11 Aug 2026
Python
★ 16
Detection Labs for Palantir-Style Activity is an educational resource designed for blue team practitioners focusing on detection engineering and threat hunting. It leverages open-source tools and Sigma rules within SIEM environments to enhance competencies in cybersecurity operations, incident response, and threat intelligence analysis. Notable features include a flexible simulation environment, advanced jitter analysis for continuous monitoring, and comprehensive learning resources for SOC management.
11 Aug 2026
HTML
★ 28
CScorza is a personal GitHub profile showcasing various projects and stats related to the user's activity. It utilizes automated badges and visual elements to present information about the developer’s work and social connections, facilitating networking and project visibility. Notably, it emphasizes the integration of dynamic content to enhance presentation and engagement.
11 Aug 2026
Python
★ 28
The Nmap Scanning Tool is an interactive wrapper for Nmap that simplifies the execution of common scans and enhances readability of results. It supports multiple scan profiles, including SYN, aggressive, and vulnerability scans, along with an optional output filter to highlight open ports. The tool requires Python and Nmap to be installed on the user's system and aids in providing helpful error messages regarding user permissions and installation checks.
11 Aug 2026
Python
★ 11
XSScan is a Playwright-based automated tool designed for bug bounty hunters and security researchers to detect executed cross-site scripting (XSS) vulnerabilities. Key features include real browser execution using Chromium, intelligent form submission, recursive crawling, and auto-generated reports of confirmed XSS findings, ensuring focus on vulnerabilities that are genuinely executed rather than merely reflected.
11 Aug 2026
Python
★ 68
The tool exploits the vulnerability CVE-2025-55182 to achieve remote code execution through prototype pollution in Next.js React Server Components. Its primary use cases include executing arbitrary commands or establishing a reverse shell on a target server, with features for specifying various listener and payload options. Additionally, a lab environment is provided for testing the exploit in a controlled Docker setup.
11 Aug 2026
Python
★ 154
The CVE-2023-22515 exploit script is designed to target and exploit the critical Broken Access Control vulnerability in Confluence Server and Data Center instances, enabling unauthorized access. It offers two operational modes: Normal for single-target exploitation via a provided URL, and Mass for bulk processing using a list of target URLs from a file, with output detailing the success of the exploitation attempts. Notable features include real-time logging of the exploitation process and clear output indicating whether unauthorized access was achieved.
11 Aug 2026
Ruby
★ 18
Windfall is an exploitation framework that targets critical vulnerabilities in Windmill and Nextcloud Flow, specifically focusing on unauthenticated path traversal and authenticated SQL injection vulnerabilities. Its primary use case is to demonstrate how these vulnerabilities can lead to credential leaks and remote code execution, thereby enabling an attacker to exploit the affected systems. Notable features include a comprehensive assessment of the vulnerabilities' impact with high CVSS scores and detailed analysis of attack vectors, enhancing the tool's utility for security researchers and penetration testers.
11 Aug 2026
Python
★ 260
The CVE-2026-21858 tool demonstrates a full exploitation chain involving unauthorized arbitrary file read (AFR) and remote code execution (RCE) in the n8n automation platform. By leveraging content-type confusion and expression injection vulnerabilities, it allows an attacker to forge admin tokens and execute commands with critical impact. Key features include automated exploitation via a Python script and specific exploit requirements, such as vulnerable configurations of n8n workflows.
11 Aug 2026
Kotlin
★ 319
Root My Pixel is an Android application that automates the acquisition of temporary root access on Google Pixel devices using the NebuSec IonStack exploit (CVE-2026-43499) and integrates with ReSukiSU / KernelSU. It employs a sophisticated installation workflow for device detection and exploit execution while providing real-time log monitoring and management features like soft reboot and log exporting. This tool specifically targets a range of supported Pixel models and requires prerequisites such as the Shizuku service and ReSukiSU Manager for optimal functionality.
11 Aug 2026
Java
★ 13
OpenLPX is an anti-packet exploit tool designed for Minecraft servers, focusing on protecting against crash packet exploits, specifically NettyCrasher attacks, without requiring any external dependencies. Key features include a smooth packet limiter with a configurable violation system, advanced packet logging capabilities for analyzing potential exploits, and compatibility with Minecraft mods like Printer and Schematica, ensuring minimal disruption to player experiences. The tool provides detailed configuration options to tailor protection measures while allowing for real-time alerts and server management commands.
11 Aug 2026
Go
★ 48
pgread is a tool designed to extract data from PostgreSQL databases without requiring user credentials, leveraging direct access to database files. It facilitates a range of output formats, such as JSON, SQL, and CSV, and includes features for password extraction, secret detection, and WAL (Write-Ahead Logging) analysis. Additionally, it supports low-level forensic operations like parsing database control files and recovery of deleted rows, making it adept for both security audits and database recovery tasks.
11 Aug 2026
TypeScript
★ 11
Kali + OpenCode Portable Pentest USB is a bootable USB solution that integrates Kali Linux Live with a suite of AI-driven penetration testing tools. Its primary use case is to provide a comprehensive and portable pen-testing environment that automates workflows, maintains documentation, and operates without leaving traces on host systems. Notable features include persistent storage for configurations, an autonomous pentesting plugin called Shannon, and support for a variety of tools streamlined for efficient security assessments.
11 Aug 2026
Go
★ 10
CeWL AI is an advanced reconnaissance tool designed to crawl various protocols including HTTP, FTP, SFTP, SMB, and S3, extracting valuable information such as emails, metadata, credentials, and secrets. It combines functionalities of traditional tools like CeWL and CUPP, offering features such as AI-powered wordlist generation, password mutation, multi-protocol support, and secret scanning, all implemented in a single Go binary. This tool enhances security assessments by facilitating in-depth data extraction and analysis in one command.
11 Aug 2026
C
★ 15
Slave I is an offensive-security firmware specifically designed for the M5Stack Tab5, facilitating wireless research through an integrated toolkit for Wi-Fi, BLE, and 802.15.4 recon and attack capabilities. Notable features include a touch UI, a physical-keyboard workflow, extensive scanning and capturing functions, and a desktop emulator for development. It allows users to implement advanced wireless attacks while emphasizing ethical usage and compliance with legal standards.
11 Aug 2026
★ 43
This repository offers a curated collection of over 70 free cybersecurity books organized by domain and difficulty, facilitating self-paced learning in various cybersecurity disciplines. Notable features include a structured learning roadmap progressing from beginner to advanced levels, an emphasis on community maintenance for up-to-date resources, and a direct link to an extensive Google Drive library containing the materials.
11 Aug 2026
Python
★ 27
Red-Team AI is a white-box red teaming tool designed specifically for agentic AI applications, capable of reading source code to identify vulnerabilities that are unique to a particular technology stack. Its primary use case involves generating tailored attacks based on an application's specific implementation, rather than relying on generic adversarial prompts. Notable features include a modern React dashboard for scan management and compliance tracking, as well as integrations with popular agent frameworks, facilitating extensive security assessments and risk assessments for AI systems.
11 Aug 2026
Python
★ 15
ShadowRAT is a Telegram-based Remote Access Trojan designed for Windows that provides complete remote control of a machine using Telegram bot commands with password authentication. Primarily targeted at cybersecurity professionals, security researchers, and educators, it serves to demonstrate RAT functionalities, enhance malware detection techniques, and facilitate authorized penetration testing in controlled environments. The tool emphasizes responsible use solely for educational and research purposes, providing insights into attacker methodologies and improving defensive security measures.
11 Aug 2026
★ 49
The Penetration Testing Roadmap is a comprehensive, self-paced 60-week curriculum aimed at developing expertise in penetration testing, ethical hacking, and network security. It features structured learning paths, hands-on practice through over 500 free labs, and an extensive tools directory, enabling learners to transition from novices to market-ready professionals. Additionally, it encompasses crucial topics such as web application vulnerabilities and emerging cybersecurity trends.
11 Aug 2026
Shell
★ 21
OSINT Skills is an open-source intelligence tool designed to facilitate automated investigations by agents like Cursor and Claude. It provides 28 customizable skills for various reconnaissance tasks, enabling users to pivot across data points such as emails, domains, and social accounts, all while generating reports with source citations and confidence levels. Key features include pre-defined workflows, individual techniques for advanced inquiries, and comprehensive reference materials for effective tradecraft in OSINT.
11 Aug 2026
Shell
★ 127
CamSniff is an automated reconnaissance toolkit designed for discovering and profiling IP cameras and network video streams within local networks. It employs both active and passive scanning methods to generate structured and auditable datasets, while enabling users to acquire snapshots and streams from various protocols, including RTSP and ONVIF. Notable features include its mode-aware scanning capabilities, multi-protocol support, and the ability to produce comprehensive output formats such as structured JSON files and logs.
11 Aug 2026
Python
★ 65
NoiseHound is a detection-aware Active Directory attack-path scoring tool that enables cybersecurity operators to identify the quietest routes to administrative control within a network, leveraging BloodHound graph data. Its primary use case is for operational security (OPSEC) planning in authorized engagements, providing better risk assessments by incorporating expected detection costs instead of just hop counts. Notable features include support for multiple detection tiers, a calibration harness to measure edge effectiveness, and the ability to ingest various data formats for comprehensive path analysis.
11 Aug 2026
Ruby
★ 10
The OpenVAS add-on for Dradis facilitates the integration of OpenVAS vulnerability assessment results into the Dradis framework by allowing users to upload OpenVAS XML files. Its primary use case is to create a structured representation of security findings, including nodes and notes corresponding to hosts, ports, and services. Notable features include support for OpenVAS v6 and v7 output, enhancing the usability of security reports within Dradis CE and Dradis Pro environments.
11 Aug 2026
★ 12
Cyber Security Sources is a comprehensive repository that aggregates various resources, methodologies, and checklists pertinent to distinct fields of cybersecurity. Its primary use case is to provide practitioners with a centralized reference for best practices and tools in cybersecurity. Notable features include curated lists that facilitate efficient resource identification and access for cybersecurity professionals.
11 Aug 2026
Go
★ 29
The "BSCP Exam Guide by N3OARI 2026" repository provides a comprehensive collection of personal cheatsheets and methodologies tailored for the BSCP exam, encompassing key topics and relevant labs. Notable features include organized content that facilitates learning through practical examples, alongside recommended resources for each phase of the exam focused on web security vulnerabilities and exploitation techniques. This tool serves as a structured guide for preparing for the BSCP exam, emphasizing the importance of creating individualized study materials.
10 Aug 2026
CycloneDX is a comprehensive Bill of Materials (BOM) standard designed to enhance supply chain security by providing detailed inventory and risk assessment frameworks across various domains, including software, hardware, and machine learning. It supports multiple BOM types such as Software Bill of Materials (SBOM), Hardware Bill of Materials (HBOM), and Vulnerability Disclosure Reports (VDR), and conforms to ECMA-424, ensuring broad applicability and standardization. Notably, CycloneDX offers a range of schema implementations and is supported by a community-driven Tool Center for resources and integrations.