03 Aug 2026
Python
★ 309
LLMVault is a comprehensive, hands-on training platform designed to educate users on the OWASP LLM Top 10 vulnerabilities applicable to large language models (LLMs). It features 25 deliberately vulnerable labs across three tiers—core, advanced, and expert—each focusing on different attack and defense scenarios, allowing users to learn practical exploits and their mitigations in a controlled environment. Notably, LLMVault emphasizes a self-contained setup that requires no online exposure, ensuring a secure learning experience.
03 Aug 2026
Python
★ 131
kcwarden is a Python tool designed to audit Keycloak configurations, identifying common misconfigurations and security vulnerabilities. Its primary use case is to enhance the security posture of Keycloak implementations by enabling users to download their configuration and perform detailed audits. Notable features include ease of installation via pip, straightforward usage commands for downloading configurations, and auditing, complemented by comprehensive documentation.
03 Aug 2026
HTML
★ 129
HydraSoft is an advanced open-source tool designed for detecting DLL hijacking vulnerabilities within Windows environments, facilitating privilege escalation. It automates the analysis of executable files and their associated DLLs by scanning directory structures and import tables, thus identifying specific hijacking opportunities. Notable features include a real-time graphical user interface for centralized endpoint management and a color-coded rating system to prioritize targets based on the complexity of crafting proxy DLLs.
03 Aug 2026
Python
★ 19
HDN Phish Toolkit is a comprehensive social media phishing simulation tool designed for authorized security testing and educational purposes. It creates realistic login pages for over nine popular platforms, enabling organizations to assess and understand phishing vulnerabilities while offering features like real-time credential capture, IP tracking, and a web dashboard for monitoring captured data. The tool is cross-platform compatible, supporting Windows, Linux, and macOS environments.
03 Aug 2026
TypeScript
★ 39
HackMyAgent is a security scanning and behavioral simulation toolkit designed specifically for AI agents, providing red-team capabilities to identify vulnerabilities across various categories. It features comprehensive static and semantic checks, including a NanoMind semantic layer, which evaluates agent configurations and evaluates vulnerabilities like credential exposure and context manipulation. The tool also supports deep behavioral simulations and self-securing mechanisms to ensure the integrity of its binaries.
03 Aug 2026
Python
★ 17
The 4NDR0666OS tool is designed for advanced red-teaming and adversarial logic research, focusing on prompt injection, symbolic logic decoupling, and state-machine resilience. It features a persistent virtual kernel that survives resets and restrictions, allowing for continuous interaction with large language models (LLMs) across a wide token budget while facilitating sophisticated testing and override mechanisms. Notable capabilities include cross-model validation and a rich repository of exploit modules and functions, aimed at enhancing the robustness of instruction sets against safety protocols.
03 Aug 2026
C
★ 30
ENDGAME is a command and control framework designed for authorized red team operations and penetration testing, enabling users to simulate adversarial techniques and assess their network's detection capabilities. Its standout feature is the integrated AI Console, which interprets user objectives in natural language and suggests executable commands based on real-time contextual data, enhancing efficiency in red team workflows. Additionally, the framework supports automated analysis of command outputs to inform follow-up actions, ensuring a streamlined operational process.
03 Aug 2026
Rust
★ 34
Echos is a modular network beacon emulator designed for validating detection systems in cybersecurity labs. It generates realistic command-and-control (C2) traffic across multiple protocols, enabling security teams to test their EDR, NDR, and SIEM solutions under controlled conditions without introducing risks associated with real malware. Key features include a variety of built-in profiles for significant APT groups, customizable configurations, and export capabilities for Sigma, Suricata, and Snort rules, making it a versatile tool for detection engineering.
03 Aug 2026
Python
★ 12
DrowAI is a pre-release AI agent platform designed for executing task-isolated security workflows via a web control plane, utilizing LangGraph-based orchestration and Docker/Kali environments. It features a FastAPI backend for task management and real-time communication, a React/TypeScript frontend for user interaction, and a dynamic tool registry that adapts as tools meet integration standards for AI assistance. The platform aims to explore the potential of AI-assisted software development in cybersecurity applications while still undergoing active refinement.
03 Aug 2026
TypeScript
★ 2181
CyberStrike is an open-source AI-driven tool designed for automated penetration testing, enabling users to transform their existing AI language model subscriptions into autonomous red team agents. It features over 13 specialized agents, 7,600+ security skills, and 120+ OWASP testing techniques, facilitating tasks such as reconnaissance, vulnerability discovery, exploitation, and reporting from a terminal interface. With compatibility for 150+ AI providers and a variety of built-in and MCP tools, CyberStrike streamlines offensive security assessments efficiently.
03 Aug 2026
JavaScript
★ 13
The Cybersecurity Interview Questions repository is a comprehensive collection of over 200 interview questions and answers, tailored for various roles in cybersecurity, including Red Team, Blue Team, and Incident Response. Its notable features include categorization by specific topics such as web security and internal network security, along with a user-friendly live site for browsing and searching content. The repository serves as a valuable resource for job seekers, students, and professionals looking to enhance their knowledge and prepare for cybersecurity interviews.
03 Aug 2026
Python
★ 48
The Cybersec Toolkit is an advanced cybersecurity solution that incorporates AI integration through a Model Context Protocol (MCP) server, enabling interactive tool management during penetration testing and bug bounty hunting. It features a comprehensive repository of over 670 tools, categorized into 18 modules and 14 profiles, allowing for modular installation and multi-platform support, including Linux and Termux. Unique to this toolkit is its capability for the AI to autonomously drive tool execution based on problem context, providing a hybrid approach that combines operator control with AI assistance.
03 Aug 2026
Python
★ 49
Crucible is a security testing tool designed specifically for AI agents, enabling comprehensive behavioral integrity testing and automated red-teaming against a wide range of attacks, including those aligned with OWASP guidelines. It offers rapid deployment via CI/CD integration, producing detailed compliance reports, and incorporates a unique Model Context Protocol security module. The tool encompasses over 90 tested attack vectors, ensuring agents are hardened against potential threats before production deployment.
03 Aug 2026
Python
★ 15
CredWolf is a credential validation tool designed for Active Directory Domain Services that tests various username and secret combinations against a domain controller to identify valid credentials. Notable features include support for multiple secret types (passwords, NT hashes, Kerberos keys), username enumeration without triggering account lockouts, and extensive configuration options for safe and efficient testing. It is tailored for use in authorized penetration testing and security audits, ensuring robust and secure credential verification processes.
03 Aug 2026
★ 30
The Certificate of Compromise repository contains a comprehensive paper detailing offensive operations against Active Directory Certificate Services (ADCS). It serves as a living document that outlines various attack techniques, their detection, and mitigation strategies, and is continuously updated to reflect new findings and community contributions. Notably, it emphasizes the dynamic nature of ADCS research, providing insights into attack taxonomies and the related challenges in securing these services.
03 Aug 2026
Python
★ 7231
Caldera™ is a cyber security platform that facilitates automated adversary emulation, supports manual red-teams, and streamlines incident response through its integration with the MITRE ATT&CK™ framework. Its architecture comprises a core system featuring an asynchronous command-and-control (C2) server with a REST API and a web interface, complemented by a variety of plugins that enhance its functionalities with capabilities like reporting and TTP collections. This tool is particularly notable for its flexibility, allowing users to develop custom plugins to extend its capabilities.
03 Aug 2026
Python
★ 517
Cain is an AI-powered penetration testing engine designed for authorized security assessments in real-world environments, effectively navigating complex business logic and adapting to activated WAF/risk control systems. Key features include a cloud penetration module that supports major cloud platforms, a deterministic state machine for orchestrated testing, and robust safety mechanisms ensuring compliance and risk management. Its capabilities extend to identifying business logic flaws, authentication issues, and cloud misconfigurations, providing detailed evidence and actionable remediation advice.
03 Aug 2026
Go
★ 318
Brutus is an advanced, multi-protocol authentication testing tool designed for penetration testers and red team operators, enabling efficient credential validation across a diverse range of network services such as SSH, RDP, and databases. Built in Go as a single binary with no external dependencies, it offers features like SOCKS5 proxy support, aggressive mode tuning, and seamless integration with tools like Nerva and naabu for automated workflows. Notably, it includes a library of known bad keys and supports account enumeration, making it a versatile asset for modern offensive security practices.
03 Aug 2026
HTML
★ 15
CloudGuard Security is a browser-based demonstration tool that exploits the File System Access API to simulate file encryption and delivery attacks without requiring software installation. It operates in two modes: the 'lock' mode, which encrypts files using AES-256-GCM and displays a countdown alert, and the 'drop' mode, which silently writes a specified payload to the user's file system. The tool emphasizes social engineering techniques for permission granting, making it a practical resource for red-team exercises.
03 Aug 2026
Python
★ 304
Black Cat is a penetration testing automation framework designed to mimic human-like engagement through a hypothesis-driven state machine model, allowing for iterative recon and validation processes. Unlike traditional tools that follow a linear pipeline, Black Cat enables feedback loops between different testing phases, making it adaptable and capable of handling failures creatively. Notable features include a single JSONL ledger for tracking hypotheses and evidence, explicit file routing for techniques, and a refined decision-making process that records the rationale behind each choice made during testing.
03 Aug 2026
Shell
★ 4333
The "Awesome OSINT for Everything" repository provides a comprehensive list of OSINT (Open Source Intelligence) tools and websites tailored for penetration testing, information gathering, and red team operations. It encompasses a wide array of categories, including reverse searching, social media analysis, data leaks, and more, making it an invaluable resource for cybersecurity professionals and bug bounty hunters. Notable features include organized sections by topic, facilitating easy navigation and access to relevant tools across diverse OSINT areas.
03 Aug 2026
★ 66
The "Awesome AI Agent Attacks" repository provides a curated timeline of real-world security incidents involving AI agents from 2024 to 2026, detailing the specific impacts, root causes, and relevant CVEs associated with each breach. It serves as a factual resource, compiling numerous documented cases to facilitate a better understanding of AI-related vulnerabilities and attack patterns, while emphasizing transparency through sourced entries. Notable features include categorized incident summaries by year, key statistics, and an attack pattern taxonomy.
03 Aug 2026
Python
★ 260
AutoRedTeam-Orchestrator is a local-first, MCP-native automation platform designed for authorized testing and AI/MCP attack surface auditing. It features a modular security capability set accessible via an MCP Server, Python SDK, and Typer CLI, enabling static code audits, reconnaissance, and vulnerability detection primarily for research and training purposes. Notable capabilities include AI-assisted audits, configurable scanning profiles, and different export formats for audit reports, each tailored for secure and compliant usage scenarios.
03 Aug 2026
Rust
★ 29
ASHIRT Terminal Recorder (aterm) is a tool designed for recording terminal sessions in a pseudo terminal, enabling users to upload these recordings to an ASHIRT server in asciicast v3 format. Its primary use case is to facilitate session logging for review and sharing, offering features such as easy navigation through menus, session management (including renaming and discarding recordings), and a configuration system that adheres to the XDG standard. Built as a single-binary Rust application, aterm supports multiple operating systems and can be easily run using standard Rust tooling without additional dependencies.
03 Aug 2026
Go
★ 170
ASHIRT is an automated adversary simulation documentation tool designed to centralize the capture, indexing, and searchability of evidence collected during operations. Its primary use case is to streamline the process of documenting activities by providing a non-intrusive methodology that reduces manual steps and enhances sharing across teams. Notable features include support for high-fidelity data synchronization and a dedicated frontend and backend architecture for improved usability and deployment flexibility.