03 Aug 2026
PowerShell
★ 21
SiteSniper is an automation script designed for blackbox penetration testing, leveraging tmux for organizing and executing various penetration testing scripts across multiple phases. Its primary use case involves preparation and execution of commands for tasks such as information gathering, exploit identification, and web application analysis. Notable features include a user-friendly interface for phase selection, precompiled command execution, and a structured approach to manage multiple testing sessions efficiently.
03 Aug 2026
JavaScript
★ 13
Shells-X is a modular web shell framework designed for authorized penetration testing and security research, allowing users to deploy a single-file shell that incorporates various tools for executing commands, interacting with databases, and scanning ports. Its notable features include customizable builds with unique SHA256 fingerprints, an interactive environment for PHP and SQL commands, robust system diagnostics, and encrypted traffic handling. The framework also supports automatic detection of CMS/frameworks and provides a one-click export option for recon data to Faraday.
03 Aug 2026
C++
★ 727
The Red-Team-Exercises repository serves as a compilation of educational posts focusing on various red team tactics and techniques. This resource is primarily designed for cybersecurity professionals seeking to enhance their skills in areas such as shellcode execution, evasion techniques, and phishing campaigns. Notable features include detailed descriptions of each exercise, covering advanced topics like AMSI bypass, process injection, and Active Directory enumeration.
03 Aug 2026
Python
★ 42
ReconNinja is an autonomous multi-phase security reconnaissance framework that conducts comprehensive security assessments through a single command. It supports a myriad of functionalities including passive OSINT, port scanning, web discovery, vulnerability scanning, and Active Directory enumeration, producing reports in multiple formats like HTML, JSON, and Markdown. Notable features include an adaptive agent mode for dynamic decision-making, a user-friendly GUI, and enhanced reliability for complex scans with a uniform `PhaseContext` adapter layer.
03 Aug 2026
Go
★ 227
PromptZero is a natural-language operator designed for the Flipper Zero device, enabling users to generate, deploy, and execute various payloads through simple text commands. It primarily facilitates tasks related to RF, NFC, RFID, and HID payload creation while offering an intuitive interface for both offensive and defensive cybersecurity scenarios. Notable features include end-to-end integration with Claude AI for payload generation, a read-only operational mode for safe usage, and real-time querying of connected devices.
03 Aug 2026
PowerShell
★ 44
PrecompiledBinaries is a curated repository of precompiled binaries designed for use in authorized security testing, including penetration testing, red teaming, and exploit validation. It facilitates rapid access to essential tools across various scenarios such as privilege escalation, Active Directory assessments, and tunneling, eliminating the need for time-consuming compilation from source. Notable features include an organized layout of binaries by tool and platform, covering a wide range of use cases in security assessments.
03 Aug 2026
PowerShell
★ 58
PowerShell is a task automation and configuration management framework that enables users to script and execute administrative tasks across various operating systems, although it lacks full feature parity on non-Windows platforms. Its notable features include a robust command-line interface, scripting capabilities for system management, and a focus on script reliability and reuse. The tool is particularly useful for network troubleshooting and performance monitoring, exemplified by scripts like TimeTrack-Specific-Software-Openings.ps1, which measures application launch times.
03 Aug 2026
Shell
★ 2185
pentest-ai-agents is a suite of 50 subagents designed to enhance penetration testing by utilizing Claude Code as an offensive security research assistant. Each agent specializes in areas such as reconnaissance, web applications, Active Directory, and cloud security, offering streamlined automation for various tasks without the need for extensive setup. Notable features include the ability to route tasks to specific experts, support for easy installation as a Claude Code plugin, and a robust validation process to ensure secure and efficient operation of each agent.
03 Aug 2026
Python
★ 1639
Pentest-ai is an AI-powered penetration testing tool designed to enhance the verification of security findings by re-running exploits to confirm their validity, ensuring that each piece of evidence is backed by reproducible results. It streamlines the verification process by generating multi-step attack paths and providing a reporting mechanism that only includes findings validated by its oracle system, achieving 100% precision with zero false positives across multiple vulnerability classes. The tool operates offline without cloud reliance, making it ideal for authorized testing in a controlled environment.
03 Aug 2026
JavaScript
★ 22
OverQuack is a customizable HID automation tool designed for scripted payload execution, featuring an open-source platform that runs on Raspberry Pi Pico boards. Its notable capabilities include full DuckyScript support, wireless payload management via built-in Wi-Fi, and a browser-based IDE that enhances the development experience with real-time error checking and auto-completion. The tool is geared towards transparency and extensibility, making it suitable for educational purposes and research while providing a modern setup workflow.
03 Aug 2026
Python
★ 267
OSINT-D2 is an advanced open-source intelligence platform designed to transform usernames and emails into comprehensive identity dossiers, leveraging agentic AI for autonomous investigations. The tool features multi-source correlation across over 30 platforms, cognitive profiling through a six-dimension analysis, and seamless integration with ScrapingAnt's proxy infrastructure for efficient data gathering. Additionally, it supports premium PDF reporting, incorporates breach exposure checks via HaveIBeenPwned, and offers cross-platform executable binaries.
03 Aug 2026
★ 17
The OSCP / OSCP+ Cheatsheet serves as a comprehensive penetration-testing reference specifically designed for the 2026 OSCP+ exam, organizing critical information across various attack phases. Users can efficiently navigate through self-contained modules covering reconnaissance, footholds, privilege escalation, and Active Directory exploitation, making quick lookups feasible during the exam without internet access. Notable features include clear exam strategy guidelines, restrictions on tool usage, and offline operation recommendations, ensuring candidates can reference essential tactics under exam conditions.
03 Aug 2026
PowerShell
★ 32
MSFT-IP-Tracker is a tool designed to monitor and track Microsoft IP addresses for applications in security research, firewall configurations, routing, and troubleshooting. It collects data from a range of Autonomous System Numbers (ASNs) and publishes daily updates featuring IPv4 and IPv6 addresses in CIDR notation. Notable features include automated daily releases and a comprehensive source of Microsoft’s ASN IP ranges, providing users with up-to-date information for network decision-making.
03 Aug 2026
Go
★ 21
Maldev is a comprehensive Go library designed for malware engineering, providing tools for syscall manipulation, evasion techniques, code injection, credential harvesting, and persistence mechanisms. Its capabilities include a variety of syscall calling methods, extensive evasion techniques against detection mechanisms, and robust injection methods, all integrated through a unified syscall caller for enhanced stealth and flexibility. The library is aimed at authorized security research, red teaming, and penetration testing, ensuring a modular approach to malware development with an emphasis on cross-compilation without CGO dependencies.
03 Aug 2026
Python
★ 10
MailSpoof is an open-source email spoofing and phishing simulation tool designed for authorized penetration testing and security awareness training. It features a built-in multi-threaded SMTP server, 62 pre-built phishing templates, custom template creation, and comprehensive audit logging alongside report generation capabilities. This tool is compatible across multiple platforms, including Linux and macOS, and supports bulk targeting, external SMTP relay configurations, and advanced header functionalities for enhanced testing scenarios.
03 Aug 2026
Go
★ 34
Lain C2 is a command-and-control framework designed to facilitate secure communication between compromised hosts and operators across multiple platforms including Windows, Linux, macOS, and Android. It supports various communication protocols such as HTTP/1, 2, and 3, and integrates third-party libraries for enhanced functionality, making it a versatile tool for conducting remote management and operations. Notable features include cross-platform compatibility and efficient handling of system metrics and processes.
03 Aug 2026
C
★ 53
KHAØS LOADER is a multi-stage Windows x64 loader that utilizes AES-256-CBC to decrypt and inject donut shellcode into a `rundll32.exe` process spawned under `explorer.exe`, employing advanced evasion techniques such as indirect syscalls with call stack spoofing. Notable features include early-bird APC injection, unhooking capabilities, and robust sandbox evasion mechanisms, which ensure stealthy operation against various security measures. This tool is designed for authorized use only and integrates multiple sophisticated methods to remain undetected during execution.
03 Aug 2026
PowerShell
★ 17
JMP-AMSI is a Proof of Concept tool designed to demonstrate the manipulation of managed code pointers in the PowerShell runtime, specifically targeting the Antimalware Scan Interface (AMSI) to bypass its scanning capabilities. Notable features include in-memory execution, native memory manipulation without using highly monitored functions, and multi-architecture support for dynamic assembly patching. The tool provides options for telemetry interruption and detailed verbose output for testing and research purposes.
03 Aug 2026
HTML
★ 14
The iOS ClickFix Template is a red team tool designed for executing a ClickFix → WebClip social engineering attack chain on iOS devices. It creates a convincing lure page that prompts targets to install a malicious `.mobileconfig` profile, which then adds a shortcut to the attacker's designated web page on the target's Home Screen. Notable features include personalized links for each target, generating unique profiles, and easy configuration to customize the WebClip functionality.
03 Aug 2026
Python
★ 305
InfraGuard is a red team infrastructure tracker and command-and-control (C2) redirector designed to enhance operational security by validating incoming traffic against customizable C2 profiles. Key features include multi-domain proxying, scoring-based filtering with JA3 TLS fingerprinting, and detection mechanisms for headless browsers and path enumeration attempts, enabling precise filtering of malicious requests while allowing legitimate beacon traffic. This tool serves as a modern alternative to existing solutions, providing a comprehensive suite for defending against reconnaissance and automated probing activities.
03 Aug 2026
JavaScript
★ 15
HoneyAI is an all-in-one, AI-powered honeypot designed to proactively intercept and deceive attackers across various protocols using a local LLM. It generates dynamic, realistic responses to malicious attempts such as SQL injections and SSH logins, with customizable commands and automated reporting to multiple threat intelligence platforms. Notable features include a wide range of protocol emulation, real-time attack notifications, and the ability to integrate with any LLM, ensuring comprehensive coverage and adaptive defenses against cybersecurity threats.
03 Aug 2026
PowerShell
★ 50
🎒 An up-to-date collection of precompiled binaries and hacking scripts.
03 Aug 2026
Go
★ 12
GoFenrir is an Active Directory enumeration and attack framework developed in Go, leveraging the Manticore protocol backend for efficient operations without dependency complexities. It supports various protocols, including LDAP/LDAPS for full enumeration, Kerberos for advanced credential attacks, and has a plan to support SMB v2/v3, providing a robust suite of enumeration and exploitation features ideal for penetration testing. Notable functionalities include user and group enumeration, domain controller discovery, and advanced Kerberos attack capabilities like Kerberoasting and AS-REP roasting.
03 Aug 2026
Go
★ 40
`git-fire` is a command-line interface (CLI) tool designed for efficiently checkpointing multiple Git repositories simultaneously. Its primary use case is to facilitate the safe backup of local changes across numerous repos by discovering repositories, optionally auto-committing uncommitted changes, and pushing backup branches with added recovery safety. Notable features include the ability to perform dry-run previews for safety and a streamlined emergency mode for quick execution under pressure.
03 Aug 2026
TypeScript
★ 34
Gideon is an autonomous cybersecurity operations agent designed for intelligent threat analysis and red teaming. It automates the process of gathering intelligence and conducting thorough security research by breaking down complex questions into actionable tasks, utilizing real-time data from various sources. Notable features include dual-mode operation for both defensive and offensive engagements, goal-directed autonomy, and an evidence-based approach to generating actionable security insights.