03 Aug 2026
Go
★ 274
Octoscan is a static vulnerability scanner designed for GitHub action workflows, enabling users to identify potential security issues within their CI/CD pipelines. Its primary use case is analyzing workflows for various vulnerabilities, including dangerous actions, credentials exposure, and expression injection. Notable features include the ability to download workflows from remote repositories, customizable rule sets for scanning, and support for multiple output formats, ensuring flexibility in vulnerability reporting.
03 Aug 2026
Java
★ 222
NTRGhidra is a plugin for Ghidra that serves as a Nintendo DS loader, enabling users to analyze and debug DS software within the Ghidra environment. It supports Ghidra version 12.0.4 and allows for dynamic loading and unloading of overlays, enhancing the tool's functionality for developers working with Nintendo DS applications. Notable features include extension installation for Ghidra and comprehensive build instructions for developers interested in modifying the loader.
03 Aug 2026
C++
★ 195
The NmiCallbackBlocker is a driver concept that modifies kernel memory to prevent Non-Maskable Interrupts (NMIs) from executing by altering processor affinity masks. Its primary use case is to aid in bypassing anti-cheat mechanisms within gaming environments, leveraging techniques like signature scanning and structure manipulation for stealth operations. Notable features include the ability to evade detection through spoofing techniques and encrypted signatures, though it is important to note that the project includes no built-in anti-cheat protections.
03 Aug 2026
Swift
★ 13
Neospring is a tool designed to facilitate the respring process in LiveContainer environments, addressing limitations found in existing solutions like InstaSpring and respringapp. By leveraging a method originally developed by neon and ported to Swift by skadz, it offers a streamlined and effective approach for developers and users working with iOS customization. Notable features include enhanced compatibility with LiveContainer, enabling efficient system refresh without typical constraints.
03 Aug 2026
C#
★ 349
MS-RPC Fuzzer is a PowerShell module designed for automated vulnerability research in Microsoft Remote Procedure Call (MS-RPC) implementations. Its primary use case involves dynamically building RPC clients to fuzz various RPC procedures using random inputs, aiming to identify potential vulnerabilities in RPC services efficiently. Notable features include a structured three-phase process for inventorying RPC interfaces, performing fuzzing based on gathered data, and analyzing results with options for visualization in a Neo4j database.
03 Aug 2026
Python
★ 77
Mephisto is a WordPress vulnerability scanner and exploitation framework designed for authorized penetration testing, enabling security professionals to assess multiple WordPress installations for security weaknesses. Key features include multi-CVE support, mass scanning capabilities, automatic detection of vulnerable plugins and themes, and the ability to upload web shells for post-exploitation access, all while ensuring anonymity through proxy support and anti-detection measures.
03 Aug 2026
PowerShell
★ 50
The "Malware" repository offers a collection of malware samples and resources for cybersecurity professionals. Its primary use case is to facilitate testing and analysis of malware, including the ability to download various samples using proxy tools like proxychains. Notable features include the inclusion of the EICAR test file for antivirus testing and the ability to aggregate IP addresses from logs for streamlined malware acquisition.
03 Aug 2026
PHP
★ 29
Magento PolyShell is an advanced exploitation toolkit designed for unauthenticated remote code execution (RCE) on Magento 2.x through polyglot file uploads via the REST API. It tests over 45 PHP extension variants while utilizing multi-header support, server fingerprinting, and advanced WAF bypass techniques to maximize exploitation success across a wide range of environments. Key features include interactive and CLI modes, categorization of results by target, and extensive post-exploitation capabilities for system information retrieval.
03 Aug 2026
★ 485
Lost-NDS-TV is a project aimed at restoring the hidden television composite video output feature of the Nintendo DS Lite's SoC through custom hardware designs and software solutions. Its primary use case is to enable video output from the DS Lite for enhanced viewing experiences, supported by comprehensive schematics, production files, and installation tutorials. Notable features include detailed documentation and video tutorials for installation, making it accessible for users interested in retro gaming modifications.
03 Aug 2026
C
★ 18
The Linux-Exploitation repository provides a comprehensive set of tools and techniques for performing privilege escalation on Linux systems. Its primary use case is to assist security professionals in identifying vulnerabilities that can be exploited to gain higher access levels, featuring sections on manual enumeration, automated tools, password mining, misconfiguration exploitation, and maintaining access through SSH key uploads. Notable features include detailed guides on various escalation methods, scripts for automated enumeration, and an exhaustive list of potential exploits tailored for Linux environments.
03 Aug 2026
HTML
★ 42
The k8gege.org repository hosts a website that serves as a centralized platform for Kubernetes-related resources and tools. Its primary use case is to provide educational content, documentation, and best practices for Kubernetes users and developers. Notable features include curated links to tutorials, articles, and other valuable resources in the Kubernetes ecosystem.
03 Aug 2026
C
★ 389
Isolation Alloc (IsoAlloc) is a secure, C11-based memory allocator designed as a drop-in replacement for `malloc` on 64-bit Linux and MacOS systems, emphasizing memory allocation isolation to enhance security by spatially separating objects of various sizes and types. Key features include the management of memory through distinct zones for specific sizes, comprehensive debugging support for memory leaks and usage, and built-in compatibility with Address Sanitizer and similar tools. IsoAlloc is particularly suitable for applications where security and performance of memory management are crucial.
03 Aug 2026
Python
★ 329
HatSploit is a modular penetration testing framework designed for writing, testing, and executing exploit code. Its primary use case is to facilitate security assessments and vulnerability exploitation in a structured manner. Notable features include its extensibility through modules and a user-friendly interface for deploying exploits.
03 Aug 2026
Python
★ 8332
GEF (GDB Enhanced Features) is a powerful tool designed to enhance the functionality of GDB (GNU Debugger) for exploit development and reverse engineering across multiple architectures such as x86/64, ARM, and MIPS. Notable features include architecture agnosticism, a single installation script, full Python 3 support, and a variety of commands that optimize the debugging experience while facilitating dynamic analysis. The tool is designed to reduce cognitive load on developers by offering a more intuitive interface and extensive community contributions.
03 Aug 2026
C++
★ 12
The external-process framework provides mechanisms for interacting with external Win32 processes, enabling operations such as reading and writing process memory, allocating memory, calling functions with various calling conventions, and performing code injection. It is primarily used for creating trainers or utilities that modify the behavior of running applications. Notable features include the ability to search for byte sequences in memory and a built-in external process simulator for testing purposes.
03 Aug 2026
JavaScript
★ 562
EXT-REMOVER is a curated collection of exploits designed specifically for ChromeOS, facilitating various forms of system modifications and enhancements, such as unenrollment from management systems and disabling or freezing browser extensions. It includes notable capabilities like bypassing security measures, tampering with policies, and modifying system configurations, though users are cautioned against misuse that can cause significant damage. The repository serves as a resource for those seeking to explore the security aspects of ChromeOS within legal boundaries.
03 Aug 2026
JavaScript
★ 21
Express Honeypot is a honeypot tool designed to detect and log remote file inclusion (RFI) and local file inclusion (LFI) attacks against web applications. It functions by serving fake URLs generated from a list of known vulnerable paths, dynamically logging any malicious requests, and downloading the attempted remote files for analysis. Key features include a lightweight log viewer and the ability to customize monitored URLs, making it an effective solution for catching and studying automated scanning bots.
03 Aug 2026
Python
★ 64
PwnLand is an open-source resource designed for security researchers and CTF participants, focusing on binary exploitation techniques. It provides an extensive collection of practical examples, tutorials, and research materials on various vulnerabilities, including buffer overflows, format string vulnerabilities, heap exploitation, and kernel exploits. Notable features include structured directories for different exploitation methods, debugging guides, and challenges for hands-on practice.
03 Aug 2026
Python
★ 618
SourApple is a ported exploit targeting iOS 17 devices that uses BLE pairing requests to induce crashes on vulnerable iPhones. It specifically operates on ESP32 and Raspberry Pi platforms, allowing users to evaluate the security of their devices under controlled conditions. Notable features include a focus on educational use, testing on multiple iOS models, and the provision of troubleshooting guidance for common compilation errors.
03 Aug 2026
C++
★ 11
End-To-End-SOC-Home-Lab is a comprehensive project designed to construct a Security Operations Center (SOC) lab on a personal computer, utilizing Splunk for monitoring and detection of cybersecurity threats. It enables users to simulate various attack scenarios, analyze the resultant logs and telemetry, and develop effective detection mechanisms, thereby fostering skills pertinent to both red team attack simulations and blue team defensive strategies. Notable features include detailed guidance on setting up infrastructure, practical use cases for threat detection, and a focus on hands-on learning through real-world attack techniques.
03 Aug 2026
C
★ 29
dirtyfrag-arm64 is an ARM64/AARCH64 exploit tool adapted from the original x86_64 dirtyfrag PoC, targeting vulnerabilities CVE-2026-43284 and CVE-2026-43500. Its primary use case is for privilege escalation by corrupting system binaries, specifically employing an ESP path for exploitation due to limitations on the ARM64 architecture. Notable features include detailed analysis of AppArmor bypass methods and architecture-specific payload adaptations, allowing it to interact with existing user and network namespaces on vulnerable systems.
03 Aug 2026
C
★ 18
Dirty Frag is a proof-of-concept tool that demonstrates how an unprivileged Kubernetes Pod can exploit the Dirty Frag vulnerability (CVE-2026-43284) to achieve node-level code execution on Amazon EKS by corrupting in-memory cached pages of shared container image layers. Its primary use case is to illustrate the risks associated with privileged DaemonSets in Kubernetes clusters that share image layers, as it allows for direct execution of compromised binaries by these privileged workloads. Notable features include the ability to target any privileged DaemonSet, leveraging kernel page-cache corruption alongside the sharing of image layers, thereby exposing a significant security vulnerability in Kubernetes environments.
03 Aug 2026
★ 258
CVE Scores is a tool designed to aggregate and analyze vulnerability scores from various sources, specifically the Exploit Prediction Scoring System (EPSS) and the Vulnerability & Exploit Data Aggregation System (VEDAS). Its primary use case is to predict future exploitation of vulnerabilities and estimate the prevalence and exploit maturity of identified vulnerabilities. Notable features include real-time data updates, integration of proprietary and open source intelligence, and the ability to assess vulnerabilities across multiple identifiers.
03 Aug 2026
Python
★ 12
CVE Mapper is a tool designed to correlate Nmap scan results with relevant CVEs specific to the discovered product versions, minimizing false positives. It utilizes the Vulners API to provide version-accurate vulnerability mappings while re-validating the affected version ranges and generating confidence levels for each finding. The tool supports multiple output formats including JSON, CSV, and HTML, making it versatile for reporting and further analysis.
03 Aug 2026
Python
★ 16
CVE-2026-48908-PoC is a proof-of-concept exploit for a critical unauthenticated remote code execution vulnerability in the SP Page Builder component for Joomla. This tool leverages the improper access control in the asset.uploadCustomIcon task to upload malicious files to a publicly accessible directory, ultimately enabling an attacker to execute arbitrary code on the target server. Notable features include an adaptive payload mechanism that tests various file extensions and .htaccess file injections to bypass server restrictions, as well as cleanup functionality to remove uploaded artifacts after exploitation.