03 Aug 2026
Shell
★ 168
XSSRocket is a cybersecurity tool designed for conducting offensive security assessments, primarily focusing on Cross-Site Scripting (XSS) vulnerabilities. It leverages the Wayback Machine to retrieve and filter URLs, uses httpx for live URL verification, and employs a remote XSS payload list to perform GET requests, potentially exposing vulnerabilities. Notable features include stealth mode scanning, automated result storage, customizable payload lists for other injection types, and a user-friendly interface that enriches the output with random security quotes.
03 Aug 2026
★ 27
The WordPress BugBounty tool is designed for educational purposes to assist security researchers in identifying high-impact vulnerabilities within WordPress sites. It catalogues common attack surfaces and vulnerabilities such as SQL Injection, Remote Code Execution, and Authentication Bypass, providing insights into exploiting these flaws via the REST API and various plugin endpoints. Notable features include detailed descriptions of vulnerabilities and links to relevant resources for further learning in WordPress security.
03 Aug 2026
★ 102
The Wireless Security & WiFi Penetration Testing course offers an advanced, lab-driven educational experience aimed at mastering wireless security testing and attack techniques against Wi-Fi networks. It covers a comprehensive range of topics including 802.11 standards, encryption methods, various cracking techniques, and wireless penetration testing methodologies, all delivered through practical, hands-on labs. Noteworthy features include configuration guidance for wireless adapters, ethical attack methodologies, and a focus on both offensive and defensive strategies, ensuring learners can apply knowledge directly to real-world scenarios.
03 Aug 2026
Python
★ 1170
WifiForge is a tool designed to provide a safe and legal environment for learning WiFi hacking, built on the Mininet-WiFi framework. It automates the setup of networks and necessary tools to conduct various WiFi exploitation labs, eliminating the need for extensive hardware and overhead. Key features include easy installation, detailed documentation, and a focus on educational use for cybersecurity professionals.
03 Aug 2026
Shell
★ 422
WiFiChallengeLab-docker is a containerized environment designed for security practitioners to simulate and practice WiFi attacks on various types of networks, including OPN, WPA2, WPA3, and Enterprise setups. It features a range of updated challenges with new attack vectors, such as WPA3 brute-force and captive portal evasion, alongside enhanced stability by using Docker instead of nested virtual machines. The tool also incorporates nzyme for monitoring and detection, making it a comprehensive solution for hands-on learning in WiFi security.
03 Aug 2026
PHP
★ 60
WebVulnLab is a comprehensive learning platform designed for identifying and exploiting web vulnerabilities within a controlled and secure environment. It features more than 30 types of vulnerabilities for practical training, an enhanced user-friendly interface for easier management of Docker containers, and a control panel for overseeing active containers, ensuring an effective ethical hacking practice.
03 Aug 2026
Python
★ 22
WebAnalyzer v3.6.2 is a professional-grade cybersecurity platform designed for advanced domain analysis, vulnerability assessment, and intelligence gathering. It features enterprise bulk processing capabilities, allowing users to analyze thousands of domains efficiently with a MySQL-backed queue system, AI-powered analysis modules, and enhanced stealth techniques. Notable features include real-time metrics, comprehensive reporting, and scalable architecture that supports dynamic resource management and concurrent processing.
03 Aug 2026
Python
★ 75
web2shell is a Python tool designed to automate the conversion of webshells into reverse shells, streamlining the process often required in Capture The Flag (CTF) competitions, Hack The Box (HTB) challenges, and red team exercises. Its notable features include a customizable command interface, the ability to specify local listener settings, and support for various payloads that can be easily extended. The tool is primarily intended for use with Linux machines and facilitates quick testing and execution of reverse shells from web-based vulnerabilities.
03 Aug 2026
PHP
★ 12
VexiumCTF is an intentionally vulnerable web application framework designed for security training and education. It facilitates hands-on practice with security vulnerabilities through Docker or XAMPP setups, featuring a web interface and a database management system via phpMyAdmin for effective experimentation. Key functionalities include easy configuration for SQL initialization and comprehensive logs to aid analysis during testing sessions.
03 Aug 2026
Go
★ 24
urlX is a high-performance reconnaissance tool for bug bounty hunters, penetration testers, and security researchers, facilitating passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling for hidden endpoints. Its key features include smart file and extension filtering, concurrent processing using Go routines, and optional integration with various API keys to enhance results. Designed for swift and effective attack surface identification, urlX requires minimal setup and is built for real-world reconnaissance workflows.
03 Aug 2026
Python
★ 34
TransparentTorProxy (TTP) is a Linux command-line tool designed to route all system traffic transparently through the Tor network using nftables, thereby enhancing user privacy without requiring per-application configuration. Key features include zero DNS leaks through kernel-level handling, a fail-closed design that secures network routing during failures, and the use of volatile memory to ensure no persistent data is left on the system. TTP offers a modern solution for users seeking to anonymize their internet traffic effortlessly.
03 Aug 2026
Python
★ 56
Touti Cracker is a cross-platform ethical hacking toolkit designed for educational purposes, featuring capabilities for password cracking, WiFi auditing, and reverse shell payload generation to illustrate system vulnerabilities. Notable features include an enhanced neon-styled user interface, automatic Hashcat setup, error handling enhancements, and compatibility with multiple operating systems, making it a comprehensive tool for security professionals and educators.
03 Aug 2026
C#
★ 37
TheSprayer is a cross-platform tool designed to help penetration testers spray passwords against an Active Directory domain without locking out accounts.
03 Aug 2026
Shell
★ 337
TerminatorZ is an Offensive CVE Exploitation Framework specifically designed for red teamers and offensive security professionals, focusing on active exploitation rather than mere vulnerability scanning. It automates reconnaissance across multiple sources, validates live endpoints, and executes 31 deterministic CVE checks, providing real-time feedback with zero false positives and proof-of-concept URLs for confirmed vulnerabilities. With its modular Bash architecture and unique features like asset-type intelligence and production-quality reporting, TerminatorZ streamlines the exploitation process for faster and more credible results.
03 Aug 2026
Python
★ 40
SSRF-Scanner is an advanced tool designed to identify Server-Side Request Forgery (SSRF) vulnerabilities through 14 comprehensive attack phases, emphasizing speed and accuracy. Leveraging asynchronous processing for up to 200 concurrent requests and featuring real confirmation via a self-hosted callback listener, it effectively distinguishes genuine vulnerabilities from false positives. The tool also provides extensive reporting capabilities in various formats and supports custom payloads and CVE probes, making it a versatile asset for security assessments.
03 Aug 2026
Shell
★ 163
SQLMutant is a mutation testing tool designed for Red Teams and Bug Bounty Hunters that automates the process of identifying SQL injection vulnerabilities within a specified domain. It leverages tools like Waybackurls, HTTPX, Arjun, and SQLMAP to perform domain enumeration, URL fetching, and SQL injection testing, while providing various fuzzing capabilities for URLs, headers, and form data. Notable features include integration with historical web page archives and aggressive parameter extraction to enhance vulnerability detection.
03 Aug 2026
Clojure
★ 640
SQLiDetector is a Python-based tool designed to identify SQL injection vulnerabilities using error-based methods. It systematically tests target URLs by sending a variety of payloads, while leveraging regex patterns specific to different databases to spot potential errors. Additionally, it integrates with BurpBounty for enhanced testing capabilities across various request parameters, providing an efficient workflow for security professionals assessing web applications.
03 Aug 2026
C
★ 25
SKELETONKEY is a comprehensive Linux local privilege escalation (LPE) tool that consolidates 46 modules targeting 41 distinct CVEs from 2016 to 2026, offering both red team and blue team functionalities. It features verified exploits, automatic module selection based on safety, detection rules for security audit logging, and a scanning capability for system administrators to identify unpatched vulnerabilities. This tool is designed for authorized testing only, ensuring ethical hacking practices while providing robust functionality for pentesters and system administrators alike.
03 Aug 2026
Go
★ 95
Secbutler is a utility tool designed for penetration testers, bug bounty hunters, and security researchers, streamlining common tasks in cybersecurity assessments. It includes features such as generating reverse shell commands, setting up proxies, downloading payloads, and managing wordlists, thus enhancing productivity during security audits. The tool aims to cater to community needs, welcoming suggestions and contributions for continuous improvement.
03 Aug 2026
Shell
★ 77
ScopeHunter is a targeted reconnaissance tool designed for Red Teams and bug bounty hunters, leveraging up-to-date databases from platforms like HackerOne, BugCrowd, Intigriti, and YesWeHack to facilitate efficient target discovery. Its key features include an intuitive command-line interface, rapid execution, and access to the latest bug bounty program data. The tool is compatible with major operating systems, making it an essential asset for security professionals seeking to streamline their target identification process.
03 Aug 2026
Go
★ 126
RUDY (R-U-Dead-Yet?) is a Denial of Service tool designed for executing low-rate "slow and low" attacks that target web servers by sending long form data in small packets at a slow rate. Its interactive console facilitates user-friendly operation, allowing users to simulate concurrent POST requests with customizable parameters such as request intervals, payload sizes, and the ability to use a TOR proxy for anonymity. This tool is primarily intended for educational and testing purposes to analyze server behavior under resource-saturation attacks.
03 Aug 2026
★ 97
The Robot Security Framework (RSF) provides a standardized methodology for conducting security assessments specifically in robotic systems. Its primary use case is to identify and address vulnerabilities related to communication ports, ensuring adequate protection against potential physical and cyber threats. Notable features include comprehensive criteria for evaluating both external and internal communication ports, along with recommendations for inspection methods to ascertain security measures.
03 Aug 2026
HTML
★ 30
RRW (Rick Roll WiFi) is a prank tool that sets up a rogue access point designed to capture captive portal probes and serve a fake Wi-Fi login page that redirects connected devices to a rickroll video. It utilizes standard network utilities like `hostapd`, `dnsmasq`, and `iptables` to manage the AP and traffic redirection without collecting credentials or intercepting user data, making it a non-malicious tool meant for entertainment. Users can customize the SSID, video, and HTML templates, allowing for tailored rickroll experiences.
03 Aug 2026
C++
★ 12
Pwning OpenEDR is a vulnerability research tool that identifies and showcases high-severity flaws in OpenEDR version 2.5.1, emphasizing reproducible exploits for security assessments. Notable features include detailed CVSS scoring for various vulnerabilities, comprehensive runtime proof evidence, and a structured approach for reproducing each advisory in a controlled environment. This tool is particularly useful for security researchers evaluating endpoint detection and response (EDR) solutions for potential weaknesses.
03 Aug 2026
Python
★ 172
`pwneye` is an offensive security tool designed for interacting with IP cameras that support ONVIF and RTSP protocols, streamlining various tasks such as discovery, authentication testing, metadata collection, and stream validation through a single command-line interface. Notable features include multithreaded bruteforce attacks for credential guessing, ONVIF device enumeration, RTSP stream handling, and a dedicated live preview client, all aimed at facilitating security assessments of surveillance systems.