, and detailed reporting tools, making it ideal for security researchers and penetration testers to identify exposed resources and vulnerabilities on web servers. The tool emphasizes ethical usage, requiring explicit permission for testing.
2026-08-03
Shell
★ 16
B1ackOS is a Debian-based international operating system designed to simplify software installation while emphasizing user privacy and security. It features a lightweight setup, live usage capability, a rolling release model for up-to-date software, and extensive repositories catering to a wide range of applications from mundane tasks to advanced programming and penetration testing. The system prioritizes stability and compatibility, making it a robust choice for users seeking a secure computing environment.
2026-08-03
HTML
★ 31
OSCP+ Complete Exam Checklist & Attack Chains (2025-26) is a comprehensive resource designed to aid candidates in navigating the OSCP exam format, emphasizing techniques for enumeration, exploitation, and lateral movement within a simulated environment. It offers structured methodologies for tackling Active Directory and standalone systems, alongside practical strategies for efficient time management during the exam. Notable features include a universal enumeration framework, a detailed breakdown of point allocation, and specific attack chains related to various scenarios, ensuring candidates are well-prepared for the challenges they will face.
2026-08-03
TypeScript
★ 1337
Pentest Copilot is an AI-driven penetration testing agent that autonomously connects to a Kali attack box to execute various security tools, analyze results, and iterate based on user-defined targets. It features a curated registry of over 100 capabilities, integration with Burp Suite for enhanced testing, real browser automation, VPN management, and the ability to utilize custom AI models. This comprehensive tool is designed for practical engagement scenarios, including CTFs and boot2root challenges.
2026-08-03
JavaScript
★ 64
PHANTOM is an AI-powered penetration testing command center designed to autonomously execute a range of security tasks without requiring constant human input. It features real-time tool execution, a multi-agent architecture for parallel processing, and self-improvement capabilities to enhance its toolset over time, all while providing a user-friendly dark UI and persistent context retention across sessions.
2026-08-03
Python
★ 371
`phantom-frida` is a tool that facilitates the building of customized Android Frida Server and Gadget from source while obfuscating specific runtime identifiers to enhance stealth capabilities against detection mechanisms. Its primary use case is for authorized application testing on Android devices, providing robust verification processes through unit and fixture tests, strict input validation during builds, and smoke tests on rooted devices. Notable features include support for custom builds, detailed artifact verification, and a comprehensive configuration for various architectures and specific runtime flags to reinforce security.
2026-08-03
Python
★ 187
PRISM is a self-hosted Open Source Intelligence (OSINT) platform that provides comprehensive scanning of domains, IPs, emails, phone numbers, and usernames across over 22 modules, delivering insights such as WHOIS data, threat intelligence, and OPSEC scoring. Notable features include real-time web dashboards, AI-driven summary analyses, and detailed report generation in HTML/PDF formats, making it an effective tool for risk assessment and threat investigation.
2026-08-03
Python
★ 27
pSlip is a comprehensive security scanning tool for Android applications, designed to detect cryptographic vulnerabilities, OAuth implementations, and manifest issues using a streamlined HTML reporting engine. Its notable features include a powerful searchable HTML report leveraging a field-scoped query language, structured extraction and export of recovered key material and secrets, and a user-friendly interface that supports rapid identification of findings without requiring Java dependencies. The tool optimizes scanning performance and minimizes false positives, enhancing the efficiency of mobile application security assessments.
2026-08-03
Python
★ 22
Python-Pentest-Tools is a collection of open-source Python scripts designed for penetration testing and cybersecurity research. The toolset emphasizes ethical usage for learning and understanding security practices, embodying core development principles for real hacking scenarios. Notable features include a variety of testing utilities suitable for educational purposes, though the author stresses responsible and ethical application.
2026-08-03
Nix
★ 27
Red-Flake Nix is a customized NixOS flake designed for penetration testing, red teaming, and CTFs, providing a pre-configured environment with essential tools and themes. Notable features include support for encrypted root on ZFS, a non-persistent root on tmpfs, systemd-boot with EFI, and integration of databases like PostgreSQL and Neo4j for Enhanced Metasploit and BloodHound capabilities. The setup is tailored with a customized KDE desktop and a variety of standalone tools, exploits, and wordlists for comprehensive cybersecurity operations.
2026-08-03
Go
★ 374
RF Swift is a versatile tool designed to quickly set up a comprehensive hardware and RF security lab using containerized applications, allowing security professionals to utilize over 200 tools without altering their primary operating system. It supports multiple platforms, including Linux, Windows, and macOS, across various architectures while offering the ability to run specialized images for different engagement types. Notable features include rapid deployment, host OS preservation, and the ability to run on x86_64, ARM64, and RISC-V64 systems.
2026-08-03
Go
★ 12
Rosemary is a cross-platform tool for transparent network pivoting and tunneling over QUIC, enabling seamless traffic interception on remote hosts without the need for proxies or special configurations. Its key features include kernel-level interception of TCP, UDP, ICMP, and DNS traffic, a comprehensive web dashboard for real-time monitoring, and support for multi-hop connections through multiple agents. This tool is designed for scenarios where secure and efficient access to remote networks is required without altering client configurations.
2026-08-03
Python
★ 129
S3DNS is a specialized DNS server designed for identifying exposed cloud storage buckets across various platforms such as AWS S3, Google Cloud Storage, and Azure Blob. Key features include recursive CNAME resolution, detection of potential subdomain takeovers, caching and rate limiting capabilities, and support for IPv6 checks against known cloud IP ranges. This tool is particularly beneficial for penetration testers and cloud security analysts engaged in reconnaissance activities.
2026-08-03
PowerShell
★ 111
Scoop Security is a Scoop bucket specifically designed for penetration testing and cybersecurity tools, enabling users to easily install and manage various security applications via PowerShell commands. Key features include a curated list of tools such as vulnerability scanners, webshell management clients, and advanced web scanning utilities, providing a comprehensive resource for security professionals. The setup process is streamlined through straightforward installation commands, facilitating quick access to essential cybersecurity tools.
2026-08-03
Python
★ 31
SecTools is a comprehensive repository of curated open-source and public tools designed for various cybersecurity applications, including OSINT, vulnerability analysis, and application security testing (SAST/DAST). It offers a user-friendly table that categorizes tools with their descriptions, licenses, and activity indicators, facilitating streamlined access to resources for security workflows. Notable features include a focus on UNIX compatibility and an organized structure that enhances usability across multiple security domains.
2026-08-03
Python
★ 90696
Hunt down social media accounts by username across social networks
2026-08-03
Python
★ 40
ShiftGrid is an open-source prompt engine designed for agentic penetration testing while maintaining human oversight. It facilitates the management of testing workflows through structured checklists and detailed observations, ensuring transparency and traceability of actions performed by agents. Notable features include an easily modifiable workflow system, real-time monitoring of agent activities, and the ability to switch between agents or manual testing seamlessly, all while maintaining independence from the specific models and workflows used.
2026-08-03
Rust
★ 12
Sniper is an open-source web security proxy designed for macOS that allows penetration testers, bug bounty hunters, and developers to intercept, inspect, and modify HTTP/HTTPS traffic. Built in Rust, it offers a lightweight and efficient alternative to traditional proxy tools, featuring capabilities such as HTTP forwarding, passive vulnerability scanning, request replay, and an integrated command-line interface for automation. Notable for its rapid startup time and low memory usage, Sniper provides a user-friendly experience without the overhead of Java-based platforms.
2026-08-03
C
★ 97
Specter transforms the Flipper Zero into a sophisticated counter-surveillance tool designed for detecting active 13.56 MHz NFC readers. This tool passively listens for RF emissions from hidden skimmers or covert readers, providing real-time feedback on the presence and type of detected devices, as well as the cleanliness of the environment. Notable features include an analog EMF gauge for proximity detection, a fingerprinting capability to classify the type of NFC reader, and the ability to log and monitor over time, enhancing situational awareness for security professionals.
2026-08-03
Go
★ 42
go-appsec/toolbox is a collaborative security testing tool designed for application security assessments through the Model Context Protocol (MCP). It enables users to interact with web applications via a proxy while an agent analyzes and manipulates the traffic, facilitating complex testing scenarios and more thorough identification of vulnerabilities. Notable features include built-in HTTP proxy capabilities, support for wire-fidelity and various protocols, and the ability to seamlessly integrate with existing tools like Burp Suite for enhanced testing workflows.
2026-08-03
Python
★ 184
The toolbox-pentest-web repository provides a lightweight Docker image designed for the assessment of web-based applications, including websites and APIs. It offers an up-to-date collection of offensive and defensive tools and scripts, optimized for size and usability, with recent expansions into mobile assessment. Key features include a non-root operating environment, continuous updates via GitHub Actions, and a comprehensive index of available scripts and resources.
2026-08-03
TypeScript
★ 250
VSCodium-Rust is a high-performance, agentic integrated development environment (IDE) tailored for AI engineers, enabling local machine learning model training and software development with enhanced data sovereignty. Key features include a multi-agent orchestration architecture for simultaneous task management, a native PyTorch ML studio for streamlined machine learning workflows, and robust Git integration, all while ensuring that user data remains secure and private. The IDE is built upon a lightweight Rust, Tauri, and TypeScript stack, promoting efficiency and autonomy in development processes.
2026-08-03
TypeScript
★ 577
VULNRΞPO is a client-side vulnerability report manager designed for security professionals, enabling users to generate, store, and manage vulnerability reports locally with a focus on privacy. The tool features client-side encryption, customizable issue templates for various security frameworks, and supports imports from multiple scanners, along with diverse export formats such as PDF and DOCX. Notable capabilities include integrated methodology tools, automated versioning, and optional backend storage via API for enhanced reporting functionalities.
2026-08-03
Python
★ 9772
The OWASP Web Security Testing Guide (WSTG) is a comprehensive framework designed for assessing the security of web applications and services through standardized testing methodologies. It provides structured scenarios with unique identifiers to facilitate consistent reporting and tracking of vulnerabilities, making it an essential resource for penetration testers and organizations worldwide. Notable features include detailed documentation of testing best practices and versioning for scenario identifiers to ensure clarity and consistency across updates.
2026-08-03
Python
★ 446
Zen-AI-Pentest is an AI-powered penetration testing framework designed for security professionals and red teams, leveraging advanced language models alongside over 72 integrated security tools. Its notable features include a user-friendly dashboard, REST API, and modular agent system for tasks like reconnaissance, exploitation, and reporting, as well as compliance mapping and risk scoring functionalities for thorough assessments.
2026-08-03
Go
★ 268
aiscan is an AI-driven penetration testing tool that integrates traditional security scanning with large language model (LLM) capabilities. It operates in three primary modes: a deterministic scanning pipeline, an autonomous natural language assessment agent, and multi-agent distributed collaboration for comprehensive security evaluations. Notable features include a single-binary architecture, a web console for management, and support for both standard and full editions that offer additional reconnaissance capabilities.
2026-08-03
HTML
★ 156
JAMBOREE is a comprehensive sandbox environment designed for Android security research, integrating tools like Magisk for root access, Burp Suite for proxy interception, and Objection for runtime manipulation within a unified system. Its primary use case is to facilitate seamless penetration testing and reverse engineering of Android applications, streamlining the workflow with features such as automated module management, efficient proxy configurations, and optimized emulator settings. Notable enhancements include a self-healing configuration system and multi-version compatibility, significantly reducing setup time and improving testing efficiency.
2026-08-03
TypeScript
★ 306
Pensar Apex is an AI-driven penetration testing tool that facilitates blackbox and whitebox assessments directly from the terminal. Its primary use case includes automating vulnerability detection with features like severity scoring, evidence collection, and integration into CI/CD workflows. Notable features include agent-driven swarm testing for large attack surfaces, persistent memory for automated workflows, and support for manual investigations through an operator mode.
2026-08-03
Go
★ 53
bgscan is a high-performance, modular multi-protocol network scanner implemented in Go, designed for host discovery and validation across various protocols including ICMP, TCP, HTTP, and DNS. Notable features include a fully keyboard-driven terminal user interface (TUI) for real-time monitoring, the ability to chain scan stages into pipelines for efficient scanning workflows, and robust data handling capabilities with options for output to CSV and integration with existing IP lists.
2026-08-03
★ 102
The "CIDR IP Ranges By Country" repository provides a comprehensive directory of CIDR IP ranges for both IPv4 and IPv6, organized by country. This tool is primarily used for network management and geolocation services, with the notable feature of being updated every hour to ensure accuracy and relevancy. Users can easily access IP range files for specific countries to facilitate their networking needs.
2026-08-03
Python
★ 61
CyberDeck is a terminal-based penetration testing command dictionary and cookbook designed for information security professionals, featuring a sci-fi CRT aesthetic. Its primary use case is to provide quick access to organized commands and multi-command playbooks across various phases of penetration testing, enhanced by a dynamic command database and full-text search capabilities. Notable features include customizable interfaces, clipboard integration for instant command copying, and fallback CLI functionality for environments lacking a `curses` interface.
2026-08-03
Python
★ 880
DarkMoon is an open-source, AI-powered autonomous penetration testing platform designed to conduct end-to-end security assessments without manual intervention. Notable features include a privacy gateway that ensures sensitive data remains secure, integration with over 50 pen-testing tools, and automated vulnerability reporting. This tool is particularly advantageous for security teams and DevSecOps engineers seeking to streamline and scale their defensive operations while maintaining strict data sovereignty.
2026-08-03
Shell
★ 3619
EMBA is a comprehensive security analyzer specifically designed for the firmware of embedded devices, catering to penetration testers, product security teams, and developers. The tool facilitates the entire security analysis workflow, including firmware extraction, static and dynamic analysis through emulation, SBOM generation, and the creation of web-based vulnerability reports, effectively identifying potential weaknesses such as insecure components or hard-coded passwords. Its command-line interface and ability to present findings in an accessible web format enhance usability and streamline the security assessment process.
2026-08-03
Crystal
★ 87
gori is a versatile interception and analysis tool that acts as a capturing proxy for various protocols including HTTP/1.1, HTTP/2, WebSocket, gRPC, and SSE. Its primary use case is to capture, replay, fuzz, and scan HTTP flows, providing features like a searchable flow history, inline decoding of tokens, and integration with AI agents for automated engagement. Notable features include an intruder-style fuzzer, a command palette for efficient navigation, and a headless mode for scripting, making it suitable for both manual and automated testing scenarios.
2026-08-03
Shell
★ 116
Hacknetics is a comprehensive resource repository designed for OSCP students and Red Teaming professionals, offering a curated collection of code snippets, guides, and pentesting tools. Notable features include ready-to-use code in multiple programming languages, high-level strategies, step-by-step guides, and regular updates to ensure access to the latest techniques and tools essential for penetration testing.
2026-08-03
CSS
★ 12193
HackTricks is a comprehensive repository that serves as a knowledge base for cyber security methodologies, tools, and techniques. Its primary use case is to provide users with an extensive collection of hacking tricks and strategies, including guides on various domains, penetration testing, and vulnerabilities. Notable features include organized categories for easy navigation and curated links to external resources for deeper exploration of security concepts.
2026-08-03
Python
★ 131
Humanbound is an open-source adversarial testing engine designed specifically for AI agents, enabling users to simulate realistic user interactions and potential attacks through live endpoints and multi-turn conversations. Its notable features include the ability to transform test failures into deployable firewall rules and compatibility with both local environments and the Humanbound Platform, making it straightforward to initiate tests without authentication. The tool also supports various integration options, allowing for flexible deployment and configuration.
2026-08-03
C
★ 521
KASLD is a tool designed to recover the Linux kernel's virtual and physical memory layout, specifically the kernel text base, from a local process by leveraging various system evidence and architectural invariants. Its primary use case is kernel Address Space Layout Randomization (KASLR) derandomization, which allows users to infer potential kernel text placements even in hardened environments. Notable features include support for multiple architectures, an inference engine that fuses evidence from various techniques, and the ability to report the upper bounds of KASLR protection based on the collected data.
2026-08-03
Go
★ 177
The rix4uni/medium-writeups repository aggregates recent articles and write-ups focused on cybersecurity, penetration testing, and security awareness from Medium. Its primary use case is to provide users with timely content related to various security topics, including the OWASP Top 10 vulnerabilities and advanced pentesting techniques. Notable features include categorization by tags such as "security," "hacking," and "infosec," allowing for easy navigation and discovery of relevant materials.
2026-08-03
Python
★ 24
OpenEASD is an open-source external attack surface discovery (EASD) tool designed for red teamers and defenders, enabling users to rapidly map and assess external surfaces of authorized targets without the expense of commercial solutions. It integrates multiple recon tools—such as `subfinder`, `amass`, and `nmap`—into a single web interface, offering features like scheduling, alerts, and findings tracking, while ensuring results remain local to the user's infrastructure. This self-hosted platform emphasizes transparency and security through careful sourcing of its components and is aimed at small security teams, consultancies, and individual security learners.
2026-08-03
TypeScript
★ 24697
Promptfoo is a command-line interface (CLI) and library designed for evaluating and red-teaming large language model (LLM) applications. Its primary use case involves automated testing of prompts, vulnerability scanning, and model comparison, enabling developers to enhance security and reliability in their AI applications while running evaluations locally without exposing data. Notable features include integration with CI/CD workflows, comprehensive security reporting, and support for multiple LLM providers, allowing for a developer-centric, flexible, and data-driven approach to AI application development.
2026-08-03
Python
★ 13
RCEKit is a Python-based toolkit designed for the detection and confirmation of remote code execution (RCE) vulnerabilities, specifically for authorized penetration testing and security research. It provides a robust CLI interface to assess targets by employing multiple verification methods against real-world CVEs, generating definitive "confirmed" verdicts that can be utilized in security reports. Noteworthy features include support for various RCE classes, an easy-to-use setup without third-party dependencies, and the ability to produce evidence-based results, ensuring accurate detection rather than mere conjecture.
2026-08-03
★ 23
The "resolvers" tool provides a regularly updated list of DNS resolvers, with updates executed every hour. Its primary use case is to supply reliable and fresh DNS resolver information, categorized into three distinct files based on the recency of updates: resolvers updated within the last hour, stable resolvers from the past 24 hours, and all available resolvers. Notable features include automated saving of fresh resolvers using `dnsvalidator` and systematic organization for user accessibility.
2026-08-03
Shell
★ 98
scope is a CLI tool that provides a curated dataset for querying bug bounty program scopes across various platforms, including Bugcrowd and HackerOne. It enables security researchers to efficiently identify in-scope domains and assets through regular automated updates and a command-line interface for targeted searches. Notable features include categorized files for wildcards, domains, and GitHub repositories, along with a comprehensive list of in-scope and out-of-scope targets for enhanced usability in bug bounty activities.
2026-08-03
★ 436
Shodan Dorks is a specialized query catalog for Shodan that enhances the search experience by providing categorized and frequently updated dork lists, specifically for discovering various internet-connected devices such as cameras, industrial control systems, and network infrastructure. It features real-time updates every six hours to reflect current results and automatically purges queries that return zero results, making it a valuable tool for security professionals and researchers. The repository includes a wide array of search filters and exploitation details, enabling users to efficiently locate and assess vulnerable devices.
2026-08-03
Rust
★ 54
Subscan is a Rust-based tool designed for monitoring and analyzing blockchain data, primarily focusing on Polkadot and its ecosystem. Its notable features include automated testing workflows, extensive documentation, and container support via Docker, enabling seamless integration into development pipelines. Subscan aims to enhance visibility and insight into blockchain activity, providing developers with essential tools for data analysis and monitoring.
2026-08-03
★ 328
The "wordlists" repository provides curated French wordlists aimed at enhancing password cracking efforts targeting French-speaking individuals. It features pre-compiled lists free from complex characters for easier input, supporting integration with popular cracking tools like Hashcat and John the Ripper, while also referencing various online resources for comprehensive coverage. This tool is particularly useful for penetration testing and security assessments within the French context.
2026-08-03
★ 26
The wordpress-plugins repository is an automated monitoring tool that continuously aggregates and updates data from the official WordPress Plugin Directory, providing actionable insights for developers and security researchers. It utilizes GitHub Actions to refresh the metadata every six hours, allowing easy access to essential plugin information such as installation statistics, updates, and compatibility details in structured JSON format. Notable features include a custom data mining tool, JSON processing capabilities, and comprehensive analytics for tracking the overall health of the WordPress plugin ecosystem.
2026-08-03
★ 11
Writeups by zer00d4y
2026-03-30
Java
★ 739
Damn Vulnerable Bank is an intentionally vulnerable Android application designed to educate users on security flaws in banking apps. Its primary use case is for security professionals and developers to explore various vulnerabilities, such as root detection and insecure storage, by interacting with features like user registration, fund transfers, and transaction history. Notable features include fingerprint and PIN verification for transactions, as well as a gamified approach to discovering hidden vulnerabilities within the app.
2026-03-30
Go
★ 728
DllShimmer is a tool designed to facilitate DLL hijacking by allowing users to backdoor any function in a DLL without disrupting the normal operation of the host program. It generates proxy DLLs through a boilerplate C++ file and a corresponding .def file, ensuring that all exported functions maintain their original names and ordinal numbers, thus avoiding detection. Key features include support for both dynamic and static linking, the option to prevent multiple executions of the backdoor, and comprehensive debug logging capabilities.
2026-03-30
Python
★ 890
EvilWAF is a sophisticated transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing purposes. It operates at the transport layer, allowing seamless integration with various security tools while employing advanced techniques such as TCP and TLS fingerprint rotation, source port manipulation, and automated WAF detection to evade defensive mechanisms. Notable features include a comprehensive multi-layer WAF scanning capability, direct origin bypass, and a robust IP rotation strategy through Tor and proxy pools, ensuring effective assessment of firewall vulnerabilities.
2026-03-30
Go
★ 882
Fridare is an automation tool for modifying the Frida server on iOS, Android, Linux, and Windows platforms, designed to enhance security and flexibility by allowing users to change server names and ports while bypassing jailbreak detection. The tool features a dual-mode interface, offering both a robust command line and a modern graphical user interface (GUI) based on the Fyne framework, facilitating intuitive server modifications and visual feedback. Notable functionalities include cross-platform support, binary replacement, custom packaging, and dependency management, making it a comprehensive solution for Frida users across different environments.
2026-03-30
Shell
★ 740
GooHak is an automated tool designed for launching Google hacking queries against specified target domains to uncover vulnerabilities and facilitate enumeration. Its primary use case is to streamline the process of gathering information through tailored search queries, leveraging Google’s search capabilities. Notable features include straightforward command-line usage and dependencies tailored for Linux environments.
2026-03-30
Rust
★ 712
Heroinn is a cross-platform command-and-control (C2) and post-exploitation framework developed in Rust, designed primarily for research and educational purposes. Notable features include a graphical user interface (GUI), an interactive PTY shell, system information collection, file management with support for large files and resuming broken transfers, and compatibility with multiple operating systems including Windows, Linux, BSD, and macOS, leveraging various communication protocols such as TCP, HTTP, and reliable UDP.
2026-03-30
Ruby
★ 781
KillShot is a comprehensive penetration testing framework designed for information gathering and website vulnerability scanning. Its primary use case involves automating data collection through integrated tools such as WhatWeb and Nmap, while offering features like a CMS Exploit Scanner and web application vulnerability assessments, including XSS and SQL injection detection. The framework also facilitates backdoor generation and includes a fuzzer, making it a versatile tool for security professionals.
2026-03-30
Go
★ 726
NMAP-Formatter is a versatile tool designed to convert NMAP XML output into various formats such as HTML, CSV, JSON, Excel, and more, facilitating the analysis and reporting of network scan results. Notable features include support for output via stdin, the ability to generate diagrams using Graphviz, and options to skip down hosts, enhancing usability for security professionals and network administrators. This tool can also be utilized as a library in Golang for integration into other applications.
2026-03-30
PowerShell
★ 732
o365recon is a PowerShell script designed for retrieving information from Office 365 and Azure AD using valid credentials. Its primary use case is to facilitate information gathering for security assessments, with a notable feature allowing optional Azure querying through a simple command-line interface. The tool requires the installation of MSOnline and AzureAD modules and includes support for multi-factor authentication.
2026-03-30
Python
★ 747
onedrive_user_enum is a tool designed for enumerating valid OneDrive users by leveraging the HTTP response codes from file share URLs. Its primary use case is passive user enumeration, which avoids direct login attempts, making it less detectable by the target organization. Notable features include options for remote logging to MySQL, local SQLite database support, user list truncation, and mechanisms for de-duplication and user list management.
2026-03-30
★ 2083
The Pentest Book is a comprehensive resource for penetration testers, offering a collection of information, scripts, and methodologies gathered during various pentests. It serves as a practical guide for conducting recon, exploring vulnerabilities in web and cloud services, and utilizing tools like Burp Suite, complemented by cheat sheets and checklists. Key features include easy navigation, a searchable interface, and continuous updates to ensure relevance and accuracy in the fast-evolving cybersecurity landscape.
2026-03-30
Python
★ 761
Spoilerwall is a network hardening tool that obscures open ports by serving movie spoilers whenever a scan is performed, effectively misleading potential attackers. Its primary use case is to create a deceptive environment that appears vulnerable but instead provides mundane content, deterring unwanted attention and scans. Notable features include customizable spoiler content, easy server setup, and the ability to redirect all TCP traffic to the Spoilerwall service, enhancing security through obfuscation.
2026-03-30
Python
★ 750
Spoofy is a Python-based tool designed to evaluate the spoofability of domains by analyzing their SPF and DMARC records. It features authoritative lookups with a known DNS fallback, accurate bulk processing, and a customizable spoof logic derived from real-world testing, enabling users to conduct comprehensive assessments of domain security configurations. Additionally, Spoofy offers DKIM selector enumeration via API as an optional feature, making it a valuable resource for cybersecurity assessments.
2026-03-30
Shell
★ 1706
TermuxCyberArmy is a cybersecurity toolkit designed for Termux, primarily facilitating various hacking and scripting tasks. Notable features include compatibility with multiple Linux distributions such as Kali Linux and Parrot OS, as well as ease of installation using basic command-line operations. The tool is particularly suited for security practitioners seeking to enhance their skills in penetration testing and ethical hacking.
2026-03-30
HTML
★ 771
THC-Archive is a repository that consolidates all releases from The Hacker’s Choice, a prominent security research group. This collection serves as a backup for their work, ensuring that projects are preserved despite the lack of a full web server. Notable active projects include THC-Hydra, THC-IPv6, and utilities aimed at various hacking and security tasks.
2026-03-30
Shell
★ 732
TOP is a vulnerability cataloging tool designed for bug bounty hunters and penetration testers, focusing on proof-of-concept (PoC) exploits for various Common Vulnerabilities and Exposures (CVEs) from recent years. It compiles a list of notable CVEs along with their respective exploits and corresponding GitHub repositories, thereby facilitating ease of access and research for security professionals. Key features include organized yearly summaries of significant vulnerabilities, making it an essential resource for monitoring and exploiting security weaknesses.
2026-03-30
★ 806
Web Hacking is a comprehensive repository of notes focused on bug bounty hunting and penetration testing, collating various techniques for vulnerability discovery and exploitation. The tool features extensive reconnaissance and OSINT methods, a detailed list of common vulnerabilities, and bypass techniques, making it a valuable resource for security professionals seeking to enhance their skills and methodologies in web application security. Additionally, it encourages community contributions, fostering continuous improvement and updates of its content.
2026-03-30
Python
★ 743
WebKiller V2 is a Python-based tool designed for information gathering and CMS detection in web applications. Its primary use case is to aid cybersecurity professionals in identifying vulnerabilities and obtaining crucial data about target websites. Notable features include a user-friendly command-line interface, compatibility with multiple operating systems, and comprehensive installation instructions.
2026-03-30
TypeScript
★ 729
ZeusCloud is an open-source cloud security platform designed to discover, prioritize, and remediate security risks across AWS environments. Its notable features include asset inventory creation, attack path discovery, graphical visualization of risks, customizable security controls, and comprehensive remediation guides, all aligned with compliance standards such as PCI DSS and CIS benchmarks. This tool addresses the complexities and challenges of securing expanding cloud workloads with user-friendly and actionable insights.
2026-03-22
C++
★ 5651
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
2026-03-22
★ 2232
This challenge is Inon Shkedy's 31 days API Security Tips.
2026-03-22
★ 1933
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
2026-03-22
HTML
★ 1079
Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.
2026-03-22
Python
★ 843
Network Security Sniffer
2026-03-22
PowerShell
★ 2762
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
2026-03-22
★ 6722
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
2026-03-22
Shell
★ 1950
ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!
2026-03-22
Go
★ 4375
A Security Tool for Bug Bounty, Pentest and Red Teaming.
2026-03-22
Shell
★ 7958
This is a multi-use bash script for Linux systems to audit wireless networks.
2026-03-22
Shell
★ 6114
All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.
2026-03-22
★ 1157
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
2026-03-22
Rust
★ 1947
802.11 Attack Tool
2026-03-22
Python
★ 31783
734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
2026-03-22
★ 1435
API Security Project aims to present unique attack & defense methods in API Security field
2026-03-22
Go
★ 959
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
2026-03-22
Go
★ 882
Extract endpoints from APK files
2026-03-22
Python
★ 3514
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
2026-03-22
TypeScript
★ 1067
Automated pentest reporting with custom templates, project tracking, customer dashboard and client management tools. Streamline your security workflows effortlessly!
2026-03-22
JavaScript
★ 2445
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
2026-03-22
Shell
★ 982
基于ARL-V2.6.2修改后的版本
2026-03-22
Python
★ 1201
A modular vulnerability scanner with automatic report generation capabilities.
2026-03-22
Vim Script
★ 1267
Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!
2026-03-22
C++
★ 1609
RubberDucky like payloads for DigiSpark Attiny85
2026-03-22
Python
★ 1033
AutoPentestX – Automated Pentesting & Vulnerability Reporting Tool
2026-03-22
Python
★ 1094
AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.
2026-03-22
★ 973
A curated list of tools officially presented at Black Hat events
2026-03-22
★ 4079
A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
2026-03-22
C
★ 2011
A collection of awesome resources & modules for the Flipper Zero device. Best used with Rogue Master Flipper Zero Custom Firmware.
2026-03-22
Shell
★ 11108
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
2026-03-22
Python
★ 3788
Awesome hacking is an awesome collection of hacking tools.
2026-03-22
★ 1382
A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and enhance your hacking toolkit!
2026-03-22
★ 17364
A collection of hacking / penetration testing resources to make you better!
2026-03-22
★ 902
🦄🔒 Awesome list of secrets in environment variables 🖥️
2026-03-22
★ 3448
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
2026-03-22
★ 3384
A curated list of awesome OSCP resources
2026-03-22
★ 1597
A curated list of awesome privilege escalation
2026-03-22
★ 1268
Red Team Cheatsheet in constant expansion.
2026-03-22
★ 7282
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
2026-03-22
★ 4440
⚡️An awesome list of the best Termux hacking tools
2026-03-22
★ 7251
A list of web application security
2026-03-22
HTML
★ 1045
:baby: BabySploit Beginner Pentesting Toolkit/Framework Written in Python :snake:
2026-03-22
PowerShell
★ 2896
The Official Bash Bunny Payload Repository
2026-03-22
Python
★ 10522
The recursive internet scanner for hackers. 🧡
2026-03-22
Rust
★ 4394
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
2026-03-22
Shell
★ 3475
An ArchLinux based distribution for penetration testers and security researchers.
2026-03-22
Python
★ 5873
An OSINT tool to search for accounts by username and email in social networks.
2026-03-22
Go
★ 1100
↕️🤫 Stealth redirector for your red team operation security
2026-03-22
CSS
★ 950
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
2026-03-22
Go
★ 2529
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 28 protocols.
2026-03-22
HTML
★ 890
These are my checklists which I use during my hunting.
2026-03-22
Kotlin
★ 1438
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
2026-03-22
Python
★ 1465
Burp Suite Certified Practitioner Exam Study
2026-03-22
Java
★ 2285
A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.
2026-03-22
HTML
★ 3965
有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file
2026-03-22
Python
★ 1286
An advanced tool for email reconnaissance
2026-03-22
Python
★ 9668
Cybersecurity AI (CAI), the framework for AI Security
2026-03-22
Shell
★ 2568
🚀 Caido releases, wiki and roadmap
2026-03-22
Go
★ 5176
Cameradar hacks its way into RTSP videosurveillance cameras
2026-03-22
Python
★ 907
Web Content Discovery Tool
2026-03-22
Ruby
★ 966
Vagrant VirtualBox environment for conducting an internal network penetration test
2026-03-22
Go
★ 4741
📦 Make security testing of K8s, Docker, and Containerd easier.
2026-03-22
Python
★ 845
⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.
2026-03-22
Go
★ 1039
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
2026-03-22
Python
★ 1503
A default credential scanner.
2026-03-22
PowerShell
★ 1575
Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
2026-03-22
Rust
★ 21587
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
2026-03-22
Python
★ 1509
Obtain GraphQL API schema even if the introspection is disabled
2026-03-22
Python
★ 1414
ClatScope Info Tool – The best and most versatile OSINT utility for retrieving geolocation, DNS, WHOIS, phone, email, data breach information and much more (70+ features). Perfect for investigators, pentesters, or anyone looking for an effective reconnaissance / OSINT tool.
2026-03-22
Python
★ 4390
Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation
2026-03-22
Python
★ 1653
CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection
2026-03-22
Python
★ 2043
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
2026-03-22
Go
★ 1146
Awesome cloud enumerator
2026-03-22
Python
★ 2529
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
2026-03-22
★ 2101
Collection of quality safety articles. Awesome articles.
2026-03-22
Python
★ 5832
Automated All-in-One OS Command Injection Exploitation Tool
2026-03-22
Batchfile
★ 1076
Leaked pentesting manuals given to Conti ransomware crooks
2026-03-22
Python
★ 2137
Know the dangers of credential reuse attacks.
2026-03-22
Python
★ 879
All in One CRACKER911181's Tool. This Tool For Hacking and Pentesting. 🎭
2026-03-22
Python
★ 1582
LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping
2026-03-22
Python
★ 2548
CTF challenge (mostly pwn) files, scripts etc
2026-03-22
HTML
★ 796
Everything needed for doing CTFs
2026-03-22
Python
★ 2089
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
2026-03-22
C
★ 851
CTF Cheat Sheet + Writeups / Files for some of the Cyber CTFs that I've done
2026-03-22
HTML
★ 8032
Gather and update all available and newest CVEs with their PoC.
2026-03-22
Java
★ 950
🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
2026-03-22
Python
★ 1474
A collection of essential and foundational cybersecurity knowledge, thoughtfully organized for easy comprehension.
2026-03-22
★ 2020
Cybersecurity Career Path
2026-03-22
Go
★ 6573
60 Cybersecurity Projects | Certification Roadmaps |Everything you need to build your cybersecurity portfolio
2026-03-22
Go
★ 6077
CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, role-based testing with predefined security roles, a skills system with specialized testing skills, and comprehensive lifecycle management capabilities.
2026-03-22
Rust
★ 904
Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text
2026-03-22
Shell
★ 881
A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
2026-03-22
Python
★ 1623
Uses Empire's (https://github.com/BC-SECURITY/Empire) RESTful API to automate gaining Domain and/or Enterprise Admin rights in Active Directory environments using some of the most common offensive TTPs.
2026-03-22
Python
★ 5371
Autonomous Multi-Agent Based Red Team Testing Service / AI hacker
2026-03-22
Python
★ 1005
Unofficial DedSec Project GitHub Repository
2026-03-22
Python
★ 6727
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
2026-03-22
Shell
★ 2037
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
2026-03-22
Python
★ 1983
Find web directories without bruteforce
2026-03-22
Python
★ 3374
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。
2026-03-22
Shell
★ 3931
Custom bash scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux.
2026-03-22
Go
★ 2139
Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
2026-03-22
Python
★ 1052
DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discovery and security assessments.
2026-03-22
★ 2005
A multifunctional Telegram based Android RAT without port forwarding.
2026-03-22
JavaScript
★ 779
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
2026-03-22
★ 2553
List of Github repositories and articles with list of dorks for different search engines
2026-03-22
Ruby
★ 840
Dradis Framework: Collaboration and reporting for IT Security teams
2026-03-22
Python
★ 1850
Drone pentesting framework console
2026-03-22
Python
★ 1562
一款信息泄漏利用工具,适用于.git/.svn/.DS_Store泄漏和目录列出
2026-03-22
Python
★ 1035
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
2026-03-22
Objective-C
★ 1743
iOS/macOS/Linux Remote Administration Tool
2026-03-22
Python
★ 925
An Intelligent wordlist generator based on user profiling, permutations, and statistics. (Named after the same tool in Mr.Robot series S01E01)
2026-03-22
Python
★ 770
An OSINT tool that helps detect members of a company with leaked credentials
2026-03-22
Python
★ 1647
A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.
2026-03-22
Python
★ 1682
An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻
2026-03-22
★ 3429
Practical Ethical Hacking Labs 🗡🛡
2026-03-22
Ruby
★ 5298
The ultimate WinRM shell for hacking/pentesting
2026-03-22
Python
★ 2010
Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access.
2026-03-22
Python
★ 2416
An evil RAT (Remote Administration Tool) for macOS / OS X.
2026-03-22
Python
★ 3076
Fully featured and community-driven hacking environment
2026-03-22
HTML
★ 814
A security research site.
2026-03-22
Python
★ 1279
Convolutional neural network for analyzing pentest screenshots
2026-03-22
Shell
★ 2157
红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool
2026-03-22
Python
★ 6699
Open Source Vulnerability Management Platform
2026-03-22
★ 2436
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
2026-03-22
C++
★ 1024
Loading Remote AES Encrypted PE in memory , Decrypted it and run it
2026-03-22
Python
★ 2958
All In One Web Recon
2026-03-22
★ 770
:fire: Firecrack pentest tools: Facebook hacking random attack, deface, admin finder, bing dorking:
2026-03-22
Python
★ 768
:cookie: Flask Session Cookie Decoder/Encoder
2026-03-22
JavaScript
★ 1139
A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform
2026-03-22
Python
★ 12284
fsociety Hacking Tools Pack – A Penetration Testing Framework
2026-03-22
Python
★ 1820
A Modular Penetration Testing Framework
2026-03-22
Python
★ 3330
File upload vulnerability scanner and exploitation tool.
2026-03-22
Python
★ 8275
You Know, For WEB Fuzzing !
2026-03-22
★ 1775
Tips and Tutorials for Bug Bounty and also Penetration Tests.
2026-03-22
Shell
★ 812
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
2026-03-22
Go
★ 890
A tool to fastly get all javascript sources/files
2026-03-22
Python
★ 8228
Useful tool to track location or mobile number
2026-03-22
Python
★ 1895
The SpecterOps project management and reporting engine
2026-03-22
Python
★ 1471
A collection of tools to perform searches on GitHub.
2026-03-22
Go
★ 828
Find subdomains on GitHub.
2026-03-22
Go
★ 1598
🔪 :octocat: Leak git repositories from misconfigured websites
2026-03-22
★ 1500
Attack surface mapping
2026-03-22
Go
★ 1038
Interactive Network Scanner
2026-03-22
Go
★ 3643
🔍 Search anyone's digital footprint across 300+ websites
2026-03-22
Python
★ 873
被动式漏洞扫描系统
2026-03-22
Python
★ 1859
Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate intelligent, step-by-step penetration testing workflows while maintaining ethical hacking standards.
2026-03-22
Go
★ 14476
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
2026-03-22
★ 1047
Security Apps for Android
2026-03-22
★ 1237
A detailed plan to achieve proficiency in hacking and penetration testing, with pathways including obtaining a degree in cybersecurity or earning relevant certifications.
2026-03-22
Python
★ 1785
All in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog
2026-03-22
Python
★ 935
HackGPT Enterprise is a production-ready, cloud-native AI-powered penetration testing platform designed for enterprise security teams. It combines advanced AI, machine learning, microservices architecture, and comprehensive security frameworks to deliver professional-grade cybersecurity assessments.
2026-03-22
★ 1297
A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other notable sources.
2026-03-22
Python
★ 1230
Helping Ethical Hackers use LLMs in 50 Lines of Code or less..
2026-03-22
TypeScript
★ 6663
The all-in-one browser extension for offensive security professionals 🛠
2026-03-22
JavaScript
★ 2020
A container repository for my public web hacks!
2026-03-22
Python
★ 11464
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
2026-03-22
★ 1985
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
2026-03-22
Python
★ 1156
HostHunter a recon tool for discovering hostnames using OSINT techniques.
2026-03-22
TypeScript
★ 1249
Hundreds of Offensive and Useful Docker Images for Network Intrusion. The name says it all.
2026-03-22
Shell
★ 1074
Self contained htaccess shells and attacks
2026-03-22
★ 830
Handbook of information collection for penetration testing and src
2026-03-22
CSS
★ 5988
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
2026-03-22
Kotlin
★ 1745
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
2026-03-22
Python
★ 1303
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
2026-03-22
Shell
★ 1603
Asset inventory of over 800 public bug bounty programs.
2026-03-22
★ 1195
Most usable tools for iOS penetration testing
2026-03-22
Shell
★ 1171
🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
2026-03-22
Java
★ 2734
Plugin for JADX to integrate MCP server
2026-03-22
★ 3173
The cheat sheet about Java Deserialization vulnerabilities
2026-03-22
Java
★ 1639
HeapDump敏感信息提取工具
2026-03-22
HTML
★ 1077
Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework
2026-03-22
Java
★ 1778
jSQL Injection is a Java application for automatic SQL database injection.
2026-03-22
TypeScript
★ 13751
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
2026-03-22
Python
★ 836
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
2026-03-22
Python
★ 1301
K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动
2026-03-22
PowerShell
★ 6206
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
2026-03-22
Python
★ 817
KawaiiGPT — Open-source LLM gateway accessing DeepSeek, Gemini, and Kimi-K2 through reverse-engineered Pollinations API with no API keys required, built-in prompt injection capabilities for security research, Termux/Linux native support, and Rich console interface
2026-03-22
Python
★ 3414
A minimalist command line knowledge base manager
2026-03-22
C++
★ 2363
A simple keylogger for Windows, Linux and Mac
2026-03-22
Go
★ 4257
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
2026-03-22
Go
★ 2371
无状态子域名爆破工具
2026-03-22
HTML
★ 5448
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
2026-03-22
C#
★ 5272
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange
2026-03-22
Python
★ 8259
The most powerful Android RPA agent framework, next generation of mobile automation robots.
2026-03-22
★ 1029
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
2026-03-22
Python
★ 5518
Study Notes For Web Hacking / Web安全学习笔记
2026-03-22
★ 1694
This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.
2026-03-22
Go
★ 4901
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
2026-03-22
Python
★ 1647
OSINT Tool: Generate username lists for companies on LinkedIn
2026-03-22
Python
★ 1011
🔍 An OSINT tool for discovering linked social accounts and associated emails across multiple platforms using a single username.
2026-03-22
C
★ 5588
linux-kernel-exploits Linux平台提权漏洞集合
2026-03-22
Shell
★ 3974
Linux enumeration tool for pentesting and CTFs with verbosity levels
2026-03-22
Python
★ 1838
linuxprivchecker.py -- a Linux Privilege Escalation Check Script
2026-03-22
Shell
★ 2201
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
2026-03-22
Python
★ 1550
🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
2026-03-22
Rust
★ 1049
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
2026-03-22
Python
★ 37179
🕵️♂️ Collect a dossier on a person by username from thousands of sites
2026-03-22
Python
★ 4294
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
2026-03-22
Python
★ 1021
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.
2026-03-22
★ 1843
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.
2026-03-22
Go
★ 1737
OSINT tools and more but without API key
2026-03-22
★ 5174
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
2026-03-22
Go
★ 5396
Modlishka. Reverse Proxy.
2026-03-22
Python
★ 1331
🔥 A powerful MongoDB auditing and pentesting tool 🔥
2026-03-22
Python
★ 6979
Infection Monkey - An open-source adversary emulation platform
2026-03-22
Go
★ 5759
An automated e-mail OSINT tool
2026-03-22
Python
★ 1016
MSDAT: Microsoft SQL Database Attacking Tool
2026-03-22
★ 770
An extremely effective subdomain enumeration wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.
2026-03-22
C
★ 885
NetCat for Windows
2026-03-22
Python
★ 5821
The Network Execution Tool
2026-03-22
Python
★ 846
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of Netlas.io.
2026-03-22
Python
★ 5545
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
2026-03-22
Rust
★ 1360
NeuroSploit is an advanced, AI-powered penetration testing framework designed to automate and augment various aspects of offensive security operations. Leveraging the capabilities of large language models (LLMs).
2026-03-22
PowerShell
★ 9805
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
2026-03-22
Go
★ 1047
Idiomatic nmap library for go developers
2026-03-22
Go
★ 2087
A secure, efficient TCP/UDP tunneling solution that delivers fast, reliable access across network restrictions using pre-established TCP/QUIC/WebSocket or HTTP/2 connections.
2026-03-22
Crystal
★ 1396
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
2026-03-22
Go
★ 1555
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
2026-03-22
Java
★ 1656
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
2026-03-22
Rust
★ 2315
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
2026-03-22
Python
★ 3346
Automated NoSQL database enumeration and web application exploitation tool.
2026-03-22
Python
★ 1278
70k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
2026-03-22
Python
★ 985
Username enumeration and password spraying tool aimed at Microsoft O365.
2026-03-22
Python
★ 765
Open source pre-operation C2 server based on python and powershell
2026-03-22
Python
★ 1776
ODAT: Oracle Database Attacking Tool
2026-03-22
Dockerfile
★ 770
Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
2026-03-22
★ 1258
OffSec OSINT Pentest/RedTeam Tools
2026-03-22
★ 935
Offensive Security OSCP+, OSEP, OSWP, OSWA, OSWE, OSED, OSMR, OSEE, OSDA, OSIR, OSTH Exam and Lab Reporting / Note-Taking Tool
2026-03-22
Python
★ 9682
OneForAll是一款功能强大的子域收集工具
2026-03-22
Go
★ 3094
Rockyou for web fuzzing
2026-03-22
Go
★ 1104
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
2026-03-22
PowerShell
★ 3833
OSCP Cheat Sheet
2026-03-22
★ 849
My own OSCP guide
2026-03-22
★ 1074
OSCP Preparation Guide | Courses, Tricks, Tutorials, Exercises, Machines
2026-03-22
HTML
★ 2190
OSINT cheat sheet, list OSINT tools, wiki, dataset, article, book , red team OSINT for hackers and OSINT tips and OSINT branch. This repository will grow every time will research, there is a research, science and technology, tutorial. Please use it wisely.
2026-03-22
Python
★ 12474
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
2026-03-22
Go
★ 6541
A Modern Orchestration Engine for Security
2026-03-22
PHP
★ 2742
Single-file PHP shell
2026-03-22
Python
★ 1297
Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.
2026-03-22
Python
★ 1410
Passphrase wordlist and hashcat rules for offline cracking of long, complex passwords
2026-03-22
HTML
★ 7479
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
2026-03-22
PHP
★ 842
Work in progress...
2026-03-22
PowerShell
★ 2915
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
2026-03-22
Go
★ 22195
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
2026-03-22
Python
★ 1606
:no_entry: offsec batteries included
2026-03-22
Python
★ 3286
A collection of custom security tools for quick needs.
2026-03-22
★ 3439
⚔️Windows11 Penetration Suite Toolkit 🔰 The First Windows Penetration Testing Environment on Mac M Chips
2026-03-22
Python
★ 3025
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
2026-03-22
★ 1769
Awesome Pentest Tools Collection
2026-03-22
Python
★ 1055
Perun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架
2026-03-22
PHP
★ 885
Ruby on Rails Phishing Framework
2026-03-22
Python
★ 6147
An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.
2026-03-22
Go
★ 1636
:hammer: A modern multiple reverse shell sessions manager written in go
2026-03-22
Python
★ 1952
渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework
2026-03-22
Python
★ 3830
pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.
2026-03-22
Python
★ 1024
Find exploit tool
2026-03-22
Python
★ 1207
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
2026-03-22
PowerShell
★ 832
A post exploitation tool based on a web application, focusing on bypassing endpoint protection and application whitelisting
2026-03-22
PowerShell
★ 1447
This repository is a collection of powershell functions every hacker should know
2026-03-22
Python
★ 1179
Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment.
2026-03-22
Go
★ 1273
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
2026-03-22
C
★ 985
A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.
2026-03-22
PowerShell
★ 3937
Privilege Escalation Enumeration Script for Windows
2026-03-22
PowerShell
★ 1171
Dominate Active Directory with PowerShell.
2026-03-22
Go
★ 5934
Monitor linux processes without root permissions
2026-03-22
Python
★ 1468
Generates millions of keyword-based password mutations in seconds.
2026-03-22
Python
★ 2089
Notes about attacking Jenkins servers
2026-03-22
Python
★ 2892
(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.
2026-03-22
Shell
★ 1933
pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)
2026-03-22
Python
★ 1243
pentest framework
2026-03-22
Python
★ 4009
A high performance offensive security tool for reconnaissance and vulnerability scanning
2026-03-22
Python
★ 2128
:new: The Multi-Tool Web Vulnerability Scanner.
2026-03-22
JavaScript
★ 976
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
2026-03-22
Python
★ 2188
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
2026-03-22
Python
★ 1786
Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal
2026-03-22
★ 4463
Wiki to collect Red Team infrastructure hardening resources
2026-03-22
★ 10650
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
2026-03-22
Python
★ 2370
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
2026-03-22
PowerShell
★ 1214
RedSnarf is a pen-testing / red-teaming tool for Windows environments
2026-03-22
Java
★ 2569
红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具
2026-03-22
★ 9633
Tools and Techniques for Red Team / Penetration Testing
2026-03-22
PowerShell
★ 4682
Red Teaming Tactics and Techniques
2026-03-22
Java
★ 915
Java RMI Vulnerability Scanner
2026-03-22
HTML
★ 8805
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
2026-03-22
★ 1047
The most exhaustive list of reliable DNS resolvers.
2026-03-22
★ 11910
A list of resources for those interested in getting started in bug bounties
2026-03-22
Go
★ 1454
SSH based reverse shell
2026-03-22
Go
★ 2058
Reverse Shell as a Service
2026-03-22
Go
★ 1036
Statically-linked ssh server with reverse shell functionality for CTFs and such
2026-03-22
Shell
★ 843
Quickly analyze and reverse engineer Android packages
2026-03-22
Go
★ 2301
A tool to abuse Exchange services
2026-03-22
Rust
★ 813
Rustcat(rcat) - The modern Port listener and Reverse shell
2026-03-22
Rust
★ 1134
Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀
2026-03-22
Rust
★ 20345
🤖 The Modern Port Scanner 🤖
2026-03-22
Python
★ 1178
红队综合渗透框架
2026-03-22
Go
★ 6171
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
2026-03-22
★ 9023
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
2026-03-22
Go
★ 1264
Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration
2026-03-22
Python
★ 844
🍉一款基于Python-Django的多功能Web安全渗透测试工具,包含漏洞扫描,端口扫描,指纹识别,目录扫描,旁站扫描,域名扫描等功能。
2026-03-22
★ 914
Open source templates you can use to bootstrap your security programs
2026-03-22
★ 866
Some of my security stuff and vulnerabilities. Nothing advanced. More to come.
2026-03-22
★ 5051
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
2026-03-22
Python
★ 923
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
2026-03-22
PHP
★ 1802
Hashtopolis - distributed password cracking with Hashcat
2026-03-22
Go
★ 1634
ServerScan一款使用Golang开发的高并发网络扫描、服务探测工具。
2026-03-22
PowerShell
★ 1314
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.
2026-03-22
TypeScript
★ 47370
Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
2026-03-22
Go
★ 1132
An IIS short filename enumeration tool
2026-03-22
Rust
★ 923
Dangerously fast DNS/network/port scanner
2026-03-22
Python
★ 2763
Low bandwidth DoS tool. Slowloris rewrite in Python.
2026-03-22
Rust
★ 2517
Semi-automatic OSINT framework and package manager
2026-03-22
Shell
★ 11175
Attack Surface Management Platform
2026-03-22
Python
★ 3748
Snoop — инструмент разведки на основе открытых данных (OSINT world)
2026-03-22
JavaScript
★ 22260
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
2026-03-22
CSS
★ 4690
Phishing Tool & Information Collector
2026-03-22
★ 973
SpiderSuite releases, wiki and roadmap
2026-03-22
Python
★ 38321
Automatic SQL injection and database takeover tool
2026-03-22
Python
★ 1464
SSH-MITM - ssh audits made simple
2026-03-22
Python
★ 2507
SSRF (Server Side Request Forgery) testing resources
2026-03-22
Python
★ 1624
Automatic SSTI detection tool with interactive interface
2026-03-22
C++
★ 1290
:zap: Worlds fastest steghide cracker, chewing through millions of passwords per second :zap:
2026-03-22
Go
★ 3412
👻Stowaway -- Multi-hop Proxy Tool for pentesters
2026-03-22
Go
★ 2110
DNS Takeover tool written in Go
2026-03-22
Python
★ 1026
Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
2026-03-22
Go
★ 962
A Powerful Subdomain Takeover Tool
2026-03-22
Python
★ 973
Subdomain and target enumeration tool built for offensive security testing
2026-03-22
Shell
★ 2482
A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
2026-03-22
Shell
★ 2350
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
2026-03-22
JavaScript
★ 916
A cross-platform note-taking & target-tracking app for penetration testers.
2026-03-22
C
★ 12215
hydra
2026-03-22
Python
★ 1847
The Offensive Manual Web Application Penetration Testing Framework.
2026-03-22
★ 1848
For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙
2026-03-22
Python
★ 4008
🕵️ (2-in-1) Emaill and Username OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investigations, legitimate analysis
2026-03-22
Ruby
★ 1342
Username tools for penetration testing
2026-03-22
Python
★ 1562
Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns
2026-03-22
Go
★ 2152
Venom - A Multi-hop Proxy for Penetration Testers
2026-03-22
Python
★ 1310
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
2026-03-22
Python
★ 4441
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
2026-03-22
Python
★ 3505
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能
2026-03-22
Python
★ 2091
vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.
2026-03-22
Lua
★ 3781
Advanced vulnerability scanning with Nmap NSE
2026-03-22
Python
★ 1758
python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。
2026-03-22
★ 862
A OWASP Based Checklist With 500+ Test Cases
2026-03-22
Go
★ 1201
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
2026-03-22
HTML
★ 2590
Web Fuzzing Box - Web 模糊测试字典与一些Payloads
2026-03-22
Go
★ 1171
Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.
2026-03-22
Python
★ 1854
Reverse proxies cheatsheet
2026-03-22
Python
★ 844
WeirdAAL (AWS Attack Library)
2026-03-22
Python
★ 806
A deauth attack that disconnects all devices from the target wifi network (2.4Ghz & 5Ghz), WPA3 also supported (PMF not tested)
2026-03-22
C
★ 8618
windows-kernel-exploits Windows平台提权漏洞集合
2026-03-22
PowerShell
★ 3695
Automation for internal Windows Penetrationtest / AD-Security
2026-03-22
★ 1791
Real-world infosec wordlists, updated regularly
2026-03-22
Python
★ 974
Wordpress Attack Suite
2026-03-22
Go
★ 938
A fast WordPress plugin enumeration tool
2026-03-22
PHP
★ 764
WhiteWinterWolf's PHP web shell
2026-03-22
Perl
★ 1758
X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter
2026-03-22
Shell
★ 915
Android Penetration Tool [ RAT for Android ]
2026-03-22
Go
★ 1390
渗透测试C2、支持Lua插件扩展、域前置/CDN上线、自定义profile、前置sRDI、文件管理、进程管理、内存加载、截图、反向代理、分组管理
2026-03-22
Python
★ 1462
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
2026-03-22
JavaScript
★ 2207
XSS'OR - Hack with JavaScript.
2026-03-22
Python
★ 3595
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
2026-03-22
TypeScript
★ 7710
Cyber Security ALL-IN-ONE Platform