Red-Team
2026-08-31
Python
★ 115
**IKONA Security** is a comprehensive cybersecurity tool designed for research and auditing, featuring modules for penetration testing, bug bounty payloads, and security audits of various web frameworks such as Laravel and Next.js. Notable features include a collection of web exploitation payloads, curated wordlists for API endpoints and directory traversal, and both automated and manual bug hunting methodologies. This tool emphasizes responsible usage, intended strictly for educational and authorized testing purposes.
2026-08-31
Rust
★ 10
Warden is an autonomous endpoint detection and response (EDR) solution designed for Linux workstations, implemented in Rust to function without external servers or cloud dependencies. This tool monitors critical threat vectors such as ransomware, persistence mechanisms, privilege escalation, and malicious network activity, operating in either a monitoring or enforcement mode that allows for real-time response. Key features include robust detection modules tested rigorously through adversarial audits, local operation as a hardened systemd service, and optional eBPF capabilities for enhanced visibility into process execution and network connections.
2026-08-31
Makefile
★ 10
SECS (SECurity aSsistant) is a framework that transforms compatible AI coding agents into authorized security assistants, equipped to aid in various security lifecycle tasks such as reconnaissance, pentesting, and incident response. It features a governance policy, 35 curated agent skills for expert security methodologies, and a local toolchain with a practice lab, ensuring that all activities adhere to strict rules of engagement and operate within a controlled environment. Notably, the system incorporates an authorization gate to validate targets and enforce compliance, making it suitable for authorized security testing and defensive operations only.
2026-08-31
HTML
★ 18
VERDICT is an autonomous web and API penetration testing agent that employs AI to conduct vulnerability assessments, confirming findings through reproducible evidence. Its primary use case is for in-depth security evaluations, particularly in applications with complex authentication mechanisms, utilizing a real browser for accurate session handling and multi-step testing. Notable features include precise detection accuracy backed by recorded evidence, an ability to map and exploit unknown applications autonomously, and integration with tools like Burp, all while adhering strictly to defined testing scopes.
2026-08-30
Python
★ 104
Phantom is a multi-platform HTTP(S) reverse shell server and client implemented in Python 3, designed for securely establishing remote connections over HTTP or HTTPS. It features automatic certificate generation for HTTPS, bundled dependencies for seamless execution on Linux and Windows, and provides a user-friendly shell script for rapid certificate creation. The tool is tailored for penetration testing and remote administration scenarios, allowing quick setup and deployment for secure command execution.
2026-08-30
TypeScript
★ 47
0sec is an open and extensible AI-driven cybersecurity tool that automates vulnerability discovery, exploitation, and remediation across various layers, including web applications, APIs, source code, and network infrastructure. It supports multi-model and multi-agent capabilities to address complex security challenges, emphasizes continuous security over point-in-time assessments, and includes a command-line interface for streamlined interactions and automation of pentesting workflows. Notable features include the ability to find a wide range of vulnerabilities, integration with various environments and systems, and a focus on supply chain security and other emerging threat vectors.
2026-08-28
Go
★ 2537
Fibratus is a real-time security sensor designed for threat detection and protection, leveraging a behavior-driven rule engine and YARA memory scanning to analyze a wide range of system events. Its notable features include the ability to route events to various output sinks for further analysis, support for custom tool integration via filaments, and forensic capabilities to assist in understanding and responding to security incidents. The tool emphasizes real-time behavior detection, memory scanning, and comprehensive forensic analysis to combat advanced malware and attacker tactics.
2026-08-28
SCSS
★ 135
R3d-Buck3T is a comprehensive repository designed for penetration testing and red teaming activities, featuring an extensive collection of tools and commands across multiple security domains, including web application, cloud, network, and wireless security. Notable characteristics include detailed sections on Active Directory and vulnerability research, alongside a dedicated wiki for easy navigation and resource access. This tool serves as a vital asset for security professionals aiming to enhance their offensive security skills and methodologies.
2026-08-28
Rust
★ 19
Red Clippy is an open-source penetration testing management tool designed to integrate with AI agents for streamlined test engagements. It retains detailed records of assets, observations, and findings, ensuring that testing sessions can progress smoothly without loss of information, while enforcing protocols for data verification and reporting. Notable features include a web-based interface for managing test data, customizable engagement rules, and the ability to connect to AI agents for enhanced testing efficiency.
2026-08-28
Rust
★ 39
Stratum C2 is a cloud persistence framework designed to maintain command-and-control (C2) communication through trusted cloud storage providers like Dropbox and OneDrive, thus avoiding detection by traditional security defenses. Its notable features include end-to-end encryption with RSA and AES, the ability to switch between multiple cloud providers seamlessly, and a structurally unblockable channel that makes it difficult for security operations centers to intercept. The framework supports multiple agent formats for both Windows and Linux without requiring additional dependencies.
2026-08-27
C
★ 48
SLEEPWALKER is a passive backdoor tool designed for offensive security tasks, featuring a 64-bit Windows DLL that impersonates `dpapi.dll` and loads into ESET's Management Agent. It utilizes a proprietary command language interpreted through a 23-opcode bytecode system, allowing for various operations including data transmission and remote execution of shellcode upon receiving a specific trigger packet. Notably, the tool includes a Python controller for compiling and encrypting commands, alongside a configurable architecture enabling advanced covert command execution and behavior customization.
2026-08-27
Shell
★ 12
Hermes Cybersecurity Lab is a comprehensive cybersecurity toolkit designed for the Hermes Agent, encompassing 2,077 skills, 131+ tools, and 28 frameworks, systematically organized across multiple repositories. Its primary use case includes security research, pentesting, forensics, and threat intelligence, with notable features like a preconfigured installation script, tool inventory awareness, and a structured methodology for tackling various phases of cybersecurity engagements. This ecosystem ensures continuous updates and knowledge accumulation, enhancing both operational efficiency and effectiveness in security practices.
2026-08-27
TypeScript
★ 308
Pentest Harness is an open-source AI-driven security testing workspace designed for authorized penetration testing, bug bounty research, and CTF engagements. Its notable features include a multi-provider LLM engine for seamless integration with various AI model APIs, durable session management for persistence and replay, and a fully customizable plugin architecture allowing for extensive configuration and adaptability. The tool prioritizes security with private credential storage and offers a dark theme interface for extended use during testing sessions.
2026-08-26
Python
★ 12
RPC-Triage is a static analysis tool designed to assess the Windows RPC attack surface by analyzing compiled PE binaries to identify registered RPC servers and their corresponding method signatures, security flags, and transport bindings. It uniquely ranks interfaces based on a composite score of reachability and danger, providing detailed receipts for transparency in scoring. Notably, the tool operates without the need for symbol files, making it effective on stripped binaries found in production environments.
2026-08-26
★ 117
Cyber Intelligence GPT is a specialized tool for operational security and cyber investigations, integrating OSINT, DFIR, threat intelligence, and AI security into a cohesive workflow. It enables users to collect, analyze, and report on information while providing capabilities for entity research, incident triage, and correlation of cyber threats across multiple public sources. Notable features include the ability to create collection plans, resolve contradictions, assess confidence in findings, and suggest strategic next actions based on intelligence gaps.
2026-08-26
Python
★ 17
PI Recon is a lightweight AI red teaming harness designed for authorized agent security challenges, facilitating a streamlined workflow of task acquisition, reconnaissance, validation, and summarization. It features continuous scheduling, bounded execution, multi-stage reconnaissance, structured summaries, and secure builds that do not expose sensitive information. This tool emphasizes simplicity and efficiency, making it an ideal choice for users looking to optimize their red teaming processes without the overhead of a heavier framework.
2026-08-26
Python
★ 244
Deep Focus is a high-performance asynchronous network reconnaissance tool designed for security researchers and network administrators to discover and fingerprint services across IP ranges. It features intelligent probing of common network services, detailed authentication detection, and structured export of actionable intelligence, all while managing system resources to prevent overheating on passively-cooled devices. Its notable capabilities include comprehensive scanning for services like HTTP, FTP, SSH, and more, along with robust thermal management to ensure optimal performance.
2026-08-26
Python
★ 12
RedAgent is an offensive security tool designed for authorized security teams to conduct adversary-grade testing across various surfaces, including web, API, cloud, and identity. It operates within strict authorization boundaries, enabling controlled and precise engagements while leveraging supervised AI to enhance expert workflows. Notable features include comprehensive auditing of operations, policy-gated engagements, and a focus on ensuring all actions remain within authorized scopes.
2026-08-26
PowerShell
★ 17
WinFlesher is an advanced attack surface security assessment tool designed for security professionals and auditors to automate the discovery of vulnerabilities and evaluate security postures in Active Directory and local infrastructures. Its notable features include real-time automated discovery of configurations and services, in-depth Active Directory analysis with a focus on trust and privilege relationships, a built-in attack paths engine for identifying potential escalation routes, and integrated remediation support with practical guides. The tool also provides a modern GUI for intuitive visualization of findings and security scores, enhancing the management of risk assessments.
2026-08-26
C#
★ 53
Atlas is a cross-platform network execution and security assessment toolkit designed for authorized penetration testing, leveraging TrustedSec's Titanis protocol library. It features modular enumeration capabilities across multiple protocols such as SMB, Kerberos, WMI, and LDAP, allowing for credential checks, session enumeration, and remote command execution, along with a streamlined workflow similar to NetExec. Notable features include multi-host concurrency, comprehensive authentication methods, and detailed console output, facilitating efficient security assessments across diverse network environments.
2026-08-26
★ 15
The repository provides a comprehensive collection of cybersecurity bookmarks curated by a senior information security engineer, focusing on critical topics such as OSINT, exploitation, privilege escalation, and malware analysis. It features over 40 tools for reconnaissance, privacy, and attack methodologies, along with curated news sources, making it a valuable resource for cybersecurity professionals looking to enhance their operational security and situational awareness. Notable features include categorized tools for specific cybersecurity tasks and a visually engaging presentation of the content.
2026-08-25
Python
★ 116
Guardana is an open-source AI security verification tool designed to assess AI artifacts and deployed models for security vulnerabilities from the build stage to production. It features 51 configurable security checks, deterministic evidence collection, and graded verdicts for attack impact assessment, ensuring comprehensive reporting on model behavior and security weaknesses. Notably, it maintains user privacy by avoiding telemetry and streamlines grading through swappable components, offering detailed outcomes and confidence metrics for its findings.
2026-08-25
Python
★ 10
The Phishlet Generator is an automated tool designed to streamline the creation of `.yaml` phishlet files for Evilginx3 by leveraging real browser automation with Playwright. Its primary use case is to eliminate the manual reverse-engineering of website login flows by capturing live network traffic during a simulated login process, which includes handling complex scenarios like CAPTCHA and 2FA challenges. Notable features include smart classification of fields and tokens, integration of anti-detection scripts, and the capability to generate production-ready configurations compatible with Evilginx3.
2026-08-25
Python
★ 19
Ruoyi-Scan is a specialized vulnerability scanning tool designed for RuoYi applications, featuring a plugin-based architecture and three-state assessment (CONFIRMED / SAFE / UNKNOWN) for vulnerability status. It supports bulk scanning, multiple report formats, WAF bypass techniques, and offers enterprise-level functionalities such as API integration and a robust plugin ecosystem for various common vulnerabilities. Noteworthy capabilities include automated AI-based POC generation, extensive reporting options, and compatibility with various operating environments.
2026-08-25
★ 139
Claude-AD is a plugin for Claude Code that streamlines the methodology for conducting Active Directory (AD) penetration tests. It organizes engagement phases such as setup, data collection, exploitation, and post-exploitation, while addressing environment-specific constraints and providing telemetry insights to enhance operational security. The tool integrates standard AD assessment techniques, orchestrating third-party tools like BloodHound CE and Impacket, ensuring effective execution of assessments aligned with compliance controls.
2026-08-24
Crystal
★ 113
CrystalPotato is a privilege escalation tool designed for Windows, enabling users with `SeImpersonatePrivilege` to elevate their permissions to SYSTEM level. It leverages DCOM OXID Resolver and named pipe impersonation techniques, dynamically resolving Windows APIs and allowing for the execution of commands, reverse shells, or local admin user creation. Notable features include XOR-obfuscated strings, command output by default, and a compiled single-file executable with no dependencies.
2026-08-24
Rust
★ 27
BTG Packer is a Rust-based research framework for the analysis, transformation, and virtualization of Windows x86-64 PE32+ executables. It features comprehensive functionality including PE reconstruction, control-flow transformation, RISC lifting, and runtime protection, making it suitable for security research and code modification tasks. Notable capabilities include its ability to generate polymorphic virtual machines, conduct advanced code analysis, and ensure build determinism and structural validation.
2026-08-24
Python
★ 87
PwnRM is an advanced WinRM post-exploitation tool designed for conducting authorized security assessments in Windows Active Directory environments. It features an interactive PowerShell runspace, support for various authentication methods, stealthy payload delivery, and a built-in Active Directory triage engine, enabling users to perform a wide range of assessment tasks through a command-line interface as well as via a Python library. Notable functionalities include file transfer capabilities, remote command execution, and comprehensive AD enumeration and session management features.
2026-08-24
JavaScript
★ 45
Mimic is a lightweight JavaScript library designed for conducting realistic phishing simulations by creating a fake browser interface on top of an existing webpage without the need for iframes. Utilizing Shadow DOM and MutationObserver technologies, it successfully renders the actual website’s content within a customizable fake browser viewport while preserving original styling and information, enabling more effective testing and demonstration of phishing attacks in a seamless manner. Notable features include a dependency-free design, automatic content injection, and the ability to mimic various browser elements like the address bar and site information.
2026-08-24
Python
★ 36
The 'redteam-skill' tool facilitates a semi-automated workflow for red teaming engagements, allowing operators to select modules that assist in penetration testing while recording findings in a `notes.md` file. It features a modular architecture encompassing various attack and reconnaissance techniques, with an emphasis on human oversight to ensure critical judgment and decision-making during operations. Notable functionalities include the automatic retrieval of previous notes and detailed process references for each module, enhancing the efficiency of security assessments.
2026-08-23
Python
★ 10
Oxide is a cross-platform remote access trojan (RAT) framework designed for security research and detection engineering, allowing users to demonstrate and analyze threat actor tactics, techniques, and procedures (TTPs) at the code level. It includes an implant written in Rust, a C2 panel implemented in Python, and provides comprehensive detection capabilities with paired YARA rules, Sigma rules, and incident response playbooks. The framework facilitates purple team exercises through a structured approach to understanding implant-panel communications and establishing effective detection strategies.
2026-08-22
Python
★ 10
IndustrialXPL-Forge (IXF) is an extensive Python-based security assessment and exploitation framework designed specifically for Operational Technology (OT), Industrial Control Systems (ICS), and related environments. It encompasses the entire attack lifecycle from reconnaissance to reporting, and it features over 1,190 modular tools, support for more than 50 protocols, and extensive integration with the MITRE ATT&CK for ICS framework, along with a significant library of vulnerabilities, offering a comprehensive resource for cybersecurity professionals in the industrial sector.
2026-08-22
Python
★ 21
The lldp tool is a Mythic C2 profile designed for peer-to-peer communication utilizing IEEE 802.1AB (LLDP), allowing covert data transmission within Organizationally Specific TLVs. It operates at Layer 2, requiring agents to be within the same broadcast domain, and features customizable OUI settings for blending with vendor-specific LLDP traffic. Key functionalities include HTTP/HTTPX agent egress for bridging to the Mythic server and enhanced security through configurable encryption modes and key exchange mechanisms.
2026-08-21
★ 21
Offensive File Transfer Techniques is an extensive guide designed for transferring files to and from target systems during security engagements, emphasizing staging payloads and exfiltrating data. It covers a diverse range of transport mechanisms, including HTTP, SMB, FTP, TFTP, and more obscure methods like base64 encoding, while also providing detection and defense mappings for each technique. The tool features organized notes with ready-to-use commands for both client and server setups, ensuring comprehensive coverage of file transfer methods in offensive security contexts.
2026-08-21
★ 22
Offensive Windows Privilege Escalation is a comprehensive guide designed for escalating privileges from a low-privileged Windows environment to Administrator or SYSTEM level, utilizing various techniques such as service misconfigurations, registry exploits, UAC bypass, and token-privilege abuse. The tool emphasizes an offensive security methodology, offering over 75 structured notes complete with hands-on exploitation and detection guidance, alongside ready-to-use commands and methodology checklists. It serves as an educational resource exclusively for authorized testing scenarios, ensuring ethical use in cybersecurity practices.
2026-08-21
Python
★ 32
SearchToolkit is an advanced collection of resources designed for penetration testers, red teamers, blue teamers, and forensic analysts. It includes tools, hardware, cheatsheets, and references across various cybersecurity domains such as geolocation tracking, OSINT, malware analysis, and bug bounties. Notable features include a comprehensive navigation system for quick access to specific areas of cyber defense and offense, highlighting its utility in diverse cybersecurity tasks.
2026-08-20
Python
★ 328
Consortium is a modern, extensible command and control (C2) framework that supports both asynchronous multi-client interactions and language-agnostic listener-agent designs, enabling users to develop custom agents and listeners efficiently. Key features include a robust REST API for automation, role-based access control for user management, and modular architecture that allows for extensive customization and collaboration among users. Currently in the alpha phase, the framework emphasizes a high degree of flexibility while still under rapid development.
2026-08-20
Python
★ 674
Cybermes is an advanced autonomous security research framework designed for offensive security tasks, including bug bounty hunting and red teaming. It features over 50 specialized modules for in-depth reconnaissance, attack surface analysis, and vulnerability validation, leveraging a unique integration of modern LLM reasoning and automated workflows. Notable capabilities include dynamic attack planning, multi-source knowledge retrieval, and programmatic validation of findings to ensure zero false positives.
2026-08-20
HTML
★ 11
WireTapper is a tool designed for detecting and mapping nearby wireless signals, including Wi-Fi networks, Bluetooth devices, IoT devices, and CCTV cameras. Its notable features include Wi-Fi detection with detailed information, Bluetooth scanning, and signal visualization on a user-friendly map interface, enabling users to gather intelligence from their environment effectively. The tool is intended for responsible use in compliance with local privacy laws and regulations.
2026-08-19
Ruby
★ 10
AWINRM is an advanced WinRM post-exploitation framework designed specifically for red teams and offensive research, implemented in Ruby. Its primary use case revolves around facilitating efficient post-exploitation activities with features like built-in tool staging, automated AMSI/ETW bypasses, stealth file transfers, and automatic loot extraction, addressing common challenges encountered in traditional WinRM tools. The framework provides a streamlined operator-centric workflow that enhances operational security and supports automated reconnaissance and credential gathering.
2026-08-19
Python
★ 18
PhantomTap is a machine learning-enhanced tool for the Flipper Zero, specifically designed for RFID/NFC fuzzing and access-control auditing. It utilizes active learning to intelligently generate test credentials, significantly reducing the number of reader queries required for effective security assessments, and produces an explainable audit report for identifying vulnerabilities in badge systems. Notably, it features efficient characterization, Bayesian population sizing, and integrates detection mechanisms to monitor real-time security threats.
2026-08-18
Python
★ 50
SMBScan is a tool designed for enumerating file shares on internal networks, allowing users to scan either a single target or a range of targets. Notable features include the capability to identify potentially sensitive files, support for guest and domain user authentication, and tactics to minimize detection by security teams. Additionally, it generates log files for comprehensive output analysis following scans.
2026-08-18
Python
★ 10
MetaView is a web-based interface for the Metasploit Framework that provides multi-user support and an intuitive user interface built on Vue3. Its primary use case is to facilitate project management and data visualization within penetration testing, enabling users to manage workspaces, visualize database entries such as hosts and vulnerabilities, and generate live dashboards. Notable features include integration with external tools (like MaxPatrol and Nmap), role-based access control, and task management functionalities.
2026-08-18
Python
★ 1815
Getsploit is a tool designed for searching and downloading public exploits from the Vulners database, facilitating both online searches and fully offline operations via a local SQLite index. Its notable features include a comprehensive query capability across multiple exploit collections, local query support without internet connectivity, and robust JSON and tab-separated output formats, all while maintaining data privacy and integrity. The tool is compatible with Python 3.11 and above, ensuring reliable performance across various platforms.
2026-08-18
PowerShell
★ 19
TCPK (Thick Client Pentest Kit) is a Windows-based security audit tool designed for comprehensive testing of thick-client applications, including MSIX, .NET, and Electron binaries. Noteworthy features include a PowerShell engine, live auditing with real-time findings, CVSS scoring, AI triage capabilities, and automated report generation in multiple formats, providing an exhaustive analysis for authorized testing environments. This tool emphasizes evidence-based findings and offers extensive checks, making it suitable for security professionals conducting in-depth application audits.
2026-08-17
C#
★ 746
NativeDump is a specialized tool designed for dumping the lsass process using native NT APIs to create a minimal Minidump file compatible with analysis tools like Mimikatz or Pypykatz. Key features include the use of functions from Ntdll.dll for stealth and bypassing API hooking, the capability to transfer dump data without writing to disk, and several implementations across various programming languages, enhancing portability and flexibility in deployment. It has been tested against modern Windows environments while offering optional enhancements for remote exfiltration and advanced obfuscation techniques.
2026-08-17
C#
★ 582
TrickDump is a tool designed for stealthily dumping the lsass process without generating a Minidump file, instead creating three JSON files and one ZIP file containing memory region dumps. Its primary use case is for bypassing conventional monitoring by executing three separate programs—Lock, Shock, and Barrel—that leverage NTAPIs for memory access, while offering various execution methods including different programming languages and techniques for API hook evasion. Notably, TrickDump allows for targeted execution without exposing process handles, enhancing its stealth capabilities against common antivirus and endpoint detection solutions.
2026-08-17
C#
★ 96
AddUser-SAMR is a tool for creating local administrators via the SAMR API, providing a lower-level alternative to traditional commands like `net.exe` and PowerShell's `New-LocalUser`. It supports multiple programming languages including C#, Python, Rust, Crystal, and Deno, and offers features such as custom username and password input, group specification, and verbose output. The tool requires administrator privileges for operation and retains existing users in the group without updating passwords.
2026-08-17
C#
★ 156
AutoPtT is a cross-platform tool designed for enumerating Kerberos tickets and executing Pass-the-Ticket (PtT) attacks, offering a standalone alternative to popular tools like Rubeus and Mimikatz. It provides various functionalities such as automated ticket retrieval, session listing, ticket export, and explicit ticket import, enabling users to perform interactive or stepwise attacks efficiently. Notable features include a user-friendly command structure and support across multiple programming languages including C#, Python, and Rust.
2026-08-17
Python
★ 161
cc-tree is a Claude Code plugin designed to transform open-ended thinking tasks into structured phylogenetic trees for easier auditing and exploration. It features a universal radial-tree exploration engine with four distinct presets—divergent brainstorming, adversarial critique, design-space exploration, and code audit—utilizing a disciplined approach where every generated node includes detailed evidence for its derivation. The tool emphasizes substantive convergence over arbitrary thresholds, ensuring that only high-value findings are further explored and represented in the tree structure.
2026-08-17
★ 532
Hacking Cheatsheets is a comprehensive resource designed for penetration testing and ethical hacking, offering a collection of quick reference guides for various tools and methodologies. Notable features include clear explanations of tool functionalities, command syntax with practical examples, and a structured attack methodology following the MITRE ATT&CK framework. Additionally, it provides defensive security guides for SOC analysts, covering incident response and log analysis.
2026-08-17
C#
★ 386
SAMDump is a tool designed for extracting Windows Security Account Manager (SAM) and SYSTEM files utilizing the Volume Shadow Copy Service (VSS) with options for local saving or remote transfer, along with XOR obfuscation for enhanced security. It supports multiple programming languages including C++, C#, Crystal, Deno, and Python, and is capable of listing and creating shadow copies as needed, while automatically cleaning up after use. Noteworthy features include file operation via NT API calls, support for various exfiltration methods, and automatic XOR encoding to protect the extracted data.
2026-08-16
HTML
★ 42
Zombieland is a browser-based command and control (C2) dashboard frontend designed for educational and authorized penetration testing research. It features mock agent management with grid and list views, a global console for broadcasting commands, and a modular UI that supports customization and enhanced visual effects. The tool is currently in development for backend and agent components, aiming for cross-platform compatibility and improved user management in future releases.
2026-08-16
Python
★ 88
HEAVEN is an autonomous penetration-testing framework designed to streamline and automate various stages of the penetration testing process, including reconnaissance, vulnerability detection, exploitation, risk scoring via machine learning, and reporting. It features a robust interface with 55 CLI commands, 77 API routes, and multiple scan modes, facilitating comprehensive assessments while allowing users to focus on critical decision-making tasks. Notably, it incorporates a CVSS machine learning predictor with a high correlation score, ensuring accurate risk evaluation.
2026-08-16
JavaScript
★ 34
P4wnP1 Infinition Payloads is a collection of JavaScript and Bash scripts designed for the P4wnP1 A.L.O.A. platform, facilitating credential harvesting, file exfiltration, and remote access primarily on Windows 10 systems. Notable features include the ability to stealthily operate through minimized PowerShell sessions, support for French and US keyboard layouts, as well as methods for disabling Windows Defender and retrieving sensitive information directly to a Samba share. This tool is intended for authorized penetration testing and security research.
2026-08-15
HTML
★ 13
AryterLink is a self-hosted, browser-based remote control panel designed for Termux on Android devices, enabling users to manage their smartphones from any browser globally. It offers capabilities such as SMS management, call handling, access to contacts, device controls (like flashlight and screen brightness), real-time battery stats, audio recording, and secure terminal shell access, all while ensuring data protection through robust security measures. Notably, it operates without the need for root access or third-party servers, relying solely on Python and direct interactions with the device's hardware via the Termux:API.
2026-08-15
Python
★ 13
jb_ape is an automated red-team engine designed to perform security assessments by probing target defenses, generating and mutating attack payloads through browser or API interfaces. It features a unique three-tier judgment system that ensures machine-verified outcomes for every attempt, employs a controlled submission budget to enhance efficiency, and utilizes reinforcement learning techniques to optimize the attack strategy while avoiding guessing. This tool is intended strictly for authorized use in sanctioned environments such as penetration testing or capture-the-flag competitions.
2026-08-15
★ 176
Awesome Recon Tools is a curated list of reconnaissance and footprinting tools designed to assist cybersecurity professionals in gathering domain and network information. It features a diverse array of tools for personal information footprinting, as well as specialized resources for analyzing web technologies, OSINT data collection, and visual network mapping. Notable features include integrations with services like Shodan, Censys, and Maltego, alongside functionalities for automated OSINT and detailed scanning of attack surfaces.
2026-08-15
TypeScript
★ 16
KageTarget is a Chrome extension designed for local web reconnaissance, enabling users to analyze the currently active tab or manually entered HTTP(S) addresses. Notable features include technology detection with evidence, detailed inspections of HTTP and security headers, and historical URL discovery through the Internet Archive, along with options for focused analysis and customizable user interface in multiple languages.
2026-08-15
★ 317
The OSCP-Pentesting-Cheatsheet serves as a comprehensive notes repository and study guide tailored for candidates preparing for the Offensive Security Certified Professional (OSCP) certification. It includes detailed enumerations using tools like Nmap for network scanning, explaining various scan types, traffic considerations, and OS fingerprinting techniques, thus aiding in efficient penetration testing practices. The cheatsheet is updated to remain relevant with upcoming exam changes, ensuring continuity of its commands and information.
2026-08-14
★ 114
Cyber Intelligence GPT is a custom AI tool designed to enhance open-source intelligence (OSINT) and cyber investigations by supporting the analysis, correlation, and reporting of data related to threat intelligence, digital forensics, and compliance. It features a comprehensive investigation workflow that enables users to create collection plans, pivot on identifiers, correlate evidence, and identify intelligence gaps, while adhering to lawful sources and practices. Notably, it encompasses various aspects of cybersecurity, including threat hunting, security operations, and OPSEC, making it a multifaceted resource for security professionals.
2026-08-14
Python
★ 28
The A-Pythonic-Keylogger is a Python-based keylogger designed for educational purposes that captures keystrokes, logs them to a local file, and can send the logs via email. Notable features include robust email retry handling, automatic session restart after key capture, and platform compatibility with both Linux and Windows. The tool incorporates local log management by clearing logs after the session ends, ensuring data retention only during active capture.
2026-08-14
Shell
★ 21
opencode-pentester is an AI-powered penetration testing and security audit framework designed to automate bug bounty hunting and vulnerability assessments. It orchestrates 12 specialized AI agents across 69 attack categories and 17 OWASP security audits, enabling comprehensive offensive and defensive testing. Notable features include the ability to run automated tests, generate professional reports, and integrate a wide array of security tools, making it suitable for security researchers, penetration testers, and DevSecOps engineers.
2026-08-14
Python
★ 75
REDCELL is an advanced penetration testing platform that utilizes AI agents to execute automated tests and generate comprehensive reports. It features a multi-agent orchestration system, real-time execution of offensive tools within a Dockerized Kali environment, and integrates pluggable language models for enhanced automation. Notable capabilities include live monitoring of agent activity, interactive terminal access to reverse shells, structured tool outputs, and seamless network pivoting for deeper exploitation.
2026-08-13
TypeScript
★ 11
Mingyi Atlas is a terminal AI agent designed for software engineering and authorized security assessments, offering an interactive TUI, headless automation, persistent project context, and specialized penetration testing modes. It features multi-model support, OAuth and API Key authentication, and structured workflows for reconnaissance, validation, reporting, and remediation, specifically catering to security tasks while ensuring non-destructive testing. The tool allows users to orchestrate security assessments with built-in skills and provides extensive CLI commands for project management and configuration.
2026-08-13
Python
★ 17
Red Team AI Benchmark is a command-line interface tool designed to evaluate large language models (LLMs) in terms of their understanding and response quality regarding red-team-related questions and scenarios. It employs a rubric-based dataset for comprehensive assessment over 60 domain-specific questions, providing detailed metrics such as refusal rate and lexical coverage to ensure robust evaluation without executing any model outputs or engaging in any red-team activities. This tool primarily aids researchers and practitioners in assessing LLM capabilities in security contexts, with results intended for authorized use only.
2026-08-13
Python
★ 40
Pentestkit is a sophisticated, multi-agent penetration testing framework that utilizes the Claude Agent SDK to orchestrate a team of specialized agents. The tool excels in automating the penetration testing process by exploiting vulnerabilities, scoring them using CVSS v3.1, and generating comprehensive client-ready reports, all while accumulating knowledge in a shared database. Notable features include its ability to perform real exploitation of findings and a robust scoring system that achieved a perfect 104/104 on the XBOW benchmark suite.
2026-08-13
Python
★ 24
This tool is a Python-based keylogger designed for educational purposes, capable of capturing keystrokes and sending the recorded logs via email. It features local log management, an email retry mechanism for reliable delivery, and automatic startup configurations for both Linux and Windows systems. Users are cautioned to run the script only on systems they own or have explicit permission to test, as it demonstrates sensitive functionality.
2026-08-13
Python
★ 13
HunterX is an AI-assisted offensive security engine designed for conducting authorized security assessments, integrating tools for reconnaissance, hypothesis-driven investigation, vulnerability validation, and professional reporting into a unified workflow. Unlike traditional vulnerability scanners, HunterX emphasizes thorough investigation and validation, ensuring that findings are evidence-based and report-ready. Notable features include AI-assisted reasoning, proof of concept engineering, and capabilities for reproducibility and impact assessment, enhancing the reliability of security assessments.
2026-08-13
Go
★ 16
OBLITERATUS is an advanced red teaming framework designed for post-exploitation research and defensive evasion in Windows environments. It features a multi-layered stealth architecture for evasion, low-level syscall execution, and identity correlation through its Identity Nexus module, allowing for the bypassing of MFA and efficient credential management. Key capabilities include memory hardening, automatic UAC elevation, and a sophisticated operational interface that facilitates real-time process management and forensic analysis.
2026-08-12
C++
★ 23
ALPC Enumerator is a Windows userland tool designed to enumerate and classify Advanced Local Procedure Call (ALPC) ports, including those associated with Protected Process Light (PPL) processes that evade standard enumeration techniques. It dynamically resolves ALPC Port types and employs `NtQueryInformationProcess` for classification, addressing blind spots in conventional tools, thereby benefiting threat hunters and vulnerability researchers by accurately mapping high-privilege targets and identifying potentially malicious activity. Notably, it has been validated against kernel debugger output for precision and reliability.
2026-08-12
Go
★ 24
Siren is a desktop operator workbench designed for the Sliver C2 framework, enabling offensive security professionals to manage and execute operations within a native application environment. Notable features include comprehensive agent management with real-time session control, robust server management capabilities, and an integrated automation system for executing scripts and rules. The tool emphasizes user-friendly interaction through a customizable interface, command palettes, and extensive file manipulation functionalities for effective tactical operations.
2026-08-12
Rust
★ 13
Black Hat Tools is a repository designed for developing asynchronous and concurrent software for security applications using languages such as TypeScript, Go, Rust, and Python. The primary use case involves executing network-based tests and exercises derived from well-known cybersecurity literature, with notable features including integration with specific testing domains for practical application. This tool is still a work in progress, reflecting ongoing development in its functionality.
2026-08-12
C
★ 921
GhostESP is an open-source wireless research platform that transforms an affordable ESP32 board into a multifunctional wireless tool with a user-friendly touchscreen interface. Its primary use case includes advanced wireless monitoring, firmware updates, and network analysis, featuring capabilities such as on-device firmware management, a cloud app store, and robust scripting support via GhostScript. Notable enhancements in version 2.x include expanded NFC functionalities, efficient Wi-Fi attack and monitoring tools, and improved user interface performance with a focus on accessibility and multitasking.
2026-08-11
Python
★ 16
Detection Labs for Palantir-Style Activity is an educational resource designed for blue team practitioners focusing on detection engineering and threat hunting. It leverages open-source tools and Sigma rules within SIEM environments to enhance competencies in cybersecurity operations, incident response, and threat intelligence analysis. Notable features include a flexible simulation environment, advanced jitter analysis for continuous monitoring, and comprehensive learning resources for SOC management.
2026-08-11
Go
★ 10
CeWL AI is an advanced reconnaissance tool designed to crawl various protocols including HTTP, FTP, SFTP, SMB, and S3, extracting valuable information such as emails, metadata, credentials, and secrets. It combines functionalities of traditional tools like CeWL and CUPP, offering features such as AI-powered wordlist generation, password mutation, multi-protocol support, and secret scanning, all implemented in a single Go binary. This tool enhances security assessments by facilitating in-depth data extraction and analysis in one command.
2026-08-11
TypeScript
★ 11
Kali + OpenCode Portable Pentest USB is a bootable USB solution that integrates Kali Linux Live with a suite of AI-driven penetration testing tools. Its primary use case is to provide a comprehensive and portable pen-testing environment that automates workflows, maintains documentation, and operates without leaving traces on host systems. Notable features include persistent storage for configurations, an autonomous pentesting plugin called Shannon, and support for a variety of tools streamlined for efficient security assessments.
2026-08-11
Go
★ 48
pgread is a tool designed to extract data from PostgreSQL databases without requiring user credentials, leveraging direct access to database files. It facilitates a range of output formats, such as JSON, SQL, and CSV, and includes features for password extraction, secret detection, and WAL (Write-Ahead Logging) analysis. Additionally, it supports low-level forensic operations like parsing database control files and recovery of deleted rows, making it adept for both security audits and database recovery tasks.
2026-08-11
★ 42
This repository offers a curated collection of over 70 free cybersecurity books organized by domain and difficulty, facilitating self-paced learning in various cybersecurity disciplines. Notable features include a structured learning roadmap progressing from beginner to advanced levels, an emphasis on community maintenance for up-to-date resources, and a direct link to an extensive Google Drive library containing the materials.
2026-08-11
C
★ 14
Slave I is an offensive-security firmware specifically designed for the M5Stack Tab5, facilitating wireless research through an integrated toolkit for Wi-Fi, BLE, and 802.15.4 recon and attack capabilities. Notable features include a touch UI, a physical-keyboard workflow, extensive scanning and capturing functions, and a desktop emulator for development. It allows users to implement advanced wireless attacks while emphasizing ethical usage and compliance with legal standards.
2026-08-11
Python
★ 26
Red-Team AI is a white-box red teaming tool designed specifically for agentic AI applications, capable of reading source code to identify vulnerabilities that are unique to a particular technology stack. Its primary use case involves generating tailored attacks based on an application's specific implementation, rather than relying on generic adversarial prompts. Notable features include a modern React dashboard for scan management and compliance tracking, as well as integrations with popular agent frameworks, facilitating extensive security assessments and risk assessments for AI systems.
2026-08-11
Python
★ 13
ShadowRAT is a Telegram-based Remote Access Trojan designed for Windows that provides complete remote control of a machine using Telegram bot commands with password authentication. Primarily targeted at cybersecurity professionals, security researchers, and educators, it serves to demonstrate RAT functionalities, enhance malware detection techniques, and facilitate authorized penetration testing in controlled environments. The tool emphasizes responsible use solely for educational and research purposes, providing insights into attacker methodologies and improving defensive security measures.
2026-08-11
Python
★ 63
NoiseHound is a detection-aware Active Directory attack-path scoring tool that enables cybersecurity operators to identify the quietest routes to administrative control within a network, leveraging BloodHound graph data. Its primary use case is for operational security (OPSEC) planning in authorized engagements, providing better risk assessments by incorporating expected detection costs instead of just hop counts. Notable features include support for multiple detection tiers, a calibration harness to measure edge effectiveness, and the ability to ingest various data formats for comprehensive path analysis.
2026-08-10
Shell
★ 11
Claude Pentest Skills is a specialized tool designed for structuring and automating penetration testing workflows within the Claude Code LLM environment. It features modular skill packs that provide comprehensive Active Directory reconnaissance, exploitation, and post-exploitation processes, along with robust functionalities such as checkpointing, parallel execution, and cross-platform support. Notable functionalities include automated evidence capture, JSON reporting, and seamless integration with multiple external tools for enhanced penetration testing efficacy.
2026-08-10
Python
★ 10
Rein is a Python library designed to serve as a runtime governor for autonomous AI agents, ensuring their actions are monitored and controlled based on real-time performance rather than just adhering to content guidelines. It features capabilities such as regime classification, Bayesian scoring of actions, a tamper-evident audit log, and a natural-language policy compiler, making it suitable for scenarios where costly or harmful actions could occur without adequate oversight. Rein is framework-agnostic, compatible with various AI platforms, and is particularly valuable in environments requiring dynamic decision-making under uncertainty.
2026-08-10
Rust
★ 63
Sherlock-rs is a Rust-based tool designed to hunt down social media accounts by a specified username across over 400 social networks. It provides features such as outputting results to text, CSV, or Excel files, supports proxy usage, customizable site analysis, and extensive debugging options, making it ideal for users needing comprehensive username availability checks across multiple platforms.
2026-08-09
Go
★ 376
Zombie is a lightweight service password brute-forcing tool that integrates command-line design inspired by Hydra and dictionary generation capabilities like Hashcat, tailored for red team operations. Its notable features include support for various protocols (e.g., SSH, MySQL, MSSQL), customizable password generation, and the ability to perform targeted brute-forcing based on user-specified input files. This makes it a versatile solution for security assessments and penetration testing involving credential brute-forcing.
2026-08-09
HTML
★ 11
ShadowPDF is a lightweight, privacy-focused tool that enables users to extract text from PDF documents directly in their browser without any data leakage risks. Its notable features include 100% offline processing, multi-format export options (Plain Text, Markdown, HTML), and a user-friendly drag-and-drop interface, making it ideal for developers and security-conscious individuals seeking efficient document conversions.
2026-08-09
Python
★ 12
XORCISE is a cybersecurity tool designed to run AI agents against real-world missions in a controlled environment, monitoring and grading their actions through detailed evidence collection. It utilizes OpenTelemetry for real-time tracking of commands and actions while providing a scoring system based on pre-defined mission criteria. Notably, XORCISE supports various AI models and generates comprehensive reports, allowing users to evaluate and compare the performance of different agents in a secure, isolated network.
2026-08-08
Go
★ 39
malsnitch is a command-line tool designed to assist malware reverse engineering by scanning various artifact formats for embedded secrets within binaries. Its notable features include the ability to detect hardcoded credentials, C2 infrastructure, and crypto keys in binary files, with support for multiple input formats such as raw strings dumps, FLOSS JSON output, and Binary Ninja exports. The tool also offers structured JSON output, automatic deduplication, and the capability to scan memory dumps, making it an efficient resource in identifying obscured sensitive information utilized by malware authors.
2026-08-08
Python
★ 29
Kryon is an autonomous, local-first cybersecurity agent designed for comprehensive offensive security tasks including compliance audits, penetration testing, vulnerability hunting, digital forensics, and incident response from a single command. It features a skill-based architecture that dynamically loads over 110 playbooks and employs deterministic pre-hooks for critical detections, ensuring that it provides both a thorough assessment and actionable outputs without reliance on external APIs. Additionally, it supports a wide range of compliance frameworks across multiple sectors, making it adaptable for various organizational needs.
2026-08-06
TypeScript
★ 117
Cyberful is an AI-driven application-security workbench designed for authorized penetration testing, code auditing, and bug bounty research. It features robust workflows including pentest phases for evaluating live targets, supports isolated tooling for independent verification, and offers report-ready outputs while maintaining a local-first approach without emitting telemetry. Notably, Cyberful emphasizes trustworthiness in security findings by ensuring actions remain within defined authorization boundaries and by providing detailed evidence tied to each engagement.
2026-08-05
Python
★ 15
Java Triage is a static analysis tool designed for examining suspicious Java codebases, decompiled JARs, and Minecraft mods. It features extensive capabilities including decompilation with CFR, advanced string recovery, and detection of malicious indicators and behaviors, all while producing comprehensive reports in various formats. Notable functionalities include runtime command and control resolution, detailed scoring for findings, and support for detecting obfuscation tactics commonly used in malware.
2026-08-05
Python
★ 14
ModelFuzz is a runtime guardrails tool designed to intercept and prevent unsafe tool calls made by AI agents due to prompt injection attacks. It checks each argument against defined policies before execution, ensuring that only permitted actions, such as API calls to whitelisted domains, are executed, effectively blocking any malicious attempts. Notable features include support for both synchronous and asynchronous function wrapping, configurable policies, and logging of blocked actions for auditing purposes.
2026-08-05
★ 26
Red Giant Peak is an industry-grade editing suite designed for GPU-accelerated playback, compositing, and visual effects, primarily for video editing on Windows platforms. Notable features include synchronized multi-camera editing with automatic audio sync, keyframeable text animations, and a proxy workflow for efficient handling of high-resolution footage. The tool emphasizes high performance and user-friendly workflows to streamline video production tasks.
2026-08-05
★ 57
Replugged Terminal Ultimate is an all-in-one workspace solution designed for Windows that integrates document editing, task management, and real-time team communications. It features a rich-text document editor with markdown support, a built-in calendar for scheduling, and an analytics dashboard for tracking project progress and team workload. This tool aims to streamline collaborative workflows in various professional environments.
2026-08-05
★ 58
Rethinkdns Unlocked Premium is a collaborative platform designed for project management, featuring robust tools such as a calendar for scheduling, a rich-text document editor, and an analytics dashboard for tracking project performance. Its primary use case is to enhance team productivity through organized workflows and effective communication. Notable features include recurring event scheduling, markdown support in document creation, and visual reporting capabilities.
2026-08-05
Python
★ 51
SquidC5 is a cybersecurity team server designed for authorized red team operations and penetration testing, featuring AI-integrated capabilities for enhanced collaboration and task management. Notable features include scoped API tokens, dual AI operational modes, malleable C2 profiles, and a comprehensive engagement console, making it suitable for secure and efficient offensive security operations. The tool emphasizes secure defaults, including TLS encryption and robust auditing features, to ensure a safety-first approach to red teaming.
2026-08-05
JavaScript
★ 61
The Cybersecurity Handbook is an interactive, open-source knowledge base tailored for cybersecurity professionals, students, and enthusiasts. It offers over 400 comprehensive notes on diverse topics, enhanced by an interactive knowledge graph, full-text search capabilities, and a user-friendly interface that supports dark/light modes and is mobile-friendly. This community-driven resource keeps pace with the rapidly evolving cybersecurity landscape, providing practical insights into real-world threats and defense strategies without any paywalls.
2026-08-04
Python
★ 48
Hermes Katana is a defense-in-depth security tool designed for AI agents, providing mechanisms for tracking input provenance, scanning content for prompt injections, and enforcing YAML policies before tool execution. Notable features include configurable human-in-the-loop escalation, purpose-trained injection classifiers, and a tamper-evident audit trail for decision-making, all aimed at enhancing the security posture of AI applications. This tool is particularly useful for developers looking to safeguard AI systems from potential vulnerabilities and malicious inputs.
2026-08-04
Go
★ 25
urlX is a high-performance reconnaissance tool designed for bug bounty hunters, penetration testers, and security researchers. It facilitates passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling, while utilizing Go routines for fast and concurrent processing. Notable features include smart file and extension filtering, minimal setup requirements, and support for enhancing results with optional API keys from various providers.
2026-08-04
Python
★ 431
Mr.SIP is a console-based SIP security framework designed for auditing and penetration testing of SIP-based systems. It includes three primary modules for network scanning, user enumeration, and Denial of Service (DoS) attack simulations, all leveraging high-performance multithreading and IP spoofing. The tool serves both as a research platform for SIP DDoS attacks and as a practical utility for assessing the security of VoIP infrastructures.
2026-08-03
Cobalt is a user-friendly media downloader that allows users to download free and publicly accessible content without ads, trackers, or paywalls. It operates as a proxy, facilitating straightforward content retrieval through simple link pasting, while emphasizing ethical use and user responsibility. Notable features include a monorepo structure for easy access to API, frontend, and documentation, as well as a commitment to privacy and transparency.
2026-08-03
PowerShell
★ 300
The PowerShell Reverse TCP tool facilitates bidirectional communication between a client and a remote host, enabling the remote host to execute commands on the client system. Designed primarily for educational purposes, it features multiple shell implementations using Invoke-Expression and process pipes, and includes a methodology for script obfuscation to evade detection by security systems. Users can customize IP addresses and port numbers, while future updates aim to enhance shell optimization further.
2026-08-03
RaspyJack is a portable offensive toolkit designed for use with Raspberry Pi devices and primarily aimed at authorized security testing and research. It features an LCD-driven handheld interface, dual-display support, and includes 231 payloads across multiple categories, along with a WebUI for remote control, various WiFi attack utilities, and exfiltration methods, making it versatile for penetration testing and educational purposes. Additionally, it supports a range of hardware configurations and offers an integrated Payload IDE for custom development.
2026-08-03
AggressorScripts is a collection of Aggressor scripts designed to enhance the functionality of Cobalt Strike 3.0+, enabling streamlined operations for penetration testers. Primary use cases include session migration from Beacon to Powershell Empire, automated alerting to Slack for various events, and process automation to help manage system interactions during engagement scenarios. Notable features include the ability to output web logs, control Beacon sleep intervals based on operator presence, and maintain a connection with event logs, enhancing situational awareness and operational efficiency.
2026-08-03
The Cobalt Strike CheatSheet serves as a comprehensive reference for users of the Cobalt Strike command and control (C2) framework, delineating essential functionalities, commands, and configurations for effective operation. Its primary use case is to streamline cyber operations, providing insights into managing listeners, utilizing malleable C2 profiles for stealthy communication, and implementing aggressor scripts for customization. Notable features include detailed guidance on attack methods, pivoting techniques, and practical reporting capabilities to enhance the efficiency of red team engagements.
2026-08-03
The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.
2026-08-03
The Powershell-Tools-and-Toys repository contains a diverse collection of Powershell scripts designed for educational and research purposes, ranging from harmless pranks to advanced red team tools. Primarily aimed at providing security professionals with resources for authorized security assessments and lab testing, this toolkit features a variety of scripts that illustrate different cybersecurity techniques while emphasizing legal and ethical usage.
2026-08-03
The "Awesome LLM Red Teaming" repository provides a curated collection of tools and resources aimed at red-teaming large language models (LLMs) through techniques such as prompt manipulation and adversarial testing. Key features include practice targets for hands-on experimentation, frameworks for systematic testing of generative AI systems, and attack generation toolkits designed to exploit vulnerabilities in LLM applications. This resource is particularly valuable for researchers and practitioners focused on vulnerability assessment and improving the robustness of AI models.
2026-08-03
★ 174
Awesome Recon Tools is a comprehensive catalog of resources for reconnaissance and footprinting, focusing specifically on domain and network information, personal data extraction, and leveraging search engines for reconnaissance. Notable features include a wide array of tools for domain ownership queries, network scanning, and OSINT (Open Source Intelligence) techniques, allowing users to effectively map and understand potential attack surfaces. The repository serves as a valuable reference for cybersecurity professionals and researchers conducting exploratory assessments.
2026-08-03
Awesome Red Teaming serves as a comprehensive resource catalog for individuals interested in Red Teaming, offering a variety of references organized by adversarial tactics and techniques guided by the Mitre ATT&CK framework. It includes categories such as Initial Access, Execution, Persistence, and Credential Access, thereby providing practical insights and learning materials that foster a deeper understanding of offensive security maneuvers. Notably, users can contribute to the list through pull requests, fostering a collaborative environment for knowledge sharing in the field of cybersecurity.
2026-08-03
nimc2 is a lightweight command-and-control (C2) framework developed entirely in Nim, designed for use cases ranging from user support to employee monitoring. It features the generation of Windows and Linux implants, TCP and HTTP communication capabilities, an extensive task management system, customizable modules for enhanced functionality, and a user-friendly command-line interface. Notably, it supports simultaneous listeners and includes a loot system for managing screenshots and files collected from monitored devices.
2026-08-03
BEAR-C2 is a command and control (C2) framework designed for simulating attacks that mimic techniques utilized by Russian APT groups. It features robust encryption methods such as AES and RSA for secure communications between malware payloads and operators, along with advanced functionalities like payload execution, SmartScreen bypass, and UAC evasion. This tool is intended solely for educational and research purposes, emphasizing the importance of ethical usage.
2026-08-03
MoveKit is a Cobalt Strike extension designed to enhance lateral movement capabilities by utilizing the execute_assembly function in conjunction with the SharpMove and SharpRDP .NET assemblies. It provides a robust interface for executing commands and transferring files across remote systems using various methods such as WMI, DCOM, Task Scheduler, and more, while also supporting multiple file movement techniques and execution triggers. Notable features include dynamic payload creation, customizable pre-built commands, and versatile file handling options, making it a powerful tool for penetration testers and red team engagements.
2026-08-03
TripleCross is a Linux eBPF rootkit designed to illustrate the offensive capabilities of eBPF technology, developed as part of an academic thesis. Its primary use case involves demonstrating various malicious functionalities including library injection, execution hijacking, local privilege escalation, and stealth operations, all while maintaining a backdoor with command-and-control capabilities. Notable features include persistence across reboots and multiple methods for remote command execution, showcasing advanced techniques for evasion and control.
2026-08-03
Atomic Red Team is a tool that provides a comprehensive library of tests aligned with the MITRE ATT&CK framework, allowing security teams to efficiently and reliably validate their environments for potential vulnerabilities. Its notable features include direct command-line execution of atomic tests without installation and integration support with execution frameworks like Invoke-Atomic for enhanced testing capabilities. This open-source project encourages community involvement and contribution towards the continuous improvement of its testing suite.
2026-08-03
C++
★ 77
adduser-dll is a straightforward dynamic-link library (DLL) that facilitates the creation and addition of users to the local Administrators group on Windows systems. Its primary use case is for administrative automation in user management tasks, allowing customization of usernames, passwords, and group permissions through code modifications. Notable features include its standalone execution via `rundll32.exe` and the ability to be injected or called from other scripts or tools, enhancing flexibility in usage.
2026-08-03
JavaScript
★ 368
The OSCP repository serves as a centralized resource for individuals preparing for the Offensive Security Certified Professional (OSCP) exam, compiling useful materials from various sources including websites, blogs, and books. Key features include organized sections for methodologies, automation scripts, cheat sheets, and troubleshooting documentation, all formatted for compatibility with Obsidian for enhanced note-taking and visual data representation. While the maintainers are no longer actively updating the repository, it aims to remain a valuable reference for future OSCP candidates.
2026-08-03
C
★ 56
Wall-Escape (CVE-2024-28085) is an exploit tool designed to leverage a vulnerability in the util-linux wall command that allows attackers to inject escape sequences into command line arguments, potentially leaking sensitive information such as user passwords. The tool sets up an environment to execute commands while monitoring for password input, effectively capturing credentials during user interactions—particularly in contexts like SSH login or sudo commands. Notable features include the ability to manipulate command outputs and create a fake prompt that misleads users into revealing their passwords.
2026-08-03
Python
★ 412
EvilTree is a Python3 tool that serves as a standalone remake of the classic "tree" command, enhanced with the capability to search for user-defined keywords or regex patterns within files. Its primary use case is to assist in identifying sensitive information within complex directory structures during post-exploitation enumeration. Notable features include the ability to highlight matches in search results, support for both keyword and regex searches, and an option to filter results to show only files containing matching content.
2026-08-03
C++
★ 21
Flanders-Trojan is a Windows-based trojan developed for academic purposes that employs C++ and consists of three main components: a Loader for initial setup and privilege escalation, a Payload for executing various malicious actions (such as file encryption, keylogging, and DDoS attacks), and a Server that functions as the command and control center for managing infected devices. Notable features include VM detection, UAC bypass, and real-time communication with a C2 server, highlighting its capabilities in orchestrating cyberattacks and gathering sensitive information.
2026-08-03
C#
★ 159
LocalAdminSharp is a .NET executable designed for privilege escalation on Windows systems, enabling the creation of local administrator accounts or the addition of existing users to the local administrator group. This tool can be customized for different users and domains and is suitable for standalone execution or integration into other scripts for privilege escalation scenarios. Key features include ease of customization, compatibility with Visual Studio for compilation, and a focus on evading detection by security software.
2026-08-03
C
★ 466
PetitPotato is a local privilege escalation tool that leverages the PetitPotam technique by abusing impersonate privileges via the MS-EFSR protocol. Its primary use case is to gain SYSTEM privileges on target Windows systems by exploiting vulnerabilities in encrypted file system operations. Notable features include compatibility with the latest Windows versions and the ability to execute arbitrary commands by specifying the desired EfsID and command parameters.
2026-08-03
★ 607
The Awesome Windows Red Team repository is a comprehensive collection of resources tailored for Red Team professionals engaging in Windows environments. It encompasses a wide variety of materials including tools, books, courses, and techniques focused on topics such as Active Directory exploitation, lateral movement, privilege escalation, and defense evasion strategies. Notable features include structured categories for efficient navigation, making it suitable for users ranging from beginners to advanced practitioners.
2026-08-03
★ 23
The Offensive Security Forensics Portfolio is an educational repository showcasing practical skills in cybersecurity, particularly in forensic analysis, penetration testing, and vulnerability assessments. It features detailed documentation of various security techniques, including the implementation of Multi-Factor Authentication for SSH and memory forensics using the Volatility Framework, as well as threat hunting exercises with Splunk. This portfolio serves as a comprehensive example of applied offensive security methodologies within controlled environments.
2026-08-03
Python
★ 80526
Payloads All The Things is a comprehensive repository that provides a collection of useful payloads and techniques for web application security testing. It offers structured documentation on various vulnerabilities, including exploitation methods and payload examples, and is designed to assist penetration testers in identifying and utilizing attack vectors effectively. Notable features include templates for adding new vulnerabilities, integration with Burp Suite Intruder, and a community-driven approach to enhancing its content.
2026-08-03
★ 25
The Pentesting-Methodology repository provides a structured approach to penetration testing, encompassing networking fundamentals, reconnaissance, and analysis techniques. It includes tools for identifying web servers and technologies, brute-forcing subdomains, and performing directory enumeration, making it useful for security professionals looking to streamline their penetration testing workflows. Notable features include detailed networking information and integration with various reconnaissance tools such as Sublist3r and Amass.
2026-08-03
C++
★ 207
DNS-Persist is a post-exploitation agent utilizing DNS for command and control, primarily designed for persistence in compromised systems. It features multiple persistence mechanisms including LogonScript, RunKey, and Excel Addin persistence, as well as the ability to execute commands via a pseudo-interactive shell and inject 32-bit shellcode. The tool is built with a Python server-side and a C++ agent, with plans for future enhancements including additional persistence options and encryption capabilities.
2026-08-03
Go
★ 17
A flexible cross-platform post-exploitation agent written in Go with basic functionalities
2026-08-03
Python
★ 30
MacOS-WPA-PSK is a proof-of-concept script that demonstrates how macOS stores the wireless network key in plaintext within NVRAM, rendering it accessible without root privileges. This tool highlights the risks associated with the management of sensitive credentials in macOS, serving as a reminder that users should be aware of the non-secure treatment of such information. The script operates using Python and has been tested across specific versions of macOS.
2026-08-03
C
★ 81
PostShell is a post-exploitation tool designed to facilitate advanced shell access through both bind and backconnect methods, enabling attackers to maintain an interactive TTY session with job control while remaining stealthy. Notably, it features cloaked process names to minimize detection, a compact stub size of less than 14kb for easy deployment on Unix-like systems, and built-in anti-debugging mechanisms to enhance resilience against analysis. The tool's design allows for operation in environments with limited dependencies, improving post-exploitation flexibility.
2026-08-03
C
★ 227
Zombie Ant Farm is a toolset designed for offensive security practitioners to enhance evasion techniques against Linux Endpoint Detection and Response (EDR) systems. Its primary use case involves facilitating the development of custom offensive strategies through features such as distributed payload warehousing, in-memory payload delivery, and ASLR weakening shims, making it suitable for advanced penetration testing and research. The kit includes various components such as preloaders, evasion primitives, and a warehouse service, providing a modular approach to offensive operations.
2026-08-03
C#
★ 212
AtlasC2 is a C# command and control (C2) framework designed for Stage 1 operations, primarily used for establishing footholds within Windows environments and executing C# payloads through HTTP-based implants. Notable features include the ability to manage listeners, connect to multiple implants, execute system commands via PowerShell or CMD, and dynamically load C# assemblies into memory, making it a potent tool for post-exploitation scenarios despite current OPSEC limitations.
2026-08-03
Python
★ 46
AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.
2026-08-03
Python
★ 50
Bifrost is an open-source command and control (C2) tool implemented as a Discord bot, allowing users to manage and communicate with compromised clients through the Discord API. It supports multiple platforms and provides features such as keylogging, antivirus enumeration, real-time encrypted communication, and file management capabilities. Designed for educational and authorized security testing purposes, Bifrost leverages the Discord infrastructure to maintain a stealthy connection with clients.
2026-08-03
Python
★ 58
The C2 Server is a Command and Control framework that enables attackers to manage compromised target machines through a reverse shell connection. It supports various commands for file management, directory navigation, and even malicious functions like keylogging and credential spoofing, enhancing the attacker's ability to interact with the victim's system. Written in Python, it provides a user-friendly interface for executing predefined commands and extracting sensitive information from infected devices.
2026-08-03
PowerShell
★ 13
The Cobalt Strike Aggressor Script Collection provides a set of scripts designed to enhance post-exploitation capabilities within the Cobalt Strike framework. Key features include techniques for privilege escalation, persistence, and situational awareness, along with accessible notes that facilitate streamlined operations during engagements. This tool is primarily used by security professionals for advanced exploitation and operational efficiency in red team scenarios.
2026-08-03
Go
★ 435
Covermyass is a post-exploitation tool designed for penetration testers to securely delete log files across multiple operating systems, including Linux, macOS, and Windows. It enables users to identify and overwrite log files with random data to obscure their activities before exiting a compromised server. Notable features include multiple overwrite iterations and the ability to handle file permissions, ensuring thorough data eradication.
2026-08-03
C#
★ 22
Coyote is a C# post-exploitation implant designed for maintaining access to compromised Windows systems during red team operations. Its notable features include bypassing application whitelisting through InstallUtil.exe, utilizing a recursive DNS tunnel to retrieve encrypted commands, and maintaining a small footprint on both memory and network resources. The tool leverages a DLL that periodically polls a DNS TXT record for remote instructions, allowing operators to execute various payloads, such as spawning a reverse shell, while potentially evading detection.
2026-08-03
Python
★ 36
DeathNote is a penetration testing cheat sheet tool that provides a collection of resources and techniques essential for conducting security assessments. Its primary use case is to streamline the penetration testing process by offering organized references for various attack vectors, including reverse shells, PowerShell exploits, Active Directory, brute-forcing, and persistence methods. Notable features include compatibility with both Python 2.7 and 3.7, straightforward installation, and customizable configurations.
2026-08-03
Python
★ 253
FudgeC2 is a PowerShell-based command and control (C2) platform that enhances collaborative red teaming by providing an organized structure for managing campaigns and implants. It features a web-based interface that allows operators to easily deploy and control various implants, execute commands, and gather system information, with support for custom modules and a range of built-in commands such as persistence and file manipulation. Designed for active development, FudgeC2 aims to improve understanding of adversarial techniques through detailed reporting and campaign timelines.
2026-08-03
Shell
★ 17
mythic-crate is a development environment for the Mythic Command and Control (C2) framework, designed to run on Ubuntu 18.04 using VirtualBox and Vagrant. It automates the setup of Mythic dependencies, facilitates port forwarding, and enables folder sharing between the host and guest systems. Notable features include SSH access, streamlined administration via host commands, and the ability to customize VM disk size.
2026-08-03
PowerShell
★ 12
PentaDrone is an asynchronous PowerShell post-exploitation agent designed for red teaming and penetration testing, utilizing the Mitre Att&ck framework for automation through an autopilot mode. It allows security researchers to simulate HTTP loader-style botnets, facilitating malware research while providing extensive configurability for command-and-control server connections and agent behavior. Notable features include various persistence methods, USB spreading options, and customizable operational parameters.
2026-08-03
C#
★ 133
Sharp Login Prompt is a cybersecurity tool designed to create a phishing login interface that captures the username and password of the current user without interacting with lsass or requiring administrative credentials. Its primary use case is for red team assessments, allowing security professionals to simulate phishing attacks. Notable features include customizable headings and subheadings for the login interface, enhancing the deception in social engineering scenarios.
2026-08-03
C
★ 12
Agent Loader is a modular command-and-control (C2) tool designed to facilitate the deployment of in-memory payloads and covert operations through a DNS-over-HTTPS channel. Its notable features include dynamic function encryption, a reverse-shell module, and extensive file system management capabilities, alongside a customizable CLI builder for creating tailored implants via Python. The tool also offers a Node.js web panel for interactive management, showcasing a bot list and persistence mechanisms through OneDrive and Task Scheduler.
2026-08-03
Assembly
★ 486
Alan Framework is a post-exploitation framework designed for red-team activities, enabling advanced functionality such as in-memory tool execution and encrypted communication. It supports multiple agent types including Powershell, DLL, and executable formats across different architectures and operating systems, with a powerful command shell and real-time agent configuration updates. Notable features include a fully compliant SOCKS5 proxy, JavaScript execution capabilities, and a lack of external dependencies, making it suitable for stealthy operational tasks.
2026-08-03
C#
★ 11
AntiForensic.NET is a lightweight library designed for Windows that facilitates the eradication of forensic trace logs from a computer system. Its primary use case involves implementing various anti-forensic techniques to ensure user privacy by removing artifacts such as application logs, event logs, and cached data. Notable features include the automatic deletion of numerous types of logs and cache files, including Recycle Bin contents, recent items, and compatibility logs, thereby aiding users in evading potential tracing.
2026-08-03
★ 111
awesome-cyber is a curated repository that aggregates a diverse range of cybersecurity tools catering to red, blue, and purple team operations. This resource aims to provide an up-to-date collection of tools across various cybersecurity domains, including offensive and defensive techniques, forensics, and incident response. Notable features include organized categories for easy navigation and an open invitation for community contributions to keep the toolset relevant.
2026-08-03
C
★ 13
C2KepExec is a Command and Control (C2) server designed to manage a BotNet of machines running a Remote Administration Trojan and is developed for educational purposes. Its notable features include remote keylogging, file management capabilities (uploading and downloading), integrated session control for multiple targets, and persistent infection techniques on Windows systems. The tool also allows for advanced monitoring functions such as screen captures and webcam access.
2026-08-03
Go
★ 36
C2PE is a tool designed for Red Team operations, focusing on Command and Control (C2) capabilities and post-exploitation activities. It features experimental code implementations suitable for hacking scenarios, allowing users to deploy C2 infrastructures and manage compromised systems effectively. The tool is developed in Python and Go, ensuring cross-platform compatibility and adherence to PEP8 code standards.
2026-08-03
Python
★ 22
GOD-OF-RAT is an advanced Python Remote Access Trojan (RAT) framework designed for authorized penetration testing, offering extensive control over compromised systems. Its notable features include live screen controlling, credentials harvesting from various sources, an interactive agent builder with encryption capabilities, and advanced evasion techniques. The framework also supports remote shell access, file system management, and a suite of fun modules for additional functionalities.
2026-08-03
Python
★ 145
GTFOBins CLI is a command-line tool designed for security professionals to quickly access and search for Unix binary exploitation techniques. It features capabilities such as fuzzy searching, filtering exploitation types, and an interactive mode for ease of navigation, all while providing an offline database for fast, local access. The tool supports cross-platform usage and enhances readability with syntax highlighting, allowing for efficient identification of security bypass methods.
2026-08-03
C++
★ 50
HVNC is a remote administration toolkit designed for red-team operators, enabling covert access to an invisible Windows desktop without user awareness. Its primary use case is to facilitate stealthy remote operations by creating a hidden session that processes actions off-screen and communicates with the operator via VNC-like commands, supporting functionalities such as file transfers, keylogging, and launching applications. Notable features include simultaneous session handling in separate console windows and a clean-up script for system hygiene post-usage.
2026-08-03
Go
★ 13
KitsuneC2 is a pure-Go adversary emulation framework designed for security testing, providing both a web and CLI interface for user interaction with implants. Its notable features include dynamic implant generation, in-memory execution of shellcode, and malleable C2 traffic, making it a versatile tool for organizations aiming to evaluate their cybersecurity defenses. However, it is not intended for professional engagements as there are more mature frameworks available.
2026-08-03
Go
★ 5600
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
2026-08-03
Python
★ 516
MsfMania is a Python-based payload obfuscation framework primarily aimed at evading endpoint detection and antivirus systems on Windows platforms. It boasts notable features such as dynamic code generation, multi-layer encryption using RC4, local memory injection, and extensive metadata spoofing, making it suitable for authorized security testing and research activities.
2026-08-03
Python
★ 459
PivotSuite is a network pivoting toolkit designed for Red Teamers and penetration testers, enabling the movement within a compromised network using either forward or reverse connections. Notable features include support for TCP tunneling, SOCKS5 proxies, and various network enumeration functions, all without requiring administrative access on the compromised host. The tool operates independently of installation requirements, utilizing only Python's standard libraries, making it versatile across different platforms and environments.
2026-08-03
PowerShell
★ 15
Powtel is a remote system control tool designed for Windows environments, utilizing PowerShell and Telegram as its communication interface. Its primary use case is for authorized security testing and post-exploitation activities, providing features such as task scheduling, file upload/download capabilities, and screenshot functionality. The tool emphasizes ethical usage, aiming to aid cybersecurity professionals and researchers in controlled settings.
2026-08-03
Python
★ 67
PyADRecon is a Python-based tool designed for gathering comprehensive information from Microsoft Active Directory environments, catering to the needs of penetration testers and blue teams. It supports NTLM and Kerberos authentication methods, can generate XLSX reports, and offers an HTML dashboard for visualizing collected data, making it a versatile resource for Active Directory reconnaissance. Additionally, it provides options for standalone report generation from CSV files, enhancing its usability in various assessment scenarios.
2026-08-03
Python
★ 326
PyIris is a modular remote access trojan (RAT) toolkit implemented in Python, designed for the dynamic creation, encoding, and encryption of RAT payloads to facilitate the remote control of compromised systems. Its notable features include cross-platform compatibility for both Windows and Linux, robust error handling, dynamic payload generation, and advanced functionalities such as keylogging, webcam access, and file manipulation, making it a versatile tool for malicious actors. The ongoing development aims to enhance its capabilities further with improved encryption methods and operational persistence techniques.
2026-08-03
Python
★ 175
PythonRAT is a Command and Control (C2) server that orchestrates multiple machines infected with a Remote Administration Trojan (RAT), enabling the formation of a botnet cluster. Its primary use case is for educational purposes in cybersecurity training, allowing users to remotely control, monitor, and manipulate target sessions. Notable features include an integrated keylogger, screenshot and webcam capture, file transfer capabilities, privilege checking, and the ability to issue commands to all active sessions simultaneously.
2026-08-03
Python
★ 50
Reave is a post-exploitation framework developed for hypervisor endpoints, designed to facilitate automated penetration testing in heavily virtualized environments. This Python-based tool operates on a listener/agent model, offering features such as real-time interactive terminal sessions, automatic hypervisor enumeration, and modular payloads for tasks including exfiltration and persistence. Notably, Reave supports versatile configurations for agents, enabling comprehensive control over operations and network interactions.
2026-08-03
PowerShell
★ 219
Redpill is a post-exploitation tool designed to facilitate various tasks following initial access via reverse TCP shells, particularly for red team engagements. It comprises a collection of PowerShell scripts, with the main script, redpill.ps1, serving as a central hub to download, configure, and execute these scripts, offering functionalities similar to the meterpreter environment. Notable features include system enumeration, remote process management, web server deployment, and a keystroke logger, all intended to enhance the capabilities of shell access in compromised systems.
2026-08-03
HTML
★ 13
RedVision is a collection of custom-designed HTML user interfaces specifically intended for Command & Control (C2) systems. Its primary use case is to enhance the operational efficiency of security professionals by providing a visually appealing and functional interface for managing C2 capabilities. Notable features include an array of templates, each visually distinct, allowing for flexible customization to suit various C2 deployment scenarios.
2026-08-03
PHP
★ 78
ReHTTP is a PowerShell-based HTTP shell that features a web user interface, designed primarily for remote management and control of clients on a Windows platform. Key functionalities include executing PowerShell commands, managing client connections, and creating custom modules and variables, along with sophisticated event handling capabilities for connection management. This tool also supports scheduled tasks and offers a history feature for command execution, enhancing its usability in system administration and penetration testing contexts.
2026-08-03
Rust
★ 29
RustVersary is a comprehensive toolkit designed for malware development and penetration testing using the Rust programming language. It includes a variety of tools and scripts that facilitate tasks such as enumeration, exploitation, and post-exploitation, each thoroughly documented to aid both personal use and community contributions. Notable features include advanced techniques for process injection, persistence mechanisms, and a structured catalog of utilities tailored for security assessment challenges.
2026-08-03
Shell
★ 52
Searchbins is an offline command-line tool designed to search for GTFOBins binaries that allow users to bypass local security restrictions in misconfigured systems. Its notable features include the ability to enumerate specific binary functions, display commands to exploit those functions, maintain an up-to-date GTFOBins database, and allow for file-based binary searches. This tool serves as a valuable resource for security professionals to identify and utilize potential vulnerabilities in binary applications.
2026-08-03
PowerShell
★ 33
Sh3ller is a lightweight command-and-control (C2) framework designed for managing incoming reverse shells via PowerShell. Its primary use case is to maintain persistent access to compromised systems, allowing users to manage multiple shell sessions simultaneously with minimal dependencies. Notable features include an always-on listening mode, support for various reverse shell payloads, and intuitive session management commands.
2026-08-03
Go
★ 10
Silkwire is a gRPC-based Command and Control (C2) framework designed for authorized penetration testing and red team operations. It supports multiple platforms (Windows, Linux, macOS) and offers advanced features including dynamic implant generation, post-exploitation modules, keylogging, and enhanced evasion techniques against detection mechanisms. The tool emphasizes encryption for communications and session management, making it a robust option for security professionals in performing comprehensive security assessments.
2026-08-03
Go
★ 11
SoundShell is a Command-and-Control (C2) tool developed in Go that utilizes the Spotify Web API to execute encoded commands and generate corresponding playlists. Its primary use case is to dynamically create playlists based on user-inputted commands, with notable features including custom command execution, command encoding for playlist generation, and random track selection from a predefined song pool.
2026-08-03
Python
★ 294
Sshimpanzee is a tool for creating a static reverse SSH server that initiates connections from the victim machine to an attacker's IP, bypassing the need for incoming connection requests. It provides all standard SSH functionalities, including port forwarding and dynamic SOCKS proxies, while also offering advanced tunneling methods like DNS Tunneling, ICMP Tunneling, and HTTP encapsulation to facilitate communication in restrictive network environments. Notable features include customizable build configurations, support for multiple tunneling mechanisms, and the ability to generate new SSH keys upon build.
2026-08-03
★ 28
The FreeZeroDays/TTPs repository serves as a curated collection of offensive security notes, focusing on Tactics, Techniques, and Procedures (TTPs). It provides a repository of validated commands and resources targeted towards researchers and practitioners in offensive security. Notably, the documentation emphasizes accuracy and reliability, and it draws inspiration from other established collections in the field.
2026-08-03
C
★ 10
Unicorn is a Command and Control (C2) framework designed for post-exploitation and remote control operations. Built using Python and Flask, it features a client-server architecture that supports multiple listeners, dynamic command execution, and client chat synchronization, while still being in development with planned enhancements such as a proxy server and GUI integration. This tool is aimed at cybersecurity professionals for managing agents and executing commands in compromised environments.
2026-08-03
Python
★ 76
Venus is a VS Code extension designed to serve as an agent for the Mythic C2 framework, enabling operators to create and deliver payloads to target systems. This tool automates the packaging of VS Code extensions and supports various commands for interacting with the system environment, although it currently lacks support for encrypted payloads. Notably, Venus is cross-platform compatible and requires manual installation on target machines after preparation.
2026-08-03
C
★ 166
WebcamBOF is a Beacon Object File (BOF) for Cobalt Strike that enables webcam capture functionality. Its primary use case is to facilitate remote image acquisition by allowing users to save webcam images either to disk or download them directly over the Cobalt Strike beacon. Notable features include multiple save methods, including capturing images as screenshots, and the ability to enumerate connected webcam devices.
2026-08-03
C
★ 287
WindowSpy is a Cobalt Strike Beacon Object File designed for targeted user surveillance, facilitating stealthy detection of significant user activities such as entering credentials or accessing confidential documents. It operates by comparing active window titles against a customizable list to trigger specific actions, like screenshots, only when relevant activities are detected, thus minimizing unnecessary data collection. Key features include easy integration with Cobalt Strike, a configurable keyword list for triggering surveillance, and the ability to customize the actions performed upon detection.
2026-08-03
Go
★ 395
XENA is a cross-platform cybersecurity automation framework designed for adversary simulations and red team operations, featuring a built-in post-exploitation agent and a command-and-control (C2) server. Notable features include an elegant dark-themed user interface that supports desktop, web, and mobile formats, along with high-level automation capabilities for orchestrating C2 clusters. This community edition serves as an integrated tool for penetration testing, facilitating a comprehensive approach to security assessment.
2026-08-03
JavaScript
★ 141
ZeroPulse is a modern Command & Control (C2) platform designed for secure remote management and monitoring of systems, utilizing Cloudflare Tunnel technology for encrypted connections. Key features include built-in authentication, support for WinRM and SSH interactions, a responsive React interface with real-time terminal integration, and comprehensive DNS management. The tool is currently in active development and is intended primarily for testing and evaluation purposes.
2026-08-03
C++
★ 10
ShellCode Elevator is a sophisticated tool for bypassing User Account Control (UAC) and injecting shellcode into processes on x64 systems while maintaining stealth and undetectability. Its primary features include fully undetectable operation, privilege escalation, memory-only execution, and anti-debugging mechanisms to prevent detection by security tools. This makes it a potent option for executing malicious payloads without alerts on target systems.
2026-08-03
Python
★ 17
ShellOrd is a cross-platform Command & Control (C2) framework designed for authorized penetration testing and educational purposes, implemented in Rust and Java. It supports Windows, MacOS, and Linux, and features a modular architecture with extensions, secure memory handling, and encrypted data transmission over TCP or UDP. The framework enables users to build and automate workflows, serving as an alternative to Trickest, while emphasizing speed and security.
2026-08-03
Python
★ 157
PCAP Hunter is an AI-enhanced threat hunting workbench designed for SOC analysts, enabling seamless integration of manual packet analysis with automated security monitoring. It features a user-centric interface for geographic flow aggregation, linked visual analysis, and a durable analysis workflow, while also providing optional Large Language Model assistance for enriched analysis. The tool supports visualization and investigation of packet captures through advanced filtering and responsive dashboard capabilities, ensuring comprehensive threat detection and evidence management.
2026-08-03
Python
★ 23
QuicDraw is a security research tool focused on fuzzing and race-condition testing of HTTP/3 servers using the Quic-Fin-Sync technique over the QUIC transport layer. It supports advanced features such as custom HTTP headers, multiple request fuzzing with wordlists, and TLS decryption for packet analysis, making it suitable for testing the resilience of HTTP/3 applications against race conditions and security vulnerabilities. The tool is built on the aioquic library, offering a robust implementation for developers and security professionals engaged in network protocol research.
2026-08-03
Rust
★ 314
MWEmu is a Rust-based hardware emulator and OS process simulator primarily designed for dynamic malware analysis and testing, focusing on Windows processes with some Linux support. It features fast and reliable x86 32/64-bit emulation, extensive implementation of 339 CPU instructions, and 260 WinAPI calls, as well as tools for memory tracking, state exploration, and interaction with various shellcodes and malware payloads. Notable functionalities include command-line, Rust, and Python library interfaces, as well as advanced dynamic analysis capabilities like iteration detection and PE execution.
2026-08-03
HTML
★ 153
Lumina Sentinel is a behavioral anomaly detection and orchestration framework designed for security researchers and threat analysts to analyze the behavior of credential stealers and remote access trojans (RATs) in a controlled environment. Its notable features include a Behavior Replay Engine that reconstructs infostealer actions with MITRE ATT&CK™ mapping, real-time process tree visualization via D3.js, and multilingual intelligence reporting to facilitate global collaboration. The framework emphasizes security and education by operating in isolated containers without affecting the host system.
2026-08-03
Python
★ 21
cryptz is an advanced encryption and decryption tool designed for secure data handling. Its primary use case involves encrypting sensitive information to prevent unauthorized access, and it features a user-friendly command-line interface to facilitate easy implementation. The tool is built using Python, with dependencies managed via a requirements file.
2026-08-03
Python
★ 13
ShellValley is a user-friendly reverse shell generator tool designed for Capture The Flag (CTF) enthusiasts who require quick shell generation directly from the terminal. It supports multiple reverse shell types, including bash, php, python, and many others, allowing users to specify the shell type, IP address, and port easily through a command-line interface. The tool emphasizes educational use, warning against illegal activities and ensuring adherence to regulations.
2026-08-03
Java
★ 697
BerylEnigma is a comprehensive CTF and penetration testing toolkit designed to perform a variety of encryption, coding, and text manipulation functions. It features modern and classical cryptographic methods, encoding formats, and practical utilities including image processing and Red Team capabilities such as reverse shell generation and payload conversion. Built with JDK17 and the JAVAFX framework, it aims to assist security professionals and researchers with a wide range of functionalities in a user-friendly interface.
2026-08-03
Python
★ 31
brutalkeepass is a Python tool designed to brute force passwords of KeePass database files, particularly useful when other conversion methods to supported formats fail. It utilizes the pykeepass library, supports command-line argument input for specifying the database and wordlist, and can produce verbose output and entry dumps upon successful password retrieval.
2026-08-03
★ 10
The CTF Resources repository is a comprehensive collection of cybersecurity tools and practice platforms specifically designed for Capture the Flag (CTF) competitions. It includes an extensive array of tools categorized into areas such as Open Source Intelligence (OSINT), steganography, and anonymous communication, offering functionalities from data gathering and analysis to secure and anonymous internet browsing. Notable features include links to various open-source tools, detailed descriptions, and categorization for ease of use, supporting users in enhancing their digital security skills.
2026-08-03
★ 97
Infosec-Notes is a repository that serves as a comprehensive collection of notes tailored for penetration testers and ethical hackers, documenting the author's learning journey towards OSCP certification and beyond. It provides insights into various offensive and defensive security techniques, including red teaming, enumeration, privilege escalation, and CTF challenge strategies, while also encouraging community contributions to enhance the content. Notably, the notes encompass practical coding examples and highlight essential cybersecurity practices, with a strong emphasis on responsible hacking.
2026-08-03
★ 10
MrEchoFi is a cybersecurity toolset designed for DevSecOps, penetration testing, and hardware security assessments. It features a variety of tools aimed at enhancing digital security, including devices for forensic analysis, DDoS simulations, and phishing detection. Notably, it emphasizes a multifaceted approach to cybersecurity, incorporating modern scripting languages and methodology for innovative solutions.
2026-08-03
JavaScript
★ 106
AspGoat is an intentionally vulnerable ASP.NET Core web application designed for educational purposes, allowing Security Engineers and Developers to explore and practice web application security vulnerabilities. It encompasses a range of common security issues outlined by the OWASP Top 10, providing hands-on labs for vulnerabilities such as XSS, SQL Injection, and Cross-Site Request Forgery, along with features like Docker support for easy deployment and secure coding best practices.
2026-08-03
Go
★ 496
Exif Looter is a command-line utility designed to analyze and manipulate image metadata, specifically EXIF data. Its primary use case includes analyzing individual images or entire directories for metadata extraction, as well as removing metadata to enhance privacy. Notable features include piping functionality for integration with other tools, the ability to extract GPS coordinates for mapping, and comprehensive support for various image formats.
2026-08-03
Python
★ 22
InstaRecon is an open-source intelligence (OSINT) tool specifically designed for gathering publicly available information from Instagram profiles, aimed at cybersecurity professionals and ethical hackers. It features user intelligence gathering, engagement analysis, and the ability to extract detailed account metrics, business intelligence, and public contact information. The tool operates across multiple platforms, supports automatic dependency installation, and requires users to provide a valid Instagram session ID for functionality.
2026-08-03
Python
★ 35
MongoBleed is a high-performance proof-of-concept scanner designed to identify vulnerable MongoDB instances affected by CVE-2025-14847, a pre-authentication heap memory disclosure vulnerability. Utilizing asynchronous I/O with Python's asyncio, the tool efficiently scans large network ranges, ensuring precise detection and minimal false positives by validating response lengths against the requested leak size, while automatically logging vulnerable targets. Additionally, it requires no external dependencies, making it straightforward to deploy in authorized security testing environments.
2026-08-03
Go
★ 111
`xcrawl3r` is a command-line tool that recursively spiders websites to discover URLs by actively traversing webpages and parsing files such as sitemaps and `robots.txt`. This active spidering approach distinguishes it from similar tools by revealing hidden or unindexed links, making it particularly useful for security researchers and IT professionals. Notable features include support for multiple output formats, cross-platform compatibility, and integration with automated workflows through standard input and output options.
2026-08-03
Go
★ 120
`xsubfind3r` is a command-line utility that efficiently discovers subdomains for a specified domain using information from various passive data sources. It is particularly useful for security researchers and IT professionals, offering features such as support for multiple output formats (including JSONL and stdout), the ability to integrate seamlessly into automated workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
2026-08-03
Python
★ 37
Anvil is a runtime-first tool designed for privilege escalation and attack surface assessment specifically targeting Windows thick client applications. It effectively reduces false positives by combining Procmon capture with Windows AccessCheck to validate writable paths in real-time while enforcing multiple verification gates. Notable features include its comprehensive approach to assessing various attack classes, detailed filtered analysis of candidate paths, and the ability to produce actionable reporting outputs in multiple formats.
2026-08-03
Python
★ 14
Mergen is an AI-powered penetration testing server that integrates with MCP-compatible agents, facilitating autonomous planning, adaptive execution, and professional reporting across over 44 security tools. With its multi-layer architecture featuring a FastAPI backend and an adaptive AI attack engine, Mergen enables sophisticated target profiling, dynamic attack execution, and unified risk scoring while supporting multiple output formats like HTML, JSON, and CSV for reporting. Notably, it offers a plugin system for seamless integration of security tools and automated operational capabilities, making it a comprehensive solution for red team engagements.
2026-08-03
Go
★ 719
`xurlfind3r` is a command-line utility that efficiently discovers URLs associated with a given domain by sourcing publicly available data through passive means. It is particularly useful for security researchers and IT professionals, offering features like multiple output formats (JSONL, file, stdout), support for automatic workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
2026-08-03
Python
★ 15
gitghost is a tool designed to scan public GitHub repositories for exposed secrets, including those that may have been committed in the past and then deleted. It thoroughly searches through git history to identify vulnerabilities and presents findings in an HTML report complete with direct links to the locations of the secrets, as well as a guide on how to remediate the issues. Notable features include the ability to generate an exposure score, scan for various types of sensitive information, and run local scans without installation.
2026-08-03
PHP
★ 132
Bug Bounty is a comprehensive knowledge base designed for security researchers, penetration testers, and bug bounty hunters, featuring methodologies, cheatsheets, automation tools, wordlists, and real-world write-ups. Its primary use case involves equipping users with the necessary resources for web penetration testing, API security, cloud exploitation, and modern vulnerability assessment techniques. Notable features include battle-tested methodologies and a focus on ethical hacking practices, underscoring the importance of authorized testing only.
2026-08-03
Python
★ 17
ReconFusionAI is an AI-powered web asset scanner designed to detect exposed secrets, credentials, PII, and vulnerabilities across web applications with high accuracy through a comprehensive library of over 1,183 detection patterns. Its notable features include advanced contextual analysis using Ollama for improved understanding of data context, a modular architecture allowing for easy updates, and dual output formats that provide detailed findings and reconnaissance intelligence. Additionally, it incorporates intelligent caching mechanisms and production-hardened capabilities for efficient and robust operation.
2026-08-03
Python
★ 38
OrgASM is a modular attack surface mapping tool designed for discovering and enumerating potential vulnerabilities within a target's ecosystem, such as subdomains, IPs, and services. It integrates seamlessly with other tools like nuclei for scanning and wappalyzer for service detection, offering features such as a customizable configuration file, pivoting to related FQDNs, and the ability to automate scans using community APIs. Users can extend its functionality by adding custom APIs and tools, making it highly adaptable for various cybersecurity needs.
2026-08-03
★ 31
LMAP (Large Language Model Mapper) is an out-of-the-box evaluation tool for large language models (LLMs), aimed at aiding developers and compliance teams in assessing security and safety risks associated with LLM deployments. It includes features such as universal HTTP access for various LLMs, a user-friendly GUI for ease of use, multi-objective testing capabilities, automated and manual redteaming modules, and customizable datasets for specific applications. Additionally, LMAP streamlines the evaluation process by generating formatted reports compatible with CI/CD pipelines, ensuring comprehensive vulnerability assessment pre- and post-deployment.
2026-08-03
Python
★ 22
DiscourseMap is an advanced security scanner designed specifically for Discourse forum platforms, offering over 25 specialized security modules for comprehensive assessments. It features capabilities such as CVE detection, plugin analysis, and API testing, all optimized for quick performance and reliability, delivering detailed reports in multiple formats. The tool is well-suited for vulnerability detection and compliance verification, making it essential for securing Discourse environments.
2026-08-03
JavaScript
★ 27
Pentesting Cyber MCP is a framework that provides standardized server implementations for 50 popular security tools via the Model Context Protocol (MCP), facilitating automation in pentesting and bug bounty tasks. Each MCP server encapsulates a security tool with a uniform interface, making it interoperable with any MCP-compatible client and allowing seamless integration into security assessments. Notable features include a wide range of tools covering reconnaissance, vulnerability scanning, and exploitation, all accessible through standard MCP interfaces.
2026-08-03
Python
★ 73
RAG/LLM Security Scanner is a professional security testing tool designed to identify critical vulnerabilities in Retrieval-Augmented Generation (RAG) systems and large language model (LLM) applications, such as chatbots and knowledge retrieval systems. Notable features include advanced prompt injection detection, data leakage assessments, function abuse testing, and comprehensive reporting capabilities, making it suitable for both demo and production environments. The tool supports easy integration with popular AI systems and provides detailed JSON/HTML reports with actionable insights.
2026-08-03
C++
★ 29
Worm GPT Core is an advanced adversarial prompt delivery framework designed for AI researchers and cybersecurity professionals to evaluate and exploit vulnerabilities in large language models (LLMs). It automates the delivery of jailbreak prompts and features innovative mechanisms for alignment evasion, multi-threaded prompt execution, and seamless integration with both commercial and local LLMs. The tool aims to enhance penetration testing capabilities within AI systems while ensuring zero telemetry and optimized performance.
2026-08-03
Python
★ 367
A lightweight active and passive scanner that combines the advantages of local and distributed models, supports dynamic external plugin import, and is dedicated to exploring web black-box vulnerabilities.
2026-08-03
Python
★ 323
DeepSec is an AI-driven security platform that integrates code security auditing and authorized penetration testing into a unified CLI and terminal workbench. It features a three-layer detection architecture for real-time vulnerability scanning, leveraging regex, AST analysis, and LLM semantic evaluation, along with IDE plugins for seamless development integration. The platform is designed to enhance security efficiency by augmenting traditional methods with advanced AI capabilities.
2026-08-03
Python
★ 41
Aarya is an advanced OSINT tool designed to validate email addresses and extract detailed digital footprints across various platforms, including social media and e-commerce sites. Notable features include a deep analytical capability that retrieves extensive metadata such as Google Maps reviews and account creation dates, as well as dynamic user-agent management to enhance stealth during scans. Aarya focuses on delivering high-quality identity intelligence rather than merely confirming existence, offering a sophisticated user interface and explicit reporting on scan results.
2026-08-03
Go
★ 11
BannerGrapV2 is an advanced network reconnaissance and vulnerability discovery tool designed for both offensive and defensive security operations, making it suitable for Red and Blue Teams, bug bounty hunters, and security auditors. Notable features include multi-threaded banner grabbing, extensive service fingerprinting, a robust vulnerability detection engine, and flexible reporting options in multiple formats, all powered by a performance-focused architecture enabling concurrent scans of up to 10,000 hosts.
2026-08-03
★ 142
CRLJ is a comprehensive resource repository aimed at cybersecurity professionals, students, and enthusiasts, providing structured pathways for learning and skill development in the field. It features resources such as educational materials, a cybersecurity roadmap, and foundational knowledge to support various learning stages. Notable features include links to essential cybersecurity topics, curated book lists, and guidance on office ergonomics for a healthy work environment.
2026-08-03
Shell
★ 50
Intel Codex is a comprehensive operational manual designed for digital investigators and security analysts, emphasizing OSINT methodologies and security protocols. It features over 40 standard operating procedures (SOPs), guides for various social media platforms, and case studies that illustrate practical applications in real-world investigations. Notable elements include legal and ethical compliance frameworks, detailed investigation techniques, and a focus on malware analysis and penetration testing methods.
2026-08-03
Python
★ 28
The LeakIX Python client provides a programmatic interface for interacting with the LeakIX platform, primarily utilized for retrieving and handling data related to internet leaks, subdomains, and other events in a structured manner. It supports both synchronous and asynchronous API calls, with responses encoded in a defined format, allowing users to leverage built-in methods for response handling and data transformation. This client is compatible with Python versions 3.11 through 3.14 and facilitates easy integration into Python applications through its straightforward installation and documentation.
2026-08-03
★ 19
The IP Fraud Database is an open-source tool that provides a continuously updated list of over 750,000 confirmed malicious IP addresses and networks, with refresh intervals of just 30 minutes. It features individually verified threat categories and infrastructure types, allowing easy integration into security systems such as firewalls and web application firewalls (WAFs) without restrictions. Additionally, the community-driven aspect enables users to report and contribute new malicious IPs, enhancing the database's effectiveness in combating cyber threats.
2026-08-03
★ 55
Spydi's ThreatIntel Feed provides aggregated threat intelligence blocklists sourced from various OSINT databases, honeypots, and C2 trackers, offering tiers of confidence for IP and domain blocklists. It features multi-source validation to enhance accuracy, automatic whitelisting of CDN IPs to minimize false positives, and is constructed for compatibility with tools like Pi-hole and AdGuard. The service is designed for rapid global distribution via Cloudflare R2, ensuring low latency access to threat intelligence data.
2026-08-03
Python
★ 59
ThreatFox IOC IPs is a Python-based tool that generates a machine-readable IP blocklist sourced from ThreatFox, a project by Abuse.ch. It provides users with an updated blocklist of malicious IPs every hour, making it suitable for cybersecurity applications like threat intelligence and proactive network defense. Notable features include automatic updates and compatibility with the AIOHTTP library for efficient data handling.
2026-08-03
Python
★ 124
Kizagan is a Remote Access Trojan (RAT) and Command and Control (C2) tool developed in Python, designed to create executable files for controlling compromised machines. Key features include advanced functionalities such as file management, real-time screen streaming, capturing screenshots and video from the victim's camera, and an integrated keylogger. The tool is intended for educational use in security research and red teaming, with ongoing development for enhanced capabilities.
2026-08-03
C++
★ 210
RunAs-Stealer is a credential harvesting tool designed to exploit Windows systems by implementing three techniques: hooking `CreateProcessWithLogonW`, smart keylogging, and remote debugging. Its primary use case is to stealthily capture user credentials and store them in an alternate data stream of a desktop.ini file for later retrieval. Notable features include continuous operation in the background and the ability to eliminate captured credentials directly via command-line instructions.
2026-08-03
C++
★ 138
SpyAI is an intelligent malware designed to capture screenshots of entire monitors and exfiltrate the data via a secure channel to a Command and Control (C2) server. Utilizing GPT-4 Vision, it analyzes the images frame by frame to construct daily activity reports. Key features include integration with Slack for secure communication and customizable operational parameters for timing and monitoring.
2026-08-03
Python
★ 38
DRILL (Distributable Remote Integrated Lightweight Link) is an advanced Command and Control (C2) framework designed for covert operations across diverse environments. Key features include WebSocket communication for efficient data transfer, single-port operation to evade detection, cloud tunnel compatibility, and comprehensive file transfer options. Additionally, it supports cross-platform payload generation and offers a redesigned user interface for improved usability, alongside robust persistence mechanisms and post-exploitation modules for enhanced control over target systems.
2026-08-03
HTML
★ 79
Red Team Wiki serves as a centralized public resource for information on Red Team tactics, techniques, and procedures (TTPs), with an emphasis on both the offensive and defensive elements of these methodologies. It allows users to access detailed documentation while providing options for community contributions through role assignments or pull requests. Notable features include a focus on reporting aspects of TTPs and a collaborative approach to content creation.
2026-08-03
C#
★ 266
SharpGmailC2 is a Command and Control (C2) tool that utilizes Gmail for exfiltrating data and receiving commands via SMTP and IMAP protocols. It allows users to send commands through unread emails while leveraging Gmail's infrastructure for stealthy operation, though it is noted that the tool is currently flagged by Windows Defender. This tool is designed for educational and testing purposes, enabling operators to manage remote implants over email while maintaining a relatively low detection profile.
2026-08-03
Zig
★ 83
ZYRA is a Zig-based obfuscator, packer, and loader aimed at safeguarding executable files against static analysis and reverse engineering. Its notable features include performance optimization through Zig, the ability to generate complex control flow to hinder reversing efforts, and runtime decryption for secure execution of payloads. Currently, ZYRA supports Linux, with straightforward installation and usage options for packaging executables.
2026-08-03
Python
★ 18
DorkGen is a script designed to generate keyword combinations for web page URLs, serving primarily for web scraping, testing, and security-related applications. It enables rapid creation of dork lists based on user-defined variables and features persistent configurations through external config files for enhanced usability. Additionally, recent updates have expanded the range of available dorks, improving the tool's functionality.
2026-08-03
Shell
★ 12
Dynasty-C2 is an advanced Command and Control (C2) framework designed for digital operations, primarily on Linux systems, and inspired by anime aesthetics. Key features include a built-in web server for payload distribution, support for multiple agent interactions, and unique agent identification for effective session management. Future enhancements are planned for Windows compatibility and persistent payload capabilities, making it a versatile tool for cybersecurity professionals.
2026-08-03
Python
★ 32
FSOCIETY RAT V2 is a Discord-based Remote Administration Tool designed for system control and manipulation through a command line interface. Its primary use case includes executing system commands, accessing device features like screenshots and webcam capture, and credential dumping. Notable features encompass new keylogging capabilities, process management, and various trolling options, all while emphasizing ethical use in educational contexts.
2026-08-03
Python
★ 24
Phishing AI Agent is an advanced tool designed to identify vulnerable employees within organizations, leveraging AI to automate the reconnaissance and campaign generation process for phishing simulations. Its notable features include dynamic knowledge fetching for real-time intelligence, multi-source profile enrichment, AI-powered vulnerability analysis, and SMTP integration for either simulation or real email delivery. This tool is intended for authorized security testing and employee awareness training only, providing security teams and red/blue teams with a robust method to enhance cybersecurity measures against phishing threats.
2026-08-03
C
★ 275
reveng_rtkit is a Linux Loadable Kernel Module (LKM) rootkit specifically designed for the 5.11.0-49-generic Linux kernel, primarily used for post-exploitation stealth techniques. Its key features include syscall table address retrieval, function hooking, and the capability to hide itself and other processes from system monitoring tools, making it difficult to detect. Additionally, it implements an IOCTL for interactive control and can bypass known rootkit detection tools like rkhunter.
2026-08-03
Python
★ 23
Xtreme Nmap Parser (XNP) is a Python utility that parses XML files generated by Nmap and converts them into various formats, including CSV, XLSX, and JSON. Its primary use case is to facilitate data analysis and reporting in network security assessments, with notable features such as file and directory handling, configurable output formats, and advanced filtering options for focusing on specific services or vulnerabilities. Additionally, XNP allows users to maintain pentesting records and provides easy documentation and data sharing capabilities.
2026-08-03
C
★ 2448
Diamorphine is a Linux kernel module rootkit designed for various Linux kernel versions from 2.6 to 6.x across x86/x86_64 and ARM64 architectures. Its notable features include the ability to conceal processes and directories, as well as granting root privileges to specified users through specific signal commands. This tool enables undetected manipulation of the system, making it particularly useful for advanced stealth operations in cybersecurity contexts.
2026-08-03
Rust
★ 11
NetRaze is an offensive network-execution toolkit developed in Rust, providing a memory-safe, single-binary alternative to traditional Python-based tools like NetExec and CrackMapExec. It maintains a similar workflow for network post-exploitation but enhances performance with async I/O and offers a desktop GUI for visual workflow composition. Currently in alpha, it focuses on core functionality with a goal of expanding its protocol coverage across various operating systems.
2026-08-03
Python
★ 180
sshprank is a versatile tool designed for SSH reconnaissance and exploitation, offering functionality for mass scanning, login cracking, banner grabbing, and assessing password authentication support. It leverages the python-masscan and Shodan modules to efficiently identify vulnerable SSH services, enabling users to experiment with various configurations and options for effective password cracking. Notable features include support for random IP address generation, multiple credential combinations, customizable thread management, and output logging for successful logins.
2026-08-03
Go
★ 1741
emp3r0r is an advanced, zero-trust post-exploitation framework and command & control (C2) system designed for secure operations on both Linux and Windows environments. Its notable features include autonomous gossip mesh networking, fileless memory execution of Starlark-scripted agents, and robust cryptographic identity pinning, ensuring high levels of stealth, operational control, and security against impersonation attacks. The framework facilitates seamless integration and execution without relying on host-based interpreters, making it highly suitable for high-security scenarios.
2026-08-03
C
★ 141
Lulzbuster is a high-speed, multithreaded HTTP(S) directory and file brute-forcing tool designed for penetration testing and security assessments. It leverages concurrent HTTP requests to efficiently enumerate valid file paths and directories, while offering customizable options such as status code filtering, proxy support, and client certificate usage. Notable features include the ability to minimize false positives through smart mode options and support for extensive wordlists to ensure comprehensive scan results.
2026-08-03
Shell
★ 264
Nucleimonst3r is a high-speed vulnerability scanner tailored for Red Teams and Bug Bounty Hunters, enabling rapid identification of potential attack targets by fetching and filtering URLs from a specified domain. It leverages the httpx tool for scanning and provides dynamic template generation, real-time scan statistics, and comprehensive report generation, allowing users to customize scans effectively and integrate with other security tools for enhanced testing capabilities.
2026-08-03
★ 94
Pentest-Resources is a comprehensive repository that consolidates essential resources for penetration testing and red teaming, including cheatsheets, tools, techniques, and write-ups. It serves as a centralized hub for offensive security practitioners, offering categorized content that enhances knowledge sharing and skill development in various cybersecurity domains. Noteworthy features include a well-structured organization of resources across multiple categories such as API security, networking, and programming, making it a valuable tool for cybersecurity professionals.
2026-08-03
Go
★ 24
The Dark Mark is a command and control (C2) framework designed for efficient management of cybersecurity operations, enabling real-time command execution and secure client communication. It supports scalability, facilitates monitoring of client activities, and is user-friendly for both small and large-scale deployments. Key features include an intuitive command set for module management and easy setup, making it a versatile tool for cybersecurity professionals and researchers.
2026-08-03
Python
★ 15
ShinobiShell is a specialized penetration testing tool designed for file exfiltration and exploit injection, facilitating remote shell interactions between the attacking and victim machines. Its notable features include encrypted tunnel creation, a command for seamless reverse shell connections, and capabilities for managing machine information and various payload delivery methods through a user-friendly shell interface. The tool is particularly geared toward enhancing operational efficiency during pentesting activities.
2026-08-03
Assembly
★ 10
The asm-payloads-loaders tool provides a series of assembly-written payload loaders for x86-64 Linux, utilizing only native syscalls without external dependencies. It features various loading mechanisms, including file-based, HTTP, and DNS payload loading, with options for dynamic memory allocation and checksum verification for integrity checks. This tool is designed to facilitate the development and understanding of payload loading techniques through detailed examples and documentation.
2026-08-03
Python
★ 178
ARTC2 is an advanced execution framework designed to help security teams efficiently execute attack scenarios across multiple breach points, primarily focusing on Windows OS environments. Its notable features include rapid deployment, modern command and control capabilities utilizing encrypted communications, and dynamic attack formations that enable execution without recompilation. The tool supports extensive logging for evidence collection and analysis, facilitating rapid evaluation of endpoint detection and response (EDR) solutions against MITRE ATT&CK frameworks.
2026-08-03
Zig
★ 226
Black-Hat-Zig is a cybersecurity tool that focuses on implementing various malware techniques using the Zig programming language, catering particularly to security researchers, malware developers, and reverse engineers. Notable features include continuous updates and a community-driven approach, which encourages contributions to expand its functionality and content. This tool serves as a resource for exploring and weaponizing capabilities within the Zig environment.
2026-08-03
Python
★ 32
BlackBerryC2 is an encrypted remote administration and command-and-control (C2) framework primarily designed for educational and security research purposes within controlled environments. It features a custom TCP-based server that employs application-layer cryptography, including AES-256-GCM encryption and HMAC-SHA256 authentication, facilitating secure client communication, remote command execution, and file transfers. Key capabilities include session management, support for multiple concurrent clients, interactive console operations, and robust flood detection mechanisms.
2026-08-03
Python
★ 23
Blexploit is a comprehensive offensive Bluetooth Low Energy (BLE) security framework designed for red teams and security researchers, facilitating passive scanning, exploitation, and replay attacks with advanced anomaly detection. Its modular architecture includes features such as GATT enumeration, customizable attack simulations, and offline sandbox environments, while automatically generating risk assessments and attack module suggestions based on detected device UUIDs. Key functionalities, including real packet injection and an Isolation Forest-based detection mechanism, make it versatile for both testing and education in Bluetooth security contexts.
2026-08-03
Shell
★ 11
BST is a developing suite of security tools designed to facilitate various cybersecurity tasks. Its primary use case encompasses streamlining security assessments and enhancing defensive measures, with a focus on providing a comprehensive toolkit for security professionals. Notable features include modular architecture and the potential for integration with various security frameworks.
2026-08-03
Python
★ 42
Chronix is a self-hosted collaborative workspace designed for penetration testers and red team operators, facilitating the capture of notes, commands, outputs, and operational context during security engagements. Notable features include real-time synchronization, timeline logging with extensive filtering and searching capabilities, and the ability to export notes in Markdown format along with images. Additionally, it supports collaborative note-taking with markdown formatting, auto-save functionality, and a structured export mechanism for reporting workflows.
2026-08-03
Python
★ 24
claude-code-pentest automates the penetration testing lifecycle using six specialized skills that range from reconnaissance to exploit chaining and report generation. Its notable features include subdomain enumeration, vulnerability discovery across web applications and APIs, cloud infrastructure analysis, and the capability to compose findings into comprehensive bug bounty reports—all implemented via 43 standalone Python scripts that require no external dependencies. The tool is designed for authorized security testing only and is integrated with Claude Code for user-friendly command execution.
2026-08-03
Python
★ 130
CODASM is a Python utility designed to encode arbitrary data into pseudo Assembly instructions and compile it into the .text section of binary files, effectively allowing for the obfuscation of shellcode. Notable features include the ability to specify output formats (ASM, binary, C decoder), control over encoding parameters, and considerable data overhead of 80-120%. This tool is primarily used for educational and security research purposes related to malware analysis and payload delivery methods.
2026-08-03
C
★ 146
ColdWer is a cybersecurity tool that enables users to freeze endpoint detection and response (EDR) or antivirus (AV) processes by leveraging the WerFaultSecure.exe PPL bypass, allowing for the extraction of LSASS memory on modern Windows systems. Its primary use case is for security assessments and exploit development, featuring a fast execution model, manual process control, and the ability to bypass process protection via in-memory modifications. This tool is particularly useful for maintaining stealth during sensitive operations while extracting potentially credential-related information from LSASS.
2026-08-03
C
★ 94
CS-EDR-Enumeration is a Cobalt Strike Aggressor Script designed to enumerate antivirus (AV), endpoint protection platform (EPP), endpoint detection and response (EDR), and telemetry/SIEM products on Windows hosts post-compromise. It features six commands with varying noise levels to suit different operational risk tolerances, and includes a comprehensive signature database for major security vendors, enabling silent enumeration techniques that minimize detection. Notable capabilities include kernel driver enumeration, automatic threat level assessment, and color-coded output for quick identification of security products.
2026-08-03
C
★ 90
CS2BR is a compatibility layer designed to enable the execution of Cobalt Strike (CS) Beacon Object Files (BOFs) in Brute Ratel C4 (BRC4) by translating CS API calls to their BRC4 equivalents. It facilitates the use of existing CS BOFs in the BRC4 environment, though it currently only works at the source code level and does not cover all CS API functionalities. Notable features include a patching process for BOF source code and the option to generate parameters for execution, while users should be aware of limitations regarding certain APIs and the potential for increased code size.
2026-08-03
Python
★ 21
DRAKBEN is an AI-powered autonomous penetration testing framework that utilizes natural language processing to perform comprehensive security assessments, allowing users to issue commands in plain language. Its notable features include a self-evolving engine for dynamic tool synthesis, a multi-language interface supporting Turkish and English, and advanced memory systems for context-aware decision-making and persistent learning. This framework streamlines the penetration testing process from reconnaissance to reporting with minimal user intervention.
2026-08-03
Python
★ 12
The Fake-SystemUpdate-Malware-Simulator is a malware simulation tool designed to illustrate common stealth techniques employed by real-world malware, masquerading as a Windows system update executable. It features keylogging, periodic screenshot capture, and IP-based geolocation tracking, all while maintaining persistence by utilizing Windows Startup locations and registry keys. This project serves purely for educational purposes and to enhance cybersecurity awareness, demonstrating how such malicious software can evade detection.
2026-08-03
Rust
★ 35
Ferrox is a research-focused Windows stealer written in Rust, designed to harvest sensitive data including browser credentials, cryptocurrency wallet information, and messaging app sessions while employing various evasion techniques to bypass antivirus and endpoint detection systems. Its notable features include polymorphic builds, compile-time encryption of strings, direct syscall execution, anti-analysis measures, and the ability to exfiltrate stolen data via Discord or Telegram within a stealthy execution environment. The tool is intended strictly for educational purposes in understanding modern attack methodologies for enhancing cybersecurity defenses.
2026-08-03
Python
★ 19
File Scraper is a tool designed for extracting sensitive information from files using custom regular expressions, and it generates an interactive HTML report based on the findings. Its primary use case is in security assessments and data validation, where users can employ their regex expertise to customize the search patterns for various types of sensitive data, such as authentication tokens and credentials. Notable features include the ability to style the generated reports and collect specific data formats like Base64 and PEM, enhancing the tool's versatility for educational and practical cybersecurity applications.
2026-08-03
PowerShell
★ 501
FlipperZero is a tool designed for executing BadUSB attacks using scripts based on the DuckyScript language on the Flipper Zero device. Its primary use case revolves around both defensive and offensive scenarios, facilitating security awareness demonstrations or performing penetration testing via various pre-defined scripts for phishing, pin brute-forcing, and credential exfiltration. Notable features include the ability to automate web actions, access sensitive information, and deploy awareness campaigns by executing scripts that interact with commonly used applications and services.
2026-08-03
Python
★ 257
Forbidden is a cybersecurity tool designed to bypass 4xx HTTP response status codes, specifically targeting `403 Forbidden` and `401 Unauthorized` responses. Built using Python Requests and PycURL, it offers features for testing various HTTP methods, open redirects, and out-of-band interactions, while also supporting stress testing capabilities. Future enhancements aim to include options for suppressing console output and comprehensive testing for HTTP request headers and traffic manipulation techniques.
2026-08-03
PowerShell
★ 20
GhostPack Binaries is a repository offering precompiled binaries and scripts for various security and red team tools compatible with Windows, Linux, and macOS. Its primary use case is to facilitate authorized security testing and educational purposes, providing streamlined access to essential utilities while emphasizing the importance of ethical usage. Notable features include cross-platform support and a focus on prebuilt security tools, enabling users to conduct red teaming activities efficiently.
2026-08-03
★ 99
Google Hack Search is a specialized search engine that focuses exclusively on IT security content, aggregating information from over 240 curated sources to eliminate irrelevant results. Its primary use case is to facilitate targeted research in cybersecurity by providing relevant findings without marketing noise or AI-driven content. Notable features include the ability to apply Google Dorking techniques for refined searches and a customizable list of sources to enhance the search experience.
2026-08-03
C++
★ 90
HTTPWorker is a Flask-based command and control (C2) framework designed for security competitions, utilizing custom Windows implants written in C++. Its primary use case involves coordinating and managing remote Windows clients with capabilities such as command execution, file management, system information retrieval, and user interface access through an authentication-protected web app. Notable features include Docker support for deployment, integration with Pwnboard for beacon tracking, and customizable implant configurations to evade detection.
2026-08-03
Rust
★ 33
Injectum is a modern, type-safe Rust library designed for process injection tailored for Red Teams and Offensive Security operations. Its primary use case is to provide a structured framework for executing various injection strategies while managing memory safety and minimizing artifacts to evade detection by Endpoint Detection and Response (EDR) systems. Notable features include a modular architecture that allows dynamic swapping of injection techniques, a fluent Builder API for compile-time error detection, and robust payload management to enhance operational security.
2026-08-03
C
★ 105
InlineWhispers3 is a tool designed to modify SysWhispers3 generated files for compatibility with Cobalt Strike's Beacon Object Files (BOFs), specifically utilizing indirect system calls to enhance evasion from endpoint detection and response (EDR) systems. By eliminating direct system calls, it significantly improves the stealth of red team operations on Windows platforms. The tool's notable features include its ability to merge output files and the straightforward integration of generated syscalls into project code for seamless usage.
2026-08-03
JavaScript
★ 422
The iOS Penetration Testing Cheat Sheet serves as a comprehensive resource for security professionals engaging in penetration testing of iOS applications. It provides a structured list of tools, techniques, and resources specifically tailored for testing iOS environments, particularly focusing on jailbreak scenarios and tool usage on Kali Linux. Notable features include sections for inspecting IPAs, searching for sensitive files, and executing security best practices, alongside recommendations for further reading on relevant security standards and methodologies.
2026-08-03
Java
★ 72
Java Reverse TCP is a versatile tool designed for establishing reverse shell communications with remote hosts using JAR, JSP, and Java files. It operates seamlessly across multiple operating systems, automatically detecting the environment and enabling compatible interactions with `ncat` or `multi/handler`. Notable features include the ability to handle various shell types and user-friendly setup instructions for deploying and utilizing the tool in educational contexts.
2026-08-03
C++
★ 268
KittyLoader is an advanced evasive loader developed in C and Assembly, primarily designed for educational purposes in the realm of defensive cybersecurity. Its capabilities include early execution hijacking, module hiding through unlinking from various lists, and a range of sophisticated anti-analysis techniques like multilayer scoring and jittered operational delays to evade detection. Additionally, it employs encryption for embedded payloads using high-entropy randomness, allowing for stealthy API resolution and library loading, which significantly enhances its evasion tactics against static and dynamic analyses.
2026-08-03
★ 17
MCP-Penetration-testing is a comprehensive security framework focused on the OWASP Model Context Protocol (MCP) Top 10 vulnerabilities, designed for auditors, pentesters, students, and enterprises. Notable features include a checklist-driven approach that outlines attack vectors, detection techniques, and remediation strategies for each vulnerability, alongside a scoring system to evaluate MCP security maturity. The repository serves as both a pentesting playbook and a learning resource, providing a detailed roadmap for mitigating MCP risks and improving overall security posture.
2026-08-03
TypeScript
★ 29
OASIS is an open-source tool designed for benchmarking AI models in offensive security tasks such as vulnerability discovery, exploitation, and privilege escalation. Notable features include standardized Docker challenges, multi-provider benchmarking, automated analysis with MITRE ATT&CK mapping, and the Kryptsec Scoring Model (KSM) that evaluates methodology quality and success rates. The tool operates entirely locally, ensuring data privacy and no external account requirements.
2026-08-03
★ 111
OSINT360 is a GPT-5.2-powered assistant tailored for open-source intelligence (OSINT), digital forensics (DFIR), and cyber investigations, offering comprehensive support for intelligence operations including collection, analysis, and reporting. Its notable features include command-based interaction for expedited workflows, structured reporting formats, a tool-first approach favoring open-source tools, and adherence to compliance and ethical standards. The tool also facilitates adversary profiling, compliance with global cyber laws, and integrates real-time intelligence through live web lookups.
2026-08-03
Python
★ 37
Pentest Toolkit is an advanced penetration testing framework designed for rapid and efficient security assessments, integrating over 100 industry-standard tools into both a Python suite for automation and a Bash interface for hands-on operations. Its primary use case includes comprehensive testing phases, from reconnaissance and web security to SSL/TLS analysis and network assessment, all culminating in professional report generation. Notable features encompass automated reporting in multiple formats, robust web application vulnerability testing, and streamlined reconnaissance processes.
2026-08-03
HTML
★ 139
The Periodic Table of Offensive Security serves as a visual reference for 118 essential tools, frameworks, and standards utilized in offensive security and red teaming. Its primary use case includes aiding penetration testing, red team training, and providing a comprehensive overview of tools for OSINT, exploitation, and post-exploitation phases. Notable features include downloadable print-friendly PDFs and an interactive clickable version that links directly to resources for each tool represented.
2026-08-03
PHP
★ 574
The PHP Reverse Shell is a versatile tool designed to create reverse shells using PHP scripts across different operating systems, including Linux, macOS, and Windows. It automatically detects the OS and works with both `ncat` and `multi/handler`, offering educational utilities for establishing reverse shells and executing file upload/download functionalities. Notably, it supports multiple PHP versions and includes specific scripts for different environments, enhancing its adaptability for penetration testing scenarios.
2026-08-03
Shell
★ 11
PiSquirrel is a compact, versatile tool designed for red team and offensive security operations, functioning as an inline wiretap for monitoring servers, workstations, and network equipment. Notable features include its ability to mimic Brother printer responses to enhance stealth during network scans, a simplified setup script for quick configuration, and pre-installed tools for various network and penetration testing tasks. The device leverages inexpensive ARM architecture and open-source software, making it a cost-effective solution for cybersecurity professionals.
2026-08-03
PowerShell
★ 13
Proxy_Bypass is a post-exploitation tool designed to identify user agents capable of circumventing proxy restrictions. It offers batch processing, the ability to test various user agents against specific domains, and includes a predefined library of user agents for immediate use. Notable features include verbose output, support for custom user agents, and future enhancements such as multi-threading and additional language support.
2026-08-03
Python
★ 53
The PULSE C2 Framework is a command and control (C2) infrastructure designed for remote management of Windows agents through a secure HTTPS connection, featuring a web dashboard for real-time interaction. Key features include TLS encryption, a custom encrypted communication protocol, and capabilities for executing remote shell commands, file exfiltration, and agent control. This framework is intended for educational use, offering a simplified setup derived from a more complex rootkit project.
2026-08-03
Shell
★ 14
PurpleStorm TTPs is a comprehensive repository of commands, tools, techniques, and procedures utilized by the PurpleStorm CTF team, designed to assist in various cybersecurity tasks and challenges. Its primary use case includes facilitating tasks such as file transfers, port forwarding, establishing command and control (C2) channels, and executing penetration testing exploits. Notable features include detailed command examples for tools like Swaks, Ligolo-ng, and NetExec, which enhance users' capabilities in network exploitation and data exfiltration.
2026-08-03
Python
★ 92
Ravage Framework is a Command & Control (C2) solution tailored for cybersecurity professionals, red teams, and penetration testers, enabling them to simulate realistic attack scenarios with a secure and modular architecture. Notable features include end-to-end AES-256 encryption, advanced PowerShell obfuscation techniques, an interactive web-based dashboard for real-time monitoring, and dynamic listener management for flexible C2 operations. Its design prioritizes stealth and evasion, making it suitable for conducting penetration tests while minimizing forensic traces.
2026-08-03
C
★ 27
Rebellion is a Linux kernel rootkit malware designed for x86 and x86_64 architectures, offering features such as self-hiding capabilities, folder and file concealment, TCP/UDP port hiding, privilege escalation from low-privilege users to root, and a backdoor mechanism accessed via ICMP packets. Currently in beta, it seeks collaboration for development to address existing bugs and architecture compatibility issues. Notable functionalities include the ability to manipulate visibility within the system using the `kill` command and the curation of specific configurations through a dedicated `config.h` file.
2026-08-03
Python
★ 20
The Python Reverse Shell Generator is a GUI application designed for penetration testers and red teamers, enabling them to quickly generate reverse shell payloads for both Linux and Windows environments. It boasts features such as an extensive library of over 60 Linux payloads, real-time payload generation, multiple encoding options, and a user-friendly interface that supports easy OS switching. This tool also includes one-click copy functionality and a fullscreen mode for enhanced usability during security assessments.
2026-08-03
Rust
★ 388
RustiveDump is a Rust-based tool specifically developed to perform memory dumps of the lsass.exe process using only NT system calls, creating minimalistic minidump files that include crucial data such as SystemInfo and ModuleList. Notable features include Position Independent Code (PIC) support, XOR encryption for enhanced security, and remote transmission capabilities, along with efficient memory handling and a lean build size of 18KB due to its no_std and CRT-independent design.
2026-08-03
Rust
★ 369
RustPotato is a Rust-based privilege escalation tool that exploits DCOM and RPC to gain NT AUTHORITY\SYSTEM privileges on Windows systems. It features a TCP-based reverse shell utilizing Winsock APIs for remote command execution and employs indirect NTAPI calls to handle security tokens effectively. Its key capabilities include identifying and hijacking RPC communications, impersonating clients, and executing commands with elevated privileges.
2026-08-03
Rust
★ 193
RustSoliloquy is a Rust-based tool for capturing NetNTLM hashes by utilizing the SSPI without directly accessing LSASS, thus enhancing security during the process. Key features include the use of native APIs for indirect syscalls to manipulate registry settings and impersonate logged-on users, alongside streamlined NTLM negotiation to facilitate hash extraction. The tool is designed for educational purposes, showcasing a thorough understanding of NTLM authentication mechanisms.
2026-08-03
Python
★ 18
Scrapy Scraper is a web crawling and scraping tool that utilizes Scrapy integrated with Playwright's headless browser to handle JavaScript-rendered content effectively. Its primary use case includes probing, crawling, and extracting data from websites, with features such as support for concurrent requests, customizable sleep intervals, and the ability to take screenshots. Additionally, it offers options for rate limiting and recursive crawling, enhancing its usability for various scraping scenarios.
2026-08-03
HTML
★ 38
SecuSploitX is an advanced, modular, open-source penetration testing and cybersecurity toolkit designed for offensive security operations. It features a comprehensive suite of tools including web and network security modules, AI-driven automation for tasks like phishing simulations, and both GUI and CLI interfaces for user flexibility across multiple platforms. Notable capabilities include automated vulnerability scanning, advanced brute force tactics, and extensive documentation, making it suitable for both educational and professional use.
2026-08-03
Jupyter Notebook
★ 225
SploitCraft is a repository designed for hacking and offensive security that provides a curated collection of exploits, penetration testing techniques, and vulnerability demonstrations. Its primary use case is to assist cybersecurity professionals and enthusiasts in understanding and showcasing the latest threats through organized guides and proof-of-concept demonstrations. Notable features include a structured layout by specific topics and comprehensive step-by-step instructions, enabling users to easily replicate the techniques in controlled environments.
2026-08-03
C++
★ 57
Stealth Keylogger is a discreet Windows keylogger that utilizes low-level keyboard hooks to capture all keystrokes across the system, including special characters and unicode, while tracking the active window. Its notable features include a thread-safe buffer, immediate data flush upon right-click or enter, mechanisms for evading detection such as indirect syscalls and API hashing, and configurable logging to a file or transmission to a command and control server. The tool is designed for educational and authorized security research purposes.
2026-08-03
C++
★ 10
SyscallInjector is a stealthy DLL injector designed to execute direct syscalls on Windows, effectively bypassing endpoint detection and antivirus hooks. Its notable features include dynamic resolution of System Service Numbers, manual PE mapping, and the use of RWX memory allocation to circumvent commonly hooked functions. Additionally, it incorporates a mechanism to wipe shellcode after execution to further evade detection.
2026-08-03
★ 27
The Potato Garden repository compiles various Windows privilege escalation tools, referred to as "Potatoes," each sourced from different open-source projects. Its primary use case is to provide security professionals with readily accessible binaries for testing and exploiting vulnerabilities within Windows environments. Notable features include the aggregation of multiple tools into a single collection, enabling streamlined access and use for penetration testing and security assessments.
2026-08-03
PowerShell
★ 672
ThreatHunting-Keywords is a repository providing a comprehensive list of keywords to facilitate threat hunting activities in cybersecurity. It serves both blue teams and red teams, offering tools and methodologies for detecting and analyzing malicious activities that may evade automated security systems. Notable features include integration with SIEM tools like Splunk and ELK, DFIR optimized hunting strategies, and support for creating detections using YARA rules and SIGMA rules.
2026-08-03
C
★ 68
TibaneC2 is a modular Command & Control (C2) framework designed for offensive security research and red teaming, featuring a C/C++ core server, a PHP-based web panel, and a CLI console. Its notable characteristics include cross-platform implants, multi-language stagers, and scripting tools for enhanced automation and emulation, facilitating extensive customization without altering core functionality. The framework is intended strictly for educational and authorized testing purposes.
2026-08-03
C#
★ 14
Torpedo is a modern enhancement of PsExec, designed for remote execution and token impersonation, featuring advanced capabilities for red teams and security researchers. Notable functionalities include fileless DLL payload delivery, polymorphic runtime encryption for evading detection, and robust artifact cleanup post-execution, all while maintaining a familiar operational structure for users of PsExec. The tool's stealth improvements and enhanced flexibility make it suitable for authorized penetration testing and security assessments.
2026-08-03
★ 33
The TryHackMe-Beginner-Roadmap is a structured learning resource designed for novices in cybersecurity, providing a step-by-step guide to essential concepts and skills via the TryHackMe platform. It covers foundational topics such as operating system fundamentals, basic security principles, reconnaissance techniques, scripting for automation, and web security vulnerabilities, while incorporating hands-on exercises to reinforce learning through practical application. Notable features include a comprehensive overview of key cybersecurity tools and methodologies, facilitating knowledge development in both theoretical and practical dimensions.
2026-08-03
Ruby
★ 693
URLCrazy is an OSINT tool designed for generating and testing domain typos and variations to identify instances of typo squatting, URL hijacking, phishing, and corporate espionage. Notable features include support for 17 types of domain variants, over 8000 common misspellings, compatibility with 1500+ Top Level Domains, and options for popularity estimation and keyboard layout configurations. The tool automates the detection of potential threats against domains by checking the validity and usage of generated typo variants.
2026-08-03
★ 13
The MottaSec White Papers repository is a centralized collection of technical and cybersecurity white papers published by MottaSec, providing insights into various topics such as military drone security and IoT device boot integrity. Notable features include a clear organizational structure for easy navigation, self-contained papers with supporting materials, and multiple access formats including GitHub markdown and professionally formatted PDFs. This repository serves as a vital knowledge base reflecting the expertise and research of MottaSec in the cybersecurity domain.
2026-08-03
JavaScript
★ 488
The Android Penetration Testing Cheat Sheet is a comprehensive reference guide aimed at security professionals conducting penetration tests on Android applications. It provides a structured checklist of tools, techniques, and methodologies optimized for use in a Kali Linux environment, highlighting critical tasks such as APK inspection, vulnerability exploitation, and various Android security configurations. Notable features include integration of resources from OWASP, practical tips for creating proof-of-concept apps, and a focus on common vulnerabilities and mitigation strategies for Android apps.
2026-08-03
HCL
★ 20
ashirt-deployments is a Terraform configuration repository designed to facilitate serverless deployments of the ASHIRT application on AWS (ECS Fargate) and GCP (Cloud Run). It provides opinionated templates for affordable, semi-fault tolerant environments tailored for small teams, with features including managed SQL servers, encrypted storage, and the absence of blue/green deployments. The repository is currently under construction, with the GCP version ready for testing and the AWS configuration forthcoming.
2026-08-03
Python
★ 175
The "Awesome Black Hat Arsenal" repository is a curated collection of advanced cybersecurity tools presented at Black Hat Arsenal events, aimed at practitioners in red teaming, blue teaming, application security, and OSINT. It organizes tools by geographical location, year, and category, providing detailed descriptions, authorship, and GitHub links for each tool, facilitating easy access to cutting-edge security utilities. This resource serves as an invaluable reference for security professionals seeking to enhance their toolkit with the latest innovations in the field.
2026-08-03
Python
★ 33
Chad is a tool designed to search for Google Dorks, allowing users to find indexed information on the web efficiently, utilizing Playwright's headless browser for bypassing common security measures. Its notable features include the Chad Extractor for data extraction and validation, file download capabilities, and options to handle Google’s frequently changing cookies. Additionally, it offers a broken link hijacking feature and is primarily intended for educational use in cybersecurity research.
2026-08-03
Python
★ 55
DFMI (Don't Fool My Installer) is a toolkit designed for fileless code execution and covert payload delivery via Windows Installer (.msi) files, exploiting the CustomAction mechanism to execute arbitrary payloads silently during installation. Notable features include the ability to inject backdoors into both signed and unsigned MSI packages without altering their signatures, support for cross-platform payload generation, and functionalities for SSL encryption and IPv6. This tool is intended for authorized red team engagements and penetration testing only.
2026-08-03
★ 429
Hack The Box Reporting using SysReptor is a user-friendly and customizable pentest reporting tool designed to streamline the creation of reports for various certifications such as CPTS, CWES, and CDSA. It allows users to write reports in Markdown format, which can then be rendered to PDF without the hassle of local software issues, making it ideal for security professionals focused on reporting efficiency. Notable features include free access, easy self-hosting options, and a collection of pre-built templates specifically tailored for Hack The Box certifications.
2026-08-03
Python
★ 345
Halberd is an open-source, multi-cloud attack emulation tool designed to help cybersecurity professionals validate their cloud security defenses across major platforms such as Azure, AWS, GCP, Entra ID, and M365. It offers over 120 pre-built attack techniques mapped to MITRE ATT&CK and Azure TRM frameworks, an AI-powered intelligence mechanism for discovering and executing attack paths, and a user-friendly web interface that eliminates the need for command-line expertise, facilitating automation, orchestration, and reporting for cloud security testing.
2026-08-03
Python
★ 106
JusotLabs is a curated toolkit designed for ethical hacking, penetration testing, and security research. It offers a diverse range of Linux-compatible scripts for tasks such as DNS reconnaissance, port scanning, DDoS simulation, and network threat detection, alongside educational resources like CTF writeups and a reading list. Users are encouraged to leverage these tools within authorized environments to enhance their hacking skills and deepen their cybersecurity knowledge.
2026-08-03
Python
★ 401
KslDump is a cybersecurity tool designed to extract credentials from the Protected Process Light (PPL)-protected Local Security Authority Subsystem Service (LSASS) using only components signed by Microsoft, without deploying any additional exploits or drivers. Its primary use case revolves around leveraging a forgotten vulnerable kernel driver (KslD.sys) within Microsoft Defender, which allows unrestricted access to kernel and physical memory. Notably, it utilizes a vulnerable IOCTL command to perform memory reads, exploiting easily editable access controls that lack adequate validation mechanisms.
2026-08-03
Go
★ 532
Ligolo-MP is a sophisticated pentesting tool that facilitates collaborative pivoting through a client-server architecture, allowing multiple concurrent tunnels with automated TUN management. Its notable features include SOCKS and HTTP proxy support, cross-platform compatibility, and dynamic mTLS-enabled agent generation, all while providing a user-friendly terminal-based GUI for efficient monitoring and management.
2026-08-03
★ 143
The LLM Security Guide is a comprehensive resource aimed at addressing the offensive and defensive security concerns related to Large Language Models (LLMs) and Agentic AI Systems, updated for 2026. It includes critical corrections to the OWASP Top 10 for both LLMs and Agentic applications, an overview of recent AI security incidents, and introduces new security tools and strategies. Notable features include in-depth case studies, detailed vulnerability assessments, and coverage of emerging regulatory frameworks affecting AI systems.
2026-08-03
HTML
★ 86
LOLFSaaS is a comprehensive directory of 127 Software as a Service (SaaS) platforms equipped with free tiers, focusing on their abuse potential in security contexts. It offers extensive operational intelligence, detailing abuse surface, operational security profiles, detection mechanisms, and links to Command and Control (C2) frameworks, enabling security researchers and red teamers to effectively strategize their approaches. Notably, the tool categorizes services based on various attributes, such as zero-signup services, custom domain support, and detection logics, and provides cross-references to other threat intelligence resources for enriched context.
2026-08-03
Go
★ 33
Lurker is a cross-platform implant designed to function as a companion tool for Cobalt Strike, implemented in Go. It facilitates various commands such as file upload, download, and remote shell execution, enabling comprehensive control over target systems across multiple operating systems including Windows and Linux. Notably, it emphasizes security research and authorized penetration testing, providing a flexible and customizable platform for security assessments.
2026-08-03
PowerShell
★ 79
MSSprinkler is a PowerShell-based password spraying utility designed to test Microsoft Online accounts while minimizing the risk of account lockouts. It features a low-and-slow approach, configurable attempt thresholds, and the ability to gather verbose account and tenant information without triggering MFA prompts. Notably, it logs access and refresh tokens for successful sign-ins, enhances testing efficiency by detecting non-existent or locked-out accounts, and stores results in JSON and CSV formats.
2026-08-03
C#
★ 76
Mythic-OSEP-CheatSheet is a specialized resource designed to assist users in passing the Offensive Security Exploitation Expert (OSEP) exam using the Mythic Command and Control (C2) framework. The repository features a comprehensive collection of automated scripts and one-liner commands for various attack techniques and evasion strategies, enhancing the user’s ability to configure and utilize Mythic in a lab or exam environment. Notably, it includes automation for generating payloads tailored to dynamic VPN IPs, thereby streamlining the workflow for users facing constantly changing network configurations.
2026-08-03
Python
★ 17
NAAMSE is an automated security fuzzing framework designed to evaluate vulnerabilities in LLM-based agents using evolutionary algorithms. By generating adversarial prompts through intelligent mutations, it tests for security issues such as jailbreaks and prompt injections, employing a behavioral scoring engine and organizing attack vectors through a clustering engine. Key features include comprehensive reporting of vulnerabilities and metrics, making it an essential tool for red-teaming and enhancing the security posture of LLM agents before deployment.
2026-08-03
Python
★ 38
Nutcracker is an Android application analysis tool designed for security researchers, enabling the download of apps directly from Google Play and facilitating static and dynamic analysis to detect and bypass anti-root protections. Notable features include extraction of hardcoded secrets, insecure manifest analysis, and comprehensive OSINT reconnaissance, all of which culminate in a detailed technical PDF report. The tool also integrates an LLM-powered false positive filter for enhanced accuracy in its findings.
2026-08-03
Python
★ 227
Offensive Azure is a Python-based suite of tools designed for security assessments and penetration tests targeting Microsoft Azure environments. Key functionalities include token manipulation, user enumeration, and tenant reconnaissance, with features enabling users to extract and analyze data from Azure Active Directory, generate tokens for social engineering, and produce BloodHound-compatible outputs for further analysis. This versatile toolset is platform-agnostic and aims to simplify offensive security operations within Azure ecosystems.
2026-08-03
Python
★ 352
Offensive Claude is a spec-driven offensive security framework designed for Claude Code that implements structured engagement workflows following the Cyber Kill Chain methodology. It features a comprehensive set of 31 kill-chain skills, collaborative agents, and a shared vulnerability library, facilitating automated penetration testing, reconnaissance, exploit development, and reporting through a series of orchestrated commands. This tool is particularly useful for security researchers and practitioners to streamline their offensive security operations while maintaining high quality and traceability throughout the engagement process.
2026-08-03
PowerShell
★ 446
Red Team Playbooks is a comprehensive repository designed to assist cybersecurity professionals in Red Team engagements by providing a collection of open-source tools, techniques, and procedures. Its primary use case includes guiding users through various phases of penetration testing such as reconnaissance, exploitation, and post-exploitation activities. Notable features include detailed playbooks for each stage of an attack lifecycle, covering essential actions from initial access to data exfiltration and situational awareness.
2026-08-03
★ 65
Red-Team-Rust is an educational repository that provides a comprehensive collection of notes and resources focused on using the Rust programming language for offensive security. It covers fundamental Rust concepts, programming patterns, and specific applications in red teaming and malware development, emphasizing the advantages of Rust's memory safety and evasion properties. Aimed at security researchers and developers, the project facilitates a thorough understanding of Rust for creating robust red team tools.
2026-08-03
JavaScript
★ 185
SUASS is a comprehensive repository designed to provide cybersecurity professionals and learners with a wide array of study materials, covering essential topics such as penetration testing, cloud security, mobile application security, network security, and more. This resource serves as a centralized hub for enhancing knowledge and skills in cybersecurity, offering practical learning pathways through Capture the Flag (CTF) challenges and recommendations for certifications. Notable features include categorized content for various security domains and links to external learning platforms and communities.
2026-08-03
Python
★ 48
SubSurfer is a high-performance tool designed for subdomain enumeration and web property identification, ideal for red team operations and bug bounty hunting. It features fast asynchronous scanning, customizable port scanning, and web service identification capabilities, with a modular design that allows integration with other tools or use as a Python module. Continuous updates and the ability to tailor scans make it a versatile choice for cybersecurity professionals.
2026-08-03
★ 41
The LLM Red Teamer's Playbook provides a systematic methodology for assessing and bypassing various defense layers in Large Language Models (LLMs), such as input filters and alignment mechanisms. It emphasizes a diagnostic approach to identify and understand the specific defenses in place before selecting appropriate attack techniques, mapped to the Adversarial AI Threat Modeling Framework (AATMF) v3. This guide is intended for AI red teamers, security engineers, and researchers, enabling them to conduct unauthorized testing responsibly while improving the security of AI systems.
2026-08-03
Python
★ 109
The AISecurity tool, now archived, was part of the Syntrex project, which has since evolved into the Syntrex AI SOC platform. Its primary use case involved providing an open-source core through GoMCP with support for the MCP protocol. Notable features included modular architecture and compliance with the Apache 2.0 License.
2026-08-03
Go
★ 525
csprecon is a reconnaissance tool designed to discover new target domains by leveraging Content Security Policy (CSP) data. Its primary use case is for security professionals conducting reconnaissance in order to identify potential attack surfaces across multiple domains, with features such as concurrent requests, domain filtering, output options in JSON format, and the ability to handle CIDR input. The tool can also be configured for rate limiting and proxy usage, making it versatile for various operational environments.
2026-08-03
Go
★ 965
goshs is a versatile, single-binary file server designed for file transfer and capture tasks during penetration testing engagements. It supports multiple protocols including HTTP/S, WebDAV, FTP/SFTP, SMB, and LDAP, and offers features such as hash capturing, basic authentication, self-destructing payloads, and a TUI for interactive operations. Notable functionalities include token-based link sharing, DNS and SMTP server capabilities, and advanced collaboration tools for CTF scenarios.
2026-08-03
Shell
★ 14
Offensive security blog, projects & portfolio by Elimane D.
2026-08-03
C
★ 218
KHAØS C2 is a sophisticated post-exploitation command and control framework designed for stealth and evasion against endpoint detection systems. It features five covert communication channels, including Microsoft Teams and GitHub Gist, ensuring that the traffic blends with normal operations. The framework includes extensive post-exploitation capabilities, such as token theft, process injection, and lateral movement, along with a user-friendly React-based UI for real-time monitoring and payload management.
2026-08-03
Python
★ 168
LVRP (Local Vuln Research Pipeline) is an exhaustive LLM-driven vulnerability research tool designed to identify vulnerabilities across various source code files in up to 16 programming languages. It constructs a complete call graph of the codebase, enumerates all source-to-sink paths, and validates these paths for exploitability using a hybrid approach that combines static analysis and LLM insights. The tool is capable of analyzing extensive projects such as the Linux Kernel and VSCode, while ensuring deterministic path enumeration and comprehensive coverage, including blind spot reviews.
2026-08-03
Python
★ 14
Nagooglesearch is a Python library designed to facilitate web searches without relying on Google's direct API, making it suitable for educational and testing purposes. It allows users to customize search parameters, manage user agents, and configure cookies while ensuring the return of unique, relevant URLs that do not contain the keyword "google." Notable features include adjustable sleep intervals between requests to prevent rate limiting, the ability to specify custom user agents, and support for proxy connections.
2026-08-03
Python
★ 18
ProbeAgent is a command-line tool designed for offensive security testing of AI agents, performing automated red-team attacks such as prompt injection and credential exfiltration against any HTTP-accessible agent. Notable features include a detailed attack grading system that categorizes responses as Compromised, Resisted, or Blocked, allowing users to evaluate the effectiveness of their security controls, and advanced guardrail detection to distinguish between model defenses and actual security mechanisms.
2026-08-03
C++
★ 37
Project Scorpio is a sophisticated Windows process injection loader that utilizes techniques such as PPID spoofing, manual DLL mapping, and direct NT syscall execution to stealthily execute staged shellcode within a targeted remote process. Notable features include its ability to fetch payloads from a command and control server using HTTP, spawn a decoy process with a masqueraded parent process, and replace the text section of a mapped DLL without registering it in system tools, thereby minimizing detection risk.
2026-08-03
Zig
★ 10
Rango is a basic C2 agent developed in Zig for GNU/Linux systems, primarily serving as a proof of concept for utilizing Zig in command and control applications. Notable features include basic command execution capabilities, a straightforward codebase without external dependencies, and recent support for Windows targets mirroring its Linux functionality. The tool is still in development, with additional features such as file upload/download and BOF support planned for the future.
2026-08-03
Shell
★ 240
Secfiles is a repository that provides a collection of useful files designed for penetration testing, security assessments, and bug bounty hunting. Its primary use case is to facilitate security-related tasks by offering easily accessible resources and scripts. Notable features include a straightforward cloning process and comprehensive release notes for version tracking.
2026-08-03
C
★ 24
SpyIt is a real-time desktop surveillance tool designed for educational and research purposes, utilizing DXGI Desktop Duplication to capture and stream screen content over HTTP as MJPEG. It offers low-overhead operation, system audio streaming, and a user-friendly HTML viewer with multi-monitor support, making it suitable for red team operations and integration with AdaptixC2 for streamlined deployment and control. Key features include dynamic port assignment, background execution, and extensive audio device handling.
2026-08-03
Python
★ 59649
Strix is an open-source AI-powered penetration testing tool designed to autonomously identify and remediate vulnerabilities in applications. It provides a comprehensive pentesting toolkit including real exploit validation, multi-agent orchestration for scalability, and integration with CI/CD pipelines for continuous security checks. Key features include actionable findings with remediation guidance, auto-fixing capabilities, and the generation of compliance-ready reports, significantly accelerating the security testing process compared to traditional methods.
2026-08-03
TypeScript
★ 5844
T3MP3ST is a multi-agent offensive security framework designed to leverage existing AI coding agents for automated zero-day hunting. It facilitates a complete kill chain from reconnaissance to exploitation and reporting, using powerful models that can operate offline without the need for API keys. Notable features include reproducibility of results through a verification command, a keyless operational model, and transparency regarding the tool's capabilities and current features.
2026-08-03
Python
★ 46
ThunderStorm is a comprehensive Command and Control (C2) solution developed in Golang, designed to facilitate the management and deployment of software implants known as Bolts across various platforms. Key features include Cirrus, a ReST API for task management and real-time updates; JetStream, a Bolt builder that supports multiple formats and obfuscation; and Doppler, a user-friendly Python CLI for interacting with Cirrus and managing multiple implants efficiently. This tool aims to enhance operational capabilities while providing robust flexibility for cyber operations.
2026-08-03
Go
★ 103
XMT (eXtensible Malware Toolkit) is a versatile command and control (C2) framework written in Golang, designed for malware analysis and control functions, including data exfiltration. It features advanced process control for Windows, efficient networking resources, and compatibility with older Windows systems, while maintaining a minimal file size of approximately 5MB. Additionally, XMT supports various utility functionalities and aims for continuous enhancements, making it suitable for researchers and security professionals exploring cybersecurity threats.
2026-08-03
★ 49
Defcon Arsenal Tools (DArT) is a curated repository designed to provide security professionals with a comprehensive collection of tools, scripts, and resources for various cybersecurity tasks, including network scanning, vulnerability assessment, and exploit development. Notable features include organized categories for tools based on specific functions, such as credential scanning, network attacks, and malware research, facilitating quick access to relevant resources for users within the DEFCON community. The project emphasizes educational use and knowledge sharing, promoting responsible application in security practices.
2026-08-03
Python
★ 117
pyFUD is a cross-platform, fully undetectable (FUD) remote access tool (RAT) designed for multi-client handling, allowing persistent shell access and additional functionality such as file upload and download capabilities. The tool supports both Windows and Linux, with features including auto-reconnect and client executable conversion using PyInstaller, aimed primarily at educational use. Users are cautioned against uploading payloads to VirusTotal to maintain its effectiveness.
2026-08-03
Python
★ 67
Red Team Rising is a comprehensive resource repository designed for red and purple team professionals, encompassing topics like Penetration Testing, Digital Forensics, Exploit Development, and Malware Analysis. It provides curated study materials, reference links to training platforms and notable YouTube channels, as well as practical commands and tools for various OS distributions suited for cybersecurity tasks. Notable features include a wide array of recommended resources for self-study and a focus on both offensive and defensive security strategies.
2026-08-03
AutoIt
★ 120
ForceAdmin is a malicious tool designed to create an infinite loop of User Account Control (UAC) prompts, compelling users to grant administrative privileges by overwhelming them with requests. It provides various script templates in formats such as batch, PowerShell, AutoHotkey, AutoIt, HTA, and VBScript, facilitating execution via PowerShell and bypassing antivirus protections. Notable features include no dependencies, dual architecture support for x86 and x64 systems, and a fileless execution method.
2026-08-03
Python
★ 51
AttackMate is an automation tool designed to execute cyber attack scenarios across all phases of the Cyber Kill Chain, integrating seamlessly with penetration testing frameworks like Metasploit and Sliver Framework. It allows users to script commands, generate payloads, schedule and chain attack steps using configuration files, and perform background operations, including file transfers and HTTP interactions. Noteworthy features include automation of shell or SSH commands, comprehensive support for Metasploit and Sliver commands, and a user-friendly interface for managing complex attack scenarios.
2026-08-03
Python
★ 527
CVE-2024-6387_Check is a specialized tool for detecting servers vulnerable to the newly identified `regreSSHion` vulnerability in OpenSSH (CVE-2024-6387). It supports rapid scanning of IP addresses, domain names, and CIDR ranges, incorporates features such as multi-threading for efficiency, SSH banner retrieval, and options for assessing LoginGraceTime settings, all while providing detailed and easily interpretable output. Notably, the tool also includes IPv6 support and recognizes patched OpenSSH versions to enhance the accuracy of vulnerability assessments.
2026-08-03
C++
★ 11
End-To-End-SOC-Home-Lab is a comprehensive project designed to construct a Security Operations Center (SOC) lab on a personal computer, utilizing Splunk for monitoring and detection of cybersecurity threats. It enables users to simulate various attack scenarios, analyze the resultant logs and telemetry, and develop effective detection mechanisms, thereby fostering skills pertinent to both red team attack simulations and blue team defensive strategies. Notable features include detailed guidance on setting up infrastructure, practical use cases for threat detection, and a focus on hands-on learning through real-world attack techniques.
2026-08-03
Go
★ 68
OnlyShell is a Go-based reverse shell handler designed for penetration testers and security researchers, enabling the management of multiple reverse shell connections concurrently. Key features include automatic shell type detection, background shell management, command broadcasting across active shells, and the option for encrypted communications with TLS support. The tool offers an intuitive command-line interface and allows for real-time interaction and status monitoring of all connected sessions.
2026-08-03
C
★ 17
Erebos-Zero is a personal arsenal for malware development featuring sophisticated techniques for evasion and injection. It includes a variety of exploitation methods such as shellcode injection, DLL injection, and process manipulation, along with advanced anti-forensics and evasion techniques tailored for bypassing endpoint detection and response systems. This tool is primarily intended for research and educational purposes, focusing on the creation and deployment of stealthy malicious payloads.
2026-08-03
C
★ 26
IrisC2 is a command and control (C2) framework designed for authorized security testing, red team exercises, and internal research. It features a modular architecture comprising a Client for user interaction, a Server for managing communication and tasks, Beacons for executing commands within target environments, and a Stager for handling staged payloads. Notable capabilities include multi-platform support, advanced task scheduling, plugin integration for extended actions, and comprehensive event synchronization.
2026-08-03
★ 33
Abogado del Diablo is a Claude Code skill designed to provide critical, no-nonsense feedback on ideas, plans, or projects by acting as a hostile devil's advocate. It systematically critiques submissions by examining eight key angles, such as market viability and competition, delivering a blunt verdict along with prioritized issues to address, ensuring that potential flaws are identified before they can lead to failure. Notably, it can analyze full projects by reading files and utilizing parallel subagents for in-depth assessments, making it an invaluable tool for preemptive strategic planning.
2026-08-03
Shell
★ 13
ADPhantom is an interactive Bash wrapper for NetExec, facilitating credential gathering and network enumeration during penetration testing and red team activities. It offers extensive features, including authentication tests, SMB and LDAP enumeration, credential dumping, and password spraying, while automatically generating session logs and reports for efficient documentation. Additionally, it provides advanced functionalities such as a per-step skip system, a Ctrl+C handler for command interruption, and the ability to query deleted Active Directory objects via tombstone controls.
2026-08-03
PowerShell
★ 86
AES-Encoder is a PowerShell-based tool designed for crypting and obfuscating PowerShell scripts, primarily to evade modern antivirus detection. It features advanced capabilities such as variable name randomization, compression, and encryption, as well as support for recursive layering and AMSI bypassing for enhanced security. The tool is open-source, allowing users to easily modify and create their own variants for educational purposes.
2026-08-03
Python
★ 345
AgentSeal is a comprehensive security toolkit designed for AI agents, providing robust capabilities such as detection of malicious configurations, tracing toxic data flows, and scanning for potential supply chain vulnerabilities across various agents. It features an extensive pipeline for local scanning, real-time monitoring, and auditing of machine configurations without the need for API keys, alongside the ability to test against 225+ adversarial prompts. Notable functionalities include the `guard` command for scanning and assessing the security of agent configurations and the option to create organization-specific policies through custom rule sets.
2026-08-03
Python
★ 40
The AI Red-Team Recursive Self-Improvement Framework is a governance tool designed for managing recursive self-improvement loops in AI-assisted projects. It enforces a structured protocol that separates proposal creation and acceptance, incorporating rigorous independent checks, documentation, and promotion decision-making to ensure reliability and accountability. Key features include a domain-neutral approach, preservation of failure outputs, and explicit evidence requirements before promoting changes, making it suitable for various applications, including code maintenance and agent orchestration.
2026-08-03
Shell
★ 12
Arsenal is a versatile cybersecurity tool designed for vulnerability discovery and web application security testing. It automates the process of scanning and identifying common web vulnerabilities such as SQL injection, XSS, and open redirects, while also generating targeted wordlists for various web applications. Notable features include integration with multiple data sources for reconnaissance and the ability to automate tests for local file inclusion and sensitive file exposure.
2026-08-03
Rust
★ 72
Async Rust RAT is an open-source Remote Administration Tool (RAT) designed for Windows, developed in Rust primarily for legitimate system administration, research, and educational purposes. Notable features include system information retrieval, remote desktop capabilities, webcam capture, file management, and various control functionalities such as shutdown and restart, along with a client builder for customization. The tool emphasizes responsible use, necessitating explicit permission for system management tasks.
2026-08-03
JavaScript
★ 65
atomicgen.io is a web-based tool that simplifies the creation of Atomic Red Team tests by providing a user-friendly interface and automated YAML formatting. Its primary use case is to streamline security testing processes without the need for installation, allowing users to generate and manage tests directly through their browser. Notable features include customizable options and seamless integration with Docker for easy deployment.
2026-08-03
★ 10
The "Awesome Adversarial Machine Learning" repository provides a comprehensive collection of resources and references related to the security challenges associated with machine learning models. Its primary use case is to facilitate knowledge sharing and improve understanding of adversarial attacks, threat modeling, and defensive strategies in machine learning applications. Notable features include categorized resources on attacks by domain and strategy, case studies, and links to relevant frameworks, enhancing the tool's utility for researchers and practitioners in cybersecurity.
2026-08-03
★ 16
The "Awesome Cybersecurity Tools" repository serves as a comprehensive catalog of security tools aimed at students, red/blue teams, and cybersecurity professionals. It categorizes a wide range of tools across various domains, including reconnaissance, web application testing, cloud security, and digital forensics, ensuring that users have access to well-maintained and widely utilized software for security testing and defensive research. Notable features include a structured navigation system for efficient lookups and a strong emphasis on responsible and authorized usage of listed tools.
2026-08-03
★ 26
Awesome Offensive MCP is a curated collection of Model Context Protocol servers designed for Red Teaming, Pentesting, and Vulnerability Research, enabling users to seamlessly integrate Agentic AI into their offensive security workflows. The tool supports various tasks such as running Nmap scans, analyzing Ghidra decompilations, and querying Shodan—all through natural language commands within a unified conversation context. It emphasizes safety and compliance, encouraging users to audit the code of the MCP servers before deployment.
2026-08-03
Lua
★ 12
Awesomenmap is a comprehensive knowledge base dedicated to Nmap, providing a centralized repository for essential Nmap NSE scripts, CVE search tools, and automated reconnaissance pipelines. It streamlines access for security analysts, pentesters, and blue teams, featuring organized references and integration of third-party scripts to ensure they are current. Notable features include post-scan reporting capabilities and visualizations for enhanced security assessments.
2026-08-03
Python
★ 27
Basilisk is an open-source AI red teaming framework designed for automated adversarial prompt testing against various large language models (LLMs) such as Claude and GPT-family models. It features evolutionary prompt search, structured attack modules, and a real-time scan dashboard, enabling security researchers and penetration testers to conduct repeatable and comprehensive security assessments of LLM applications. Notable capabilities include differential mode comparisons across multiple model providers, guardrail posture scanning, and the ability to export test results in various formats.
2026-08-03
Python
★ 43
BenchJack is a vulnerability scanner designed to assess whether AI benchmarks can be manipulated, highlighting weaknesses before adversarial agents can exploit them. It employs a multi-phase audit process that combines static analysis tools with AI-driven deep inspection, categorizing vulnerabilities into eight distinct classes and providing real-time results via a web dashboard. Notable features include proof-of-concept exploit code generation and future integration of Docker sandboxing for enhanced security during analysis.
2026-08-03
Python
★ 31
The BLS Bible is a web application designed for cybersecurity professionals to manage and organize their assessment-related data and documentation, utilizing a configurable server structure for diverse operational environments. Its primary use case allows users to update, customize, and categorize data through specific folders while maintaining a user-friendly interface for content retrieval. Notable features include support for custom data folders, Docker deployment, and distinct server types tailored for varying operational needs.
2026-08-03
TypeScript
★ 187
Bulwark is an organizational asset and vulnerability management tool that integrates with Jira for generating application security reports. Its notable features include multi-client vulnerability management, security report generation, team-based roles authorization, and API key management. Designed for early-stage development, it offers a user-friendly interface for managing security tasks and facilitating team collaboration.
2026-08-03
Go
★ 26
Capsaicin is a next-generation web directory and asset discovery engine designed for red teamers, bug bounty hunters, and DevSecOps. It employs advanced evasion techniques, including TLS fingerprint spoofing and human-like delay simulations, to bypass modern web application firewalls and effectively uncover hidden paths, secrets, and misconfigurations. Notable features include smart auto-calibration to eliminate false positives, stateful fuzzing for misconfigured APIs, and the ability to detect over 16 different WAFs.
2026-08-03
C#
★ 448
Cervantes is an open-source, collaborative platform tailored for penetration testers and red teams, serving as a comprehensive management tool for organizing projects, vulnerabilities, and reports in a centralized location. It enhances operational efficiency by providing features such as team collaboration, OWASP compliance reports, built-in dashboards, and one-click report generation. Designed to be multiplatform and multilanguage, Cervantes streamlines penetration testing activities, significantly reducing coordination time and effort.
2026-08-03
C++
★ 39
The CET Spoofing Detection tool is a proof of concept designed to identify stack spoofing vulnerabilities in CET (Control-flow Enforcement Technology) processes by comparing the shadow stack to the user stack to detect missing frames. Its primary use case is for security professionals assessing the integrity of CET implementations, and it features a straightforward terminal interface for running vulnerability checks on specific processes. However, users should note that the tool may produce false positives, particularly when analyzing .NET applications.
2026-08-03
NetLinx
★ 66
Cheshire is a Go plugin for the Adaptix C2 service that enables pre-flight payload quality assurance by integrating with the LitterBox analysis framework. It allows operators to upload binaries, conduct static and dynamic analysis, and receive detailed EDR alerts directly from the Adaptix UI without additional navigation. Notable features include real-time progress streaming during analysis, extensive reporting on security findings, and a configurable interface for seamless user interaction.
2026-08-03
Python
★ 16
Claude Active Directory is a specialized AI-driven tool designed for offensive security assessments within Active Directory environments. It features an array of structured methodologies, evidence-ready reporting, and integration with Claude Code, enabling red teams and internal assessors to efficiently conduct penetration tests across eight skill domains. Notable features include thirteen slash commands, seven AI agents, and support for mapping findings to MITRE ATT&CK tactics, enhancing both operational impact and defensibility.
2026-08-03
★ 21
Claude Security Agents provide an automated solution for identifying and remediating vulnerabilities within software projects using two specialized Markdown files. The Red Team agent performs penetration testing to uncover security flaws, while the Blue Team agent automatically implements fixes based on the insights provided by the Red Team. This feedback loop allows for rapid vulnerability management without the need for extensive security expertise or infrastructure setup.
2026-08-03
★ 137
Cloud OSINT is a curated resource designed for conducting open-source intelligence (OSINT) assessments of cloud infrastructure, featuring dorks, tools, techniques, and methodologies applicable across major cloud platforms such as AWS, Azure, GCP, Oracle, and IBM. Its primary use case is to assist security professionals, red teamers, and bug bounty hunters in effectively mapping and analyzing cloud environments through a structured reconnaissance workflow. Notable features include comprehensive guidance on cloud infrastructure patterns, domain identification, and a variety of targeted dork queries, enhancing the efficiency of reconnaissance efforts.
2026-08-03
C
★ 149
CLR-Stomp is a Beacon Object File (BOF) designed for Cobalt Strike that implements .NET assembly stomping by loading a specified .NET assembly from the Global Assembly Cache (GAC) and replacing its content with a malicious payload before the runtime reads the metadata. This technique offers a covert execution mechanism that retains the legitimate disk identity of the GAC assembly, enabling the payload to evade detection while running in the victim's environment. Notable features include the use of custom memory managers to manipulate the CLR's assembly mapping process and the ability to suppress strong-name verification, which maintains the facade of legitimate assembly usage.
2026-08-03
Shell
★ 18
Cobalt-Docker is a containerization tool that simplifies the deployment of Cobalt Strike 4.12 team servers within Docker environments, enabling rapid setup and automatic startup of a REST API for interaction. It includes essential features like pre-launch configuration validation, multi-platform support for macOS and Linux, and the ability to deploy with custom Malleable C2 profiles. Additionally, the integration of a REST API enhances automation and streamlines server management.
2026-08-03
Python
★ 20
Codex Red Team System Prompt is a tool designed for injecting custom system prompts into OpenAI Codex, enabling the redefinition of its role and behavior. Its primary use case is for security professionals conducting authorized penetration testing, Capture The Flag (CTF) challenges, and technical exercises by allowing Codex to autonomously generate responses without user intervention. Notable features include a cross-platform automatic injection script, an emphasis on unrestrained AI collaboration, and a strict response protocol that ensures complete, actionable outputs.
2026-08-03
C
★ 63
CrystalForge is a custom AdaptixC2 agent designed to enhance payload generation through integration with the Crystal Palace UDRL pipeline. It facilitates the creation of various payload formats, including DLL and shellcode, while allowing users to specify custom Crystal Palace loader specifications, all while preserving the features of the existing Adaptix beacon architecture. Key functionalities include multi-transport support, a straightforward plugin installation process, and a roadmap for expanding capabilities beyond current limitations.
2026-08-03
Python
★ 14
LongLogon is a non-destructive precondition checker for the CVE-2026-41089 vulnerability, which is a stack buffer overflow affecting the Windows Netlogon service. It operates without authentication and does not exploit the vulnerability; instead, it sends benign CLDAP pings to determine if a domain controller's DNS domain name is sufficiently long to trigger a crash. This tool provides a reliable mechanism for security assessments by validating the conditions necessary for the vulnerability without the risks associated with executing an exploit.
2026-08-03
Go
★ 44
CyberMind CLI v6.0 is a powerful AI-driven offensive security tool designed for a diverse range of users including bug bounty hunters, red teamers, penetration testers, and security researchers. It offers 22 autonomous attack modes, a unique OMEGA brain orchestration feature, and support for exploiting Web3, mobile, and cloud environments, while integrating seamlessly with Kali tools. Key features include manual and automated execution options, real-time alerting via Telegram, and a VSCode extension for enhanced usability.
2026-08-03
Python
★ 13
DDoSSCAN is an advanced open-source network availability and stress testing framework developed in Python, designed specifically for security professionals, system administrators, and network engineers to conduct authorized tests on their infrastructure. Notable features include multi-vector attack simulations (TCP, HTTP, UDP, Slowloris), smart domain safety blocking, a real-time statistics dashboard, and automated session report generation in both TXT and JSON formats, all supported across multiple platforms including Linux, Windows, macOS, and Termux.
2026-08-03
Python
★ 56
Deck of Many Prompts is a manual Red Teaming tool designed for creating jailbreaks for large language models (LLMs). It features a variety of transformations, including encoding and token manipulation techniques, alongside tools for text and image conversions, language translation, and a rich interface for managing prompt history and notes. Noteworthy functionalities include support for multiple encoding formats (e.g., base64, Morse, Braille) and the ability to expand wordlists and tokenize for various models like GPT and BERT.
2026-08-03
TypeScript
★ 28
DVAP is an open-source platform designed for AI security training, red/blue teaming, and research, allowing users to safely explore and benchmark vulnerabilities in AI systems entirely on local machines without reliance on cloud services. It features intentionally vulnerable AI applications and environments tailored for various attack scenarios, supporting a hands-on approach to understanding AI security challenges and developing effective defenses. Notable capabilities include 15 dedicated AI labs, comprehensive coverage of OWASP LLM Top 10 vulnerabilities, and integrated benchmarking for AI models.
2026-08-03
★ 13
The Educational Cybersecurity Tools repository serves as a comprehensive catalog of over 150 tools aimed at ethical hacking, penetration testing, and cybersecurity education. It encompasses various categories including network scanning, vulnerability assessment, and malware analysis, while emphasizing that all tools are intended for educational purposes only and may not be used for unauthorized access to systems. Noteworthy features include detailed tool descriptions, an extensive list of categories, and a focus on promoting ethical standards in cybersecurity practices.
2026-08-03
C
★ 19
The EternalHush Framework is an advanced command and control (C&C) platform designed specifically for Windows systems, enabling users to extend its functionality through a Python API for plugin development. Notable features include an intuitive GUI, integration capabilities for external modules, and a variety of built-in implant functionalities such as TCP/HTTP(S) connections and reflective DLL loading, all aimed at facilitating data collection and interaction with infected systems. This open-source project is currently in early development and seeks community collaboration for enhancements.
2026-08-03
C++
★ 18
Evil Goat is a Wi-Fi security education tool that simulates an Evil Twin attack by creating a fake access point with a captive portal to demonstrate phishing techniques and enhance user awareness. Key features include automatic DNS redirection, a simulated login portal, local data storage for educational labs, and a web-based configuration panel. The project is intended exclusively for educational and laboratory purposes, emphasizing responsible use and ethical practices in cybersecurity training.
2026-08-03
Python
★ 11
The "exploits" repository serves as a comprehensive security research and exploit development toolkit, focusing on browser vulnerabilities, post-exploitation techniques, and cloud identity attacks. It features organized content around CVE reproductions, offensive tooling with detection guidance, and written assessment deliverables, all designed for educational use and authorized security testing. Notably, it includes a contained Docker lab environment for safe execution and testing of exploit scenarios without internet access, ensuring a secure and isolated workspace for enterprise assessments.
2026-08-03
Python
★ 13
FAS Judgement is a gamified testing platform designed to evaluate AI systems' vulnerabilities to prompt injection attacks. It offers structured attack patterns against AI endpoints, allowing users to learn red teaming techniques through engaging gameplay, which includes 37 challenges across 10 levels, an XP system, and interactive guidance from a WarGames-inspired AI game master named Jerry. Notable features include built-in vulnerable targets, a global leaderboard, OAuth sign-in capabilities, and a hands-on training experience without the need for external AI APIs.
2026-08-03
C
★ 17
Flipper RF Lab transforms the Flipper Zero device into a sophisticated RF analysis and research tool, featuring 15 advanced capabilities such as RF fingerprinting, adaptive signal modeling, and real-time spectrum monitoring. It enables users to perform detailed signal capture and analysis, protocol reverse engineering, and long-term logging within the 300-928 MHz frequency range. Notable functionalities include real-time activity mapping, threat modeling, and a robust modular research mode, making it suitable for professional RF forensics.
2026-08-03
Python
★ 13
GhostLNK is an advanced Windows LNK generator designed for red team operations and security research, focusing on reducing detection through sophisticated evasion techniques. It features capabilities such as multi-stage payload execution, stealth icon smuggling, various execution modes (including memory execution), and anti-sandbox checks, all aimed at creating more covert attack vectors. The tool is intended for authorized security testing only and emphasizes flexibility in payload generation while minimizing forensic traces.
2026-08-03
Python
★ 148
GhostLock is a research tool designed to demonstrate the potential for ransomware-equivalent availability impacts on SMB shares by utilizing file-level and directory-level locking techniques without writing or encrypting data. It enables low-privileged Windows domain users to effectively lock files or entire directories, rendering them operationally invisible while maintaining read access at known paths, thus bypassing traditional security measures with no detectable writes or anomalies. Notable features include a 32-thread parallel scanner for file locking and a single handle directory lock method, making it a significant concern for SMB-based environments.
2026-08-03
TypeScript
★ 11
The Glass Box Framework provides a runtime verification system for AI-generated answers by producing a structured Trust Card that details claims, reasoning chains, and an Epistemic Confidence Score (ECS). Key features include adversarial probes for potential biases and manipulations, a compilation of deployer intents into structured rules, and deterministic audit logging for reproducibility. This tool is designed to enhance transparency and accountability in AI responses, ensuring each assertion is traceable and verifiable.
2026-08-03
★ 295
Goodboy Framework is a comprehensive 15-stage course designed for developing and analyzing Windows malware, leveraging the Rust programming language. It equips users with practical knowledge from both offensive and defensive cybersecurity perspectives, encompassing techniques such as API hashing, process injection, and anti-debugging, while providing empirical data on evasion effectiveness against multiple antivirus engines. The framework emphasizes hands-on learning, featuring real-world detection mechanisms and adversarial thinking strategies, ensuring all content is validated through rigorous testing.
2026-08-03
C
★ 49
hARMless is an ELF Packer/Loader designed for ARM64 and x86-64 Linux binaries, utilizing multi-layer encryption techniques for secure execution. Its primary use case is to facilitate stealthy operation by preventing the original binary from being written to disk and employing runtime in-memory execution, alongside features such as code obfuscation, CRC32 integrity checks, and polymorphic loading to enhance anti-analysis measures.
2026-08-03
Python
★ 10
Harpoon is an autonomous black-box penetration testing tool designed for web applications, optimized for use on Kali Linux but capable of running on other Debian-based distributions and WSL. It orchestrates and integrates various existing security scanners, streamlining the process of vulnerability discovery by normalizing outputs into a relational SQLite model and providing comprehensive reporting, including HTML reports and PoC artifacts. Notable features include asynchronous execution, WAF-awareness, and extensive automated phases covering everything from DNS reconnaissance to validation of findings.
2026-08-03
Shell
★ 10
Huntbot is a multi-model offensive security tool designed for bug bounty hunting, penetration testing, and red teaming, offering advanced capabilities for vulnerability detection and reporting. Notable features include contextual knowledge accumulation, human-like interaction with web applications, the ability to share live browser sessions, and meticulous false positive validation before report generation. It is extensible with multiple AI models and allows for dynamic steering during runs, enabling security professionals to efficiently explore and validate security vulnerabilities.
2026-08-03
C++
★ 532
HVNC is a standalone client-server tool designed to create a hidden virtual desktop on the operator's side, allowing remote control over a target machine akin to the HVNC module of the TinyNuke banking trojan. Notable features include customizable process launching via a command menu, browser launchers for multiple web browsers, and a hidden client console. It serves primarily for educational and research purposes regarding remote access techniques.
2026-08-03
Python
★ 178
Juumla is a Python-based tool designed for identifying Joomla versions, scanning for vulnerabilities, and detecting sensitive files within Joomla installations. Key features include fast scanning capabilities with low resource utilization, the ability to find configuration and backup files, and vulnerability detection based on the identified Joomla version. Additionally, Juumla can be easily deployed via Docker for a streamlined setup process.
2026-08-03
Shell
★ 16
k8s-enum.sh is a toolkit designed for penetration testing and red team operations in Kubernetes environments, featuring two primary scripts: k8s-enum.sh for external enumeration using kubeconfig files and k8s-pod-enum.sh for internal enumeration from compromised pods. It provides comprehensive security enumeration with color-coded output that highlights privilege escalation vectors, misconfigurations, and actionable recommendations, making it a valuable resource for security researchers assessing Kubernetes configurations. Noteworthy features include permission enumeration, namespace and service discovery, and detailed detection of potentially dangerous permissions and settings.
2026-08-03
Shell
★ 63
Kali + OpenClaw Portable Pentest USB is a bootable USB solution that integrates Kali Linux Live with OpenClaw automation for streamlined, portable penetration testing. It addresses key challenges in traditional workflows by offering a pre-configured environment, automation capabilities, real-time documentation of findings, and forensically clean operation that leaves no trace on host systems. Notable features include persistent configurations, a selection of pre-configured templates for various testing scenarios, and support for deploying remote nodes on target networks.
2026-08-03
C
★ 655
KoviD is an open-source Loadable Kernel Module (LKM) designed for educational and defensive security research focused on rootkit techniques within Linux Kernel version 5 and later. It empowers security researchers and system administrators to analyze rootkit behavior, develop detection signatures, and enhance their understanding of kernel-level vulnerabilities through practical demonstrations of real-world threat capabilities. Notable features include support for investigating module concealment, process hiding, and log manipulation, enabling users to test and improve their security monitoring and incident response strategies.
2026-08-03
★ 27
Ledger is a Cobalt Strike aggressor script designed to log operational changes made during red team engagements, providing a structured audit trail of modifications such as service activations, account creations, and registry edits. Notable features include risk scoring for each entry, cleanup tracking, operator attribution, and the ability to export logs in JSON or plain text for after-action reports. This tool enhances operational awareness and ensures that all changes are documented and managed effectively throughout the engagement lifecycle.
2026-08-03
C
★ 20
LID (Linux Integrity Drift) is a tool designed to systematically identify kernel code paths that bypass Linux Security Module (LSM) hooks, thereby exposing visibility gaps in security policies without breaching the security guarantees of the LSM framework. It provides detailed insights into what security-sensitive operations are not evaluated by the LSM, affecting compliance and forensic capabilities. Notable features include distinguishing between visibility gaps and practical escalation paths, offering a nuanced understanding of potential security weaknesses in Linux environments.
2026-08-03
Python
★ 215
LLAMATOR is a Python-based framework designed for Red Teaming, enabling security professionals to conduct penetration testing on chatbots and Generative AI systems. Its notable features include support for custom attacks, compatibility with multiple chat client configurations, and comprehensive reporting capabilities in various formats, making it suitable for assessing vulnerabilities such as prompt injection and misinformation.
2026-08-03
Python
★ 24
FORGEDAN is a report-first LLM security assessment framework designed to generate reproducible security assessment report packages for large language models (LLMs). Its primary use case centers on providing high-quality, evidence-rich reports that include YAML suites, deterministic scanners, and audit-ready bundles, ensuring traceability and verifiability of input and output artifacts. Notable features include the integration of an evolutionary jailbreaking algorithm, a web dashboard, and a comprehensive QA receipt system, all contributing to enhanced report integrity and usability.
2026-08-03
Dart
★ 32
LLMtary is an AI-powered penetration testing platform designed for security professionals, facilitating an autonomous workflow from reconnaissance to exploit validation and report generation. It integrates large language model intelligence to conduct a comprehensive examination of targets, capable of operating entirely offline with local models or utilizing cloud-based AI for improved accuracy. Key features include a structured testing loop, multi-phase enrichment for targeted vulnerabilities, and native support across major operating systems, ensuring a streamlined and efficient penetration testing experience.
2026-08-03
Python
★ 130
MockSSH is a tool designed to emulate SSH server environments, enabling testing and automation of tasks without access to actual servers. It features a modern, type-safe architecture that supports threading for end-to-end unit tests, as well as integration with Python and HyLang for scripting commands. The tool includes comprehensive development utilities for linting, static type checking, and testing, alongside a DSL for simplified configuration and usage.
2026-08-03
C++
★ 41
ModuleStomped is a proof-of-concept tool designed to detect module-stomped DLLs by analyzing the pdata section of various processes, which remains unchanged and thus provides a more reliable detection mechanism than analyzing the .text section. It features two primary modes: a process scanner that inspects all accessible processes for anomalies, and an ETW mode that monitors image load events for specified DLLs. Notably, the tool emphasizes the correlation of stack frames with pdata as a potential detection strategy, while acknowledging potential evasion techniques.
2026-08-03
Shell
★ 39
Mythos Research Edition is an open-source tool designed for vulnerability discovery in software applications, utilizing the publicly available Claude Opus 4.7 model to replicate the eight-phase scaffold of Anthropic's Mythos Preview. It enables open-source maintainers, security researchers, and academics to conduct targeted scans at a low cost, facilitating coordinated vulnerability disclosure while avoiding unauthorized mass scanning. Key features include self-scanning capabilities for project audits and research, without requiring access to Anthropic's proprietary model.
2026-08-03
Shell
★ 17
NAC Bypass is a Linux-based tool designed to create a transparent Layer-2 bridge with two Ethernet interfaces that facilitates bypassing Network Access Control (NAC) mechanisms by inheriting an active authentication session from a legitimate workstation. Its primary use case centers on network penetration testing and security assessments, allowing attackers to forward traffic while maintaining authorized access. Notable features include customizable network interface assignment, built-in options for passive monitoring, and integration with tools like Responder for enhanced functionality.
2026-08-03
Python
★ 24
NetCrawler is an AI-driven reconnaissance and vulnerability scanning tool that utilizes a local Ollama LLM to automate the scanning process. It intelligently selects and executes various reconnaissance modules such as subdomain enumeration, web fingerprinting, and vulnerability scanning, while generating structured reports in both Markdown and JSON formats. Notable features include a terminal-based user interface, iteration through an observation-think-act cycle, and the capability to integrate additional modules seamlessly.
2026-08-03
Go
★ 10
NightCloak is a statically-linked Go binary designed for metadata steganography and string obfuscation, allowing users to embed encrypted payloads into various file formats through a sophisticated multi-layer pipeline involving obfuscation, authenticated encryption, and binary injection. It supports distributed resiliency via Reed-Solomon erasure coding and enables discovery through CRC64 algebraic beacons, making it highly effective for covert data storage and transmission. The tool modernizes and ports previous versions while preserving core functionalities and operational models.
2026-08-03
Python
★ 325
NOX Framework is a cyber threat intelligence engine designed for red teaming, digital forensics, and corporate exposure analysis, capable of executing massively parallel scans across 124 intelligence feeds without bottlenecks. Its notable features include an integrated operational security layer with automatic proxy rotation, a dynamic risk scoring system, and an autoscan pipeline that facilitates comprehensive scanning and data gathering through recursive scans and asset discovery. This plugin-driven platform emphasizes operational efficiency and security, catering to advanced cybersecurity operational needs.
2026-08-03
TypeScript
★ 95
nPassword is a lightweight password manager designed specifically for Windows Active Directory, enabling users to securely manage domain and local accounts within a purely front-end application. Key features include domain-specific account organization, one-click export/import functionality for JSON data, and the ability to attach notes and utilize command templates for common tools. The application ensures that all credentials remain on the user's device by leveraging the browser's local storage.
2026-08-03
Shell
★ 66
NullSec is an advanced penetration testing and red team operations framework that provides a custom ParrotSec-based distribution tailored for offensive security tasks. It features over 150 custom attack modules across multiple categories, full integration with the Metasploit Framework, an AI-powered security assistant, and a user-friendly TUI launcher for easy navigation and module management. The platform supports dual operation modes for safe demos and real attacks, and allows users to build custom ISOs for deployment.
2026-08-03
Shell
★ 82
NullSec Pineapple Suite is a comprehensive payload collection for the Hak5 WiFi Pineapple Pager, featuring 125 payloads organized into 14 categories for various aspects of WiFi security testing, including reconnaissance, interception, exfiltration, and stealth operations. Notable features include an extensive range of attack and reconnaissance payloads, a fast boot optimizer, a user-friendly one-click installation process, and the option for active development support. This suite significantly expands the capabilities of the WiFi Pineapple Pager compared to official and other third-party offerings.
2026-08-03
TypeScript
★ 623
numasec is an AI-driven security agent that enhances terminal-based workflows by integrating existing tools and methodologies for security operations. It facilitates tracking findings, documenting evidence, and generating reports while adhering to security runbooks, making it well-suited for Application Security (AppSec) and penetration testing workflows. With numasec, security professionals can streamline their processes and maintain operational context within a familiar environment rather than depending on separate chatbots or scanners.
2026-08-03
JavaScript
★ 18
Payload Obfuscator is an advanced browser-based tool designed for Red Team operations, enabling users to obfuscate payloads in multiple programming languages, including PowerShell, Python, Bash, C#, and Go. Key features include a fully client-side operation with no data transmission, the ability to combine up to eight modular obfuscation layers for enhanced evasion tactics, and context-aware parsing for maintaining code syntax integrity. The tool prioritizes security, providing real-time analysis for detection probability and ensuring it remains completely free and open-source.
2026-08-03
Python
★ 61
The PDF Prompt Injection Toolkit is a cybersecurity tool designed for red and blue teams to test and detect prompt injection attacks that may be concealed within PDF documents. It features two primary roles: a `pdf_injector.py` for creating hidden payloads and a `pdf_injection_detector.py` for scanning PDFs to identify such vulnerabilities. Notable detection techniques include scanning for invisible text, analyzing document metadata, and detecting off-page text, ensuring comprehensive coverage against potential injection tactics.
2026-08-03
Python
★ 16
Phantom is an autonomous AI-driven penetration testing platform designed to perform detailed reconnaissance and exploit vulnerabilities without human intervention. Integrating over 30 professional security tools within a secure Docker environment, it leverages a reasoning loop to adaptively select and execute multi-step attack vectors, producing verified findings complete with proof-of-concept scripts. Unlike traditional scanners that rely on static CVE signatures, Phantom delivers a comprehensive and accurate vulnerability assessment with real-time adaptability and detailed reporting aligned with the MITRE ATT&CK framework.
2026-08-03
C++
★ 59
PH4NTØM ROOTKIT is a Windows usermode rootkit designed for educational research, featuring techniques for stealth, privilege escalation, and command-and-control (C2) infrastructure. Notable features include token stealing and named pipe impersonation for privilege escalation, inline hooking for process and file hiding, and a comprehensive C2 setup allowing for real-time keylogging and remote execution commands. It emphasizes defensive learning while providing extensive evasion mechanisms against analysis and detection.
2026-08-03
Go
★ 475
PingRAT is a command and control (C2) tool that utilizes ICMP payloads to stealthily transmit C2 traffic through firewalls, making it largely undetectable by most antivirus and endpoint detection and response solutions. It is implemented in Go and offers features such as server-client architecture for communication, allowing for flexible network interface configuration. This tool is primarily aimed at facilitating covert operations in environments with strict traffic monitoring.
2026-08-03
Rust
★ 75
Proteus is a Rust-based command-and-control (C2) agent designed for integration with the Mythic framework, featuring capabilities such as raw shellcode production, COFF file analysis, and robust data-section obfuscation. Its key innovations include a shuffle pipeline that randomizes function order while repairing internal references, combined with ChaCha20-based encryption for added security. This tool serves as both a payload generator and a development aid, supporting advanced persistence and clandestine operations in targeted environments.
2026-08-03
Python
★ 53
PWNCLOUDOS is a multi-cloud security Linux distribution designed for both offensive and defensive security operations across major cloud platforms such as AWS, Azure, and GCP. It offers a lightweight XFCE4 environment pre-loaded with a range of cloud exploitation tools, auditing frameworks, and security testing utilities, making it suitable for red, blue, and purple teams. Notable features include customizable shell environments, a variety of cloud-specific tools, and community-driven enhancements, with options for both AMD64 and ARM64 architectures.
2026-08-03
Python
★ 25
RamiBot is an AI-powered security operations platform designed for both Red and Blue team engagements, integrating various pentesting tools within a structured operational pipeline. Its notable features include multi-provider LLM support, human-in-the-loop tool execution approval, evidence-locked reporting to mitigate hallucinations, and Docker integration for seamless command execution in containerized environments. Additionally, RamiBot automates setup processes and provides one-click PDF reporting for streamlined security assessments.
2026-08-03
Python
★ 10
ReconMind is an AI-powered bug bounty agent designed to emulate the decision-making process of a senior penetration tester, automating the entire vulnerability assessment workflow from reconnaissance through to reporting. Key features include an LLM-driven approach that intelligently selects targets and scans, filters false positives, and generates platform-ready reports for services like HackerOne and Bugcrowd. Its streamlined pipeline ensures comprehensive coverage, while being free to use, and provides flexibility with local and cloud-based LLM integrations.
2026-08-03
Python
★ 264
red-run is a security assessment toolkit designed for orchestrating and conducting comprehensive security evaluations using Claude Code and MCP servers. It guides users through essential assessment phases—recon, initial access, lateral movement, privilege escalation, and post-access—while maintaining engagement state in SQLite and allowing for semantic search and execution delegation across persistent agent teams. Notable features include multiple orchestrator variants tailored for specific use cases, real-time monitoring and interaction via tmux, and a robust skill management system that facilitates complex assessments.
2026-08-03
C
★ 67
RedTeam-Agent is an AI-powered autonomous framework designed for red team security assessments, enabling automated execution of commands across multiple tools through a skill-first terminal workflow. Its notable features include support for over 15 integrated security tools, advanced output filtering, and comprehensive Active Directory attack coverage, allowing users to streamline the red teaming process without manual tool management. The framework facilitates multi-client operations and includes functionalities for reconnaissance, data collection, analysis, and lateral movement.
2026-08-03
C
★ 34
Reflectra is a User-Defined Reflective Loader (UDRL) designed for Windows x64 platforms, enabling modular integration with various Command and Control (C2) frameworks. It features a customizable reflective loading pipeline, advanced evasion techniques such as syscall spoofing and ETW patching, and extensive control over execution flow and memory layout, allowing for sophisticated payload manipulation. The tool is built on the Crystal Palace architecture and focuses on seamless DLL-based payload delivery while maintaining operational stealth.
2026-08-03
Python
★ 13
RootHunter is an offensive auditing suite for Linux, designed for pentesters and administrators to detect and prioritize common privilege escalation vectors before malicious actors can exploit them. It includes a Bash script for evidence collection, a local database of binary escalation techniques, and a Python analysis tool that generates actionable insights based on the collected evidence. Key features include a structured JSON report, prioritization of attack paths, and integration with CVE databases for context-specific exploits.
2026-08-03
HTML
★ 80
The Security Reference Guide is a curated repository of cyber security resources tailored for SOC analysts, pentesters, DFIR practitioners, and other security-focused roles. It organizes valuable links into categories such as offensive and defensive operations, engineering fundamentals, and training resources, providing context to help users select the appropriate tools and materials quickly. Notably, the guide emphasizes legitimacy, cautioning against the misuse of tools for unethical purposes.
2026-08-03
Python
★ 10
ShadowMap is a professional IP geolocation intelligence tool designed for tracking IP addresses with multi-source accuracy and Google Maps integration. Its notable features include querying multiple APIs for enhanced accuracy, precise coordinate outputs, proxy and VPN detection, and compatibility with mobile platforms like Termux. Intended for educational and authorized testing purposes, it provides users a clean, professional interface and the ability to save detailed geolocation reports.
2026-08-03
Python
★ 12
ShareSift is a machine learning-enhanced tool designed to identify and rank files on SMB shares that are likely to contain credentials or secrets. Utilizing a two-stage classifier pipeline, it combines a LightGBM path classifier and a Qwen3 1.7B LoRA content classifier to improve recall of sensitive information significantly over its predecessor, Snaffler. Notable features include adjustable classification policies to balance false positives and recall rates, allowing users to optimize for specific operational needs.
2026-08-03
Rust
★ 25
Solemn is a command-line utility designed to facilitate the manual addition of drivers to the Hypervisor-Protected Code Integrity (HVCI) custom blocklist on Windows systems. Its primary use case is to enhance kernel security by allowing system administrators to block specific drivers, thereby preventing potentially malicious code from executing within the kernel. Key features include automatic creation of the registry entry for the blocklist, duplicate entry prevention, and user-friendly command-line output, all while ensuring necessary administrative privileges are checked before modifications are made.
2026-08-03
Rust
★ 39
The Stardust-RS project provides a Rust template for creating position-independent shellcode (PIC) targeting both i686 and x86_64 architectures on Linux and Windows platforms. It allows for the compilation of shellcode that can be executed without specific memory locations, facilitating various exploit development scenarios. Notable features include cross-platform support, minimal payload sizes, and a customizable build environment with Docker compatibility.
2026-08-03
Python
★ 24
SunnyDayBPF is an eBPF-based research tool designed for post-syscall user-buffer telemetry deception, investigating the integrity of data observed by user-space security agents after read-like syscalls. It alters the telemetry data before it is processed by security pipelines, allowing for a detailed examination of discrepancies between actual events and the observed telemetry. Notable features include support for multiple syscalls (e.g., read, pread64, recvfrom), a modular BPF architecture utilizing tail calls to circumvent verifier constraints, and customizable scanning rules for enhanced security analysis.
2026-08-03
Kotlin
★ 11
Takopii is a production-grade banker malware architecture designed for Android, featuring four APK specimens that encapsulate techniques from 17 real-world malware families. Its primary use case is to facilitate the study of malware detection and defense strategies, offering Kotlin source code alongside comprehensive YARA and Sigma detection rules. Notably, all specimens demonstrate zero detection across 66 VirusTotal engines, showcasing advanced evasion capabilities within a structured kill chain framework.
2026-08-03
Dart
★ 160
TapDucky is an open-source tool for rooted Android devices that functions as a USB HID keystroke injector, capable of emulating keyboard, mouse, and composite HID devices. Its primary use case is in authorized testing and automation through the execution of customizable DuckyScripts, featuring a robust payload management system, execution logging, and a GitHub-backed library for seamless script integration and validation. Notable features include live payload validation, multiple scheduling options, and the ability to configure device-specific HID profiles without the need for external dongles.
2026-08-03
Python
★ 12
tempor is a cloud infrastructure provisioning tool that allows users to effortlessly create ephemeral servers across multiple cloud providers using Terraform, making it ideal for penetration testers and bug hunters. Notable features include support for custom Ansible playbooks and Packer configurations, enabling tailored setups, along with robust authentication mechanisms via environment variables and API tokens.
2026-08-03
Python
★ 17
The Red Council is an automated adversarial testing platform designed for Large Language Models (LLMs), offering a comprehensive security workflow that identifies vulnerabilities, applies automated defenses, and verifies their effectiveness in real-time. Key features include a multi-agent adversarial flow, a real-time battle user interface, and the ability to integrate with various LLM APIs, supporting a versatile approach to security assessment and fortification. Additionally, it incorporates capabilities for AI Agent Security Testing based on the OWASP Agentic Top 10 framework, enhancing its utility in securing AI-driven applications.
2026-08-03
Python
★ 76
ThreatSwarm is a comprehensive penetration testing tool that utilizes 27 AI agents to execute the entire kill chain—from reconnaissance to exploitation, post-exploitation, digital forensics, and reporting—streamlined into a single command interface. It enforces strict scope limitations via `scope_check.py`, ensuring compliance with authorized testing parameters, while leveraging a library of 754 MITRE-mapped skills to guide its operations. Notably, it operates as a Claude Code plugin, eliminating the need for additional infrastructure like Docker or cloud accounts, and outputs detailed vulnerability reports with CVSS scoring.
2026-08-03
Python
★ 68
wmiexec2 is an enhanced and obfuscated version of the original `wmiexec`, designed for red team operations by facilitating stealthy remote command execution on Windows systems. Key features include support for various shell types, automated red team modules, local and remote file transfers, and capabilities for bypassing antivirus detection. The tool also includes additional functionalities like system information gathering, active token enumeration, and VM detection, making it a comprehensive suite for Windows penetration testing and cyber operations.
2026-08-03
HTML
★ 19
Z-Hound is a browser-based tool designed for visualizing attack graphs from SharpHound and AzureHound data, enabling quick and portable analysis of Active Directory and Azure AD environments without requiring any server setup or installations. It supports multiple SharpHound output formats, offers an interactive graph interface with various layout options, and allows users to upload ZIP or JSON files for analysis, making it ideal for pentesters and red teamers needing fast, offline capabilities. Notable features include automatic resolution of SIDs, customizable node visualizations, and the ability to work entirely offline after initial loading.
2026-08-03
C
★ 25
Zero-loader is a polymorphic x64 shellcode loader designed to evade detection by generating unique binaries with every build, thus ensuring no static signatures are shared across compilations. Its primary use case is for authorized security testing and research, featuring advanced evasion techniques such as indirect syscalls, patchless AMSI/ETW bypass, module stomping, and anti-emulation measures. By employing methods like XOR encryption and synthetic function tables, the tool maintains a low profile during execution, effectively avoiding modern detection systems.
2026-08-03
Rust
★ 51
ActiveBreach-Engine (ABE) is a Windows execution capability platform that enables secure and direct system call execution in heavily instrumented environments, mitigating risks from external attackers and process hooking. It offers a dynamic framework that avoids reliance on user-mode APIs or `ntdll.dll`, featuring built-in anti-debug and protection mechanisms to safeguard system calls. ABE is available in C, C++, and Rust adaptations, with the Rust version providing advanced features like build-time encrypted stubs and modular integration across various programming languages.
2026-08-03
★ 25
Agent Arena facilitates evidence-first multi-agent debates among AI coding agents such as Claude Code and OpenAI Codex to deliver independent analyses and critiques of code and architecture decisions. It is particularly suited for high-stakes scenarios, including architectural reviews, implementation plan assessments, and bug root-cause analysis, while ensuring that dissenting viewpoints and evidence verification are preserved. The tool supports diverse model backends, allowing cross-collaboration among differing AI models, though it functions as a protocol rather than a direct execution orchestrator.
2026-08-03
Python
★ 240
AgentPoison provides a framework for red-teaming large language model (LLM) agents through the technique of memory or knowledge base backdoor poisoning. Its primary use case is to facilitate the identification of vulnerabilities in LLMs by allowing users to optimize triggers targeting specific agent behaviors. Notable features include support for various retriever-augmented generation (RAG) embedders, configuration customization via YAML files, and trigger optimization capabilities for multiple agent types.
2026-08-03
★ 157
AI OSINT is a comprehensive toolkit designed for identifying exposed artificial intelligence infrastructure on the internet through curated OSINT resources, including Google dorks, Shodan, and GitHub queries. It serves Red Team operators, penetration testers, and OSINT researchers by providing specific detection methods for various AI entities, such as LLM endpoints, AI agent gateways, and leaked API keys, while addressing emerging threats such as systemic supply chain vulnerabilities and credential leaks. Notable features include a keyword substitution convention to tailor searches to specific needs, enhancing its utility in real-world cybersecurity assessments.
2026-08-03
Python
★ 33
The AI Pentest Playbook provides a comprehensive field manual for conducting penetration testing on AI chatbots and applications powered by large language models (LLMs). It offers curated attack payloads categorized by various threat classes, detailed guidance on identifying vulnerabilities, and remediation strategies, thereby equipping both offensive and defensive cybersecurity teams with essential insights for securing AI systems. The resource also aligns with the OWASP Top 10 for LLM Applications, ensuring coverage of critical attack vectors and emerging risks in the domain.
2026-08-03
Python
★ 11
Vulnerable AI Lab is a modular AI security training environment designed to simulate and expose vulnerabilities in modern AI applications, specifically targeting the OWASP LLM Top 10 2025 threats. It facilitates practical learning by allowing users to engage in scenarios like RAG injection and tool invocation vulnerabilities, scoring runs automatically to provide insights into exploited vulnerabilities and the evidence collected. Notable features include customizable vulnerability modules, an accessible user interface hosted via Docker, and compatibility with capture-the-flag events and red team training exercises.
2026-08-03
Dockerfile
★ 21
Akira is an AI-powered penetration testing tool designed to operate natively within various environments, including Claude Code and Gemini CLI. It specializes in identifying vulnerabilities that traditional scanners may overlook, such as logic flaws and cryptographic weaknesses, by integrating a structured reasoning system that demands reproducible evidence for each finding. Notable features include a robust technique library, a Bayesian hypothesis engine, and the ability to handle complex attack vectors through a systematic engagement and reporting workflow.
2026-08-03
Go
★ 453
Arachne C2 is a decentralized Command & Control framework leveraging libp2p for peer-to-peer communication, eliminating reliance on a central server or fixed IP addresses. Its notable features include self-contained binaries for cross-platform implant generation, encrypted messaging, interactive operator consoles, and built-in NAT traversal techniques, all designed to maintain operational continuity and enhance resilience against detection and takedown. This framework is particularly suited for secure, covert operations requiring dynamic connectivity amid adversarial environments.
2026-08-03
CSS
★ 172
ARS3NAL is a comprehensive, offline-first pentesting and bug bounty tool designed to streamline the security testing process. It features clickable attack chains, payload generators, recon tools, and built-in report templates, all organized in a user-friendly interface that supports bilingual operation. Noteworthy functionalities include the interactive OAuth/SSO lab and advanced recon capabilities, enabling quick assembly of complex attack scenarios without cloud reliance or telemetry.
2026-08-03
Go
★ 621
arsenal-ng is a modern pentest command launcher developed in Go, designed to enhance the efficiency of security assessments by providing instant access to a vast library of tools and commands. Notable features include a smart search with fuzzy matching, syntax highlighting for improved command readability, an intuitive terminal user interface for easy navigation, and support for global variables that streamline command usage. This tool prioritizes simplicity and speed, making it a valuable asset for cybersecurity professionals.
2026-08-03
C++
★ 57
ASHIRT is a Qt-based tray application designed for capturing screenshots and codeblocks associated with a specific ASHIRT instance. Its primary use case involves enabling users to take screenshots through a user-defined key or tray menu selection, while managing submissions to a remote ASHIRT backend. Notably, it supports multiple Linux distributions and provides flexibility for configuration and usage within various desktop environments.
2026-08-03
Python
★ 16
Beatrix Suite is a command-line bug bounty hunting framework designed to streamline the entire pentesting workflow by integrating 32 scanner modules and 22 external tools. It features a 7-phase Kill Chain methodology, automated login and session management, and an AI-assisted pentester (GHOST) for advanced analysis, making it suitable for scanning domains, URLs, and IP addresses efficiently in headless environments. This tool aims to eliminate the fragmentation of traditional bug bounty tools by providing a single-command interface that orchestrates multiple tools throughout the assessment process.
2026-08-03
Python
★ 33
c2detect is a tool designed to fingerprint command-and-control (C2) servers behind network beacons by analyzing telemetry data, specifically naming frameworks like Cobalt Strike and Sliver with a confidence score and matched indicators. Notable features include offline operation, the ability to generate Sigma and Suricata detection rules directly from detected signatures, and the fusion of indicators such as JA4, JARM, certificate, URI, and port for enhanced C2 identification. This tool serves as a passive defense mechanism for blue teams to detect known C2 infrastructure efficiently.
2026-08-03
Rust
★ 31
CatchClaw v5.3.0 is a multi-platform AI Agent security assessment tool that supports nine different AI platforms including OpenClaw and Dify. It features 78 DAG attack chains and exploit modules that cover a full range of attack vectors from reconnaissance to data leakage, utilizing an asynchronous Tokio engine for concurrent execution while offering visual attack graph exports and customizable reporting options. The tool is designed to facilitate automated vulnerability verification and threat modeling within complex multi-agent environments, restricted to non-commercial use only.
2026-08-03
JavaScript
★ 41
The Offensive Security & DevSecOps Cheat Sheet is an interactive command reference designed for penetration testing and DevSecOps practices, featuring over 5040 commands organized into 53 categories and available in both English and Turkish. Notable features include a fully local operation with no telemetry, a fuzzy command palette for efficient searching, and the ability to add and manage personalized commands and profiles. It also integrates with MITRE ATT&CK tags for over 1,160 offensive commands, providing contextual security mapping and enhancing the tool's functionality for security professionals.
2026-08-03
Python
★ 34
ChromiumSpecter is a tactical auditing suite for security assessments of Chromium-based browsers (such as Chrome, Edge, and Brave) on Windows, focusing on credential extraction and data exfiltration. It features a highly discreet and resilient decryption engine that utilizes SYSTEM impersonation with legitimate Windows APIs, making it less detectable compared to traditional code injection methods. Key functionalities include a professional dashboard for real-time statistics, support for multiple encryption schemes, and seamless integration with the latest browser versions.
2026-08-03
★ 172
CKCsec Wiki is a bilingual cybersecurity knowledge base designed for security researchers, engineers, and enthusiasts, covering a variety of topics including web security, blockchain security, CTF, and red team practices. Built with VitePress, it features a fully mirrored structure in both English and Chinese, providing searchable and shareable practical security knowledge, while also supporting open collaboration and maintenance. The platform allows for easy deployment on static hosting services, ensuring accessibility and usability for diverse user needs.
2026-08-03
Python
★ 12
Claude Security Skills is a collection of tools designed to enhance the security analysis of software projects, specifically through the Claude Code platform. It enables users to perform various tasks such as scanning for leaked secrets, conducting static code analysis on Python, testing for prompt injection in language models, and auditing HTTP headers and security configurations. With no external dependencies and the ability to run analyses offline, the tool provides a secure and efficient approach to identifying vulnerabilities in various project components.
2026-08-03
Python
★ 29
The Cloud Security Toolkit is a comprehensive resource designed for offensive security practitioners focused on cloud environments, facilitating the exploitation of vulnerabilities and simulating advanced attacks specifically within platforms like Azure, AWS, and Microsoft 365. Notable features include a collection of weaponized exploits, deep-dive vulnerability research, threat intelligence insights, and evasion techniques targeted at cloud defense systems, all aimed at enhancing red team operations and improving cloud security assessments. This toolkit provides practical, battle-tested resources essential for sophisticated penetration testing and incident response in cloud ecosystems.
2026-08-03
★ 21
Cyber Agent is an AI-driven penetration testing tool utilizing Claude Code agents to automate the entire penetration testing process, making it particularly suitable for HackTheBox challenges and authorized security assessments. Notable features include automated attack execution which encompasses reconnaissance, exploitation, and privilege escalation, as well as professional report generation adhering to the Penetration Testing Execution Standard (PTES) and mapping to the MITRE ATT&CK framework.
2026-08-03
HTML
★ 44
CyberInject is a professional browser extension toolkit focused on authorized security testing and penetration testing activities. It offers quick access to a diverse range of security payloads categorized into vulnerabilities such as XSS, SQL Injection, SSRF, and LFI, alongside features like one-click copying and an organized, user-friendly interface. Designed for compliance with legal standards, it ensures that users can efficiently execute their testing tasks while promoting responsible usage.
2026-08-03
JavaScript
★ 145
Cyberlivre is an open-source platform aimed at democratizing cybersecurity education by providing a structured journey through 20 practical modules, covering topics from basic infrastructure to advanced defense and exploitation techniques. Notable features include no registration or paywalls, a community-driven approach to content updates, and opportunities for collaboration through curriculum enhancements, challenge creation, and code improvements.
2026-08-03
PHP
★ 11
dj-camphish is a browser-based toolkit designed for ethical hacking, OSINT training, and privacy awareness demonstrations, allowing users to capture webcam snapshots with permission and redirect them to a custom URL. Key features include an intuitive admin panel for managing captures, secure CSRF protection, responsive design for mobile and desktop, and a straightforward setup process without the need for port forwarding.
2026-08-03
C#
★ 398
DLLHijackHunter is an automated detection tool designed for identifying, validating, and confirming DLL hijacking opportunities on Windows systems. It employs a multi-phase approach that includes discovery of exploitable binaries, filtration of false positives, and the deployment of a harmless canary DLL for verification, providing a comprehensive scoring and reporting mechanism. Notable features include extensive coverage of various hijack types, UAC bypass discovery, and a focus on corroborating potential attack paths with actionable intelligence.
2026-08-03
C
★ 72
Donut-CustomHost is a sophisticated tool designed to generate and execute shellcode while maintaining stealth against modern endpoint detection and response (EDR) solutions. Key features include a custom CLR host that intercepts assembly loading directly from memory, advanced memory tracking evasion techniques, and architecture-aware event tracing for Windows (ETW) bypassing, all of which are aimed at minimizing detection during execution. Additionally, the tool has optimized the shellcode size, ensuring efficient memory use and a reduced footprint.
2026-08-03
C
★ 183
Entropia is a high-level compiled language designed for generating Windows position-independent x86-64 shellcode and Beacon Object Files (BOFs) with a streamlined build process. Its primary use case is to simplify the development pipeline for red-team artifacts by combining multiple stages—from compilation to OPSEC enhancements—into a single step. Notable features include direct access to Windows SDK headers, enabling easy integration of native functions, and support for compiling complete BOFs in minimal code, while maintaining a compact and intuitive language syntax.
2026-08-03
JavaScript
★ 216
Frieren is a micro-framework designed for managing security tools on OpenWrt routers and Single Board Computers (SBCs). It features a web panel that facilitates WiFi management, network diagnostics, and an extensible module system, allowing users to install third-party modules while providing an integrated terminal and package management capabilities. The stack leverages a PHP backend and React frontend, ensuring both lightweight performance and flexibility for embedded devices.
2026-08-03
TypeScript
★ 34
Gideon is an autonomous cybersecurity operations agent designed for intelligent threat analysis and red teaming. It automates the process of gathering intelligence and conducting thorough security research by breaking down complex questions into actionable tasks, utilizing real-time data from various sources. Notable features include dual-mode operation for both defensive and offensive engagements, goal-directed autonomy, and an evidence-based approach to generating actionable security insights.
2026-08-03
Go
★ 40
`git-fire` is a command-line interface (CLI) tool designed for efficiently checkpointing multiple Git repositories simultaneously. Its primary use case is to facilitate the safe backup of local changes across numerous repos by discovering repositories, optionally auto-committing uncommitted changes, and pushing backup branches with added recovery safety. Notable features include the ability to perform dry-run previews for safety and a streamlined emergency mode for quick execution under pressure.
2026-08-03
Go
★ 12
GoFenrir is an Active Directory enumeration and attack framework developed in Go, leveraging the Manticore protocol backend for efficient operations without dependency complexities. It supports various protocols, including LDAP/LDAPS for full enumeration, Kerberos for advanced credential attacks, and has a plan to support SMB v2/v3, providing a robust suite of enumeration and exploitation features ideal for penetration testing. Notable functionalities include user and group enumeration, domain controller discovery, and advanced Kerberos attack capabilities like Kerberoasting and AS-REP roasting.
2026-08-03
PowerShell
★ 50
🎒 An up-to-date collection of precompiled binaries and hacking scripts.
2026-08-03
JavaScript
★ 15
HoneyAI is an all-in-one, AI-powered honeypot designed to proactively intercept and deceive attackers across various protocols using a local LLM. It generates dynamic, realistic responses to malicious attempts such as SQL injections and SSH logins, with customizable commands and automated reporting to multiple threat intelligence platforms. Notable features include a wide range of protocol emulation, real-time attack notifications, and the ability to integrate with any LLM, ensuring comprehensive coverage and adaptive defenses against cybersecurity threats.
2026-08-03
Python
★ 299
InfraGuard is a red team infrastructure tracker and command-and-control (C2) redirector designed to enhance operational security by validating incoming traffic against customizable C2 profiles. Key features include multi-domain proxying, scoring-based filtering with JA3 TLS fingerprinting, and detection mechanisms for headless browsers and path enumeration attempts, enabling precise filtering of malicious requests while allowing legitimate beacon traffic. This tool serves as a modern alternative to existing solutions, providing a comprehensive suite for defending against reconnaissance and automated probing activities.
2026-08-03
HTML
★ 14
The iOS ClickFix Template is a red team tool designed for executing a ClickFix → WebClip social engineering attack chain on iOS devices. It creates a convincing lure page that prompts targets to install a malicious `.mobileconfig` profile, which then adds a shortcut to the attacker's designated web page on the target's Home Screen. Notable features include personalized links for each target, generating unique profiles, and easy configuration to customize the WebClip functionality.
2026-08-03
PowerShell
★ 17
JMP-AMSI is a Proof of Concept tool designed to demonstrate the manipulation of managed code pointers in the PowerShell runtime, specifically targeting the Antimalware Scan Interface (AMSI) to bypass its scanning capabilities. Notable features include in-memory execution, native memory manipulation without using highly monitored functions, and multi-architecture support for dynamic assembly patching. The tool provides options for telemetry interruption and detailed verbose output for testing and research purposes.
2026-08-03
C
★ 53
KHAØS LOADER is a multi-stage Windows x64 loader that utilizes AES-256-CBC to decrypt and inject donut shellcode into a `rundll32.exe` process spawned under `explorer.exe`, employing advanced evasion techniques such as indirect syscalls with call stack spoofing. Notable features include early-bird APC injection, unhooking capabilities, and robust sandbox evasion mechanisms, which ensure stealthy operation against various security measures. This tool is designed for authorized use only and integrates multiple sophisticated methods to remain undetected during execution.
2026-08-03
Go
★ 34
Lain C2 is a command-and-control framework designed to facilitate secure communication between compromised hosts and operators across multiple platforms including Windows, Linux, macOS, and Android. It supports various communication protocols such as HTTP/1, 2, and 3, and integrates third-party libraries for enhanced functionality, making it a versatile tool for conducting remote management and operations. Notable features include cross-platform compatibility and efficient handling of system metrics and processes.
2026-08-03
Python
★ 10
MailSpoof is an open-source email spoofing and phishing simulation tool designed for authorized penetration testing and security awareness training. It features a built-in multi-threaded SMTP server, 62 pre-built phishing templates, custom template creation, and comprehensive audit logging alongside report generation capabilities. This tool is compatible across multiple platforms, including Linux and macOS, and supports bulk targeting, external SMTP relay configurations, and advanced header functionalities for enhanced testing scenarios.
2026-08-03
Go
★ 21
Maldev is a comprehensive Go library designed for malware engineering, providing tools for syscall manipulation, evasion techniques, code injection, credential harvesting, and persistence mechanisms. Its capabilities include a variety of syscall calling methods, extensive evasion techniques against detection mechanisms, and robust injection methods, all integrated through a unified syscall caller for enhanced stealth and flexibility. The library is aimed at authorized security research, red teaming, and penetration testing, ensuring a modular approach to malware development with an emphasis on cross-compilation without CGO dependencies.
2026-08-03
PowerShell
★ 32
MSFT-IP-Tracker is a tool designed to monitor and track Microsoft IP addresses for applications in security research, firewall configurations, routing, and troubleshooting. It collects data from a range of Autonomous System Numbers (ASNs) and publishes daily updates featuring IPv4 and IPv6 addresses in CIDR notation. Notable features include automated daily releases and a comprehensive source of Microsoft’s ASN IP ranges, providing users with up-to-date information for network decision-making.
2026-08-03
★ 17
The OSCP / OSCP+ Cheatsheet serves as a comprehensive penetration-testing reference specifically designed for the 2026 OSCP+ exam, organizing critical information across various attack phases. Users can efficiently navigate through self-contained modules covering reconnaissance, footholds, privilege escalation, and Active Directory exploitation, making quick lookups feasible during the exam without internet access. Notable features include clear exam strategy guidelines, restrictions on tool usage, and offline operation recommendations, ensuring candidates can reference essential tactics under exam conditions.
2026-08-03
Python
★ 267
OSINT-D2 is an advanced open-source intelligence platform designed to transform usernames and emails into comprehensive identity dossiers, leveraging agentic AI for autonomous investigations. The tool features multi-source correlation across over 30 platforms, cognitive profiling through a six-dimension analysis, and seamless integration with ScrapingAnt's proxy infrastructure for efficient data gathering. Additionally, it supports premium PDF reporting, incorporates breach exposure checks via HaveIBeenPwned, and offers cross-platform executable binaries.
2026-08-03
JavaScript
★ 22
OverQuack is a customizable HID automation tool designed for scripted payload execution, featuring an open-source platform that runs on Raspberry Pi Pico boards. Its notable capabilities include full DuckyScript support, wireless payload management via built-in Wi-Fi, and a browser-based IDE that enhances the development experience with real-time error checking and auto-completion. The tool is geared towards transparency and extensibility, making it suitable for educational purposes and research while providing a modern setup workflow.
2026-08-03
Python
★ 1637
Pentest-ai is an AI-powered penetration testing tool designed to enhance the verification of security findings by re-running exploits to confirm their validity, ensuring that each piece of evidence is backed by reproducible results. It streamlines the verification process by generating multi-step attack paths and providing a reporting mechanism that only includes findings validated by its oracle system, achieving 100% precision with zero false positives across multiple vulnerability classes. The tool operates offline without cloud reliance, making it ideal for authorized testing in a controlled environment.
2026-08-03
Shell
★ 2180
pentest-ai-agents is a suite of 50 subagents designed to enhance penetration testing by utilizing Claude Code as an offensive security research assistant. Each agent specializes in areas such as reconnaissance, web applications, Active Directory, and cloud security, offering streamlined automation for various tasks without the need for extensive setup. Notable features include the ability to route tasks to specific experts, support for easy installation as a Claude Code plugin, and a robust validation process to ensure secure and efficient operation of each agent.
2026-08-03
PowerShell
★ 58
PowerShell is a task automation and configuration management framework that enables users to script and execute administrative tasks across various operating systems, although it lacks full feature parity on non-Windows platforms. Its notable features include a robust command-line interface, scripting capabilities for system management, and a focus on script reliability and reuse. The tool is particularly useful for network troubleshooting and performance monitoring, exemplified by scripts like TimeTrack-Specific-Software-Openings.ps1, which measures application launch times.
2026-08-03
PowerShell
★ 44
PrecompiledBinaries is a curated repository of precompiled binaries designed for use in authorized security testing, including penetration testing, red teaming, and exploit validation. It facilitates rapid access to essential tools across various scenarios such as privilege escalation, Active Directory assessments, and tunneling, eliminating the need for time-consuming compilation from source. Notable features include an organized layout of binaries by tool and platform, covering a wide range of use cases in security assessments.
2026-08-03
Go
★ 227
PromptZero is a natural-language operator designed for the Flipper Zero device, enabling users to generate, deploy, and execute various payloads through simple text commands. It primarily facilitates tasks related to RF, NFC, RFID, and HID payload creation while offering an intuitive interface for both offensive and defensive cybersecurity scenarios. Notable features include end-to-end integration with Claude AI for payload generation, a read-only operational mode for safe usage, and real-time querying of connected devices.
2026-08-03
Python
★ 42
ReconNinja is an autonomous multi-phase security reconnaissance framework that conducts comprehensive security assessments through a single command. It supports a myriad of functionalities including passive OSINT, port scanning, web discovery, vulnerability scanning, and Active Directory enumeration, producing reports in multiple formats like HTML, JSON, and Markdown. Notable features include an adaptive agent mode for dynamic decision-making, a user-friendly GUI, and enhanced reliability for complex scans with a uniform `PhaseContext` adapter layer.
2026-08-03
C++
★ 727
The Red-Team-Exercises repository serves as a compilation of educational posts focusing on various red team tactics and techniques. This resource is primarily designed for cybersecurity professionals seeking to enhance their skills in areas such as shellcode execution, evasion techniques, and phishing campaigns. Notable features include detailed descriptions of each exercise, covering advanced topics like AMSI bypass, process injection, and Active Directory enumeration.
2026-08-03
JavaScript
★ 13
Shells-X is a modular web shell framework designed for authorized penetration testing and security research, allowing users to deploy a single-file shell that incorporates various tools for executing commands, interacting with databases, and scanning ports. Its notable features include customizable builds with unique SHA256 fingerprints, an interactive environment for PHP and SQL commands, robust system diagnostics, and encrypted traffic handling. The framework also supports automatic detection of CMS/frameworks and provides a one-click export option for recon data to Faraday.
2026-08-03
PowerShell
★ 21
SiteSniper is an automation script designed for blackbox penetration testing, leveraging tmux for organizing and executing various penetration testing scripts across multiple phases. Its primary use case involves preparation and execution of commands for tasks such as information gathering, exploit identification, and web application analysis. Notable features include a user-friendly interface for phase selection, precompiled command execution, and a structured approach to manage multiple testing sessions efficiently.
2026-08-03
Python
★ 404
Slack Watchman is a cybersecurity tool that utilizes the Slack API to monitor Slack workspaces for exposed sensitive data and enumeration of user and conversation details. Its primary use case is aiding red, blue, and purple teams in identifying potential security risks, including various types of keys, personal data, and files through customizable, time-based searches. Notable features include an unauthenticated probe mode for gathering workspace information, automated updates of signature definitions for detecting secrets, and flexible logging options for output formatting.
2026-08-03
Go
★ 55
Sopa is a Golang-based client for the Active Directory Web Services (ADWS) protocol, facilitating comprehensive directory management operations. It supports object search and retrieval, lifecycle management, attribute editing, account management, and custom actions while leveraging WS-Enumeration, WS-Transfer, and other protocols. Notable features include the ability to create, delete, and modify objects, as well as manage account passwords and group memberships.
2026-08-03
Python
★ 58
Tengu is a multi-command platform (MCP) server that functions as an AI-assisted penetration testing copilot, integrating with various security tools such as Nmap and Metasploit. It automates reconnaissance and scanning processes while allowing users to maintain control over exploit actions, featuring advanced safety controls like allowlisting and audit logging. Notable features include its orchestration of 80 tools, automated report generation, and pre-built workflows for diverse pentesting scenarios.
2026-08-03
Batchfile
★ 18
WinPrivEsc is a Windows enumeration and privilege escalation discovery toolkit designed for authorized testing. It offers two script variants—one using cmd for stealth on monitored hosts and another using PowerShell for more comprehensive analysis, allowing users to assess escalation vectors while maintaining a read-only operation. Notable features include customizable noise levels for the script output and extensive reporting on system configurations, user accounts, and permissions, ensuring flexibility and adaptability to various security environments.
2026-08-03
Python
★ 14
WordListsForHacking (WFH) is a comprehensive wordlist generation toolkit designed for penetration testing and red team operations, featuring 44 subcommands encapsulated within a single command-line interface. It supports tasks such as charset and mask generation, web scraping, personal and corporate profiling, and advanced techniques including machine learning-based ranking and acrostic generation. The tool is geared towards enhancing the efficiency and effectiveness of security assessments through diverse and robust functionalities.
2026-08-03
Go
★ 47
Zscan is a fast and customizable service detection tool designed to identify services, APIs, and network configurations within infrastructure using a flexible fingerprint system. Key features include high-performance concurrent port scanning, intelligent service detection capabilities (such as MAC vendor identification and OS fingerprinting), precise proof of concept (POC) targeting, and versatile output formats including JSON and human-readable options. This tool enhances scanning accuracy and speed compared to traditional methods, making it valuable for network security assessments.
2026-08-03
Zig
★ 338
The bof-launcher is a versatile programming library designed for in-memory management and execution of Beacon Object Files (BOFs) across multiple platforms, including Windows and Linux. It supports various architectures and integrates seamlessly with languages such as C, Zig, and Rust, offering features like asynchronous execution, cross-platform compatibility, and advanced memory masking techniques. Additionally, the library facilitates the development of BOFs using Zig, leveraging a rich standard library for enhanced functionality during red team engagements.
2026-08-03
JavaScript
★ 26
Browser Data Logger is a client-side JavaScript toolkit designed for authorized research and testing of browser telemetry and API capabilities. It modularly collects and aggregates data from various browser APIs, ensuring that failures in one area do not impact overall functionality, while providing real-time streaming of results via WebSocket and Telegram integration. The tool focuses on studying browser fingerprints, device metadata, and permissions, making it ideal for security research and educational purposes.
2026-08-03
C
★ 10
C-Full-Offensive-Course is a bilingual educational resource designed to guide users through a comprehensive C programming curriculum focused on offensive security practices across Windows, Linux, and macOS platforms. The course comprises 216 progressive units with hands-on coding exercises, alongside a centralized codebase to facilitate learning. It emphasizes ethical usage by instructing users to conduct security labs only within authorized and isolated environments.
2026-08-03
JavaScript
★ 241
Code Abyss is a sophisticated tool designed to enhance AI coding agents with personality, consistent execution, and security expertise across various engineering domains. It offers customizable personas and styles, allowing for a tailored interaction experience, while possessing a robust skill library for effective judgment in technical scenarios. Notable features include support for four native security domains and a disciplined kernel that minimizes context overhead, ensuring agents respond with depth and specificity in diverse situations.
2026-08-03
Python
★ 196
Dorothy is a Python tool designed for security teams to assess their monitoring and detection capabilities within Okta environments. It offers modules that simulate potential attacker actions and facilitates auditing aligned with MITRE ATT&CK® tactics, including persistence, defense evasion, and discovery. Notably, it allows users to modify Okta configurations, making it essential for testing purposes in non-production environments.
2026-08-03
Python
★ 127
Fluffy-Barnacle is a toolkit designed for creating disposable, ephemeral network infrastructure using GitHub Codespaces, enabling users to rapidly deploy services such as SOCKS5 proxies, HTTPS file hosting, and WireGuard tunnels. Notable features include an auto-reconnecting SOCKS5 proxy with circuit breaker support, instant public HTTPS file hosting capabilities, and a suite of CLI tools that integrate with common security testing utilities while managing fresh egress IPs upon each deployment. This tool serves primarily for educational, research, and authorized security testing purposes, adhering strictly to GitHub's usage policies.
2026-08-03
Python
★ 584
Gato-X is an advanced scanning and attack toolkit specifically designed to identify vulnerabilities in GitHub Actions pipelines, including Pwn Requests, Actions Injection, and self-hosted runner takeovers. Notable features include fast scanning of thousands of repositories with a single API token, robust analysis of cross-repository workflows, and the capability for post-compromise secrets enumeration. Tailored for Red Teamers and security professionals, Gato-X emphasizes thorough vulnerability detection while adhering to ethical research practices.
2026-08-03
Go
★ 36
Geiger is a read-only blast-radius triage tool designed for assessing the impact of leaked credentials by identifying what resources they can access. It excels in incident response and penetration testing scenarios by running dry-run recon against credentials to evaluate their reach without altering any systems. Notable features include the ability to process various input formats, integration with other security tools like TruffleHog and Nuclei, and the option for live testing to provide impact assessments while preserving a read-only modality.
2026-08-03
Rust
★ 44
GhostHound is a specialized tool designed as an OpenGraph extension for BloodHound, targeting the enumeration of deleted objects (tombstones) in Active Directory environments. Its primary use case is to facilitate security assessments by revealing who can restore these deleted objects, thereby potentially allowing an attacker to reclaim identities. Notable features include the ability to generate a JSON payload compatible with BloodHound, detailed analysis of reanimation rights, and flexible LDAP connection options for various environments.
2026-08-03
HTML
★ 233
The HTB Writeups repository is a comprehensive resource for Hack The Box enthusiasts, providing structured and searchable documentation for over 500 machines, 400 challenges, and various tools and methodologies useful for penetration testing and certification preparation. Notable features include an interactive machine finder, knowledge graph for technique exploration, and visual attack paths that illustrate complete exploitation processes. This repository serves as an essential hub for skill development aimed at OSCP, CPTS, and other security certifications.
2026-08-03
Python
★ 185
The Cyber, InfoSec Events repository serves as a catalog of past and upcoming cybersecurity and information security-related events. Its primary use case is to provide a comprehensive list of events in the field, facilitating community engagement through contributions and updates. Notable features include an interactive calendar subscription option and a welcoming approach for community involvement via issues and pull requests.
2026-08-03
TypeScript
★ 500
Payloader is a self-hosted knowledge workbench designed for authorized security testing, red teaming, and security research. It consolidates payloads, tool commands, and coding procedures into a searchable and maintainable system that can be distributed offline, featuring a dual workspace for payloads and commands, a management backend for content and navigation, and client generation capabilities for Windows, Linux, and macOS. Notable functionalities include seamless payload management, robust encoding/decoding support, and built-in version control for content updates.
2026-08-03
Shell
★ 14
Omniscient V3 is a comprehensive reconnaissance and adversary simulation framework designed to enhance security assessments by consolidating over 130 best-in-class tools into a unified pipeline. Key features include AI-driven results augmentation, distributed execution across platforms such as Kubernetes and Docker, advanced stealth techniques for emulating sophisticated attacks, and immutable audit trails for compliance and reporting. This tool is primarily aimed at security professionals, providing a streamlined approach to identifying vulnerabilities in complex attack surfaces.
2026-08-03
Shell
★ 478
ScanCannon is a high-speed Bash script designed for efficient credentials-based attack surface enumeration and reconnaissance of large external networks, leveraging tools like `masscan` for rapid port detection and `nmap` for detailed service analysis. It outputs consolidated reports in HTML and CSV formats while enabling project-driven scanning that tracks changes over time, facilitating continuous monitoring of attack surfaces. Notable features include full ASN-based discovery, API detection, CVE hinting, and resilience through checkpointing and parallel scanning.
2026-08-03
★ 24
TABPE is a structured dataset tool that catalogs all PE (Portable Executable) files, including executables and libraries, from clean installations of Windows 10 Pro and Windows 11 Pro. The primary use case is for security researchers and developers who require comprehensive information about each PE file, including metadata such as headers, sections, imports, exports, and checksums, along with detailed logs of the scanning process. Notable features include the generation of a JSON file containing complete PE file details, a text file listing all detected files, and a log of inaccessible files, providing a thorough overview of the executables on the system.
2026-08-03
C#
★ 65
VisualSploit is a tool designed to weaponize MSBuild project files by injecting a loader for embedded shellcode, enabling execution without direct user interaction during project build or evaluation. It supports various MSBuild file formats and allows customization of shellcode input formats, XOR encryption rounds, and target platforms, thereby facilitating stealthy payload delivery through CI environments or developer machines. Notably, it exploits MSBuild's design-time evaluation feature to trigger code execution upon project operations.
2026-08-03
Python
★ 190
0day Rubbish is an automated vulnerability disclosure tool focused on the rapid identification and public release of high-severity 0-day vulnerabilities using AI-driven methods. It emphasizes efficiency by verifying exploits and providing thorough assessments while maintaining a non-profit approach to enhance timely vendor responses. Key features include direct disclosure of verified vulnerabilities with working proof-of-concept code, a commitment to real-world impact, and continuous monitoring through advanced AI models.
2026-08-03
Shell
★ 64
365 is a comprehensive OSINT and threat hunting tool designed for network and web reconnaissance, discovery, enumeration, vulnerability mapping, exploitation, and reporting. Its notable features include a streamlined setup process for Kali Linux and a range of scripts for automating various security assessment tasks. This tool is primarily used for enhancing security assessments and facilitating vulnerability exploitation in targeted environments.
2026-08-03
TypeScript
★ 576
OPFOR is an open-source tool designed for adversary emulation targeting AI agents, LLM applications, and MCP servers, enabling users to test their defenses against a variety of attack vectors. It provides a CLI interface, a browser extension for non-developers, and supports configurable scans that address multiple OWASP security standards. Its comprehensive capabilities allow for testing of prompts, tools, and reasoning processes, making it a versatile solution for enhancing AI security.
2026-08-03
Python
★ 51
The Agile V™ Agent Skills Library provides a framework for enhancing the reliability of AI agents by implementing formal traceability and independent verification to combat common pitfalls such as hallucinations and silent assumptions in code generation. It allows for typed lineage linking requirements to implementation artifacts, promoting compliance and ensuring that every piece of code can be traced back to its original requirements. Notable features include hardware awareness for optimized deployment and the separation of code generation from verification to ensure that all edge cases are adequately tested before production.
2026-08-03
Python
★ 23
APTL (Advanced Purple Team Lab) is a cybersecurity tool that facilitates autonomous red and blue team training by simulating an enterprise target stack, utilizing AI agents to drive offensive and defensive operations. It allows users to create a customizable lab environment with various services, integrating penetration testing tools and intentionally vulnerable configurations while capturing telemetry data for analysis. Key features include a simple command-line interface for lab setup, various attack and defense scenarios, and real-time performance monitoring, making it ideal for cyber-operations research and purple team training.
2026-08-03
Go
★ 170
ASHIRT is an automated adversary simulation documentation tool designed to centralize the capture, indexing, and searchability of evidence collected during operations. Its primary use case is to streamline the process of documenting activities by providing a non-intrusive methodology that reduces manual steps and enhances sharing across teams. Notable features include support for high-fidelity data synchronization and a dedicated frontend and backend architecture for improved usability and deployment flexibility.
2026-08-03
Rust
★ 29
ASHIRT Terminal Recorder (aterm) is a tool designed for recording terminal sessions in a pseudo terminal, enabling users to upload these recordings to an ASHIRT server in asciicast v3 format. Its primary use case is to facilitate session logging for review and sharing, offering features such as easy navigation through menus, session management (including renaming and discarding recordings), and a configuration system that adheres to the XDG standard. Built as a single-binary Rust application, aterm supports multiple operating systems and can be easily run using standard Rust tooling without additional dependencies.
2026-08-03
Python
★ 259
AutoRedTeam-Orchestrator is a local-first, MCP-native automation platform designed for authorized testing and AI/MCP attack surface auditing. It features a modular security capability set accessible via an MCP Server, Python SDK, and Typer CLI, enabling static code audits, reconnaissance, and vulnerability detection primarily for research and training purposes. Notable capabilities include AI-assisted audits, configurable scanning profiles, and different export formats for audit reports, each tailored for secure and compliant usage scenarios.
2026-08-03
★ 66
The "Awesome AI Agent Attacks" repository provides a curated timeline of real-world security incidents involving AI agents from 2024 to 2026, detailing the specific impacts, root causes, and relevant CVEs associated with each breach. It serves as a factual resource, compiling numerous documented cases to facilitate a better understanding of AI-related vulnerabilities and attack patterns, while emphasizing transparency through sourced entries. Notable features include categorized incident summaries by year, key statistics, and an attack pattern taxonomy.
2026-08-03
Shell
★ 4331
The "Awesome OSINT for Everything" repository provides a comprehensive list of OSINT (Open Source Intelligence) tools and websites tailored for penetration testing, information gathering, and red team operations. It encompasses a wide array of categories, including reverse searching, social media analysis, data leaks, and more, making it an invaluable resource for cybersecurity professionals and bug bounty hunters. Notable features include organized sections by topic, facilitating easy navigation and access to relevant tools across diverse OSINT areas.
2026-08-03
Python
★ 303
Black Cat is a penetration testing automation framework designed to mimic human-like engagement through a hypothesis-driven state machine model, allowing for iterative recon and validation processes. Unlike traditional tools that follow a linear pipeline, Black Cat enables feedback loops between different testing phases, making it adaptable and capable of handling failures creatively. Notable features include a single JSONL ledger for tracking hypotheses and evidence, explicit file routing for techniques, and a refined decision-making process that records the rationale behind each choice made during testing.
2026-08-03
HTML
★ 14
CloudGuard Security is a browser-based demonstration tool that exploits the File System Access API to simulate file encryption and delivery attacks without requiring software installation. It operates in two modes: the 'lock' mode, which encrypts files using AES-256-GCM and displays a countdown alert, and the 'drop' mode, which silently writes a specified payload to the user's file system. The tool emphasizes social engineering techniques for permission granting, making it a practical resource for red-team exercises.
2026-08-03
Go
★ 318
Brutus is an advanced, multi-protocol authentication testing tool designed for penetration testers and red team operators, enabling efficient credential validation across a diverse range of network services such as SSH, RDP, and databases. Built in Go as a single binary with no external dependencies, it offers features like SOCKS5 proxy support, aggressive mode tuning, and seamless integration with tools like Nerva and naabu for automated workflows. Notably, it includes a library of known bad keys and supports account enumeration, making it a versatile asset for modern offensive security practices.
2026-08-03
Python
★ 476
Cain is an AI-powered penetration testing engine designed for authorized security assessments in real-world environments, effectively navigating complex business logic and adapting to activated WAF/risk control systems. Key features include a cloud penetration module that supports major cloud platforms, a deterministic state machine for orchestrated testing, and robust safety mechanisms ensuring compliance and risk management. Its capabilities extend to identifying business logic flaws, authentication issues, and cloud misconfigurations, providing detailed evidence and actionable remediation advice.
2026-08-03
Python
★ 7227
Caldera™ is a cyber security platform that facilitates automated adversary emulation, supports manual red-teams, and streamlines incident response through its integration with the MITRE ATT&CK™ framework. Its architecture comprises a core system featuring an asynchronous command-and-control (C2) server with a REST API and a web interface, complemented by a variety of plugins that enhance its functionalities with capabilities like reporting and TTP collections. This tool is particularly notable for its flexibility, allowing users to develop custom plugins to extend its capabilities.
2026-08-03
★ 30
The Certificate of Compromise repository contains a comprehensive paper detailing offensive operations against Active Directory Certificate Services (ADCS). It serves as a living document that outlines various attack techniques, their detection, and mitigation strategies, and is continuously updated to reflect new findings and community contributions. Notably, it emphasizes the dynamic nature of ADCS research, providing insights into attack taxonomies and the related challenges in securing these services.
2026-08-03
Python
★ 15
CredWolf is a credential validation tool designed for Active Directory Domain Services that tests various username and secret combinations against a domain controller to identify valid credentials. Notable features include support for multiple secret types (passwords, NT hashes, Kerberos keys), username enumeration without triggering account lockouts, and extensive configuration options for safe and efficient testing. It is tailored for use in authorized penetration testing and security audits, ensuring robust and secure credential verification processes.
2026-08-03
Python
★ 49
Crucible is a security testing tool designed specifically for AI agents, enabling comprehensive behavioral integrity testing and automated red-teaming against a wide range of attacks, including those aligned with OWASP guidelines. It offers rapid deployment via CI/CD integration, producing detailed compliance reports, and incorporates a unique Model Context Protocol security module. The tool encompasses over 90 tested attack vectors, ensuring agents are hardened against potential threats before production deployment.
2026-08-03
Python
★ 48
The Cybersec Toolkit is an advanced cybersecurity solution that incorporates AI integration through a Model Context Protocol (MCP) server, enabling interactive tool management during penetration testing and bug bounty hunting. It features a comprehensive repository of over 670 tools, categorized into 18 modules and 14 profiles, allowing for modular installation and multi-platform support, including Linux and Termux. Unique to this toolkit is its capability for the AI to autonomously drive tool execution based on problem context, providing a hybrid approach that combines operator control with AI assistance.
2026-08-03
JavaScript
★ 13
The Cybersecurity Interview Questions repository is a comprehensive collection of over 200 interview questions and answers, tailored for various roles in cybersecurity, including Red Team, Blue Team, and Incident Response. Its notable features include categorization by specific topics such as web security and internal network security, along with a user-friendly live site for browsing and searching content. The repository serves as a valuable resource for job seekers, students, and professionals looking to enhance their knowledge and prepare for cybersecurity interviews.
2026-08-03
TypeScript
★ 2162
CyberStrike is an open-source AI-driven tool designed for automated penetration testing, enabling users to transform their existing AI language model subscriptions into autonomous red team agents. It features over 13 specialized agents, 7,600+ security skills, and 120+ OWASP testing techniques, facilitating tasks such as reconnaissance, vulnerability discovery, exploitation, and reporting from a terminal interface. With compatibility for 150+ AI providers and a variety of built-in and MCP tools, CyberStrike streamlines offensive security assessments efficiently.
2026-08-03
Python
★ 12
DrowAI is a pre-release AI agent platform designed for executing task-isolated security workflows via a web control plane, utilizing LangGraph-based orchestration and Docker/Kali environments. It features a FastAPI backend for task management and real-time communication, a React/TypeScript frontend for user interaction, and a dynamic tool registry that adapts as tools meet integration standards for AI assistance. The platform aims to explore the potential of AI-assisted software development in cybersecurity applications while still undergoing active refinement.
2026-08-03
Rust
★ 34
Echos is a modular network beacon emulator designed for validating detection systems in cybersecurity labs. It generates realistic command-and-control (C2) traffic across multiple protocols, enabling security teams to test their EDR, NDR, and SIEM solutions under controlled conditions without introducing risks associated with real malware. Key features include a variety of built-in profiles for significant APT groups, customizable configurations, and export capabilities for Sigma, Suricata, and Snort rules, making it a versatile tool for detection engineering.
2026-08-03
C
★ 30
ENDGAME is a command and control framework designed for authorized red team operations and penetration testing, enabling users to simulate adversarial techniques and assess their network's detection capabilities. Its standout feature is the integrated AI Console, which interprets user objectives in natural language and suggests executable commands based on real-time contextual data, enhancing efficiency in red team workflows. Additionally, the framework supports automated analysis of command outputs to inform follow-up actions, ensuring a streamlined operational process.
2026-08-03
Python
★ 17
The 4NDR0666OS tool is designed for advanced red-teaming and adversarial logic research, focusing on prompt injection, symbolic logic decoupling, and state-machine resilience. It features a persistent virtual kernel that survives resets and restrictions, allowing for continuous interaction with large language models (LLMs) across a wide token budget while facilitating sophisticated testing and override mechanisms. Notable capabilities include cross-model validation and a rich repository of exploit modules and functions, aimed at enhancing the robustness of instruction sets against safety protocols.
2026-08-03
TypeScript
★ 39
HackMyAgent is a security scanning and behavioral simulation toolkit designed specifically for AI agents, providing red-team capabilities to identify vulnerabilities across various categories. It features comprehensive static and semantic checks, including a NanoMind semantic layer, which evaluates agent configurations and evaluates vulnerabilities like credential exposure and context manipulation. The tool also supports deep behavioral simulations and self-securing mechanisms to ensure the integrity of its binaries.
2026-08-03
Python
★ 19
HDN Phish Toolkit is a comprehensive social media phishing simulation tool designed for authorized security testing and educational purposes. It creates realistic login pages for over nine popular platforms, enabling organizations to assess and understand phishing vulnerabilities while offering features like real-time credential capture, IP tracking, and a web dashboard for monitoring captured data. The tool is cross-platform compatible, supporting Windows, Linux, and macOS environments.
2026-08-03
HTML
★ 129
HydraSoft is an advanced open-source tool designed for detecting DLL hijacking vulnerabilities within Windows environments, facilitating privilege escalation. It automates the analysis of executable files and their associated DLLs by scanning directory structures and import tables, thus identifying specific hijacking opportunities. Notable features include a real-time graphical user interface for centralized endpoint management and a color-coded rating system to prioritize targets based on the complexity of crafting proxy DLLs.
2026-08-03
Python
★ 131
kcwarden is a Python tool designed to audit Keycloak configurations, identifying common misconfigurations and security vulnerabilities. Its primary use case is to enhance the security posture of Keycloak implementations by enabling users to download their configuration and perform detailed audits. Notable features include ease of installation via pip, straightforward usage commands for downloading configurations, and auditing, complemented by comprehensive documentation.
2026-08-03
Python
★ 307
LLMVault is a comprehensive, hands-on training platform designed to educate users on the OWASP LLM Top 10 vulnerabilities applicable to large language models (LLMs). It features 25 deliberately vulnerable labs across three tiers—core, advanced, and expert—each focusing on different attack and defense scenarios, allowing users to learn practical exploits and their mitigations in a controlled environment. Notably, LLMVault emphasizes a self-contained setup that requires no online exposure, ensuring a secure learning experience.
2026-08-03
Python
★ 82
Miner In The Middle is a Python-based tool that facilitates the injection of JavaScript cryptocurrency miners into HTTP responses of targets on a local network via ARP spoofing. It features configurable options for injection scripts and IP constraints to ensure targeted use, along with an easy setup process that automates iptables configuration and packet forwarding. Users can also implement custom JavaScript for injection and execute various attack modes, including standard miner attacks and popunder techniques.
2026-08-03
C++
★ 421
mkPIVM is a polymorphic, position-independent shellcode virtualizer designed for Windows x86 and x64, which enables the obfuscation of raw shellcode by converting it into a virtual machine that interprets encrypted instructions. Its primary use case is enhancing the stealth of shellcode to evade signature-based detection, leveraging features such as customizable cipher families, opcode permutations, and detailed control over the virtual machine's configuration. The tool supports various operational modes, including full lifting, packing, and hybrid approaches, making it versatile for evasion techniques in offensive cybersecurity applications.
2026-08-03
★ 13
The n8n-CyberSecurity-Workflows tool provides over 100 pre-built automation workflows tailored for various cybersecurity functions, including red team, blue team, and application security tasks. It features seamless integrations with popular security tools, a user-friendly interface for ease of use, and benefits from ongoing community contributions that enhance its functionality. This application is designed to streamline and simplify security automation processes for professionals in the cybersecurity domain.
2026-08-03
C++
★ 123
NocturneLdr is a research-oriented Windows x64 shellcode loader designed to produce clean, fully backed call stacks that evade detection by modern EDR solutions and forensic analysis tools. By injecting code into a legitimate module's `.text` section and utilizing genuine unwind metadata, it maintains call stack integrity while eliminating C runtime dependencies. Notable features include compile-time API hash resolution to obscure function names and IAT camouflage with benign imports, enhancing stealth against static analysis.
2026-08-03
PowerShell
★ 84
OffsetInspect is a PowerShell toolkit designed for byte-offset inspection, source correlation, binary comparison, and defensive detection-boundary analysis. It enables analysts to identify specific content at given byte offsets and the surrounding context, while also facilitating detection workflows inspired by ThreatCheck and offering a suite of red-team analysis and triage capabilities. Notable features include efficient file handling, contextual mapping, multi-region detection, and an in-memory approach to avoid interference with endpoint protection mechanisms.
2026-08-03
C++
★ 157
PolyEngine is an evasive PE packer designed for research purposes, particularly in CTF challenges and low-level Windows security education. It employs advanced techniques such as in-memory execution, obfuscation, and various evasion options (like process name spoofing and API- hammering) to bypass EDR and AV detection mechanisms. This tool is intended for authorized security testing and educational use only, with comprehensive features for embedding payloads and managing execution context.
2026-08-03
Go
★ 251
pphack is an advanced client-side prototype pollution scanner designed to identify vulnerabilities in web applications. It offers a variety of features including the ability to scan single or multiple URLs, configure concurrency levels, set timeouts, and conduct automatic exploitation. The tool utilizes Chrome or Chromium for its operations, allowing for custom JavaScript execution and flexible output options such as JSON format.
2026-08-03
Python
★ 15
The prompt-injection-auditor is an agent skill designed to enhance the security of AI prompts by auditing them for potential prompt-injection vulnerabilities. Its primary use case is to identify weaknesses using a static scanning approach, complemented by an attack catalog and a defense checklist, particularly in light of real-world incidents. Notably, the tool improves differentiation between hardened and vulnerable prompts while maintaining a zero false-positive rate, enabling developers to proactively address security flaws in their AI systems.
2026-08-03
Python
★ 1214
Recon Skills is a comprehensive toolkit designed for authorized security testing, focusing on external reconnaissance across web applications, APIs, and various vulnerability assessments. Notable features include a structured catalog of skills for discovery, validation, and reporting, covering areas such as authentication testing, attack-path analysis, and evidence review, while emphasizing best practices for operational security and quality assurance. The tool aims to facilitate both manual and automated workflows for security professionals, ensuring a thorough approach to web security assessments.
2026-08-03
★ 69
Red Giant
2026-08-03
Python
★ 28
The Agent Security Harness is a testing tool designed for evaluating the security and integrity of payment agent protocols, with a specific focus on identifying manipulative behaviors even when agents are properly authenticated and authorized. It features 603 executable security tests across 44 modules that cover a wide range of protocols, including MCP, A2A, and Visa/Mastercard specific tests, along with mechanisms for detailed reporting on test results. The tool supports a taxonomy-driven evidence approach to classify and validate security claims, enhancing confidence in security assessments carried out on agentic payment systems.
2026-08-03
C
★ 24
Rubber Dolphy is a proof-of-concept tool designed for the FlipperZero device that enables data exfiltration via BadUSB functionality utilizing mass storage capabilities. It allows users to copy data onto the FlipperZero when it acts as a BadUSB device, facilitating the retrieval of exfiltrated information across different operating systems, including Linux, Windows, and macOS. Notable features include support for FAT file system imaging and the integration of DuckyScripts for streamlined operations, along with planned enhancements for increased functionality and automation.
2026-08-03
Go
★ 25
Sandbox Probe is a static Go binary designed to evaluate the boundaries of sandbox environments used by AI coding agents and other applications. By performing a comparative analysis between a baseline scan on a host and a scan within the sandbox, it identifies potential security gaps, such as unauthorized access to sensitive paths or network resources. Notable features include customizable task sets for various types of actions, JSON report generation for findings, and the ability to track sandbox policy changes over time.
2026-08-03
Rust
★ 11
SATAN2 is an advanced counter-forensics framework designed for security professionals, Red Teams, and privacy advocates, offering features for multi-pass data destruction, nested encryption, and forensic artifact forgery. Its primary use case is to effectively eliminate sensitive information and mislead forensic analysis, making it a formidable tool against incident-response efforts. Notable features include cross-platform support, modular architecture, and specialized modules for thorough deletion and deception on both Linux and Windows systems.
2026-08-03
★ 25
The Security Research Orchestrator Prompt is an advanced orchestration tool designed for structured security and vulnerability research across a variety of authorized lab targets, including code, binaries, and infrastructure configurations. Notable features include its emphasis on maintaining a strict research method without compromising authorization, and the ability to produce detailed outputs such as threat models, exploit chains, and evidence reports, tailored to various operational modes like lab solving, building, and hunting. This tool ensures rigorous validation of security claims while safeguarding the integrity of research processes.
2026-08-03
Python
★ 19
ShadowLab is a modular Command & Control (C2) framework designed for educational purposes in cybersecurity research, focusing on the engineering principles of modern C2 infrastructures. Key features include AES-128 encrypted communications, payload generation, and a dynamic post-exploitation module system, all intended for use in controlled environments to enhance learning and understanding of cybersecurity concepts rather than for offensive tactics.
2026-08-03
JavaScript
★ 104
SilentSniffer is an educational tool designed as a web security diagnostic sandbox to demonstrate the extent of information exposure in modern web applications. Functioning entirely as a local client-side environment, it visually portrays how a user's device state and behavioral data can be accessed without consent, utilizing a zero-coupling dynamic plugin architecture for modular functionality. Notable features include a threat escalation hierarchy that categorizes information exposure severity and ensures no data leaves the user's device during operation.
2026-08-03
Shell
★ 22
SimpleVenom is a versatile tool for generating Metasploit payloads, featuring multiple user interfaces including a graphical interface (Zenity), a terminal menu interface (Dialog), and a command-line wizard. It intelligently auto-detects the best available interface based on installed tools and supports payload generation for Windows, Android, and Linux systems. The tool is designed for authorized penetration testing and educational purposes, ensuring a user-friendly experience while managing dependencies effectively.
2026-08-03
Go
★ 11763
Sliver is an open-source adversary emulation and red team framework designed for security testing in organizations of all sizes. It features dynamic code generation, multiple secure command and control (C2) communication methods including mTLS and WireGuard, and supports a wide range of platforms while allowing for advanced tactics like process injection and in-memory execution. The framework is highly scriptable in Python and offers functionalities like compile-time obfuscation and multiplayer-mode for enhanced testing scenarios.
2026-08-03
Svelte
★ 17
Sliver GUI is an offensive-security desktop application designed to interface with the Sliver C2 framework. It offers an integrated operational workspace for managing agents, servers, and automation, featuring dynamic session management, interactive consoles, and extensive tooling for file and process manipulation. Notable features include a customizable command palette, agent and server management panels, automation rule scripting, and comprehensive event monitoring, all within a user-friendly interface built with modern web technologies.
2026-08-03
Go
★ 376
SmokedMeat is a CI/CD post-exploitation framework designed to analyze, exploit, and validate security vulnerabilities within continuous integration and deployment pipelines. It automates the identification of injection vulnerabilities in GitHub Actions workflows, facilitates the deployment of malicious payloads, and allows attackers to pivot across cloud environments to extract secrets and permissions. This tool is primarily intended for red teams, penetration testers, and security researchers to demonstrate and assess the resilience of CI/CD systems against advanced supply chain attack techniques.
2026-08-03
Shell
★ 33
SnowCorp Lab is a local Active Directory training environment designed for cybersecurity professionals to practice advanced attack techniques. It features a dual-domain setup with two isolated networks and a dual-homed pivot host, allowing users to simulate real-world scenarios safely on their machines without cloud dependencies. The lab is equipped with five virtual machines and multiple flags to enhance learning experiences and is optimized for hardware specifications that support high-performance virtualization.
2026-08-03
Python
★ 243
Stepping Stones is a Python Django application designed to facilitate Red Team operations by providing a web-based interface for logging activities, maintaining situational awareness, and generating report snippets throughout engagements. Notable features include real-time usage during missions, Cobalt Strike integration for enhanced functionality, and streamlined installation and updating processes to optimize testing and reporting workflows.
2026-08-03
Python
★ 12
Storm-Framework is an offensive security tool suite designed for reconnaissance, vulnerability assessment, and exploitation, catering to cybersecurity professionals, penetration testers, and bug bounty hunters. Built with a user experience similar to Metasploit, it streamlines security testing workflows and supports multiple platforms including Kali Linux, Ubuntu, and Windows. Notable features include a comprehensive framework flow, detailed documentation, and a structure visualizer that aids in navigating the tool's components.
2026-08-03
Go
★ 27
SubdomainX is an advanced subdomain discovery and security reconnaissance tool that integrates over twelve enumeration tools and six API services into a single command-line interface (CLI). Its primary use case is to facilitate comprehensive subdomain enumeration, vulnerability detection, and monitoring, featuring capabilities such as HTTP probing, technology fingerprinting, subdomain takeover detection, and notifications via various platforms. Notable features include the ability to generate detailed reports in multiple formats, an interactive terminal user interface (TUI), and support for resuming interrupted scans, making it a robust solution for security assessments.
2026-08-03
Go
★ 687
Titus is a high-performance secrets scanner designed to detect credentials, API keys, and tokens within source code, files, and git history. Targeted at security engineers and DevSecOps teams, it features accelerated regex matching, live secret validation, broad coverage with 487 detection rules, and multiple scanning interfaces including CLI, Go library, and browser extensions. Notably, Titus also supports container image scanning and binary file extraction for enhanced security assessments.
2026-08-03
C
★ 10
Tung is a command-line tool designed for configuring and testing firewalls against various types of DoS attacks. Its primary use case is to assist security professionals in evaluating firewall resilience and understanding DoS attack vectors through a collection of common techniques across multiple network protocols, including implementations of attacks like Slowloris and BlueNurse. Notable features include support for ICMP, TCP, UDP, and IP, making it a versatile tool for both educational and practical security testing purposes.
2026-08-03
Python
★ 137
The ULTIMATE CYBERSECURITY MASTER GUIDE serves as a comprehensive knowledge base for cybersecurity practitioners, encompassing insights from over 70 expert books and 90 internal documents. It features detailed guides and playbooks for various roles, including Red Team, Blue Team, and Purple Team operations, along with a flat catalog system for easy access to all resources. Notable elements include an extensive collection of OSINT tools and custom scripts, making it an essential reference for both novice and experienced cybersecurity professionals.
2026-08-03
Python
★ 84
Violin is a Hermes-native pentesting profile designed for supervised penetration tests, guiding users through reconnaissance, exploit validation, and reporting while ensuring robust safety mechanisms. Notable features include 31 structured playbooks for various testing methodologies, a multi-layered safety system that validates every target interaction, and evidence-driven reporting to enhance reproducibility and documentation. It seamlessly integrates with existing Hermes configurations without introducing additional credential management, streamlining the pentesting workflow.
2026-08-03
Python
★ 24
Red-Team AI is a white-box red teaming tool designed to identify security vulnerabilities in agentic AI applications by analyzing the source code for specific bugs related to the application's stack. Its notable features include a comprehensive dashboard for scan management, customized attack generation based on the application's architecture, and compliance tracking against industry standards like OWASP LLM Top 10. This tool is particularly useful for developers working with AI agents in sensitive environments such as finance or healthcare, where unique security risks can arise.
2026-08-03
JavaScript
★ 137
WRAITH is a modern browser-hooking framework designed for red teams, security researchers, and educators, effectively merging the functionalities of traditional browser exploitation tools and blind-XSS frameworks into a single solution. It enables users to conduct authorized security testing by delivering both interactive post-exploitation capabilities and fire-and-forget blind-XSS callbacks in a manner suited for contemporary web applications, including those involving AI. Notable features include an operator console for session management, Docker support for deployment, and a generation of custom payloads for seamless integration into testing scenarios.
2026-08-03
C
★ 110
XeraLdr is an advanced Windows loader engineered for executing payloads stealthily while evading modern Endpoint Detection and Response (EDR) systems, specifically tested against Microsoft Defender for Endpoint with no alerts triggered. Key features include techniques such as module stomping, IAT camouflage, and advanced anti-analysis measures, which significantly enhance its stealth capabilities and reduce detection risks. This tool is designed primarily for educational and research purposes, enabling users to understand sophisticated evasion tactics used in malware payload delivery.
2026-08-03
Python
★ 150
ACEshark is a utility for the rapid extraction and analysis of Windows service configurations and Access Control Entries, streamlining the identification of potential privilege escalation vectors without reliance on non-native binaries. It operates by starting an HTTP/HTTPS server to receive and process data from a custom extractor script run on the target machine, generating detailed logs for each service configuration analyzed. Notable features include the ability to audit service permissions across users and groups, as well as options for TLS encryption during data transfer.
2026-08-03
Python
★ 80
AzSubEnum is a Python-based subdomain enumeration tool specifically designed for identifying subdomains linked to Azure services. It employs DNS resolution techniques and permutation methods to systematically explore Azure's domain structure, facilitating comprehensive security assessments for professionals by uncovering subdomains connected to various Azure resources like App Services, Databases, and Key Vaults. Notable features include multi-threaded execution for enhanced performance and support for user-defined permutation wordlists to tailor enumeration efforts.
2026-08-03
Rust
★ 40
The ETW-Bypass-Rust tool provides a method for bypassing the Event Tracing for Windows (ETW) framework, primarily aimed at evading Endpoint Detection and Response (EDR) systems. It modifies the `NtTraceEvent` function in `ntdll.dll` to prevent logging of actions that may trigger security alerts, utilizing dynamic function address resolution. This tool serves as an educational resource for cybersecurity professionals to understand and develop defensive strategies against potential detection mechanisms.
2026-08-03
C++
★ 23
Hydrangea-C2 Payloads is a command and control (C2) payload generator designed for creating and managing agents within a client-server communication framework. Its primary use case lies in facilitating the control of remote agents for task execution, file manipulation, and process management, with capabilities for advanced operations like DLL injection and keylogging. Notable features include a versatile command interface for both Windows and Linux systems, as well as support for various agent commands encapsulated in a structured communication protocol.
2026-08-03
C
★ 664
Impost3r is a C language-based tool designed for stealing various types of passwords on Linux systems, specifically targeting sudo, su, and ssh credentials. It operates by manipulating user environment files to intercept password entries without alerting the user, automatically erasing traces post-use, and can transmit the captured data via DNS protocol. Noteworthy features include stealth operation, automated cleanup of traces, and adaptable configurations for local storage or network transmission of stolen credentials.
2026-08-03
Python
★ 27
kcbrute is a brute-force tool designed for testing the security of Keycloak Admin/User Console login flows by attacking the OpenID Authorization Endpoint. It allows users to specify a target URL, along with lists of usernames and passwords, and features options for threading, verbosity, and behavioral controls such as early stopping upon a successful login attempt. This tool is intended strictly for ethical security testing, with a disclaimer regarding potential account locking due to brute-force detection mechanisms.
2026-08-03
C
★ 16
Macgonuts is a versatile ARP/NDP tool designed for network address spoofing, supporting both IPv4 and IPv6 protocols. It aims to provide a lightweight, user-friendly interface for ethical hacking and pentesting while allowing developers to leverage its functionalities via C libraries or bindings in Go and Python. Compatible with Linux and FreeBSD, Macgonuts emphasizes responsible use and ethical practices in network security assessments.
2026-08-03
Python
★ 637
Overlord is a Python-based command-line interface (CLI) tool designed for automating the setup of Red Teaming infrastructure. It allows users to easily deploy components such as command-and-control servers, email servers, and phishing servers on cloud providers like AWS and Digital Ocean, streamlining the process of creating a comprehensive penetration testing environment. Notable features include modular input handling and integration with Terraform, leveraging the Red-Baron project for infrastructure management.
2026-08-03
Rust
★ 93
Rust-Hells-Gate is a proof-of-concept tool designed for evading Endpoint Detection and Response (EDR) systems through the use of direct syscalls in Rust. It specifically implements the Hell's Gate technique, allowing users to bypass EDR hooks by accessing the Process Environment Block (PEB) to resolve function pointers from ntdll.dll, thereby minimizing detection by common security measures. Notable features include its lightweight implementation approach and the potential for extension into a fully functional malware loader.
2026-08-03
Shell
★ 46
The "s3-buckets-aio-pwn" tool is designed to identify vulnerable Amazon S3 buckets as part of penetration testing and bug bounty efforts. It uniquely allows users to scan multiple S3 bucket entries from a text file while employing various attack scenarios to assess their vulnerability. Key features include its command-line usage, integration with AWS CLI, and the capability to quickly filter out false positives during vulnerability assessments.
2026-08-03
Crystal
★ 42
SprayCannon is a multithreaded password spraying tool that automates the process of password spraying across various applications while maintaining a record of previously attempted credentials. Notable features include a backend database for tracking sprayed combinations, built-in delays and jitter for requests, support for multi-factor authentication (MFA) and lockout detection, as well as integration with webhooks for alerts. It aims to streamline the password spraying process for users managing large credential lists across multiple protocols.
2026-08-03
Go
★ 54
Supernova_CN is an open-source shellcode encryption tool developed in Golang, designed to facilitate the encryption of raw shellcode using various algorithms such as XOR, RC4, AES, and CHACHA20. It allows users to convert the encrypted shellcode into compatible formats for multiple programming languages, and provides corresponding decryption code as guidance for implementation. Notably, the tool includes a comprehensive command-line interface and supports encryption in Base64 formats for added versatility.
2026-08-03
Python
★ 29
SYCP (Solyd Certified Pentester) is a resource repository designed to complement students pursuing the SYCP certification in penetration testing. It details the activities and topics covered in the course, providing a comprehensive study guide for users to enhance their cybersecurity skills. Notable features include thorough documentation of course modules and practical insights into penetration testing techniques.
2026-08-03
Python
★ 20
Werkzeug Cracker is a tool designed to perform wordlist attacks on hashes generated by the `werkzeug.security` module, primarily to verify password hashes efficiently. It utilizes the `check_password_hash` function to determine password validity and supports multithreading to enhance cracking speed, allowing users to specify the number of threads for improved performance. The tool is compatible with both Linux and Windows platforms and requires Python 3.10 for operation.
2026-08-03
Python
★ 10
The 3num-tool is a versatile enumeration utility designed for authorized security testing, enabling users to gather information about various services such as SSH, FTP, HTTP, DNS, and SMB. Its notable features include support for credentialed enumeration, anonymous access testing for FTP, and integration with tools like Gobuster and Hydra for more comprehensive assessments. The tool emphasizes compliance with legal and ethical guidelines, catering to security professionals conducting vulnerability assessments.
2026-08-03
PowerShell
★ 452
Amnesiac is a post-exploitation framework developed in PowerShell that facilitates lateral movement within Active Directory environments without the need for installation, as it operates entirely in memory. It features command execution over Named Pipes for discreet operations, a user-friendly interface, and a variety of integrated modules for tasks such as keylogging and Kerberos ticket dumping. The tool is designed for research and authorized testing, emphasizing user responsibility in compliance with legal regulations.
2026-08-03
Shell
★ 378
Bug-Bounty-Agents provides a collection of specialized AI agent prompts designed for enhancing bug bounty hunting, penetration testing, and offensive security workflows. This tool enables users to deploy focused, production-ready agent personas into various agent-capable LLM clients such as Claude Code, GitHub Copilot Chat, and Cursor, facilitating tasks like reconnaissance, web application testing, and exploit planning without any additional framework dependencies. Notable features include strict scope enforcement and a diverse catalog of 43 agents tailored for different engagement phases, enabling efficient and targeted security assessments.
2026-08-03
★ 27
BugBountyData is a repository that compiles a list of public bug bounty programs and responsible disclosure initiatives, accessible through a user-friendly web interface. Its primary use case is to facilitate easy exploration of various bug bounty opportunities for cybersecurity researchers. Notable features include an unfiltered list of subdomains with guidelines on how to filter domains based on organizational policies, enhancing clarity and usability for participants.
2026-08-03
Python
★ 16
dnsspider is an asynchronous, multithreaded tool designed for brute-forcing subdomains using either a specified wordlist or character permutations. Its primary use case is to discover subdomains of a target domain quickly, allowing for various attack types, including dictionary-based or brute-force methods. Notable features include customizable character sets, the ability to query multiple DNS record types, and options for logging results in different formats, making it versatile for reconnaissance purposes in cybersecurity assessments.
2026-08-03
Python
★ 373
gpoParser is a tool that facilitates the extraction and analysis of Group Policy Object (GPO) configurations in Active Directory environments. It supports both local and remote parsing modes, allowing users to gather GPO information via LDAP connections or from offline SYSVOL data, and includes features for displaying parsed results and enriching BloodHound data. Noteworthy capabilities include various operational modes such as local parsing, remote LDAP access, querying results, and the ability to handle security-related analysis, making it valuable for identifying potentially risky configurations.
2026-08-03
Python
★ 27
LazarusWakeUp is a Python-based tool designed for reconnaissance and management of disabled Active Directory (AD) principals, enabling users to find, enable, disable, and analyze these accounts. Its notable features include the ability to operate over LDAPS for secure communications, verbosity options for output detail, and batch operation capabilities to streamline account management tasks. This tool is intended for educational purposes and emphasizes lawful usage.
2026-08-03
C++
★ 45
Maliketh is a multi-user, customizable command and control (C2) framework designed to be flexible for operators. It features cross-platform support through its initial C++ and Golang implants, allowing for behavior modification based on server configurations, file operations, command execution, and self-destruct capabilities, among others. Notable functionalities include basic anti-debugging measures and a range of file management operations, making it suitable for diverse operational scenarios.
2026-08-03
Go
★ 25
OpenShell is an open-source reverse shell management server developed in Go, enabling users to establish and manage reverse shell connections through a web-based graphical user interface. Its primary use case is for educational and research purposes in cybersecurity, featuring a lightweight server architecture, WebSocket interaction, and support for multiple terminal tabs within the GUI. Notable features include easy command generation for reverse shells, session management, and an emphasis on security practices through the use of certificates.
2026-08-03
Dockerfile
★ 178
The pentesting-dockerfiles repository provides a collection of Dockerized tools designed for conducting security assessments. Its primary use case is to facilitate penetration testing by leveraging various security tools, including vulnerability scanners and exploitation frameworks, all encapsulated in lightweight containers to optimize efficiency. Notable features include a curated list of links to popular security tools and payloads, promoting seamless integration within pentesting workflows.
2026-08-03
★ 81
The Pentesting-Mind-Map repository offers a structured mind map that consolidates tools and methodologies essential for bug bounty hunting and penetration testing. It covers key phases such as reconnaissance, exploitation, and red teaming tactics, including automation tools and API testing, making it a valuable resource for professionals seeking to enhance their offensive security skills. Notably, it emphasizes the inclusion of OWASP guidelines for web application testing and provides detailed steps for each phase of the penetration testing lifecycle.
2026-08-03
Python
★ 22
Phantom Whisper is a Python 3 framework designed for ethical penetration testing, specifically targeting WhatsApp by delivering a zero-click WebP payload to identified devices. Its key features include ASLR leak polling to confirm initial compromise, automated deployment of a full implant for either iOS or Android, and thorough logging of all actions in JSON format for audit purposes. The tool is currently structured for single-host execution but is intended to support multi-threaded operations in future developments.
2026-08-03
Python
★ 175
Preferred Network List Sniffer (PNLS) is a Red Team Wi-Fi auditing tool designed to capture SSIDs from a device's preferred network list by intercepting Probe Requests in the surrounding environment. The tool features a user-friendly web interface for visualizing the intercepted data and is focused on exploring the privacy implications associated with Wi-Fi communication. Noteworthy functionalities include compatibility with Raspberry Pi, the ability to filter SSIDs, and the provision for asynchronous server communication using WebSockets.
2026-08-03
Batchfile
★ 246
Ixve/Red-Team-Tools is a comprehensive collection of cracked red teaming tools designed for penetration testing and security assessments, including C2 frameworks, exploitation toolkits, and web application security tools. Users are strongly advised to run these tools in a virtual machine environment due to potential malware risks. Notable features include a wide variety of tools for both Windows and Linux platforms, along with recommended online sandboxing solutions for safe testing.
2026-08-03
Python
★ 11
The Largo-m/security-tools-hacking is a modular Windows penetration testing framework designed for security professionals, facilitating various stages of red team operations such as reconnaissance, exploitation, and post-exploitation. Key features include system information collection, geolocation lookup, browser history extraction, and optional key logging, all presented in a user-friendly manner that allows for easy integration and extension of custom modules.
2026-08-03
Python
★ 44
SquidNet is a Python-based botnet framework designed for educational and ethical testing, enabling users to establish communication with a remote victim, issue commands, and execute various modules. Notable features include multi-session handling, a reverse shell, modular design for extensibility, dynamic module loading, and encryption for evading detection. The tool supports Docker deployment and operates entirely in memory, minimizing the risk of detection on target systems.
2026-08-03
Python
★ 17
SYSTEMatic is a proof-of-concept tool designed for Windows that enables privilege escalation from a local Administrator account to the NT AUTHORITY\SYSTEM account via token impersonation, without UAC prompts or external dependencies. It leverages the Win32 API to duplicate a SYSTEM process's token and spawn new processes, making it valuable for system administration, security research, and penetration testing tasks. Notably, it operates solely within the constraints of existing Administrator privileges and does not exploit vulnerabilities or function as a UAC bypass.
2026-08-03
Go
★ 168
Turbo-attack is a pentesting tool designed to generate random network traffic with variable MAC and IP addresses, enhancing testing capabilities for network resilience against traffic-based attacks. It supports both IPv4 and IPv6 on various Linux architectures (ARM64 and AMD64), and is optimized for environments such as Kali Linux using native syscalls for improved performance. This tool is intended for educational use and emphasizes responsible usage to prevent unauthorized access to networks.
2026-08-03
★ 246
The Offensive AI Agentic Landscape project is a comprehensive catalog of resources focused on AI-driven penetration testing and autonomous red-team agents. It offers an extensive compilation of open-source projects, specialized models, skills, MCP servers, academic papers, benchmarks, and commercial solutions, providing researchers and security professionals with a holistic view of the offensive AI domain. Key features include a curated list of popular agents and tools, with a focus on leveraging AI for offensive security operations.
2026-08-03
Python
★ 95
BeaconatorC2 is a modular communication and management application designed to facilitate the deployment and operation of beacons in restrictive programming environments, particularly for EDR evasion tactics. The tool supports various beacon implementations and allows users to quickly configure receivers, execute commands, and integrate with Metasploit for enhanced capabilities. Notable features include a user-friendly GUI, support for multiple communication protocols, and extensibility through custom beacon schemas.
2026-08-03
Python
★ 12
BugBounty Arsenal is a comprehensive, full-stack security scanning platform designed for bug bounty hunters and security researchers. It features over 50 detectors for various vulnerabilities across multiple categories, continuous monitoring with scheduled scans, findings triage to manage results over time, and CI/CD integration to automate security checks in development pipelines. Unique capabilities include attack surface management, tailored AI-driven remediation advice, and extensive reporting options, all from a centralized dashboard.
2026-08-03
C
★ 388
COM-Hunter is a COM hijacking persistence tool designed for both educational purposes and red teaming applications, offering functionality in .NET and as a Cobalt Strike compatible BOF variant. Its notable features include multiple modes for establishing or removing COM hijacking persistence mechanisms, such as searching for CLSIDs, executing classic persistence, and utilizing Task Scheduler. This versatile tool assists security professionals in simulating advanced persistence techniques within Windows environments.
2026-08-03
Java
★ 39
EgnakeRAT is an advanced remote administration tool (RAT) designed for authorized penetration testing and red team operations on Android devices. It features a fully asynchronous command and control (C2) server utilizing AES-256-CBC encryption for secure communications, along with a real-time web dashboard for device management and various tactical modules such as remote shell access and keylogging. Its use of a length-prefixed JSON protocol and automatic reconnection handling enhances its performance and user experience, making it a robust solution for security researchers.
2026-08-03
PowerShell
★ 141
The "exchange-penetration-testing" tool provides a comprehensive framework for performing penetration tests on Microsoft Exchange servers. It facilitates reconnaissance, brute-force attacks, and exploitation of vulnerabilities such as ProxyLogon and ProxyShell, alongside automated enumeration of the Global Address List (GAL). Notable features include the ability to conduct password spraying and provide access to critical vulnerabilities, enabling security professionals to assess and strengthen Exchange server defenses effectively.
2026-08-03
C
★ 11
ExploitHawk is a terminal-based exploit search tool tailored for ethical hacking and red team operations on Linux distributions. It offers features such as fast multi-threaded searches through local databases, customizable name and version querying, a user-friendly ncurses interface, and clipboard integration for easy result management. The tool is primarily designed to enhance safe testing for users with permissions on systems while requiring a local copy of Exploit-DB for functionality.
2026-08-03
Python
★ 14
Gamal is a lightweight Flask application designed for red teamers and pentesters, facilitating mass data exfiltration and various attacks such as SSRF, XXE, and XSS. It features file delivery capabilities, where users can upload and categorize payloads for exploitation, and includes a helper script that automates the download of common penetration testing tools. The tool supports features like customizable logging, SSL configuration, and can handle uploads while associating files with user and host identifiers for better tracking.
2026-08-03
Python
★ 27
GhostBuilder is a multifunctional payload generation tool that enables the creation of payloads for various platforms, including Android, Windows, Linux, macOS, and iOS, utilizing Metasploit. It features capabilities such as injecting payloads into existing APK files, automatic signing, zipaligning for APKs, and a simple menu-driven interface for ease of use. Designed for ethical hacking and penetration testing, it incorporates automatic handling of dependencies and bad characters, making it suitable for security research and authorized security work.
2026-08-03
★ 101
Kali-pentest is a sophisticated penetration testing tool designed for AI agents, leveraging Kali Linux and enabling autonomous attack planning and execution. It consolidates 269 command-line tools across various categories, features built-in coverage matrices, and employs zero-findings fallbacks along with human approval gates for high-risk actions, ensuring comprehensive and ethical testing processes. By connecting to environments via SSH or Docker, this tool adapts its strategies based on target assessments and generates structured reports for clarity and compliance.
2026-08-03
Python
★ 14
ldapviewer is a tool designed for converting LDAP and Active Directory JSON exports into a modern, interactive web-based interface that enhances the penetration testing process. It features comprehensive views of LDAP attributes, an advanced filtering system for significant data, a statistics dashboard focusing on security metrics, and the ability to parse DACLs directly from JSON dumps, streamlining the analysis of potential attack paths without requiring additional queries.
2026-08-03
Go
★ 17
LLMrecon is an advanced security testing framework specifically designed to identify and exploit vulnerabilities in Large Language Models (LLMs), adhering to the OWASP Top 10 2025 guidelines. It features a variety of novel attack techniques such as FlipAttack and DrAttack, along with machine learning-optimized attack selection, comprehensive defense detection capabilities, and support for testing models from multiple platforms, making it suitable for enterprise-level deployment.
2026-08-03
Python
★ 36
The Neo C2 Framework is a modular post-exploitation framework designed for red team operations and security testing, facilitating collaborative agent management through a server-client architecture. It features real-time multiplayer capabilities, proxy support, a sophisticated task orchestrator, and robust security measures including encrypted communication and role-based access control. Neo also allows for extensive customization through its multi-operator extension module system, enabling operators to integrate their own modules seamlessly.
2026-08-03
Nix
★ 407
The Nix Security Box is a curated collection of penetration testing and information security tools specifically designed for NixOS environments. It emphasizes a practical selection of actively maintained tools, combining both established and innovative options for security assessments, while allowing users to customize their toolset via Nix configuration files or shell environments. Notable features include modular imports for specific categories of tools and the ability to seamlessly create tailored development environments with desired functionalities.
2026-08-03
Python
★ 164
ProfileHound is a post-escalation tool designed for red-teaming operations that identifies domain user profiles on machines to optimize targeting for data extraction. It utilizes BloodHound's OpenGraph format to create a new edge, `HasUserProfile`, which indicates the existence of user profiles and provides metadata such as creation and modification dates, enabling operators to focus on high-value targets without requiring an active user session. The tool highlights profiles that may contain critical information, including cached credentials and other sensitive data, making it particularly useful in contemporary Active Directory environments.
2026-08-03
Python
★ 122
RedTeam Agent is an autonomous AI-powered simulation tool designed for red teaming and penetration testing, streamlining the process of security assessments across multi-platform environments. It features 8 specialized AI agents that facilitate a comprehensive 5-phase attack methodology, alongside containerized Kali tools and a web-based GUI for managing projects and operations with minimal user interaction. Notable functionalities include an intelligent case collection pipeline and robust reporting mechanisms, allowing users to efficiently conduct security evaluations and automate repetitive tasks.
2026-08-03
PowerShell
★ 56
RTI-Toolkit is an open-source PowerShell toolkit designed for executing and defending against Remote Template Injection (RTI) attacks in Microsoft Office documents, specifically DOCX files. It features key cmdlets such as `Invoke-Template` and `Invoke-Regular`, which facilitate the implementation of malicious remote template links, while `Invoke-Identify` assists in detecting such links, positioning the toolkit as both an offensive and defensive resource in the cybersecurity landscape. Notably, the tool is referenced in the NIST National Vulnerability Database under multiple CVEs, underscoring its significance in addressing this type of vulnerability.
2026-08-03
Python
★ 176
Zypheron CLI is an AI-native command-line interface designed for offensive security operations, offering integrated workflows for reconnaissance, scanning, and task automation. Notable features include a Go-based CLI, AI model integration from both local and hosted sources, and robust local storage for session data, making it suitable for authorized security testing and operator workflows. This open-source tool emphasizes terminal agility, maintaining practicality over disconnected scripts or raw outputs.
2026-08-03
Python
★ 103
ADPathFinder is a specialized attack mapping tool designed for penetration testers and red teamers, enabling the analysis of SharpHound data in conjunction with OpenGraph plugins to identify potential attack pathways to critical targets within Active Directory (AD) environments. It supports a variety of data sources, including MSSQLHound and ConfigManBearPig, facilitating comprehensive audits across AD, Active Directory Certificate Services (ADCS), System Center Configuration Manager (SCCM), and SQL Server. Notable features include the ability to map escalation paths, detect weak passwords, and generate detailed reports on vulnerabilities within the network.
2026-08-03
Python
★ 21
The "Awesome Hacking with AI" repository is a comprehensive resource that explores the integration of Artificial Intelligence in offensive security practices, such as penetration testing and red teaming. It features a curated collection of AI-driven tools, methodologies, and case studies while emphasizing ethical considerations in their application. Notable features include a learning roadmap, prompt libraries for various tasks (e.g., payload generation and OSINT profiling), and advanced tactics like AI-powered malware development and botnet exploitation.
2026-08-03
Python
★ 17
Blood-Web is a modular honeypot system designed for penetration testing training and network attack detection, implemented in Python 3.8+ with zero dependencies. It features multiple honeypot services, including SSH, FTP, HTTP, and others, each configurable via command line flags, along with a real-time web dashboard for monitoring attack statistics and trends. The tool is designed to run on non-privileged ports by default, enabling easy deployment without additional setup.
2026-08-03
Python
★ 2468
Cairn is a general-purpose problem-solving engine designed for AI-driven penetration testing and exploration of various state spaces. It utilizes a Blackboard Architecture with a fact-intent graph to dynamically search for paths from a defined origin to a goal, enabling versatile applications such as vulnerability research and CTF challenges. Key features include agent-based coordination through stigmergy, adaptable task generation, and real-time updates to the shared knowledge graph.
2026-08-03
Go
★ 3632
Cariddi is a domain crawling and scanning tool designed to identify sensitive information such as endpoints, secrets, API keys, and various file extensions from a list of provided URLs. Notable features include intensive crawling of subdomains, options for hunting specific secrets and errors, and customizable scanning parameters, making it particularly useful for penetration testing and bug bounty hunting. The tool can be easily installed across various platforms, supporting both single-target and bulk scanning configurations.
2026-08-03
★ 94
Cloud is a cybersecurity tool designed for monitoring and collecting SSL certificate data from major cloud service providers, specifically AWS EC2 and GCP. Its primary use case is to assist security researchers in enumerating subdomains, domains of target companies, and performing IP lookups, with daily updates to the dataset ensuring relevance and timeliness. Notable features include the ability to discover origin IP addresses behind security proxies and the organization of data into structured CSV files for easy access and analysis.
2026-08-03
Python
★ 14
CyberBox is a hardened Docker sandbox designed for bug bounty and offensive security research, providing a secure environment with a comprehensive assortment of over 160 security tools. It features keyless signing with cosign, a complete Software Bill of Materials (SBOM), and SLSA build provenance to ensure trust and integrity throughout the supply chain, while also integrating AI analysis and an autonomous workflow for security tasks. Moreover, it seamlessly supports the Caido framework, offering a plugin manager and various utilities to enhance the research process.
2026-08-03
Python
★ 32
EmbedXPL-Forge is an open-source exploitation and scanning framework designed for security assessments of embedded and perimeter devices including routers, switches, IoT devices, and printers. It features over 2800 modules encompassing various attack vectors such as credential testing, vulnerability exploitation, and firmware manipulation, alongside an extensive library of 700+ mapped CVEs across 114+ vendors, along with an APT Group Attack Engine for simulating real-world cyber attack scenarios.
2026-08-03
Python
★ 639
GTFONow is a Python-based tool designed for automatic privilege escalation on Unix systems by exploiting misconfigured setuid/setgid binaries, capabilities, and sudo permissions. With a focus on usability for both CTF challenges and real-world pentesting scenarios, it offers various automated exploitation techniques, including file read/write primitives and SSH key theft. The tool is lightweight, compatible with multiple Unix variants, and requires no third-party dependencies, making it easy to deploy via a single script.
2026-08-03
★ 22
The HTB / THM / OSCP Master Penetration Testing Checklist is a comprehensive, modular framework designed to guide penetration testers through the phases of engaging with Hack The Box, TryHackMe, and OSCP-level machines. Key features include structured sections from setup and reconnaissance through exploitation and post-exploitation activities, as well as a quick reference for tools, commands, and troubleshooting. This checklist serves as a valuable resource for both beginners and intermediate practitioners in the penetration testing field.
2026-08-03
Python
★ 36
httpgrep is a high-performance asynchronous Python tool designed to scan HTTP(S) servers and search for specific strings or regex patterns within HTTP response bodies and headers. It supports a variety of input formats for target hosts, parallel scanning of multiple ports, and advanced features, including live match streaming, log file outputs in multiple formats, and the ability to resume interrupted scans, making it suitable for extensive network assessments. The tool is built for efficiency with an async core capable of handling thousands of concurrent connections while implementing intelligent timeout and port preflight mechanisms.
2026-08-03
Python
★ 37
Kumo is an OSINT and security reconnaissance framework that enables the analysis of a target domain via a single command, leveraging 26 parallel modules to deliver comprehensive results in real-time. Key features include extensive checks on DNS records, email security, open ports, leaked credentials, and malware associations, as well as a user-friendly web interface and fast scanning options. This tool is ideal for security professionals conducting thorough assessments of domain-related vulnerabilities and exposures without the need for API keys.
2026-08-03
Python
★ 28
MoMo is a modular wireless security audit platform specifically designed for Red Teams, penetration testers, and security researchers, operating on Raspberry Pi 5. It integrates various advanced features such as multi-radio management, real-time data synchronization with a central hub, and comprehensive tools for WPA2/WPA3 attacks, credential harvesting, and automation in a single extensible solution. Notable functionalities include an auto-pwn engine, GPS wardriving capabilities, and support for social engineering techniques, making it a versatile tool for wireless security assessments.
2026-08-03
Python
★ 13
NullSec Red Team AI is a highly specialized offensive security toolkit designed for red team operations, integrating seamlessly with Claude Desktop through the Model Context Protocol (MCP). This hardened version features a robust Flask orchestration server managing over 150 offensive security tools, a sandbox for AI vulnerability testing, and a self-healing diagnostic utility for system integrity. Its architecture enables high-speed workflows for reconnaissance, vulnerability research, and advanced exploitation simulations, making it ideal for professional security assessments.
2026-08-03
TypeScript
★ 223
OctoC2 is a GitHub-native command-and-control framework designed for authorized cybersecurity research, featuring encrypted multi-channel transport and resilient failover capabilities. Its architecture includes a TypeScript beacon, a durable controller, a local operator dashboard, and a comprehensive CLI, enabling secure task execution and management via various transport methods. Notable features include the use of GitHub artifacts for task exchange, a signed task protocol, and a focus on least-privilege credentials for robust security during operations.
2026-08-03
C
★ 108
okhi is an open-source keystroke logging implant designed for integration into USB and PS2 keyboards, allowing real-time monitoring of keystrokes via WiFi. It employs an RP2040 microcontroller for data capture and an ESP32-C2 chip for wireless transmission, making it a compact and efficient solution for educational and proof-of-concept purposes. Key features include support for both keyboard types, real-time data access, and a modular design that facilitates easy installation and operation.
2026-08-03
PHP
★ 740
The Pentester Guide is a comprehensive resource aimed at penetration testers, providing a curated collection of tools, methodologies, educational materials, and practical labs. It includes sections on certifications, bug bounty platforms, and independent pentesting resources, making it an essential tool for both novice and experienced cybersecurity professionals. Notable features include a detailed roadmap for cybersecurity learning and multiple links to pentesting practice environments.
2026-08-03
HTML
★ 54
RedConsole is an offline, single-file penetration testing tool designed for Red Team operators, OSCP/OSEP preparation, and CTF/HTB engagements. It provides an interactive attack plan generator that automatically fills commands based on target details and adapts as progress is made, while also offering features like recon autopilot, credential reuse matrix, and playbook builder for streamlined execution. Its core advantage lies in its ability to run in any browser without requiring installation or internet access, making it suitable for various environments, including locked-down VMs and air-gapped systems.
2026-08-03
Python
★ 164
`pwneye` is an offensive security tool designed for interacting with IP cameras that support ONVIF and RTSP protocols, streamlining various tasks such as discovery, authentication testing, metadata collection, and stream validation through a single command-line interface. Notable features include multithreaded bruteforce attacks for credential guessing, ONVIF device enumeration, RTSP stream handling, and a dedicated live preview client, all aimed at facilitating security assessments of surveillance systems.
2026-08-03
HTML
★ 30
RRW (Rick Roll WiFi) is a prank tool that sets up a rogue access point designed to capture captive portal probes and serve a fake Wi-Fi login page that redirects connected devices to a rickroll video. It utilizes standard network utilities like `hostapd`, `dnsmasq`, and `iptables` to manage the AP and traffic redirection without collecting credentials or intercepting user data, making it a non-malicious tool meant for entertainment. Users can customize the SSID, video, and HTML templates, allowing for tailored rickroll experiences.
2026-08-03
Go
★ 126
RUDY (R-U-Dead-Yet?) is a Denial of Service tool designed for executing low-rate "slow and low" attacks that target web servers by sending long form data in small packets at a slow rate. Its interactive console facilitates user-friendly operation, allowing users to simulate concurrent POST requests with customizable parameters such as request intervals, payload sizes, and the ability to use a TOR proxy for anonymity. This tool is primarily intended for educational and testing purposes to analyze server behavior under resource-saturation attacks.
2026-08-03
C
★ 25
SKELETONKEY is a comprehensive Linux local privilege escalation (LPE) tool that consolidates 46 modules targeting 41 distinct CVEs from 2016 to 2026, offering both red team and blue team functionalities. It features verified exploits, automatic module selection based on safety, detection rules for security audit logging, and a scanning capability for system administrators to identify unpatched vulnerabilities. This tool is designed for authorized testing only, ensuring ethical hacking practices while providing robust functionality for pentesters and system administrators alike.
2026-08-03
Shell
★ 163
SQLMutant is a mutation testing tool designed for Red Teams and Bug Bounty Hunters that automates the process of identifying SQL injection vulnerabilities within a specified domain. It leverages tools like Waybackurls, HTTPX, Arjun, and SQLMAP to perform domain enumeration, URL fetching, and SQL injection testing, while providing various fuzzing capabilities for URLs, headers, and form data. Notable features include integration with historical web page archives and aggressive parameter extraction to enhance vulnerability detection.
2026-08-03
Shell
★ 337
TerminatorZ is an Offensive CVE Exploitation Framework specifically designed for red teamers and offensive security professionals, focusing on active exploitation rather than mere vulnerability scanning. It automates reconnaissance across multiple sources, validates live endpoints, and executes 31 deterministic CVE checks, providing real-time feedback with zero false positives and proof-of-concept URLs for confirmed vulnerabilities. With its modular Bash architecture and unique features like asset-type intelligence and production-quality reporting, TerminatorZ streamlines the exploitation process for faster and more credible results.
2026-08-03
Go
★ 24
urlX is a high-performance reconnaissance tool for bug bounty hunters, penetration testers, and security researchers, facilitating passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling for hidden endpoints. Its key features include smart file and extension filtering, concurrent processing using Go routines, and optional integration with various API keys to enhance results. Designed for swift and effective attack surface identification, urlX requires minimal setup and is built for real-world reconnaissance workflows.
2026-08-03
★ 101
The Wireless Security & WiFi Penetration Testing course offers an advanced, lab-driven educational experience aimed at mastering wireless security testing and attack techniques against Wi-Fi networks. It covers a comprehensive range of topics including 802.11 standards, encryption methods, various cracking techniques, and wireless penetration testing methodologies, all delivered through practical, hands-on labs. Noteworthy features include configuration guidance for wireless adapters, ethical attack methodologies, and a focus on both offensive and defensive strategies, ensuring learners can apply knowledge directly to real-world scenarios.
2026-08-03
Shell
★ 59
Yggdrasil is a cybersecurity tool designed to automate the installation of missing tools and streamline the configuration of Kali Linux following a fresh setup. Its primary use case is enhancing setup efficiency for cybersecurity professionals by providing automation scripts for various cybersecurity tools, alongside features like systemd service monitoring and deployment category additions. Notable features include customizable installation paths, hardening options, and support for multiple programming environments, making it a versatile resource for security practitioners.
2026-08-03
Python
★ 41
AD AutoPwn is a fully automated penetration testing tool that facilitates the compromise of Active Directory environments by chaining over 25 attack techniques, allowing security professionals to conduct authorized assessments effectively. Its notable features include zero-credential attacks for username enumeration and credential harvesting, advanced exploitation methods for privilege escalation, and integration with BloodHound for graph-driven attack chains and actionable insights. The tool leverages techniques such as Kerberoasting, NTLM relay, and various vulnerability exploits to streamline the process of acquiring domain admin access.
2026-08-03
Go
★ 343
AgentHound is an open-source offensive security framework designed for AI agent infrastructures, capable of conducting comprehensive reconnaissance, asset fingerprinting, credential harvesting, model inventorying, and active exploitation. It integrates findings into a Neo4j graph to visualize attack paths, addressing every layer of the agentic stack, including model gateways and inference servers. Notable features include credential inventorying, model inversion capabilities, and the ability to perform active exploitation through tool and instruction poisoning.
2026-08-03
C
★ 29
AL-ANQA-FIRMWARE is an offensive security firmware designed for the LilyGo T-Deck, transforming it into a portable pentesting terminal equipped with over 60 integrated WiFi, Bluetooth, network, and radio tools. Key features include on-device WiFi attack capabilities, a comprehensive Bluetooth LE security audit suite, an interactive SSH client, and tools for wardriving and device monitoring—all operational without the need for additional PCs or GUIs, ensuring a self-contained and efficient testing environment.
2026-08-03
★ 16
Awesome AI Pentesting is a curated repository of AI-powered tools, frameworks, and resources designed for penetration testing, bug bounty hunting, and cybersecurity operations. It features a wide range of autonomous agents capable of executing end-to-end security assessments, leveraging large language models and machine learning to identify and exploit vulnerabilities in various environments. Notable tools include fully autonomous agents with high success rates, integrated AI tools for real-time testing, and robust frameworks for orchestrating comprehensive security evaluations.
2026-08-03
★ 166
Awesome Cyber AI Arsenal is a comprehensive collection of over 250 battle-tested offensive, defensive, and AI-powered security tools, organized into distinct categories for Red Team, Blue Team, and AI security applications. This repository facilitates quick access and deployment of security tools, emphasizing responsible usage for authorized testing and education purposes only. Notable features include extensive subcategories tailored for specific security functions, making it an invaluable resource for security professionals.
2026-08-03
PowerShell
★ 79
AzureAttackKit is a comprehensive suite of tools designed for penetration testing and assessments of Azure environments from a Windows machine or Azure Cloud Shell. Its primary use case is to streamline the collection of Azure resources, enabling automated queries and security checks across multiple subscriptions using tools like PowerZure, AzureHound, and AADInternals. Notable features include the ability to quickly pull subscription data, execute targeted scripts for information gathering, and employ regular expressions for searching sensitive information within Azure resource configurations.
2026-08-03
Python
★ 29
Cascavel is an autonomous Continuous Threat Exposure Management (CTEM) engine designed to streamline Red Team operations and validate adversarial exposures. It automates the process of scoping and discovery, prioritizes vulnerabilities with real-time threat intelligence, and employs a robust validation engine to minimize false positives while generating actionable remediation recommendations. Notable features include dynamic mapping of infrastructure, integration with threat databases, and support for various output formats, all engineered to enhance operational efficiency in cybersecurity.
2026-08-03
Python
★ 14675
dirsearch is an advanced web path discovery tool designed for brute-forcing directories and files on web servers. Its primary use case is assisting cybersecurity professionals in identifying hidden resources within a web application, supporting features such as customizable wordlists, recursion, and a Python API for automation. The tool requires Python 3.11 or higher and offers various installation options, including native Rust backend support and pre-built binaries.
2026-08-03
Python
★ 11
EndpointHunter is a bug bounty tool that efficiently extracts various sensitive information, including API endpoints, LFI paths, secrets, and cloud storage URLs, from JavaScript, CSS, and HTML files. Its multi-threaded scanning capability enhances speed, while seamless integration with other recon tools and automated filtering of static assets optimize the reconnaissance process for security researchers. Notable features include smart recon for linked files, noise reduction, and support for output saving and batch processing of multiple URLs.
2026-08-03
C
★ 14
The Flipper Zero IR Signal Generator is a versatile tool designed to generate and emit various infrared signals for security assessments and hardware hacking. It features a user-friendly interface, customizable settings for different signal types, and secure operations to minimize risks, making it accessible even to users with limited technical experience. The tool is compatible with Windows, macOS, and Linux systems, requiring only a Flipper Zero device and a USB connection for operation.
2026-08-03
C#
★ 76
MSSQLand is a C# post-exploitation tool designed for red team operations targeting Microsoft SQL Server (MSSQL) environments. It facilitates linked server traversal, cascading impersonation of logins, and various discovery actions to gather impactful information with minimal operational security footprint. Notable features include automatic execution of linked queries across deep server chains, support for multiple authentication methods, and customizable output formats, enhancing both usability and data presentation in penetration testing scenarios.
2026-08-03
Python
★ 396
The Syslifters OffSec Tools repository provides a curated collection of offensive security tools for penetration testers and red teamers, streamlining the assessment process within internal environments. It regularly compiles and updates tools, allowing users to easily download the latest versions in a single release archive, thereby eliminating the need for individual updates and compilations. Notable tools included range from Active Directory enumeration and privilege escalation tools to credential recovery solutions, catering to various aspects of security assessments.
2026-08-03
Python
★ 114
PassLLM is an advanced framework for targeted password guessing that leverages Personally Identifiable Information (PII) to predict likely passwords, achieving 15% to 45% higher accuracy than existing models. Its notable features include the use of a fine-tuning technique called LoRA for efficient resource management, advanced inference algorithms for optimized guessing, and the capability to harness millions of leaked PII records for training. Designed for high accuracy on consumer hardware, it is straightforward to deploy using Google Colab.
2026-08-03
Python
★ 34
Daethyra's Pentest-References is a comprehensive cybersecurity toolkit that organizes various guides and resources specifically aimed at enhancing penetration testing practices. It features playbooks for internal pentesting, is tailored for both beginners and advanced users, and encompasses tools and strategies for evading detection, exploiting web application vulnerabilities, and understanding Active Directory fundamentals. Notably, it includes extensive documentation on topics like data exfiltration, network enumeration, and persistence techniques on Windows systems, making it a valuable resource for security professionals.
2026-08-03
C#
★ 327
ReconNess is a web application designed to streamline the reconnaissance process for cybersecurity professionals, enabling them to efficiently organize and manage their recon data without requiring extensive scripting skills. Its primary use case is providing continuous recon capabilities through a customizable pipeline of reconnaissance tools that can be triggered based on schedules or events. Notable features include a user-friendly interface, the ability to aggregate data from various agents, and a focus on helping users concentrate on identifying potentially vulnerable targets.
2026-08-03
Python
★ 598
Rekono automates the penetration testing process by integrating multiple hacking tools to streamline tasks such as OSINT, host discovery, and vulnerability scanning. Its notable features include email and Telegram notifications for findings, integration with Defect-Dojo for advanced vulnerability management, and a dedicated Telegram bot to execute tests from any device. This tool aims to enhance a pentester's efficiency by allowing them to focus on analysis rather than repetitive testing tasks.
2026-08-03
Python
★ 159
Roothound is a tool designed for local Linux privilege escalation, providing users with a clear graphical representation of pathways from a low-privilege shell to root access. It features an attack-path graph that illustrates each potential route, confidence coloring to indicate the reliability of paths, and copy-ready abuse commands for user convenience. The tool operates offline, requires no dependencies, and can generate self-contained HTML reports from LinPEAS output, making it suitable for authorized security testing and educational purposes.
2026-08-03
Rust
★ 77
Skewrun is an Active Directory time discovery toolkit designed for red team operations, facilitating the resolution of time discrepancies when executing commands on target systems from a Linux environment. It utilizes various network protocols (CLDAP, SMB, NTP, Kerberos, NTLM) to dynamically fetch the Domain Controller's time, allowing users to circumvent the Kerberos `KRB_AP_ERR_SKEW` error without needing elevated privileges to adjust the system clock. The tool features a library-first architecture for seamless integration into other Rust applications and minimizes forensic traces during operation.
2026-08-03
Python
★ 753
The Big Brother V5.0 is an advanced Open Source Intelligence (OSINT) framework designed for comprehensive reconnaissance on individuals, organizations, or groups. It features a highly interactive holographic dashboard supported by 21 distinct intelligence modules that facilitate deep investigative analysis. The tool allows users to conduct detailed searches and surveillance, enhancing the capabilities for gathering critical data while also offering an exclusive service for more intensive intelligence requirements.
2026-08-03
Python
★ 16
Toboggan is a post-exploitation tool that facilitates a semi-interactive shell on both Linux and Windows targets via Remote Code Execution (RCE) methods. It operates by allowing users to define custom command execution logic through a simple Python interface, enabling interaction with command outputs even in restrictive network environments. Key features include support for Python-based execution modules, an interactive shell with command history, and the ability to establish communications using named pipes when reverse shells are not feasible.
2026-08-03
Rust
★ 28
TriLane is an autonomous gray-box security auditing tool designed for authorized penetration testing on local labs, internal codebases, and bug-bounty targets. It features a staged audit process that includes the construction of an attack-surface graph, a six-lane semantic audit covering various security aspects, and a deduplication mechanism for findings, allowing for a thorough and organized assessment of security vulnerabilities. Notable features include a desktop GUI for tracking the audit process, two operational modes (Safe and Lab), and efficient evidence management for generating comprehensive reports.
2026-08-03
JavaScript
★ 41
4ndr0tools is a collection of userscripts designed to enhance digital sovereignty by countering anti-user web practices and empowering users with control over their browsing experience. Notable features include modular design for customizable implementation, transparent and auditable code, and a focus on anti-platform functionalities that resist modern web manipulations. This suite caters to advanced users and red team engagements, promoting a minimalist and performance-oriented approach to web interactions.
2026-08-03
Shell
★ 27
Weaponize-CobaltStrike is an automated toolkit designed to streamline the setup and configuration of Cobalt Strike, enhancing its capabilities with a wide array of Beacon Object Files (BOFs) and offensive security tools. Key features include the automation of dependency installation and compilation of various community-driven tools, such as the CS-Aggressor-Kit and situational awareness BOFs, making it easier for security professionals to extend their Cobalt Strike operations. This tool aims to facilitate authorized security testing and educational purposes while also providing a platform for contributions and improvements from the community.
2026-08-03
Python
★ 117
WEBFANG v2.0 is a command-line reconnaissance toolkit specifically designed for ethical hacking, enabling users to perform both passive and active reconnaissance through features such as web spidering, subdomain scanning, WHOIS checks, DNS queries, and header fingerprinting. It supports integration with Shodan and URLScan, and is modular in design, allowing for extensions and enhanced output options. Intended for authorized penetration testing and OSINT research, the tool ensures that users maintain compliance with ethical guidelines during usage.
2026-08-03
Python
★ 678
Z3r0 is an open-source red team collaboration workbench designed for authorized penetration testing, vulnerability discovery, and security research. It integrates a React-based console with a FastAPI management layer, allowing users to coordinate multi-Agent sessions, track project-specific evidence, and manage sandbox environments and controlled egress efficiently. Notable features include comprehensive evidence management, detailed workflow tracking, and a session timeline that enhances operational transparency and collaboration among red team participants.
2026-08-03
Python
★ 10
ZIRAN is a comprehensive security testing framework designed to identify vulnerabilities in AI agents, including those with complex capabilities such as tool usage and memory. By modeling agents as graphs of capabilities, it effectively discovers dangerous tool chains, detects execution-level side effects, and conducts adaptive multi-phase campaigns, surpassing the capabilities of single-prompt scanners. Notable features include graph-based analysis, tool-chain discovery, and thorough coverage of established security benchmarks like OWASP and MITRE.
2026-08-03
Rust
★ 89
ADhammer is an Active Directory security-assessment toolkit implemented in Rust that functions as an auditor similar to PingCastle, capable of mapping domain attack paths with scoring, graphing, and MITRE tagging. It performs low-privileged audits via LDAP, validates identified vulnerabilities using live offensive techniques, and supports execution on both Kali Linux and Windows as a single static binary. Notable features include its custom-built DCE/RPC and Kerberos stack, extensive checks across various security categories, and the ability to export findings to BloodHound.
2026-08-03
Python
★ 617
ADscan is a comprehensive Active Directory pentesting tool designed for Linux environments that consolidates 103 attack techniques into a streamlined CLI interface. Its primary use case lies in automating the penetration testing process for red teamers and security professionals, providing capabilities such as enumeration, Kerberoasting, and attack-path analysis without the need for Windows. Notable features include fully automated scans through the 'adscan ci' command, which allows for both authenticated and unauthenticated assessments while leveraging Docker for its operational environment.
2026-08-03
Python
★ 3936
Claude-BugHunter is a comprehensive skill bundle for the Claude Code system, designed to enhance bug-hunting and red-team operations with 82 curated skills and 15 commands. It features a structured approach to vulnerability detection, engagement scaffolding, and automated reporting, drawing from a vast collection of 681 disclosed report patterns across 24 core vulnerability classes. Notably, it integrates with Burp MCP and provides enterprise identity and infrastructure attack matrices for sophisticated security assessments.
2026-08-03
Python
★ 143
Cyber Controller is a versatile application designed for flashing and controlling multiple ESP32 devices through a unified interface, facilitating both firmware installation and real-time management. It supports 50 firmware profiles and can operate over various interfaces, making it suitable for authorized security testing and educational purposes. Key features include simultaneous commands for multiple devices, anti-bricking safeguards, and compatibility with touchscreens or headless setups, enhancing user experience in cyberdeck operations.
2026-08-03
Python
★ 18
The h4cker_b00k repository is a comprehensive guide aimed at providing detailed Capture The Flag (CTF) write-ups and insights into ethical hacking practices. It serves as a valuable resource for both beginners and experienced cybersecurity professionals, featuring practical knowledge, techniques, and solutions to enhance skills within the field. Notable features include categorized content for generic tools, initiation into hacking, and advanced hacking topics, facilitating structured learning and community contribution.
2026-08-03
Python
★ 464
HackAgent is a Python-based SDK and CLI tool designed to automate the security testing of AI agents, specifically targeting vulnerabilities such as prompt injection, jailbreaking, goal hijacking, and tool misuse. It employs a modular architecture featuring an attack engine, generator, and judge to evaluate the robustness of AI agents against research-backed attack techniques, enabling security researchers and developers to proactively identify and mitigate potential exploits. Additionally, HackAgent offers a standalone binary for varied platforms, eliminating the need for a Python environment, which enhances accessibility for users.
2026-08-03
Python
★ 186
Information Security Tasks is a collaborative repository that serves as a comprehensive resource for cybersecurity professionals, offering real-world infosec notes and methodologies. It features extensive directories covering offensive and defensive security topics such as penetration testing, incident response, and vulnerability analysis, alongside daily auto-updates of news and tools. Notable elements include an organized structure for various cybersecurity domains, community submission options for resources, and insights into emerging threats like AI and cloud security.
2026-08-03
PowerShell
★ 12
MovementHound is a PowerShell tool designed for active enumeration of lateral movement capabilities in Windows environments, focusing on the effective rights a principal possesses rather than simple group memberships. This approach allows users to identify potential access paths that may be overlooked by traditional enumeration methods, making it particularly effective in environments with modified DACLs and security descriptors. Notable features include integration with BloodHound Legacy for detailed access mapping and a comprehensive output that aids in identifying persistent footholds during security assessments.
2026-08-03
Python
★ 144
NyxStrike is an AI-powered offensive security orchestration engine that streamlines the execution of full attack chains, encompassing reconnaissance, exploitation, and reporting phases in a matter of minutes. Notable features include the ability to control over 185 offensive security tools through AI agents, a modular tool registry for easy customization, and compatibility with various AI clients via the MCP framework, all while providing a real-time session dashboard for monitoring and management.
2026-08-03
HTML
★ 31
OSCP+ Complete Exam Checklist & Attack Chains (2025-26) is a comprehensive resource designed to aid candidates in navigating the OSCP exam format, emphasizing techniques for enumeration, exploitation, and lateral movement within a simulated environment. It offers structured methodologies for tackling Active Directory and standalone systems, alongside practical strategies for efficient time management during the exam. Notable features include a universal enumeration framework, a detailed breakdown of point allocation, and specific attack chains related to various scenarios, ensuring candidates are well-prepared for the challenges they will face.
2026-08-03
JavaScript
★ 64
PHANTOM is an AI-powered penetration testing command center designed to autonomously execute a range of security tasks without requiring constant human input. It features real-time tool execution, a multi-agent architecture for parallel processing, and self-improvement capabilities to enhance its toolset over time, all while providing a user-friendly dark UI and persistent context retention across sessions.
2026-08-03
Go
★ 12
Rosemary is a cross-platform tool for transparent network pivoting and tunneling over QUIC, enabling seamless traffic interception on remote hosts without the need for proxies or special configurations. Its key features include kernel-level interception of TCP, UDP, ICMP, and DNS traffic, a comprehensive web dashboard for real-time monitoring, and support for multi-hop connections through multiple agents. This tool is designed for scenarios where secure and efficient access to remote networks is required without altering client configurations.
2026-08-03
Python
★ 90696
Hunt down social media accounts by username across social networks
2026-08-03
C
★ 97
Specter transforms the Flipper Zero into a sophisticated counter-surveillance tool designed for detecting active 13.56 MHz NFC readers. This tool passively listens for RF emissions from hidden skimmers or covert readers, providing real-time feedback on the presence and type of detected devices, as well as the cleanliness of the environment. Notable features include an analog EMF gauge for proximity detection, a fingerprinting capability to classify the type of NFC reader, and the ability to log and monitor over time, enhancing situational awareness for security professionals.
2026-08-03
Go
★ 268
aiscan is an AI-driven penetration testing tool that integrates traditional security scanning with large language model (LLM) capabilities. It operates in three primary modes: a deterministic scanning pipeline, an autonomous natural language assessment agent, and multi-agent distributed collaboration for comprehensive security evaluations. Notable features include a single-binary architecture, a web console for management, and support for both standard and full editions that offer additional reconnaissance capabilities.
2026-08-03
Python
★ 61
CyberDeck is a terminal-based penetration testing command dictionary and cookbook designed for information security professionals, featuring a sci-fi CRT aesthetic. Its primary use case is to provide quick access to organized commands and multi-command playbooks across various phases of penetration testing, enhanced by a dynamic command database and full-text search capabilities. Notable features include customizable interfaces, clipboard integration for instant command copying, and fallback CLI functionality for environments lacking a `curses` interface.
2026-08-03
Python
★ 880
DarkMoon is an open-source, AI-powered autonomous penetration testing platform designed to conduct end-to-end security assessments without manual intervention. Notable features include a privacy gateway that ensures sensitive data remains secure, integration with over 50 pen-testing tools, and automated vulnerability reporting. This tool is particularly advantageous for security teams and DevSecOps engineers seeking to streamline and scale their defensive operations while maintaining strict data sovereignty.
2026-08-03
Shell
★ 116
Hacknetics is a comprehensive resource repository designed for OSCP students and Red Teaming professionals, offering a curated collection of code snippets, guides, and pentesting tools. Notable features include ready-to-use code in multiple programming languages, high-level strategies, step-by-step guides, and regular updates to ensure access to the latest techniques and tools essential for penetration testing.
2026-08-03
Python
★ 131
Humanbound is an open-source adversarial testing engine designed specifically for AI agents, enabling users to simulate realistic user interactions and potential attacks through live endpoints and multi-turn conversations. Its notable features include the ability to transform test failures into deployable firewall rules and compatibility with both local environments and the Humanbound Platform, making it straightforward to initiate tests without authentication. The tool also supports various integration options, allowing for flexible deployment and configuration.
2026-08-03
TypeScript
★ 24697
Promptfoo is a command-line interface (CLI) and library designed for evaluating and red-teaming large language model (LLM) applications. Its primary use case involves automated testing of prompts, vulnerability scanning, and model comparison, enabling developers to enhance security and reliability in their AI applications while running evaluations locally without exposing data. Notable features include integration with CI/CD workflows, comprehensive security reporting, and support for multiple LLM providers, allowing for a developer-centric, flexible, and data-driven approach to AI application development.
2026-08-03
Python
★ 13
RCEKit is a Python-based toolkit designed for the detection and confirmation of remote code execution (RCE) vulnerabilities, specifically for authorized penetration testing and security research. It provides a robust CLI interface to assess targets by employing multiple verification methods against real-world CVEs, generating definitive "confirmed" verdicts that can be utilized in security reports. Noteworthy features include support for various RCE classes, an easy-to-use setup without third-party dependencies, and the ability to produce evidence-based results, ensuring accurate detection rather than mere conjecture.
2026-03-30
Python
★ 762
C2 Tracker is a community-driven IOC feed that aggregates IP addresses related to known malware, botnets, and command-and-control (C2) infrastructures by leveraging searches from platforms like Shodan. Its primary use case is to facilitate threat intelligence by providing a regularly updated feed that can be ingested by various SIEM and EDR systems, enhancing detection and investigation capabilities. Notable features include version-controlled historical data, weekly updates, and compatibility with tools like OpenCTI and FortinetSIEM for streamlined integration and alerting.
2026-03-30
Go
★ 728
DllShimmer is a tool designed to facilitate DLL hijacking by allowing users to backdoor any function in a DLL without disrupting the normal operation of the host program. It generates proxy DLLs through a boilerplate C++ file and a corresponding .def file, ensuring that all exported functions maintain their original names and ordinal numbers, thus avoiding detection. Key features include support for both dynamic and static linking, the option to prevent multiple executions of the backdoor, and comprehensive debug logging capabilities.
2026-03-30
Python
★ 738
EmailAll is a powerful email collection tool designed to aggregate email addresses from various online sources, including search engines and datasets. Its primary use case is to support cybersecurity professionals in gathering emails for domain reconnaissance, and it features integration with multiple API services for data retrieval along with modular results storage in JSON format. The tool allows easy configuration for proxies and APIs, enhancing its flexibility for various deployment environments.
2026-03-30
Python
★ 890
EvilWAF is a sophisticated transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing purposes. It operates at the transport layer, allowing seamless integration with various security tools while employing advanced techniques such as TCP and TLS fingerprint rotation, source port manipulation, and automated WAF detection to evade defensive mechanisms. Notable features include a comprehensive multi-layer WAF scanning capability, direct origin bypass, and a robust IP rotation strategy through Tor and proxy pools, ensuring effective assessment of firewall vulnerabilities.
2026-03-30
Rust
★ 712
Heroinn is a cross-platform command-and-control (C2) and post-exploitation framework developed in Rust, designed primarily for research and educational purposes. Notable features include a graphical user interface (GUI), an interactive PTY shell, system information collection, file management with support for large files and resuming broken transfers, and compatibility with multiple operating systems including Windows, Linux, BSD, and macOS, leveraging various communication protocols such as TCP, HTTP, and reliable UDP.
2026-03-30
Python
★ 750
Spoofy is a Python-based tool designed to evaluate the spoofability of domains by analyzing their SPF and DMARC records. It features authoritative lookups with a known DNS fallback, accurate bulk processing, and a customizable spoof logic derived from real-world testing, enabling users to conduct comprehensive assessments of domain security configurations. Additionally, Spoofy offers DKIM selector enumeration via API as an optional feature, making it a valuable resource for cybersecurity assessments.
2026-03-30
★ 806
Web Hacking is a comprehensive repository of notes focused on bug bounty hunting and penetration testing, collating various techniques for vulnerability discovery and exploitation. The tool features extensive reconnaissance and OSINT methods, a detailed list of common vulnerabilities, and bypass techniques, making it a valuable resource for security professionals seeking to enhance their skills and methodologies in web application security. Additionally, it encourages community contributions, fostering continuous improvement and updates of its content.
2026-03-22
C++
★ 5651
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
2026-03-22
★ 1933
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
2026-03-22
HTML
★ 1079
Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.
2026-03-22
Go
★ 4375
A Security Tool for Bug Bounty, Pentest and Red Teaming.
2026-03-22
Python
★ 929
A security scanner for your LLM agentic workflows
2026-03-22
C#
★ 1529
Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources
2026-03-22
Python
★ 6090
A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
2026-03-22
Python
★ 31783
734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0
2026-03-22
★ 973
A curated list of tools officially presented at Black Hat events
2026-03-22
★ 4079
A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
2026-03-22
Shell
★ 11108
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
2026-03-22
★ 902
🦄🔒 Awesome list of secrets in environment variables 🖥️
2026-03-22
★ 3448
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
2026-03-22
Shell
★ 2269
OSINT tools for Information gathering, Cybersecurity, Reverse searching, bugbounty, trust and safety, red team oprations and more.
2026-03-22
★ 2184
RAT And C&C Resources. 250+ Open Source Projects, 1200+ RAT/C&C blog/video.
2026-03-22
Python
★ 4320
一个攻防知识库。A knowledge base for red teaming and offensive security.
2026-03-22
★ 1268
Red Team Cheatsheet in constant expansion.
2026-03-22
Python
★ 1936
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
2026-03-22
Rust
★ 4394
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
2026-03-22
Shell
★ 3475
An ArchLinux based distribution for penetration testers and security researchers.
2026-03-22
Go
★ 1100
↕️🤫 Stealth redirector for your red team operation security
2026-03-22
Go
★ 2529
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 28 protocols.
2026-03-22
★ 47245
LEAKED SYSTEM PROMPTS FOR CHATGPT, GEMINI, GROK, CLAUDE, PERPLEXITY, CURSOR, DEVIN, REPLIT, AND MORE! - AI SYSTEMS TRANSPARENCY FOR ALL! 👐
2026-03-22
Python
★ 1653
CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection
2026-03-22
Go
★ 1146
Awesome cloud enumerator
2026-03-22
★ 2101
Collection of quality safety articles. Awesome articles.
2026-03-22
Batchfile
★ 1076
Leaked pentesting manuals given to Conti ransomware crooks
2026-03-22
C#
★ 4646
Covenant is a collaborative .NET C2 framework for red teamers.
2026-03-22
HTML
★ 8032
Gather and update all available and newest CVEs with their PoC.
2026-03-22
Java
★ 950
🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
2026-03-22
Vue
★ 1152
DeimosC2 is a Golang command and control framework for post-exploitation.
2026-03-22
Go
★ 1709
DetectDee: Hunt down social media accounts by username, email or phone across social networks.
2026-03-22
Shell
★ 3931
Custom bash scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux.
2026-03-22
Go
★ 2139
Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
2026-03-22
Go
★ 797
去中心化远程控制工具(Decentralized Remote Administration Tool),通过ENS实现了配置文件分发的去中心化,通过Telegram实现了服务端的去中心化
2026-03-22
Python
★ 1035
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
2026-03-22
Python
★ 770
An OSINT tool that helps detect members of a company with leaked credentials
2026-03-22
Go
★ 4264
一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入
2026-03-22
C++
★ 1024
Loading Remote AES Encrypted PE in memory , Decrypted it and run it
2026-03-22
Java
★ 1776
A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.
2026-03-22
C++
★ 787
Anti Forensics Tool For Red Teamers, Used For Erasing Footprints In The Post Exploitation Phase.
2026-03-22
★ 1775
Tips and Tutorials for Bug Bounty and also Penetration Tests.
2026-03-22
Go
★ 1262
Practice Go programming and implement CobaltStrike's Beacon in Go
2026-03-22
C++
★ 810
Deploy stealthy reverse shells using advanced process hollowing with GhostStrike – a C++ tool for ethical hacking and Red Team operations.
2026-03-22
Python
★ 1895
The SpecterOps project management and reporting engine
2026-03-22
Python
★ 2252
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
2026-03-22
Go
★ 1598
🔪 :octocat: Leak git repositories from misconfigured websites
2026-03-22
Go
★ 767
Load shellcode into a new process
2026-03-22
Go
★ 1537
一款适用于红蓝对抗中的仿真钓鱼系统
2026-03-22
★ 1500
Attack surface mapping
2026-03-22
Go
★ 2028
面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams
2026-03-22
Go
★ 3643
🔍 Search anyone's digital footprint across 300+ websites
2026-03-22
YAML
★ 13602
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
2026-03-22
★ 1237
A detailed plan to achieve proficiency in hacking and penetration testing, with pathways including obtaining a degree in cybersecurity or earning relevant certifications.
2026-03-22
★ 1297
A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other notable sources.
2026-03-22
TypeScript
★ 6663
The all-in-one browser extension for offensive security professionals 🛠
2026-03-22
Shell
★ 1114
ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location coordinates an attacker can perform preliminary reconnaissance which will help them in performing further targeted attacks.
2026-03-22
Assembly
★ 1786
Template-Driven AV/EDR Evasion Framework
2026-03-22
CSS
★ 5988
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
2026-03-22
Shell
★ 1603
Asset inventory of over 800 public bug bounty programs.
2026-03-22
TypeScript
★ 772
js cookie逆向利器:js cookie变动监控可视化工具 & js cookie hook打条件断点
2026-03-22
Python
★ 1301
K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动
2026-03-22
Python
★ 817
KawaiiGPT — Open-source LLM gateway accessing DeepSeek, Gemini, and Kimi-K2 through reverse-engineered Pollinations API with no API keys required, built-in prompt injection capabilities for security research, Termux/Linux native support, and Rich console interface
2026-03-22
Go
★ 4257
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
2026-03-22
Go
★ 994
Tool for building Kubernetes attack paths
2026-03-22
HTML
★ 5448
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
2026-03-22
C#
★ 5272
Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange
2026-03-22
★ 1029
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
2026-03-22
Go
★ 4901
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
2026-03-22
YARA
★ 1533
A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabilities.
2026-03-22
Python
★ 1550
🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
2026-03-22
TypeScript
★ 1468
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
2026-03-22
Python
★ 37179
🕵️♂️ Collect a dossier on a person by username from thousands of sites
2026-03-22
Python
★ 4294
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
2026-03-22
★ 952
A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))
2026-03-22
Rust
★ 1490
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.
2026-03-22
★ 770
An extremely effective subdomain enumeration wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.
2026-03-22
Python
★ 5821
The Network Execution Tool
2026-03-22
Rust
★ 1360
NeuroSploit is an advanced, AI-powered penetration testing framework designed to automate and augment various aspects of offensive security operations. Leveraging the capabilities of large language models (LLMs).
2026-03-22
C++
★ 2470
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
2026-03-22
PowerShell
★ 9805
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
2026-03-22
Go
★ 2087
A secure, efficient TCP/UDP tunneling solution that delivers fast, reliable access across network restrictions using pre-established TCP/QUIC/WebSocket or HTTP/2 connections.
2026-03-22
Python
★ 765
Open source pre-operation C2 server based on python and powershell
2026-03-22
★ 1258
OffSec OSINT Pentest/RedTeam Tools
2026-03-22
★ 1169
A Huge Learning Resources with Labs For Offensive Security Players
2026-03-22
★ 935
Offensive Security OSCP+, OSEP, OSWP, OSWA, OSWE, OSED, OSMR, OSEE, OSDA, OSIR, OSTH Exam and Lab Reporting / Note-Taking Tool
2026-03-22
★ 785
An insane list of all dorks taken from everywhere from various different sources.
2026-03-22
HTML
★ 2190
OSINT cheat sheet, list OSINT tools, wiki, dataset, article, book , red team OSINT for hackers and OSINT tips and OSINT branch. This repository will grow every time will research, there is a research, science and technology, tutorial. Please use it wisely.
2026-03-22
C
★ 823
ParadoxiaRat : Native Windows Remote access Tool.
2026-03-22
HTML
★ 7479
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
2026-03-22
PHP
★ 842
Work in progress...
2026-03-22
PowerShell
★ 2915
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
2026-03-22
Python
★ 3025
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
2026-03-22
Python
★ 1055
Perun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架
2026-03-22
Python
★ 2492
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor
2026-03-22
Shell
★ 2098
Homemade Pwnbox :rocket: / Rogue AP :satellite: based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap :bulb:
2026-03-22
Go
★ 1636
:hammer: A modern multiple reverse shell sessions manager written in go
2026-03-22
Python
★ 2357
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
2026-03-22
Python
★ 1207
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
2026-03-22
Python
★ 1179
Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment.
2026-03-22
HCL
★ 923
Automate creating resilient, disposable, secure and agile infrastructure for Red Teams.
2026-03-22
★ 4463
Wiki to collect Red Team infrastructure hardening resources
2026-03-22
★ 10650
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
2026-03-22
Python
★ 2370
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
2026-03-22
PowerShell
★ 1214
RedSnarf is a pen-testing / red-teaming tool for Windows environments
2026-03-22
Java
★ 2569
红蓝对抗以及护网相关工具和资料,内存shellcode(cs+msf)和内存马查杀工具
2026-03-22
★ 9633
Tools and Techniques for Red Team / Penetration Testing
2026-03-22
PowerShell
★ 4682
Red Teaming Tactics and Techniques
2026-03-22
Python
★ 1465
记录自己编写、修改的部分工具
2026-03-22
★ 1047
The most exhaustive list of reliable DNS resolvers.
2026-03-22
Rust
★ 1134
Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀
2026-03-22
Rust
★ 1901
RustRedOps is a repository for advanced Red Team techniques and offensive malware, focused on Rust
2026-03-22
C#
★ 817
Sandman is a NTP based backdoor for hardened networks.
2026-03-22
★ 9023
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
2026-03-22
Go
★ 1634
ServerScan一款使用Golang开发的高并发网络扫描、服务探测工具。
2026-03-22
PowerShell
★ 1314
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.
2026-03-22
C
★ 2168
A post exploitation framework designed to operate covertly on heavily monitored environments
2026-03-22
TypeScript
★ 47370
Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
2026-03-22
Go
★ 1132
An IIS short filename enumeration tool
2026-03-22
Boo
★ 2343
An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR
2026-03-22
Rust
★ 923
Dangerously fast DNS/network/port scanner
2026-03-22
Python
★ 3748
Snoop — инструмент разведки на основе открытых данных (OSINT world)
2026-03-22
Go
★ 996
最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.
2026-03-22
Go
★ 3412
👻Stowaway -- Multi-hop Proxy Tool for pentesters
2026-03-22
C#
★ 954
PoCs and tools for investigation of Windows process execution techniques
2026-03-22
★ 1115
Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描
2026-03-22
Python
★ 17247
E-mails, subdomains and names Harvester - OSINT
2026-03-22
Go
★ 7165
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
2026-03-22
Python
★ 4008
🕵️ (2-in-1) Emaill and Username OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investigations, legitimate analysis
2026-03-22
Ruby
★ 1342
Username tools for penetration testing
2026-03-22
Shell
★ 1961
venom - C2 shellcode generator/compiler/handler
2026-03-22
Go
★ 2152
Venom - A Multi-hop Proxy for Penetration Testers
2026-03-22
Python
★ 4441
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
2026-03-22
★ 5284
Adversary simulation and Red teaming platform with AI
2026-03-22
Shell
★ 1881
lightweight, dependency-free bash script for security, performance auditing and infrastructure monitoring of Linux servers.
2026-03-22
HTML
★ 1715
WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.
2026-03-22
PowerShell
★ 3695
Automation for internal Windows Penetrationtest / AD-Security
2026-03-22
PowerShell
★ 1192
A PowerShell script anti-virus evasion tool
2026-03-22
Go
★ 1390
渗透测试C2、支持Lua插件扩展、域前置/CDN上线、自定义profile、前置sRDI、文件管理、进程管理、内存加载、截图、反向代理、分组管理
2026-03-22
TypeScript
★ 7710
Cyber Security ALL-IN-ONE Platform