03 Aug 2026
Python
★ 60
Temodar Agent is an AI-powered security analysis platform specifically designed for WordPress plugins and themes, offering security researchers an efficient mechanism for vulnerability assessment. Key features include risk-based target prioritization, Semgrep-powered static analysis, and AI-assisted investigation workflows that maintain context throughout the review process. Built as a local-first Docker application, it supports multi-provider LLM orchestration and facilitates structured code reviews to enhance vulnerability triage.
03 Aug 2026
Go
★ 13
Techfinder is a high-performance technology detection tool developed in Go, designed to identify web technologies and frameworks—including dynamically loaded JavaScript frameworks—using a headless browser with a reusable browser pool for enhanced scanning speeds. It features multi-threaded processing, various output formats (plain text, JSON, CSV), Discord integration for real-time alerts, and robust configuration options for large-scale scans. Key capabilities include a fast static detection mode, crash-safe resume functionality, and automated downloading of necessary fingerprint data on first use.
03 Aug 2026
Go
★ 33
Tacos is a tool designed to facilitate the creation of interactive reverse shells with minimal prerequisites, specifically targeting environments lacking the socat utility. It leverages containerization for easy deployment while offering advanced configuration options, automatic detecting of default shells, and a built-in multi-handler listener feature. Notably, Tacos allows users to obfuscate connections and easily expose listeners to the internet, enhancing accessibility and stealth during penetration testing activities.
03 Aug 2026
Python
★ 13
SpectreWeb AI is an advanced MCP server facilitating AI-assisted manual web penetration testing, which enables operators to leverage AI tools for reconnaissance, payload generation, and response analysis while maintaining direct control over testing strategies. Its notable features include context-aware payload creation, built-in WAF bypass capabilities, and session persistence for findings across multiple targets. This tool is designed to overcome challenges presented by traditional blind scanning techniques, optimizing the testing process for bug bounty hunters and security professionals.
03 Aug 2026
PowerShell
★ 150
SnafflerParser is a parsing tool designed to process the output from Snaffler, generating user-friendly reports in various formats (TXT, CSV, HTML, JSON) for easier analysis of large datasets. Key features include interactive HTML reports with filtering, dynamic sorting, keyword highlighting, review workflows, and pagination, along with the ability to export processed results and maintain state between sessions. The tool enhances visibility and manageability of Snaffler output, making it suitable for large environment assessments.
03 Aug 2026
Python
★ 571
Sippts is a comprehensive suite of tools designed for auditing VoIP servers and devices utilizing the SIP protocol, allowing security professionals to assess vulnerabilities within their own systems or those they are authorized to test. Key features include a fast SIP scanner, options for enumerating SIP extensions, capabilities for password cracking and message sending, as well as exploit functionalities for specific vulnerabilities like SIP Digest Leak. The tool is written in Python and is freely available for modification and distribution.
03 Aug 2026
Shell
★ 571
The Samurai Web Training Framework (SamuraiWTF) is a virtual machine framework designed for quickly setting up training environments containing various security tools and intentionally vulnerable applications. Its primary use case is to facilitate cybersecurity training by enabling instructors to create and distribute configured virtual machine images, using tools such as OWASP ZAP and Juice Shop. Notable features include integration with the Samurai Katana project for streamlined tool management and support for deployment on platforms like VirtualBox and Hyper-V.
03 Aug 2026
PowerShell
★ 56
RTI-Toolkit is an open-source PowerShell toolkit designed for executing and defending against Remote Template Injection (RTI) attacks in Microsoft Office documents, specifically DOCX files. It features key cmdlets such as `Invoke-Template` and `Invoke-Regular`, which facilitate the implementation of malicious remote template links, while `Invoke-Identify` assists in detecting such links, positioning the toolkit as both an offensive and defensive resource in the cybersecurity landscape. Notably, the tool is referenced in the NIST National Vulnerability Database under multiple CVEs, underscoring its significance in addressing this type of vulnerability.
03 Aug 2026
Python
★ 123
RedTeam Agent is an autonomous AI-powered simulation tool designed for red teaming and penetration testing, streamlining the process of security assessments across multi-platform environments. It features 8 specialized AI agents that facilitate a comprehensive 5-phase attack methodology, alongside containerized Kali tools and a web-based GUI for managing projects and operations with minimal user interaction. Notable functionalities include an intelligent case collection pipeline and robust reporting mechanisms, allowing users to efficiently conduct security evaluations and automate repetitive tasks.
03 Aug 2026
Shell
★ 8045
**reconFTW** is an automated reconnaissance tool aimed at security researchers and penetration testers, streamlining the information-gathering process. It integrates a variety of scanning and enumeration techniques, allowing users to gather extensive details on target domains through an intuitive interface. Notable features include support for multiple platforms, Docker compatibility, and an array of built-in reconnaissance modules that enhance operational efficiency.
03 Aug 2026
Go
★ 168
QueenSono is a Golang package designed for data exfiltration utilizing the ICMP protocol for both IPv4 and IPv6. Its primary use case is to bypass network monitoring systems that do not actively inspect ICMP traffic, making it effective in environments with limited oversight, such as public Wi-Fi networks. Notable features include the ability to send and receive files using ICMP packets, and its implementation of acknowledgment mechanisms to confirm data reception.
03 Aug 2026
Python
★ 164
ProfileHound is a post-escalation tool designed for red-teaming operations that identifies domain user profiles on machines to optimize targeting for data extraction. It utilizes BloodHound's OpenGraph format to create a new edge, `HasUserProfile`, which indicates the existence of user profiles and provides metadata such as creation and modification dates, enabling operators to focus on high-value targets without requiring an active user session. The tool highlights profiles that may contain critical information, including cached credentials and other sensitive data, making it particularly useful in contemporary Active Directory environments.
03 Aug 2026
Go
★ 39
PentLog is an evidence-first pentest logging tool designed to capture high-fidelity terminal output during penetration testing engagements. Its primary use case includes providing searchable logs, compliance-ready reports, and interactive timelines for real-world auditing and engagements such as OSCP and HackTheBox. Notable features include automatic organization of commands, AI analysis for summarization, real-time session sharing, and AES-256 encryption for secure archives, addressing the common challenges faced in traditional logging methods.
03 Aug 2026
Markdown
★ 23
Pentester is an AI-driven penetration testing workflow tool designed to facilitate the systematic execution of security assessments in compliance with the PTES framework. It employs a series of predefined phases that ensures structured data outputs, including validated vulnerabilities and comprehensive client reports, while leveraging agents that can be instructed in multiple languages for accurate task execution and management of complex assessments. Notable features include a modular skill system for phase management, adherence to authorization and scope protocols, and the integration of various testing tools through Docker support.
03 Aug 2026
TypeScript
★ 181
Open Attack Surface Management (OASM) is an AI-powered, open-source platform designed to discover, monitor, and secure digital infrastructures by providing continuous asset visibility and vulnerability assessments. Notable features include automated asset discovery, a distributed scanning engine for high scalability, real-time monitoring with alert integration, and support for AI assistants to enhance data analysis and querying capabilities. The tool streamlines security workflows and risk management through customizable scanning configurations and comprehensive reporting functionalities.
03 Aug 2026
Nix
★ 407
The Nix Security Box is a curated collection of penetration testing and information security tools specifically designed for NixOS environments. It emphasizes a practical selection of actively maintained tools, combining both established and innovative options for security assessments, while allowing users to customize their toolset via Nix configuration files or shell environments. Notable features include modular imports for specific categories of tools and the ability to seamlessly create tailored development environments with desired functionalities.
03 Aug 2026
Dockerfile
★ 315
Nightingale is a comprehensive Docker toolkit designed for penetration testing and security research, providing a reproducible multi-architecture environment with curated tools for various workflows, including web, network, mobile, and OSINT. Notable features include a browser-based terminal for easy access, community-driven tool enhancements, and integration with security-focused CI tools like Trivy. The project facilitates rapid setup and customization, allowing users to tailor the environment to specific testing needs or internal usage.
03 Aug 2026
Python
★ 36
The Neo C2 Framework is a modular post-exploitation framework designed for red team operations and security testing, facilitating collaborative agent management through a server-client architecture. It features real-time multiplayer capabilities, proxy support, a sophisticated task orchestrator, and robust security measures including encrypted communication and role-based access control. Neo also allows for extensive customization through its multi-operator extension module system, enabling operators to integrate their own modules seamlessly.
03 Aug 2026
Python
★ 92
The Mobile Pentest Toolkit (MPT) is an integrated solution designed for automating and streamlining Android penetration testing workflows, enabling users to conduct comprehensive security assessments without needing to manually manage individual tools. Notable features include a full suite of required tools for security checks, local tool installation, support for ADB, the ability to disable SSL pinning and root detection, and project-based assessments that provide a cohesive interface for launching various security tools efficiently.
03 Aug 2026
Shell
★ 38
Medusa is a Bash-based orchestration toolkit designed to deploy and manage 35 open-source cybersecurity tools through an interactive menu or command line interface. Its primary use case encompasses environments for Security Operations Center (SOC), Governance, Risk Management, and Compliance (GRC), among others, with notable features such as environment isolation via Docker, pure Bash execution without runtime dependencies, and the ability to run each tool in its own dedicated directory.
03 Aug 2026
Go
★ 17
LLMrecon is an advanced security testing framework specifically designed to identify and exploit vulnerabilities in Large Language Models (LLMs), adhering to the OWASP Top 10 2025 guidelines. It features a variety of novel attack techniques such as FlipAttack and DrAttack, along with machine learning-optimized attack selection, comprehensive defense detection capabilities, and support for testing models from multiple platforms, making it suitable for enterprise-level deployment.
03 Aug 2026
Python
★ 14
ldapviewer is a tool designed for converting LDAP and Active Directory JSON exports into a modern, interactive web-based interface that enhances the penetration testing process. It features comprehensive views of LDAP attributes, an advanced filtering system for significant data, a statistics dashboard focusing on security metrics, and the ability to parse DACLs directly from JSON dumps, streamlining the analysis of potential attack paths without requiring additional queries.
03 Aug 2026
★ 102
Kali-pentest is a sophisticated penetration testing tool designed for AI agents, leveraging Kali Linux and enabling autonomous attack planning and execution. It consolidates 269 command-line tools across various categories, features built-in coverage matrices, and employs zero-findings fallbacks along with human approval gates for high-risk actions, ensuring comprehensive and ethical testing processes. By connecting to environments via SSH or Docker, this tool adapts its strategies based on target assessments and generates structured reports for clarity and compliance.
03 Aug 2026
JavaScript
★ 18
JSpider is an advanced JavaScript-based crawler and endpoint discovery tool designed for security researchers, facilitating the extraction of hidden API routes, sensitive parameters, and hardcoded secrets directly from websites. Notable features include automated checks for over 500 critical paths, parameter discovery, recursive crawling, high-fidelity secret detection for 40 patterns, and seamless authentication header handling to access secured endpoints. The tool operates entirely client-side, offering real-time tracking and analysis of extracted data in a straightforward dashboard.
03 Aug 2026
Go
★ 10336
httpx is a versatile and high-performance HTTP toolkit designed for probing web services effectively. Its primary use case focuses on conducting a variety of HTTP-based checks such as status codes, content length, and various headers, equipped with features like smart fallback from HTTPS to HTTP, multi-threading, and error handling for WAFs. With a modular code base and customizable flags, httpx allows users to efficiently gather information from URLs, IPs, or CIDR networks while automatically managing retries and backoff strategies.