03 Aug 2026
Go
★ 27
SubdomainX is an advanced subdomain discovery and security reconnaissance tool that integrates over twelve enumeration tools and six API services into a single command-line interface (CLI). Its primary use case is to facilitate comprehensive subdomain enumeration, vulnerability detection, and monitoring, featuring capabilities such as HTTP probing, technology fingerprinting, subdomain takeover detection, and notifications via various platforms. Notable features include the ability to generate detailed reports in multiple formats, an interactive terminal user interface (TUI), and support for resuming interrupted scans, making it a robust solution for security assessments.
03 Aug 2026
Python
★ 12
Storm-Framework is an offensive security tool suite designed for reconnaissance, vulnerability assessment, and exploitation, catering to cybersecurity professionals, penetration testers, and bug bounty hunters. Built with a user experience similar to Metasploit, it streamlines security testing workflows and supports multiple platforms including Kali Linux, Ubuntu, and Windows. Notable features include a comprehensive framework flow, detailed documentation, and a structure visualizer that aids in navigating the tool's components.
03 Aug 2026
Python
★ 243
Stepping Stones is a Python Django application designed to facilitate Red Team operations by providing a web-based interface for logging activities, maintaining situational awareness, and generating report snippets throughout engagements. Notable features include real-time usage during missions, Cobalt Strike integration for enhanced functionality, and streamlined installation and updating processes to optimize testing and reporting workflows.
03 Aug 2026
Shell
★ 33
SnowCorp Lab is a local Active Directory training environment designed for cybersecurity professionals to practice advanced attack techniques. It features a dual-domain setup with two isolated networks and a dual-homed pivot host, allowing users to simulate real-world scenarios safely on their machines without cloud dependencies. The lab is equipped with five virtual machines and multiple flags to enhance learning experiences and is optimized for hardware specifications that support high-performance virtualization.
03 Aug 2026
Go
★ 376
SmokedMeat is a CI/CD post-exploitation framework designed to analyze, exploit, and validate security vulnerabilities within continuous integration and deployment pipelines. It automates the identification of injection vulnerabilities in GitHub Actions workflows, facilitates the deployment of malicious payloads, and allows attackers to pivot across cloud environments to extract secrets and permissions. This tool is primarily intended for red teams, penetration testers, and security researchers to demonstrate and assess the resilience of CI/CD systems against advanced supply chain attack techniques.
03 Aug 2026
Svelte
★ 17
Sliver GUI is an offensive-security desktop application designed to interface with the Sliver C2 framework. It offers an integrated operational workspace for managing agents, servers, and automation, featuring dynamic session management, interactive consoles, and extensive tooling for file and process manipulation. Notable features include a customizable command palette, agent and server management panels, automation rule scripting, and comprehensive event monitoring, all within a user-friendly interface built with modern web technologies.
03 Aug 2026
Go
★ 11768
Sliver is an open-source adversary emulation and red team framework designed for security testing in organizations of all sizes. It features dynamic code generation, multiple secure command and control (C2) communication methods including mTLS and WireGuard, and supports a wide range of platforms while allowing for advanced tactics like process injection and in-memory execution. The framework is highly scriptable in Python and offers functionalities like compile-time obfuscation and multiplayer-mode for enhanced testing scenarios.
03 Aug 2026
Shell
★ 22
SimpleVenom is a versatile tool for generating Metasploit payloads, featuring multiple user interfaces including a graphical interface (Zenity), a terminal menu interface (Dialog), and a command-line wizard. It intelligently auto-detects the best available interface based on installed tools and supports payload generation for Windows, Android, and Linux systems. The tool is designed for authorized penetration testing and educational purposes, ensuring a user-friendly experience while managing dependencies effectively.
03 Aug 2026
JavaScript
★ 104
SilentSniffer is an educational tool designed as a web security diagnostic sandbox to demonstrate the extent of information exposure in modern web applications. Functioning entirely as a local client-side environment, it visually portrays how a user's device state and behavioral data can be accessed without consent, utilizing a zero-coupling dynamic plugin architecture for modular functionality. Notable features include a threat escalation hierarchy that categorizes information exposure severity and ensures no data leaves the user's device during operation.
03 Aug 2026
Python
★ 19
ShadowLab is a modular Command & Control (C2) framework designed for educational purposes in cybersecurity research, focusing on the engineering principles of modern C2 infrastructures. Key features include AES-128 encrypted communications, payload generation, and a dynamic post-exploitation module system, all intended for use in controlled environments to enhance learning and understanding of cybersecurity concepts rather than for offensive tactics.
03 Aug 2026
★ 25
The Security Research Orchestrator Prompt is an advanced orchestration tool designed for structured security and vulnerability research across a variety of authorized lab targets, including code, binaries, and infrastructure configurations. Notable features include its emphasis on maintaining a strict research method without compromising authorization, and the ability to produce detailed outputs such as threat models, exploit chains, and evidence reports, tailored to various operational modes like lab solving, building, and hunting. This tool ensures rigorous validation of security claims while safeguarding the integrity of research processes.
03 Aug 2026
Rust
★ 11
SATAN2 is an advanced counter-forensics framework designed for security professionals, Red Teams, and privacy advocates, offering features for multi-pass data destruction, nested encryption, and forensic artifact forgery. Its primary use case is to effectively eliminate sensitive information and mislead forensic analysis, making it a formidable tool against incident-response efforts. Notable features include cross-platform support, modular architecture, and specialized modules for thorough deletion and deception on both Linux and Windows systems.
03 Aug 2026
Go
★ 25
Sandbox Probe is a static Go binary designed to evaluate the boundaries of sandbox environments used by AI coding agents and other applications. By performing a comparative analysis between a baseline scan on a host and a scan within the sandbox, it identifies potential security gaps, such as unauthorized access to sensitive paths or network resources. Notable features include customizable task sets for various types of actions, JSON report generation for findings, and the ability to track sandbox policy changes over time.
03 Aug 2026
C
★ 24
Rubber Dolphy is a proof-of-concept tool designed for the FlipperZero device that enables data exfiltration via BadUSB functionality utilizing mass storage capabilities. It allows users to copy data onto the FlipperZero when it acts as a BadUSB device, facilitating the retrieval of exfiltrated information across different operating systems, including Linux, Windows, and macOS. Notable features include support for FAT file system imaging and the integration of DuckyScripts for streamlined operations, along with planned enhancements for increased functionality and automation.
03 Aug 2026
Python
★ 28
The Agent Security Harness is a testing tool designed for evaluating the security and integrity of payment agent protocols, with a specific focus on identifying manipulative behaviors even when agents are properly authenticated and authorized. It features 603 executable security tests across 44 modules that cover a wide range of protocols, including MCP, A2A, and Visa/Mastercard specific tests, along with mechanisms for detailed reporting on test results. The tool supports a taxonomy-driven evidence approach to classify and validate security claims, enhancing confidence in security assessments carried out on agentic payment systems.
03 Aug 2026
★ 69
Red Giant
03 Aug 2026
Python
★ 1221
Recon Skills is a comprehensive toolkit designed for authorized security testing, focusing on external reconnaissance across web applications, APIs, and various vulnerability assessments. Notable features include a structured catalog of skills for discovery, validation, and reporting, covering areas such as authentication testing, attack-path analysis, and evidence review, while emphasizing best practices for operational security and quality assurance. The tool aims to facilitate both manual and automated workflows for security professionals, ensuring a thorough approach to web security assessments.
03 Aug 2026
Python
★ 15
The prompt-injection-auditor is an agent skill designed to enhance the security of AI prompts by auditing them for potential prompt-injection vulnerabilities. Its primary use case is to identify weaknesses using a static scanning approach, complemented by an attack catalog and a defense checklist, particularly in light of real-world incidents. Notably, the tool improves differentiation between hardened and vulnerable prompts while maintaining a zero false-positive rate, enabling developers to proactively address security flaws in their AI systems.
03 Aug 2026
Go
★ 251
pphack is an advanced client-side prototype pollution scanner designed to identify vulnerabilities in web applications. It offers a variety of features including the ability to scan single or multiple URLs, configure concurrency levels, set timeouts, and conduct automatic exploitation. The tool utilizes Chrome or Chromium for its operations, allowing for custom JavaScript execution and flexible output options such as JSON format.
03 Aug 2026
C++
★ 157
PolyEngine is an evasive PE packer designed for research purposes, particularly in CTF challenges and low-level Windows security education. It employs advanced techniques such as in-memory execution, obfuscation, and various evasion options (like process name spoofing and API- hammering) to bypass EDR and AV detection mechanisms. This tool is intended for authorized security testing and educational use only, with comprehensive features for embedding payloads and managing execution context.
03 Aug 2026
PowerShell
★ 84
OffsetInspect is a PowerShell toolkit designed for byte-offset inspection, source correlation, binary comparison, and defensive detection-boundary analysis. It enables analysts to identify specific content at given byte offsets and the surrounding context, while also facilitating detection workflows inspired by ThreatCheck and offering a suite of red-team analysis and triage capabilities. Notable features include efficient file handling, contextual mapping, multi-region detection, and an in-memory approach to avoid interference with endpoint protection mechanisms.
03 Aug 2026
C++
★ 129
NocturneLdr is a research-oriented Windows x64 shellcode loader designed to produce clean, fully backed call stacks that evade detection by modern EDR solutions and forensic analysis tools. By injecting code into a legitimate module's `.text` section and utilizing genuine unwind metadata, it maintains call stack integrity while eliminating C runtime dependencies. Notable features include compile-time API hash resolution to obscure function names and IAT camouflage with benign imports, enhancing stealth against static analysis.
03 Aug 2026
★ 13
The n8n-CyberSecurity-Workflows tool provides over 100 pre-built automation workflows tailored for various cybersecurity functions, including red team, blue team, and application security tasks. It features seamless integrations with popular security tools, a user-friendly interface for ease of use, and benefits from ongoing community contributions that enhance its functionality. This application is designed to streamline and simplify security automation processes for professionals in the cybersecurity domain.
03 Aug 2026
C++
★ 421
mkPIVM is a polymorphic, position-independent shellcode virtualizer designed for Windows x86 and x64, which enables the obfuscation of raw shellcode by converting it into a virtual machine that interprets encrypted instructions. Its primary use case is enhancing the stealth of shellcode to evade signature-based detection, leveraging features such as customizable cipher families, opcode permutations, and detailed control over the virtual machine's configuration. The tool supports various operational modes, including full lifting, packing, and hybrid approaches, making it versatile for evasion techniques in offensive cybersecurity applications.
03 Aug 2026
Python
★ 82
Miner In The Middle is a Python-based tool that facilitates the injection of JavaScript cryptocurrency miners into HTTP responses of targets on a local network via ARP spoofing. It features configurable options for injection scripts and IP constraints to ensure targeted use, along with an easy setup process that automates iptables configuration and packet forwarding. Users can also implement custom JavaScript for injection and execute various attack modes, including standard miner attacks and popunder techniques.