03 Aug 2026
Python
★ 10
Harpoon is an autonomous black-box penetration testing tool designed for web applications, optimized for use on Kali Linux but capable of running on other Debian-based distributions and WSL. It orchestrates and integrates various existing security scanners, streamlining the process of vulnerability discovery by normalizing outputs into a relational SQLite model and providing comprehensive reporting, including HTML reports and PoC artifacts. Notable features include asynchronous execution, WAF-awareness, and extensive automated phases covering everything from DNS reconnaissance to validation of findings.
03 Aug 2026
C
★ 49
hARMless is an ELF Packer/Loader designed for ARM64 and x86-64 Linux binaries, utilizing multi-layer encryption techniques for secure execution. Its primary use case is to facilitate stealthy operation by preventing the original binary from being written to disk and employing runtime in-memory execution, alongside features such as code obfuscation, CRC32 integrity checks, and polymorphic loading to enhance anti-analysis measures.
03 Aug 2026
★ 295
Goodboy Framework is a comprehensive 15-stage course designed for developing and analyzing Windows malware, leveraging the Rust programming language. It equips users with practical knowledge from both offensive and defensive cybersecurity perspectives, encompassing techniques such as API hashing, process injection, and anti-debugging, while providing empirical data on evasion effectiveness against multiple antivirus engines. The framework emphasizes hands-on learning, featuring real-world detection mechanisms and adversarial thinking strategies, ensuring all content is validated through rigorous testing.
03 Aug 2026
TypeScript
★ 11
The Glass Box Framework provides a runtime verification system for AI-generated answers by producing a structured Trust Card that details claims, reasoning chains, and an Epistemic Confidence Score (ECS). Key features include adversarial probes for potential biases and manipulations, a compilation of deployer intents into structured rules, and deterministic audit logging for reproducibility. This tool is designed to enhance transparency and accountability in AI responses, ensuring each assertion is traceable and verifiable.
03 Aug 2026
Python
★ 148
GhostLock is a research tool designed to demonstrate the potential for ransomware-equivalent availability impacts on SMB shares by utilizing file-level and directory-level locking techniques without writing or encrypting data. It enables low-privileged Windows domain users to effectively lock files or entire directories, rendering them operationally invisible while maintaining read access at known paths, thus bypassing traditional security measures with no detectable writes or anomalies. Notable features include a 32-thread parallel scanner for file locking and a single handle directory lock method, making it a significant concern for SMB-based environments.
03 Aug 2026
Python
★ 13
GhostLNK is an advanced Windows LNK generator designed for red team operations and security research, focusing on reducing detection through sophisticated evasion techniques. It features capabilities such as multi-stage payload execution, stealth icon smuggling, various execution modes (including memory execution), and anti-sandbox checks, all aimed at creating more covert attack vectors. The tool is intended for authorized security testing only and emphasizes flexibility in payload generation while minimizing forensic traces.
03 Aug 2026
C
★ 17
Flipper RF Lab transforms the Flipper Zero device into a sophisticated RF analysis and research tool, featuring 15 advanced capabilities such as RF fingerprinting, adaptive signal modeling, and real-time spectrum monitoring. It enables users to perform detailed signal capture and analysis, protocol reverse engineering, and long-term logging within the 300-928 MHz frequency range. Notable functionalities include real-time activity mapping, threat modeling, and a robust modular research mode, making it suitable for professional RF forensics.
03 Aug 2026
Python
★ 13
FAS Judgement is a gamified testing platform designed to evaluate AI systems' vulnerabilities to prompt injection attacks. It offers structured attack patterns against AI endpoints, allowing users to learn red teaming techniques through engaging gameplay, which includes 37 challenges across 10 levels, an XP system, and interactive guidance from a WarGames-inspired AI game master named Jerry. Notable features include built-in vulnerable targets, a global leaderboard, OAuth sign-in capabilities, and a hands-on training experience without the need for external AI APIs.
03 Aug 2026
Python
★ 11
The "exploits" repository serves as a comprehensive security research and exploit development toolkit, focusing on browser vulnerabilities, post-exploitation techniques, and cloud identity attacks. It features organized content around CVE reproductions, offensive tooling with detection guidance, and written assessment deliverables, all designed for educational use and authorized security testing. Notably, it includes a contained Docker lab environment for safe execution and testing of exploit scenarios without internet access, ensuring a secure and isolated workspace for enterprise assessments.
03 Aug 2026
C++
★ 18
Evil Goat is a Wi-Fi security education tool that simulates an Evil Twin attack by creating a fake access point with a captive portal to demonstrate phishing techniques and enhance user awareness. Key features include automatic DNS redirection, a simulated login portal, local data storage for educational labs, and a web-based configuration panel. The project is intended exclusively for educational and laboratory purposes, emphasizing responsible use and ethical practices in cybersecurity training.
03 Aug 2026
C
★ 19
The EternalHush Framework is an advanced command and control (C&C) platform designed specifically for Windows systems, enabling users to extend its functionality through a Python API for plugin development. Notable features include an intuitive GUI, integration capabilities for external modules, and a variety of built-in implant functionalities such as TCP/HTTP(S) connections and reflective DLL loading, all aimed at facilitating data collection and interaction with infected systems. This open-source project is currently in early development and seeks community collaboration for enhancements.
03 Aug 2026
★ 13
The Educational Cybersecurity Tools repository serves as a comprehensive catalog of over 150 tools aimed at ethical hacking, penetration testing, and cybersecurity education. It encompasses various categories including network scanning, vulnerability assessment, and malware analysis, while emphasizing that all tools are intended for educational purposes only and may not be used for unauthorized access to systems. Noteworthy features include detailed tool descriptions, an extensive list of categories, and a focus on promoting ethical standards in cybersecurity practices.
03 Aug 2026
TypeScript
★ 28
DVAP is an open-source platform designed for AI security training, red/blue teaming, and research, allowing users to safely explore and benchmark vulnerabilities in AI systems entirely on local machines without reliance on cloud services. It features intentionally vulnerable AI applications and environments tailored for various attack scenarios, supporting a hands-on approach to understanding AI security challenges and developing effective defenses. Notable capabilities include 15 dedicated AI labs, comprehensive coverage of OWASP LLM Top 10 vulnerabilities, and integrated benchmarking for AI models.
03 Aug 2026
Python
★ 56
Deck of Many Prompts is a manual Red Teaming tool designed for creating jailbreaks for large language models (LLMs). It features a variety of transformations, including encoding and token manipulation techniques, alongside tools for text and image conversions, language translation, and a rich interface for managing prompt history and notes. Noteworthy functionalities include support for multiple encoding formats (e.g., base64, Morse, Braille) and the ability to expand wordlists and tokenize for various models like GPT and BERT.
03 Aug 2026
Python
★ 13
DDoSSCAN is an advanced open-source network availability and stress testing framework developed in Python, designed specifically for security professionals, system administrators, and network engineers to conduct authorized tests on their infrastructure. Notable features include multi-vector attack simulations (TCP, HTTP, UDP, Slowloris), smart domain safety blocking, a real-time statistics dashboard, and automated session report generation in both TXT and JSON formats, all supported across multiple platforms including Linux, Windows, macOS, and Termux.
03 Aug 2026
Go
★ 44
CyberMind CLI v6.0 is a powerful AI-driven offensive security tool designed for a diverse range of users including bug bounty hunters, red teamers, penetration testers, and security researchers. It offers 22 autonomous attack modes, a unique OMEGA brain orchestration feature, and support for exploiting Web3, mobile, and cloud environments, while integrating seamlessly with Kali tools. Key features include manual and automated execution options, real-time alerting via Telegram, and a VSCode extension for enhanced usability.
03 Aug 2026
Python
★ 14
LongLogon is a non-destructive precondition checker for the CVE-2026-41089 vulnerability, which is a stack buffer overflow affecting the Windows Netlogon service. It operates without authentication and does not exploit the vulnerability; instead, it sends benign CLDAP pings to determine if a domain controller's DNS domain name is sufficiently long to trigger a crash. This tool provides a reliable mechanism for security assessments by validating the conditions necessary for the vulnerability without the risks associated with executing an exploit.
03 Aug 2026
C
★ 63
CrystalForge is a custom AdaptixC2 agent designed to enhance payload generation through integration with the Crystal Palace UDRL pipeline. It facilitates the creation of various payload formats, including DLL and shellcode, while allowing users to specify custom Crystal Palace loader specifications, all while preserving the features of the existing Adaptix beacon architecture. Key functionalities include multi-transport support, a straightforward plugin installation process, and a roadmap for expanding capabilities beyond current limitations.
03 Aug 2026
Python
★ 20
Codex Red Team System Prompt is a tool designed for injecting custom system prompts into OpenAI Codex, enabling the redefinition of its role and behavior. Its primary use case is for security professionals conducting authorized penetration testing, Capture The Flag (CTF) challenges, and technical exercises by allowing Codex to autonomously generate responses without user intervention. Notable features include a cross-platform automatic injection script, an emphasis on unrestrained AI collaboration, and a strict response protocol that ensures complete, actionable outputs.
03 Aug 2026
Shell
★ 18
Cobalt-Docker is a containerization tool that simplifies the deployment of Cobalt Strike 4.12 team servers within Docker environments, enabling rapid setup and automatic startup of a REST API for interaction. It includes essential features like pre-launch configuration validation, multi-platform support for macOS and Linux, and the ability to deploy with custom Malleable C2 profiles. Additionally, the integration of a REST API enhances automation and streamlines server management.
03 Aug 2026
C
★ 149
CLR-Stomp is a Beacon Object File (BOF) designed for Cobalt Strike that implements .NET assembly stomping by loading a specified .NET assembly from the Global Assembly Cache (GAC) and replacing its content with a malicious payload before the runtime reads the metadata. This technique offers a covert execution mechanism that retains the legitimate disk identity of the GAC assembly, enabling the payload to evade detection while running in the victim's environment. Notable features include the use of custom memory managers to manipulate the CLR's assembly mapping process and the ability to suppress strong-name verification, which maintains the facade of legitimate assembly usage.
03 Aug 2026
★ 137
Cloud OSINT is a curated resource designed for conducting open-source intelligence (OSINT) assessments of cloud infrastructure, featuring dorks, tools, techniques, and methodologies applicable across major cloud platforms such as AWS, Azure, GCP, Oracle, and IBM. Its primary use case is to assist security professionals, red teamers, and bug bounty hunters in effectively mapping and analyzing cloud environments through a structured reconnaissance workflow. Notable features include comprehensive guidance on cloud infrastructure patterns, domain identification, and a variety of targeted dork queries, enhancing the efficiency of reconnaissance efforts.
03 Aug 2026
★ 21
Claude Security Agents provide an automated solution for identifying and remediating vulnerabilities within software projects using two specialized Markdown files. The Red Team agent performs penetration testing to uncover security flaws, while the Blue Team agent automatically implements fixes based on the insights provided by the Red Team. This feedback loop allows for rapid vulnerability management without the need for extensive security expertise or infrastructure setup.
03 Aug 2026
Python
★ 16
Claude Active Directory is a specialized AI-driven tool designed for offensive security assessments within Active Directory environments. It features an array of structured methodologies, evidence-ready reporting, and integration with Claude Code, enabling red teams and internal assessors to efficiently conduct penetration tests across eight skill domains. Notable features include thirteen slash commands, seven AI agents, and support for mapping findings to MITRE ATT&CK tactics, enhancing both operational impact and defensibility.
03 Aug 2026
NetLinx
★ 66
Cheshire is a Go plugin for the Adaptix C2 service that enables pre-flight payload quality assurance by integrating with the LitterBox analysis framework. It allows operators to upload binaries, conduct static and dynamic analysis, and receive detailed EDR alerts directly from the Adaptix UI without additional navigation. Notable features include real-time progress streaming during analysis, extensive reporting on security findings, and a configurable interface for seamless user interaction.