Go
2026-08-30
Go
★ 16
nvidia-playgroud-go is a reverse-engineered Go client and multi-format proxy for accessing NVIDIA Build Playground's anonymous models. It supports dynamic model fetching and routing to prediction endpoints, utilizing a pure-Go hCaptcha solver for verification, and includes features such as Docker deployment and integration with the CLIProxyAPI for OpenAI completions and responses. This tool is designed for developers seeking to interface with multiple NVIDIA AI models programmatically without browser dependencies.
2026-08-28
Go
★ 31
FF-16-TUI is an interactive static analysis tool designed to identify frequently occurring local 16-bit patterns within files, aiding in the analysis of file structures and layouts. It features a text user interface that allows users to navigate through patterns efficiently while providing customizable filtering options for detailed pattern analysis. Notable functionalities include command-line usage with support for dictionary files, along with keyboard shortcuts for seamless interaction throughout various analysis panels.
2026-08-28
Go
★ 2537
Fibratus is a real-time security sensor designed for threat detection and protection, leveraging a behavior-driven rule engine and YARA memory scanning to analyze a wide range of system events. Its notable features include the ability to route events to various output sinks for further analysis, support for custom tool integration via filaments, and forensic capabilities to assist in understanding and responding to security incidents. The tool emphasizes real-time behavior detection, memory scanning, and comprehensive forensic analysis to combat advanced malware and attacker tactics.
2026-08-27
Go
★ 105
The SpiceDB Operator is a Kubernetes operator designed for managing SpiceDB clusters, enabling the creation, management, and scalability of these clusters through a single Custom Resource. Notable features include automated datastore migrations during version upgrades, as well as simple integration with Kubernetes tools using YAML configurations. This tool streamlines the deployment and configuration of SpiceDB, leveraging Kubernetes' orchestration capabilities.
2026-08-26
Go
★ 22
Defango is a Golang tool designed for defanging URLs, IP addresses, and emails to neutralize Indicators of Compromise (IoCs) for safer analysis and sharing. Its primary use case is to convert potentially harmful IoCs into harmless formats for security practitioners. Notable features include easy integration and usage through its package methods, enabling users to sanitize malicious content seamlessly.
2026-08-26
Go
★ 43
IFDA is a tool designed for automated reverse engineering and vulnerability discovery in IoT firmware binaries, supporting the analysis of ELF files and extracted firmware trees. It features a bilingual web UI, integrates with existing tools like Capstone and PyELFTools for disassembly and ELF parsing, and offers a structured output for findings, including severity and vulnerability classifications. The architecture includes a Python analysis core and a Go service layer for orchestration, ensuring efficient task management and live progress tracking.
2026-08-25
Go
★ 234
GitAlerts is a tool designed to detect and monitor public repositories created under organization user accounts, which cannot be controlled by GitHub administrators. It provides features such as secrets detection using TruffleHog and Gitleaks, monitoring for new repository creation, and integration with Slack for notifications, all while offering both a command-line interface and a web platform with advanced search capabilities, filtering, and asynchronous scanning.
2026-08-24
Go
★ 14
The VanMoof BMS Toolkit is a diagnostic and control utility designed for managing VanMoof DynaPack BMS batteries across various bike models. It enables users to interact with the battery management system via Modbus/UART or CAN interfaces, offering functionalities such as real-time data display, calibration, and log management. Notable features include support for multiple hardware configurations, a range of commands for battery operations, and the ability to export logs for analysis.
2026-08-23
Go
★ 20
Vex8s is a tool that generates VEX documents by analyzing container vulnerabilities and correlating them with Kubernetes security settings to assess the exploitability of CVEs within workloads. It utilizes machine learning models to classify vulnerabilities and determine mitigable conditions based on Kubernetes configurations, offering both passive and active scanning modes for versatility. Notable features include integration with existing vulnerability scanners like Trivy and Grype, facilitating the suppression of reported vulnerabilities based on real-time assessments.
2026-08-23
Go
★ 165
Zanadir is a tool designed to analyze CI/CD setups within repositories, providing enhancements and suggestions for security practices and best practices across various supported CI actions including GitHub Actions, CircleCI, and GitLab. It features a repository scanning capability that identifies issues in categories such as software composition analysis, secrets detection, and static application security testing, with customizable output formats including table, JSON, and SARIF for integration with other tools. Contributions to further enhance its features are encouraged within the open-source community.
2026-08-23
Go
★ 10
msarjun is a high-performance tool that enhances Arjun by enabling mass-scale parameter discovery through concurrent scanning of multiple URLs. Its primary use case is for efficient vulnerability assessment, significantly reducing execution time with features like automatic wordlist setup, multiple output formats, and optimized performance for extensive URL targeting. Notable features include configurable concurrency, output management for seamless tool integration, and a user-friendly command-line interface.
2026-08-21
Go
★ 38
Boggart is a low-interaction experimental honeypot designed for mimicking specific host behaviors to attract and analyze potential threats in a home lab environment. Its notable features include a customizable configuration via `config.yaml`, support for multiple open ports (including a honeypot, dashboard, and API service), and deployment capabilities using Docker. This tool serves primarily for educational and experimental purposes, providing insights into attacker behaviors without being intended for professional or industrial use.
2026-08-21
Go
★ 74
The Converged Security Suite is a comprehensive toolkit designed to implement and validate security features for Intel platforms, including Intel Trusted Execution Technology and Intel Boot Guard. Its primary use case involves providing both testing and provisioning capabilities for various Intel security features, along with support for some AMD Secure Processor functionalities. Notable features include dedicated test suites for validation and the ability to provision multiple security technologies, ensuring enhanced platform integrity and security compliance.
2026-08-20
Go
★ 211
Kontext is a runtime governance tool designed for AI agents that enables local policy decisions, pre-action enforcement, and maintains an authorization ledger. It captures tool-use events, evaluates policies prior to action execution, and provides mechanisms for recording decisions, facilitating a balance between security and agent utility. Key features include local enforcement of policies, an observation mode for testing policy impacts, and compatibility with various execution environments, ensuring that security actions are seamlessly integrated into AI workflows without constant reliance on external services.
2026-08-19
Go
★ 20
WPRecon is a WordPress reconnaissance and vulnerability scanning tool that leverages a YAML-driven template architecture for efficient vulnerability detection and configuration assessment in WordPress installations. Notable features include parallel scanning with configurable worker pools, a library of over 150 templates for comprehensive coverage, and dynamic variable resolution, offering flexibility for security engineers to extend capabilities without recompilation. The tool supports both command-line and API interfaces, allowing for versatile integration into security workflows.
2026-08-17
Go
★ 84
MORF is a Mobile Reconnaissance Framework designed for offensive security, specifically engineered to discover hardcoded secrets within compiled mobile application artifacts (Android `.apk` and iOS `.ipa`). Unlike traditional source code scanners, MORF operates on the final shipped binaries, utilizing a robust detection engine to verify the presence and activity of secrets, while also generating Software Bills of Materials (SBOM) and Common Vulnerability and Exposure (CVE) reports. Key features include a scalable service architecture, continuous integration (CI) compatibility, and compatibility with leading security standards such as SARIF and OWASP MASVS.
2026-08-17
Go
★ 52
Drop is a productivity-focused sandboxing tool for Linux that enables users to create isolated environments for executing programs and LLM agents while maintaining access to their existing work environment. Notable features include the use of Linux mount namespaces for an independent root filesystem, selective read-only access to user configuration files, and customizable TOML configuration files that specify which directories and files are mounted into the sandbox. This setup allows for secure, disposable workspaces that restrict processes and network access to enhance security and contain potential threats.
2026-08-16
Go
★ 102
url.vet is an open-source phishing detection engine designed to analyze URLs and domains, providing users with a trust score, detailed verdicts, and comprehensive security reports in real time. Key features include instant live scanning using 18 concurrent analyzers and 33 individual signals, an explainable scoring system devoid of black-box machine learning, as well as integrations for a REST API, web UI, and a Chrome extension, making it a developer-friendly alternative to existing services like VirusTotal.
2026-08-15
Go
★ 54
_rlapi_ is a Go SDK that provides access to Rocket League's internal APIs through a reverse-engineered framework, enabling functionalities like authentication, item shop access, player stats retrieval, and match history. It includes capabilities for traffic interception using Frida for dynamic instrumentation and features a MITM proxy to log API requests and responses while managing authentication tokens. The library allows developers to manipulate network traffic and reconstruct HTTP and WebSocket requests, although not all API endpoints are fully documented.
2026-08-14
Go
★ 186
Frizbee is a command-line tool that generates checksums for GitHub Actions and container images based on tags, ensuring the integrity of the respective contents. It provides robust functionalities for replacing action references within GitHub workflows and validating container images by resolving their checksums. Notable features include dry-run mode for previewing changes, integration as a GitHub Action, and a library that facilitates tag and checksum operations programmatically.
2026-08-14
Go
★ 22
Gemtracker is an interactive terminal UI tool designed to analyze Ruby gem dependencies and detect security vulnerabilities within projects. Key features include a tab-based interface for visualizing dependency trees, real-time gem search, CVE reporting, and group-based analysis, along with JSON export capabilities for integration with automated systems and AI tools. This tool enhances the management of gem versions and prioritizes security fixes, making it ideal for developers aiming to maintain safe and up-to-date Ruby applications.
2026-08-13
Go
★ 16
OBLITERATUS is an advanced red teaming framework designed for post-exploitation research and defensive evasion in Windows environments. It features a multi-layered stealth architecture for evasion, low-level syscall execution, and identity correlation through its Identity Nexus module, allowing for the bypassing of MFA and efficient credential management. Key capabilities include memory hardening, automatic UAC elevation, and a sophisticated operational interface that facilitates real-time process management and forensic analysis.
2026-08-12
Go
★ 63
Unleash is a comprehensive operator toolkit designed for managing local coding agents, providing functionalities for installation discovery, in-place binary patching, and configuration of operator authorization. It ensures the integrity and performance of tools like Claude Code and OpenAI Codex through features such as multi-install awareness, update survival mechanisms, and a robust safety model that includes timestamped backups and verification processes. With a flexible architecture that supports various platforms, Unleash enhances the operational capabilities of coding agents while safeguarding against disruptions during updates.
2026-08-12
Go
★ 45
deps.cloud is a dependency management tool designed to analyze and provide insights into the libraries and projects utilized within a software system by extracting data from common manifest files such as `pom.xml`, `package.json`, and `go.mod`. Its primary use case includes answering specific dependency-related queries, such as identifying library versions and tracking open-source library usage across projects. Notable features include comprehensive dependency detection, a supportive community for development, and various workflows for project maintenance, although the project is currently in maintenance mode due to low community engagement.
2026-08-12
Go
★ 24
Siren is a desktop operator workbench designed for the Sliver C2 framework, enabling offensive security professionals to manage and execute operations within a native application environment. Notable features include comprehensive agent management with real-time session control, robust server management capabilities, and an integrated automation system for executing scripts and rules. The tool emphasizes user-friendly interaction through a customizable interface, command palettes, and extensive file manipulation functionalities for effective tactical operations.
2026-08-12
Go
★ 71
`blackstork-cli` is a source-available, headless execution engine designed for automating cybersecurity and compliance reporting through the use of BlackStork templates. It facilitates the extraction of structured data from various external tools, evaluates template logic, and renders formatted documents, enabling engineers to version control their reporting workflows and execute them locally or within CI/CD pipelines. Notable features include modular design for data querying and content drafting, extensive plugin support for integration with external APIs and services, and a library of production-ready templates for diverse cybersecurity applications.
2026-08-11
Go
★ 33
Reconner is a self-hosted reconnaissance tool designed for bug bounty hunters and security researchers, facilitating comprehensive web and network scanning from a single dashboard. It offers a full pipeline of discovery, vulnerability assessment, and continuous monitoring without relying on third-party services, ensuring that all data remains on the user's system. Notable features include real-time logging, native context-aware DAST for multiple vulnerabilities, and seamless integration with Nuclei for enhanced scanning capabilities.
2026-08-11
Go
★ 10
CeWL AI is an advanced reconnaissance tool designed to crawl various protocols including HTTP, FTP, SFTP, SMB, and S3, extracting valuable information such as emails, metadata, credentials, and secrets. It combines functionalities of traditional tools like CeWL and CUPP, offering features such as AI-powered wordlist generation, password mutation, multi-protocol support, and secret scanning, all implemented in a single Go binary. This tool enhances security assessments by facilitating in-depth data extraction and analysis in one command.
2026-08-11
Go
★ 48
pgread is a tool designed to extract data from PostgreSQL databases without requiring user credentials, leveraging direct access to database files. It facilitates a range of output formats, such as JSON, SQL, and CSV, and includes features for password extraction, secret detection, and WAL (Write-Ahead Logging) analysis. Additionally, it supports low-level forensic operations like parsing database control files and recovery of deleted rows, making it adept for both security audits and database recovery tasks.
2026-08-11
Go
★ 29
The "BSCP Exam Guide by N3OARI 2026" repository provides a comprehensive collection of personal cheatsheets and methodologies tailored for the BSCP exam, encompassing key topics and relevant labs. Notable features include organized content that facilitates learning through practical examples, alongside recommended resources for each phase of the exam focused on web security vulnerabilities and exploitation techniques. This tool serves as a structured guide for preparing for the BSCP exam, emphasizing the importance of creating individualized study materials.
2026-08-10
Go
★ 17
Teep is a local proxy tool designed to enhance privacy when interacting with AI providers by ensuring that user prompts remain unreadable to the service provider and any third parties. It achieves this by verifying the authenticity of the hardware running the AI model and encrypting the conversation, only allowing the secure environment to decrypt the messages. Notable features include support for multiple AI providers, robust attestation mechanisms, and seamless integration with any OpenAI-compatible application.
2026-08-10
Go
★ 10
Educational dependency scanner built in pure Go—parse go.mod and go.sum, inspect direct and indirect modules, query OSV for vulnerabilities, and summarize licenses.
2026-08-09
Go
★ 40
Nixis is an AI agent firewall designed to enforce real-time governance for AI coding agents like Claude Code, by intercepting and evaluating tool calls against security policies before execution. Its notable features include blocking unauthorized actions such as sensitive file access and destructive commands, along with a user-friendly installation process and an embedded real-time governance dashboard for monitoring and policy testing. This ensures external enforcement of security policies without relying on the AI model's inherent trustworthiness.
2026-08-09
Go
★ 147
The chainreactors/templates repository provides a unified set of templates for various cybersecurity tools including gogo, spray, zombie, and found, facilitating consistent configurations and rules. Notable features include a template generator for packaging YAML and rules into embedded binary data, multiple fingerprinting and vulnerability detection rules, and configurable extraction rules for sensitive data retrieval. This tool is designed to streamline the setup and integration of various security artifacts across the chainreactors ecosystem.
2026-08-09
Go
★ 376
Zombie is a lightweight service password brute-forcing tool that integrates command-line design inspired by Hydra and dictionary generation capabilities like Hashcat, tailored for red team operations. Its notable features include support for various protocols (e.g., SSH, MySQL, MSSQL), customizable password generation, and the ability to perform targeted brute-forcing based on user-specified input files. This makes it a versatile solution for security assessments and penetration testing involving credential brute-forcing.
2026-08-09
Go
★ 15
inform-inspect is a tool designed for inspecting and debugging Ubiquiti Unifi Inform packets, which is essential for analyzing communication with Unifi SDN Controllers. Its notable features include support for both AES-128-CBC and AES-128-GCM encryption methods, a two-step decoding process for raw byte streams, and the ability to output decoded data in JSON format or as a hexdump. The tool requires access to incoming inform packets and the respective encryption keys stored in the controller’s MongoDB for effective analysis.
2026-08-09
Go
★ 23
Credential-Detector is a command-line tool designed to scan project files for hard-coded credentials, including passwords, API keys, and private keys that may have been inadvertently embedded in source code. It supports multiple file types, such as Go, JSON, YAML, and various others, and offers highly configurable scanning options to identify suspicious patterns and variable names while excluding obvious test data. Additionally, it features a web application for enhanced usability and can be integrated as a library within other Go applications.
2026-08-08
Go
★ 279
VulnAPI is an open-source dynamic application security testing (DAST) tool tailored for scanning APIs to identify common security vulnerabilities. It features a command-line interface (CLI) that allows users to discover API details and execute scans using either a curl-like syntax or OpenAPI contracts, delivering comprehensive reports on detected vulnerabilities. Notable functionalities include detailed output reports, integration with OpenAPI specifications for scanning, and the ability to leverage the discover command for gaining insights into target APIs.
2026-08-08
Go
★ 38
Deidentify is a Go library designed to detect and remove personally identifiable information (PII) from both text and structured data, employing deterministic algorithms that maintain referential integrity. Key features include support for multiple PII types (such as emails, phone numbers, and SSNs), format preservation for usability, context-aware processing, and thread safety for concurrent applications. This tool is particularly useful for organizations requiring data anonymization while retaining original data structure and format.
2026-08-08
Go
★ 163
Zed is a command-line client for managing SpiceDB, designed to streamline permission and relationship handling within applications. It offers robust features including secure context switching, a variety of commands for permissions and relationships, comprehensive schema management, and backup/restore capabilities, making it suitable for scalable access control solutions.
2026-08-08
Go
★ 39
malsnitch is a command-line tool designed to assist malware reverse engineering by scanning various artifact formats for embedded secrets within binaries. Its notable features include the ability to detect hardcoded credentials, C2 infrastructure, and crypto keys in binary files, with support for multiple input formats such as raw strings dumps, FLOSS JSON output, and Binary Ninja exports. The tool also offers structured JSON output, automatic deduplication, and the capability to scan memory dumps, making it an efficient resource in identifying obscured sensitive information utilized by malware authors.
2026-08-07
Go
★ 95
Clampdown is a cybersecurity tool designed to run AI coding agents within secure, hardened container sandboxes, thereby mitigating risks associated with arbitrary code execution. Its primary use case is confining untrusted processes to ensure limited filesystem access and controlled network egress, utilizing advanced features like custom seccomp profiles, AppArmor confinement, and mandatory read-only root filesystems. By implementing a multi-layered architecture with sidecars and nested containers, Clampdown enables robust isolation and security for AI agents operating in potentially vulnerable environments.
2026-08-07
Go
★ 46
`knockr` is a port-knocking utility written in Go that simplifies the access control mechanism of opening blocked ports through predefined sequences. It supports multiple protocols and offers features such as delay configuration, timeout settings, and the ability to verify port status after knocking, all while allowing users to save frequently used sequences as profiles in a secure configuration file. This tool is cross-platform and can be easily integrated into scripts for automated processes.
2026-08-07
Go
★ 591
The SLSA GitHub Generator is a tool designed to generate and verify SLSA Build Level 3 provenance for projects hosted on GitHub, utilizing GitHub Actions to enhance software supply chain security and integrity. Its primary use case is to help developers establish a tamper-proof statement of their software creation process, thereby mitigating risks of supply chain attacks. Notable features include the ability to build custom builders and generators for SLSA compliance and integration with GitHub artifact attestations for verified provenance.
2026-08-06
Go
★ 32
Wallarm Docker Aio is a comprehensive Docker image designed for API security, integrating Nginx with Wallarm's security modules to safeguard applications against a range of cyber threats. Its notable features include a minimal Alpine Linux base, support for multiple architectures, non-root user execution for enhanced security, and customizable configurations via environment variables. The tool facilitates seamless deployment and operation of a Wallarm Node for effective monitoring and protection in diverse environments.
2026-08-06
Go
★ 199
gonids is a Go library designed to parse and create Intrusion Detection System (IDS) rules for engines like Snort and Suricata. Its primary use case involves assisting security professionals in managing and optimizing IDS rules, featuring capabilities to parse rules, create DNS rules, and optimize HTTP rules for cross-platform compatibility. Notable features include error handling during rule parsing, support for flexible rule creation, and an optimization function for adapting rules between IDS engines.
2026-08-06
Go
★ 102
url.vet is an open-source phishing detection engine that evaluates URLs and domains in real-time, providing a trust score, verdict, and comprehensive security report with live page previews. Notable features include 18 concurrent analyzers, 33 signals analyzed for trustworthiness, detailed explanations for each verdict, and integration capabilities with a REST API and Chrome extension. This tool serves as a self-hostable alternative to established platforms like VirusTotal, offering detailed insights without relying on opaque machine learning processes.
2026-08-06
Go
★ 546
Witness is a dynamic CLI tool designed to create an audit trail for software throughout the entire software development lifecycle (SDLC) by adhering to the in-toto specification. It integrates with popular platforms such as GitHub, GitLab, AWS, and GCP to ensure that software production steps are verified, tampering is detected, and policies can be enforced using an embedded OPA Rego engine. Notable features include keyless signing support via Sigstore, timestamp authority integration, and compatibility with both containerized and non-containerized environments without requiring elevated privileges.
2026-08-06
Go
★ 336
gemini-web2api-go is a tool that acts as a reverse proxy, converting the Google Gemini web interface into an OpenAI-compatible API, enabling users to access its functionalities without requiring an official Google API key or payment quotas. Key features include OpenAI-like endpoints for model interactions, anonymous usage with advanced session management including a proxy and cookie pooling mechanism, and a built-in Chinese management panel for monitoring and configuring usage. The tool supports various models and offers enhanced security and anonymity through real browser fingerprinting and independent rate limiting for each IP.
2026-08-05
Go
★ 29
Inkog is a static analysis tool designed to perform pre-flight checks on AI agents, identifying vulnerabilities unique to agent code, such as token bombing, prompt injection, and compliance gaps. It generates detailed reports that align with standards like the EU AI Act and OWASP guidelines, offering insights into critical security flaws and oversight issues. Notable features include easy integration with CI/CD processes, a no-install command-line option, and compatibility with multiple platforms.
2026-08-05
Go
★ 11
Xpsd is a vulnerability reachability analysis tool that leverages LLMs to determine if reported vulnerabilities are actually exploitable within a specified codebase. By ingesting CVE descriptions or vulnerability scan reports, it employs structural code navigation and other tools to generate structured verdicts and detailed markdown reports compatible with GitHub code scanning. Noteworthy features include GitHub CI integration, support for multiple vulnerability scanners, and flexible model switching for tailored analysis.
2026-08-05
Go
★ 306
sbomqs is a comprehensive tool for assessing Software Bill of Materials (SBOM) quality and ensuring compliance with various regulatory standards. It provides features for quality scoring, compliance validation across multiple frameworks, vulnerability tracking, and integration into CI/CD workflows. With its user-friendly interface and multi-standard support, sbomqs enables organizations to manage their software supply chain security effectively and share compliance results easily.
2026-08-05
Go
★ 360
Dnsmonster is a passive DNS monitoring framework developed in Golang that captures and indexes DNS traffic from various sources, including live network interfaces, pcap files, and dn stap sockets. It is designed for high performance, capable of indexing over 200,000 DNS queries per second while ensuring user privacy through IP masking. The tool provides flexibility with sampling and domain filtering options, making it suitable for security teams needing to analyze DNS traffic trends effectively.
2026-08-05
Go
★ 50
The SLSA Provenance GitHub Action enables users to generate Level 1 SLSA provenance files for various artifact types, such as files and Docker images. Its primary use case is to facilitate automated analysis and auditing of software supply chains by providing provenance information in a standardized format, thereby improving traceability of software artifacts. Notable features include integration with GitHub Actions, compatibility with the SLSA framework, and support for multiple artifact types through a straightforward workflow configuration.
2026-08-05
Go
★ 13
x-cli is a command-line tool designed for retrieving and reading data from X (Twitter) without requiring any authentication or a paid API. It enables users to access tweets, user profiles, timelines, and media through a local SQLite store, strictly in a read-only manner. Key features include a pure Go implementation, built-in shell completion, and the ability to execute multiple commands efficiently, leveraging different tiers of X's public data surfaces for seamless interaction.
2026-08-04
Go
★ 320
Agent Beacon is an open-source telemetry layer designed to capture and normalize runtime events from AI agents across various environments, such as local, CI, and cloud. Its primary use case is to provide unified visibility into the behavior of AI agents by extending the OpenTelemetry GenAI standard, making it easier for Security and IT teams to deploy and manage agent telemetry. Notable features include support for multiple enterprise-grade SIEM integrations and a local dashboard for event inspection, ensuring that data processing remains under customer control.
2026-08-04
Go
★ 63
Osv-detector is an open-source auditing tool designed to identify vulnerabilities in software dependencies by leveraging advisory databases that comply with the OSV specification. Its primary use case is to analyze various package lockfiles across multiple ecosystems, including npm, Python, Ruby, and more, enabling developers to efficiently pinpoint security risks in their projects. Notable features include support for a wide range of lockfile formats and the ability to automatically determine the appropriate parser based on the filename.
2026-08-04
Go
★ 25
urlX is a high-performance reconnaissance tool designed for bug bounty hunters, penetration testers, and security researchers. It facilitates passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling, while utilizing Go routines for fast and concurrent processing. Notable features include smart file and extension filtering, minimal setup requirements, and support for enhancing results with optional API keys from various providers.
2026-08-03
Go
★ 5116
Hakrawler is a fast web crawler written in Go, designed to gather URLs and JavaScript file locations efficiently. It allows users to crawl single or multiple URLs with options for including subdomains, setting connection timeouts, and sending requests through proxies, making it versatile for reconnaissance tasks in cybersecurity. Notable features include support for custom headers, output in JSON format, and a configurable crawling depth.
2026-08-03
Go
★ 11
AuthInspector is a Golang-based tool designed for efficient authorization and authentication testing, specifically for extracting request details from BurpSuite exports. It utilizes Goroutines to conduct comprehensive checks based on user-defined headers and outputs results in a structured CSV format. Notable features include customizable request options, support for proxy configurations, and the ability to include request/response bodies in results.
2026-08-03
Go
★ 14
PrivHunterAI is a tool designed to identify unauthorized access vulnerabilities through passive proxying, utilizing various mainstream AI engines such as Kimi, DeepSeek, and GPT. The tool's notable features include support for HTTPS traffic detection, customizable request headers, and the ability to view scan results via both terminal and a web interface. It requires configuration of AI models and API keys, allowing for flexible integration and usage in vulnerability assessments.
2026-08-03
Go
★ 27
Ed is a tool designed for identifying and exploiting accessible UNIX Domain Sockets, particularly useful for locating exposed Docker.sock instances that may not be mounted in their default locations. Notable features include the ability to hunt for various types of UNIX domain sockets, perform autopwn actions, and return output in JSON format, making it suitable for both security testing in DevOps processes and integration into CI/CD pipelines.
2026-08-03
Go
★ 17
A flexible cross-platform post-exploitation agent written in Go with basic functionalities
2026-08-03
Go
★ 435
Covermyass is a post-exploitation tool designed for penetration testers to securely delete log files across multiple operating systems, including Linux, macOS, and Windows. It enables users to identify and overwrite log files with random data to obscure their activities before exiting a compromised server. Notable features include multiple overwrite iterations and the ability to handle file permissions, ensuring thorough data eradication.
2026-08-03
Go
★ 36
C2PE is a tool designed for Red Team operations, focusing on Command and Control (C2) capabilities and post-exploitation activities. It features experimental code implementations suitable for hacking scenarios, allowing users to deploy C2 infrastructures and manage compromised systems effectively. The tool is developed in Python and Go, ensuring cross-platform compatibility and adherence to PEP8 code standards.
2026-08-03
Go
★ 13
KitsuneC2 is a pure-Go adversary emulation framework designed for security testing, providing both a web and CLI interface for user interaction with implants. Its notable features include dynamic implant generation, in-memory execution of shellcode, and malleable C2 traffic, making it a versatile tool for organizations aiming to evaluate their cybersecurity defenses. However, it is not intended for professional engagements as there are more mature frameworks available.
2026-08-03
Go
★ 5600
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
2026-08-03
Go
★ 10
Silkwire is a gRPC-based Command and Control (C2) framework designed for authorized penetration testing and red team operations. It supports multiple platforms (Windows, Linux, macOS) and offers advanced features including dynamic implant generation, post-exploitation modules, keylogging, and enhanced evasion techniques against detection mechanisms. The tool emphasizes encryption for communications and session management, making it a robust option for security professionals in performing comprehensive security assessments.
2026-08-03
Go
★ 11
SoundShell is a Command-and-Control (C2) tool developed in Go that utilizes the Spotify Web API to execute encoded commands and generate corresponding playlists. Its primary use case is to dynamically create playlists based on user-inputted commands, with notable features including custom command execution, command encoding for playlist generation, and random track selection from a predefined song pool.
2026-08-03
Go
★ 395
XENA is a cross-platform cybersecurity automation framework designed for adversary simulations and red team operations, featuring a built-in post-exploitation agent and a command-and-control (C2) server. Notable features include an elegant dark-themed user interface that supports desktop, web, and mobile formats, along with high-level automation capabilities for orchestrating C2 clusters. This community edition serves as an integrated tool for penetration testing, facilitating a comprehensive approach to security assessment.
2026-08-03
Go
★ 166
Amazing Sandbox (AS) is a versatile tool designed to execute various programming environments in a secure, containerized format. It primarily mitigates risks associated with running potentially malicious packages by limiting their access to the file system and network, facilitating safer development practices. Key features include configurable access permissions, support for multiple programming languages, and the option to air-gap execution environments for enhanced security.
2026-08-03
Go
★ 660
AWS SSO CLI is a secure command-line interface tool designed to simplify the management of AWS IAM Identity Center access for organizations with multiple AWS accounts and IAM roles. It enhances security by auto-discovering available roles, supporting both interactive and CLI-based role selection, and allowing for the sharing of AWS STS token credentials. Notable features include support for multiple active AWS Console sessions, guided setup, customizable profiles, and a user-friendly experience focused on improving AWS SSO interactions.
2026-08-03
Go
★ 320
Dalec is a tool designed for securely building system packages and containers using a declarative configuration format, with a particular emphasis on supply chain security. It supports multiple package formats (DEB, RPM, and Windows containers) while ensuring minimal image sizes to reduce vulnerabilities, along with features like signed packages and build-time Software Bill of Materials (SBOMs) for provenance attestations. The tool operates with Docker as its sole dependency, simplifying the usage for various target operating systems.
2026-08-03
Go
★ 42
Layerleak is an OCI image secret scanner that leverages OCI image internals to analyze public images from various OCI-compliant registries without relying on a local Docker daemon. It offers read-only scanning capabilities, detecting over 60 types of secrets while deduplicating findings by secret fingerprint and collapsing duplicate context snippets. Notable features include support for scanning image layers, config metadata, and history, as well as a built-in HTTP API for integration.
2026-08-03
Go
★ 32
OpenRisk is an enterprise-grade risk management platform designed to streamline the identification, assessment, mitigation, and monitoring of IT and security risks through a scalable microservices architecture. Its key features include automated risk assessment, interactive real-time dashboards, and native integration with tools like Elastic and Splunk, making it suitable for CTOs, CISOs, and DevSecOps teams. With capabilities such as mitigation tracking and advanced analytics, OpenRisk enhances organizational risk oversight and compliance while enabling easy deployment via Docker and Kubernetes.
2026-08-03
Go
★ 330
Secure-Repo is a GitHub repository tool designed to automate the implementation of security best practices within GitHub workflows. Its primary use case includes enhancing repository security by automatically setting minimum GITHUB_TOKEN permissions, integrating security actions like Harden-Runner, and facilitating dependency management through Dependabot and CodeQL. Notable features include a catalog of recommended fixes that can be applied to various security vulnerabilities in CI/CD processes, alongside an actionable knowledge base for GitHub Actions permissions.
2026-08-03
Go
★ 32
uzomuzo is a dependency management tool designed to identify unmaintained packages and facilitate the safe removal of vulnerabilities that traditional Software Composition Analysis (SCA) tools fail to detect. Its primary features include the `scan` command for detecting unmonitored packages lacking CVEs and the `diet` command to rank dependencies by their removability based on various risk factors. Thus, uzomuzo addresses the critical issue of hidden lifecycle risks in software dependencies, enhancing supply chain security.
2026-08-03
Go
★ 1814
Betterleaks is a configurable and efficient secrets scanner designed for detecting sensitive information across various platforms, including Git repositories, GitHub, GitLab, and S3. It offers notable features such as advanced rule-based filtering using Expr for reduced false positives, validation of detected secrets via asynchronous HTTP requests, and support for numerous data sources, making it a versatile tool in ensuring code security. With built-in parallel processing and optimization for fast scans, it can be integrated easily into any system, enhancing its practicality in diverse development environments.
2026-08-03
Go
★ 2138
ghorg is a command-line tool that allows users to efficiently clone all repositories from an organization or user account on platforms like GitHub, GitLab, and Bitbucket into a designated directory. It features capabilities for repository filtering, backup creation, and synchronization with remote repositories, making it suitable for tasks such as audits, onboarding, and local codebase searches. Notably, ghorg can also automate cloning tasks and track metrics over time.
2026-08-03
Go
★ 93
Kubesplaining is an open-source command-line interface tool designed for Kubernetes security assessments, focused on analyzing privilege escalation paths within a live cluster or a snapshot. Unlike traditional scanners, it constructs a multi-hop RBAC privilege escalation graph that illustrates how non-system subjects can escalate their privileges to critical sinks, providing detailed remediation for each finding. Its outputs include prioritized reports in HTML, JSON, CSV, and SARIF formats, making it suitable for human review or integration into CI/CD workflows.
2026-08-03
Go
★ 564
DNS-collector is a lightweight tool designed for capturing and intelligently processing DNS queries and responses from various DNS servers, including BIND and PowerDNS. Its primary use case is to filter and enrich DNS data by removing noise such as health checks and spam before forwarding the refined data to monitoring systems or databases. Notable features include support for multiple input sources via the DNStap protocol or live network capture, flexible output formats to various logging and monitoring systems, and enhanced data processing capabilities for improved operational insights.
2026-08-03
Go
★ 85
ferret-scan is a command-line tool that enables the detection and redaction of sensitive data, such as personally identifiable information (PII) and secrets, from files and streams. Its features include context-aware confidence scoring for detected data, format-preserving redaction, and an intuitive web UI, all while ensuring no data leaves the host machine. The tool is designed for seamless integration into CI/CD pipelines and provides multiple installation methods, being lightweight with no runtime dependencies.
2026-08-03
Go
★ 987
secureCodeBox is a Kubernetes-based toolchain designed for continuous security scanning of software projects, automating various security testing tools to facilitate ongoing application security. Its primary use case is to integrate into the development pipeline, allowing for early identification of security vulnerabilities, thereby enabling developers to address issues regularly rather than relying solely on periodic penetration testing. Notable features include its modular architecture, which offers flexibility in tool selection, and its ability to orchestrate automated security tests, making it suitable for projects with continuous delivery practices.
2026-08-03
Go
★ 27637
TruffleHog is a powerful tool for discovering, classifying, validating, and analyzing leaked credentials across various platforms, including Git repositories, chat applications, and logs. It can identify over 800 types of secrets, confirm their validity by checking if they are live, and provide in-depth analysis of commonly leaked credentials. Notable features include its comprehensive secret classification and validation capabilities, making it essential for maintaining secure access credentials.
2026-08-03
Go
★ 632
YAK is a cybersecurity technology stack built around a domain-specific language (CDSL) designed for enhancing security infrastructure and vulnerability analysis. Notable features include a dedicated virtual machine (YakVM), strong typing with dynamic characteristics, and the ability to execute scripts across multiple platforms without extensive boilerplate code. This tool aims to simplify the development of security products and improve usability for non-specialists in the cybersecurity domain.
2026-08-03
Go
★ 2739
Bearer is a static application security testing (SAST) tool that scans source code for security and privacy risks by analyzing data flows. It supports a wide range of programming languages and offers features like detection of vulnerabilities in line with OWASP Top 10 and CWE Top 25, as well as identifying sensitive data flows for privacy compliance reporting. Bearer is available in both an open-source CLI version and a comprehensive commercial version, providing advanced analysis capabilities.
2026-08-03
Go
★ 194
Cynative is a read-only cybersecurity tool designed for deep infrastructure research, allowing users to query various systems such as GitHub, GitLab, AWS, GCP, Azure, and Kubernetes in a unified manner. It executes code in an ephemeral sandbox to provide verified insights while maintaining strict access controls, thereby ensuring that users can confidently audit their cloud environments without compromising security. Notable features include its ability to reason through code-to-runtime environments, a robust action-gate mechanism for authorization, and evidence-backed findings that trace back to their origins.
2026-08-03
Go
★ 74
Hadrian is an open-source API security testing framework designed to detect OWASP API Top 10 vulnerabilities in REST, GraphQL, and gRPC APIs, focusing specifically on authorization-related flaws. It features role-based authorization testing using YAML-driven templates, which enables users to define roles with permissions once and automatically conduct cross-role access checks. Additionally, Hadrian employs mutation testing methodologies to confirm the existence of write/delete vulnerabilities and offers multiple output formats for reporting findings.
2026-08-03
Go
★ 306
Hijagger is a cybersecurity tool designed to identify hijackable packages in NPM and Python PyPI registries by checking for unregistered domains or MX records associated with package maintainers. Its primary use case is to facilitate the discovery of potential security vulnerabilities that can be reported to bug bounty programs. Notable features include automatic output logging, DNS and WHOIS checks, and a color-coded output based on download activity for NPM packages, though this feature is not available for PyPI due to API limitations.
2026-08-03
Go
★ 210
Kontext CLI is a runtime governance tool designed for AI agents, enabling local policy evaluations and pre-action enforcement to enhance security during tool usage. Its primary use case involves recording policy decisions and actions in an authorization ledger while blocking or allowing actions based on predefined rules. Notable features include support for self-serve setup on macOS, an observe mode for testing policies without interruptions, and compatibility with various agent environments to ensure secure operation across different platforms.
2026-08-03
Go
★ 825
Pipelock is an open-source AI agent firewall that provides verifiable egress control by inspecting and mediating HTTP, WebSocket, and other network traffic to prevent secret exfiltration, prompt injections, and various security threats. It features content-aware boundary decisions with mediator-signed action receipts for verification, enhancing transparency in security operations. Additionally, it supports TLS interception for thorough analysis and is integrated with the public agent-egress-bench corpus for robust detection validation.
2026-08-03
Go
★ 32
Stave is an open-source cloud configuration verifier designed to validate AWS configurations offline and without credentials. Its primary use case is for cybersecurity assessments, allowing users to discover vulnerabilities and attack chains through intuitive commands and built-in templates. Notable features include automated assessment templates for various security jobs, a skill-based onboarding process, and the ability to evaluate snapshots and generate reports based on specified severity thresholds.
2026-08-03
Go
★ 329
SysWarden is an enterprise-grade Host Intrusion Detection and Prevention System (HIDS/HIPS) built entirely in Go, designed to protect critical Linux infrastructures. Its primary use case is to automate and enforce CIS Level 2 hardening, integrate global threat intelligence, and orchestrate dynamic network defense, enabling robust protection against both network and application-level threats. Notable features include support for advanced firewall orchestration, a memory-safe web application firewall daemon, and a focus on zero-trust execution, mitigating common vulnerabilities like OS command injection and memory corruption.
2026-08-03
Go
★ 6313
Syzkaller is an unsupervised coverage-guided kernel fuzzer designed to discover security vulnerabilities in various operating system kernels, including Linux, FreeBSD, and Windows. Its notable features include support for multiple OS environments, a focus on automated bug detection, and an extensive documentation set for setup and usage. Initially developed for Linux, Syzkaller has broadened its capabilities to include several other operating systems, enhancing its utility in kernel security research.
2026-08-03
Go
★ 37715
Trivy is a versatile security scanner designed for identifying vulnerabilities and misconfigurations across various targets, including container images, filesystems, Git repositories, virtual machine images, and Kubernetes environments. It can detect OS packages, known vulnerabilities, infrastructure as code (IaC) issues, sensitive data, and software licenses. Trivy is easily integrable with popular tools and platforms, supporting a wide range of programming languages and systems, making it a comprehensive choice for security assessments.
2026-08-03
Go
★ 127
Vespasian is an API discovery and specification generation tool that observes real HTTP traffic to identify API endpoints and automatically generates specifications in OpenAPI, GraphQL SDL, and WSDL formats. Designed for penetration testers and security engineers, it captures traffic through headless browsers or imports data from existing traffic dumps, utilizing classification heuristics and active probing to effectively map the API surface of applications where documentation is scarce. Notable features include REST, GraphQL, WSDL, and gRPC discovery, automatic API type detection, and support for dynamic content generated by single-page applications.
2026-08-03
Go
★ 441
Gotohp is an unofficial desktop GUI client for Google Photos that facilitates the upload of media files with a focus on user configurability and ease of use. Its notable features include drag-and-drop interface, real-time progress tracking, and support for both individual and recursive uploads, while also allowing advanced command-line interactions for streamlined workflows. The tool supports Apple Live Photos pairing and provides robust credential management, making it a versatile solution for users looking to manage their photo library effectively.
2026-08-03
Go
★ 139
Decompose is a reverse-engineering tool designed for analyzing Docker environments by extracting and visualizing all network connections from containers. It supports multiple output formats including graphviz dot, structurizr DSL, and CSV, providing detailed insights into container interconnections, including ports and statistics. Notable features include high-speed scanning capabilities, deep inspection of process connections, and a single-binary deployment for cross-platform compatibility.
2026-08-03
Go
★ 18
The VanMooof-Module ES3 is a specialized tool designed for interfacing with and extracting information from the MX25L51245GMI-08G-TR SPI Flash Chip used in VanMoof electric bicycles. Its primary use case includes reading and writing BLE keys, managing firmware updates, and performing detailed analyses of logs and sound files, which can help in troubleshooting and enhancing system performance. Notable features include authentication key extraction, firmware encryption/decryption, BLE permission inspection, and support for uploading firmware via y-modem.
2026-08-03
Go
★ 675
Malcontent is a subtle malware discovery tool that leverages context, differential analysis, and over 14,500 YARA rules to uncover supply chain compromises, primarily targeting Linux binaries but also supporting other UNIX platforms and Windows. Its three operational modes—analyze, diff, and scan—facilitate extensive program capability assessments, risk-weighted comparisons, and threshold-based scanning. Key features include support for multiple binary formats, various output formats, integration within CI/CD pipelines, and specific configurations for handling archives and container images.
2026-08-03
Go
★ 10431
IPATool is a command line utility designed for interacting with the iOS App Store, enabling users to search for applications, authenticate with their Apple ID, and download app packages (ipa files). Key features include app search by term, list available versions for download, and facilitate license purchases, all while supporting output formatting options and various command flags for enhanced usage. This tool is particularly useful for developers and researchers who need to access and manage iOS app data programmatically.
2026-08-03
Go
★ 379
Go Hacking is a comprehensive online tutorial designed for reverse engineering Golang applications, utilizing x64, ARM64, and ARM32 architectures. It systematically guides users through the process of setting up a development environment, debugging, and hacking various aspects of Go programs, including primitive types and control flow. Notable features include step-by-step lessons, free downloadable resources, and a focus on hands-on learning that caters to both beginners and seasoned practitioners in the field of reverse engineering.
2026-08-03
Go
★ 71
CTFProxy is a comprehensive Capture The Flag (CTF) infrastructure solution designed to facilitate the deployment and management of CTF challenges with a Zero-Trust Network model. It utilizes a single command for container orchestration, integrates CI for continuous deployment, and supports detailed access control policies through Starlark configuration. Notable features include multi-container management, centralized logging, secure SSO authentication, and the ability to run challenges in both Docker and Kubernetes environments.
2026-08-03
Go
★ 11
The TryHackMe_Writeups repository contains comprehensive writeups for various PwnBoxes and Rooms hosted on TryHackMe, aimed at assisting users in understanding the solutions to the challenges. Its primary use case is to provide guidance for users who may be struggling with specific tasks, while encouraging independent problem-solving. Notable features include a collection of detailed solutions that include flags and answers, structured to facilitate learning in cybersecurity challenges.
2026-08-03
Go
★ 12
ctfify is a command-line tool designed to streamline the downloading and management of Capture The Flag (CTF) challenges. It allows users to efficiently search for challenges based on name, category, or tags, facilitating quick downloads to local machines. Notable features include an easy-to-use interface and the capability of handling multiple challenges with minimal commands.
2026-08-03
Go
★ 66
goLoL is a Windows host scanner that specializes in detecting living-off-the-land binaries (LOLBAS) and vulnerable drivers (LOLDrivers) by leveraging a live catalog of techniques and hashes. It provides privilege-aware filtering based on the user's access level and includes features like MITRE ATT&CK mapping, flexible result sorting, and both LOLBAS and driver scanning modes. The tool is designed for security professionals to enhance their understanding of potential attack vectors within a Windows environment.
2026-08-03
Go
★ 148
Pkappa2 is a sophisticated packet stream analysis tool designed for Attack & Defense Capture The Flag (CTF) competitions, enabling users to upload and analyze pcap files for network traffic streams. The tool features a custom query language for structured searches, real-time updates through a responsive web interface, and the ability to save queries as services or tags, facilitating quick access to specific stream data. Notably, it supports both IPv4 and IPv6, offers scriptable data converters, and can ingest traffic through various methods including HTTP POST, making it a versatile choice for network analysis in CTF environments.
2026-08-03
Go
★ 23
sshchecker is a dedicated SSH brute-forcing tool designed to test SSH login credentials against a list of IP addresses. Its primary use case is for security assessments to identify vulnerable systems by attempting logins using specified usernames and passwords from file inputs. Notable features include the ability to process multiple IP addresses in one go and a straightforward command-line interface for ease of use.
2026-08-03
Go
★ 496
Exif Looter is a command-line utility designed to analyze and manipulate image metadata, specifically EXIF data. Its primary use case includes analyzing individual images or entire directories for metadata extraction, as well as removing metadata to enhance privacy. Notable features include piping functionality for integration with other tools, the ability to extract GPS coordinates for mapping, and comprehensive support for various image formats.
2026-08-03
Go
★ 41
grep-backURLs is an automated web security tool designed for extracting sensitive information during bug hunting by enumerating subdomains and analyzing Wayback Machine URLs. It leverages the subfinder tool for subdomain discovery and utilizes grep to filter results based on user-defined keywords, providing outputs in HTML, JSON, and Markdown formats. Key features include customizable configurations, concurrency control, and automatic report generation, effectively streamlining the process of credential discovery.
2026-08-03
Go
★ 34
PathFinder v1.1.0 is a military-grade web path discovery tool designed for professional penetration testing, featuring a real-time TUI dashboard and animated pathfinding visualization. Its notable capabilities include adaptive splash screens, live redirect tracking, recursive directory scanning, and the ability to export detailed pentest reports in multiple formats, all optimized for performance with high request rates and low resource usage. PathFinder is particularly distinguished by its animation of breadth-first search algorithm solving unique mazes, providing intuitive visual feedback during scans.
2026-08-03
Go
★ 63
Pinakastra is an AI-powered penetration testing framework designed for automated reconnaissance and exploitation, specifically tailored for penetration testers and bug bounty hunters. It features extensive capabilities for subdomain discovery, live host probing, URL analysis, and active exploitation of vulnerabilities like XSS and SQL injection, enhanced by AI-driven vulnerability detection and smart payload generation to minimize false positives. The tool also generates customizable reports in various formats, thereby streamlining the assessment process and improving efficiency in security testing.
2026-08-03
Go
★ 16
Subscan is a high-performance CLI tool designed for subdomain enumeration tailored for bug bounty hunters and security professionals. It offers both passive reconnaissance by leveraging public sources and active DNS resolution capabilities through customizable wordlists, alongside features for subdomain scoring, misconfiguration detection, and diverse output formats. Additionally, it supports concurrency for increased scanning speed and plans to introduce extensibility for plugins in the future.
2026-08-03
Go
★ 111
`xcrawl3r` is a command-line tool that recursively spiders websites to discover URLs by actively traversing webpages and parsing files such as sitemaps and `robots.txt`. This active spidering approach distinguishes it from similar tools by revealing hidden or unindexed links, making it particularly useful for security researchers and IT professionals. Notable features include support for multiple output formats, cross-platform compatibility, and integration with automated workflows through standard input and output options.
2026-08-03
Go
★ 120
`xsubfind3r` is a command-line utility that efficiently discovers subdomains for a specified domain using information from various passive data sources. It is particularly useful for security researchers and IT professionals, offering features such as support for multiple output formats (including JSONL and stdout), the ability to integrate seamlessly into automated workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
2026-08-03
Go
★ 21
Bucky is a tool designed for S3 account ID enumeration and bucket discovery, enabling users to extract the 12-digit AWS account ID of an accessible S3 bucket and discover additional associated buckets through exhaustive fuzzing of bucket names against a wordlist. Key features include the use of inline STS session policies to systematically brute-force the account ID and the ability to report the discovered account ID, bucket regions, and all identified buckets, thus facilitating reconnaissance efforts on AWS S3 resources.
2026-08-03
Go
★ 719
`xurlfind3r` is a command-line utility that efficiently discovers URLs associated with a given domain by sourcing publicly available data through passive means. It is particularly useful for security researchers and IT professionals, offering features like multiple output formats (JSONL, file, stdout), support for automatic workflows via `stdin` and `stdout`, and cross-platform compatibility across Windows, Linux, and macOS.
2026-08-03
Go
★ 13
S3Finder is a high-performance command-line interface tool designed for discovering AWS S3 buckets through intelligent name generation and high-concurrency scanning. It offers features such as decoupled input sources, an AI-powered permutation engine for bucket name variations, deep inspection with AWS SDK integration, and real-time progress tracking, all while maintaining adaptive rate limiting to avoid throttling and IP blocks. This tool supports cross-platform operation and allows for flexible output formats, making it suitable for security assessments and reconnaissance efforts.
2026-08-03
Go
★ 88
Subhunter is a subdomain takeover tool designed to identify vulnerabilities in specified subdomains, enabling users to detect potential security risks associated with unmonitored CNAME records. Notable features include automatic updates, the use of random user agents, and a built-in database of fingerprints sourced from reputable databases. It is implemented in Go and allows for customization in scanning parameters, such as threading and timeouts, enhancing its effectiveness in security assessments.
2026-08-03
Go
★ 532
JSHunter is a professional command-line tool designed for comprehensive JavaScript security analysis, specifically focused on endpoint discovery and sensitive data detection. It features high-accuracy detection algorithms for identifying API keys, tokens, and potential vulnerabilities, alongside robust reporting capabilities and advanced networking options like proxy support and customizable headers. Additionally, its multi-threaded architecture ensures efficient processing, making it suitable for security professionals and penetration testers.
2026-08-03
Go
★ 62
LeakLens is a web-aware secrets scanner designed to detect sensitive information across various sources including source code, Git history, and modern web applications. Its primary use case is to enable security professionals to identify and remediate security vulnerabilities related to exposed secrets through a high-performance, extensible scanning engine and advanced crawling capabilities, such as JavaScript discovery and source-map recovery. Notable features include live validation of secret findings, integration with the Katana web crawling tool, and support for embedding the scanner within other internal tools using its Go library.
2026-08-03
Go
★ 30
CORS-Scanner is a Go-based tool designed to identify CORS misconfiguration vulnerabilities in web applications. It allows users to specify origin headers and cookies for testing and processes line-delimited domains to check for vulnerabilities such as reflected origins with credentials and wildcard configurations. Notable features include customizable options for origin headers and cookie handling, as well as the capability to input multiple domains efficiently for scanning.
2026-08-03
Go
★ 134
Erebus is a configurable parameter-based vulnerability scanner that utilizes YAML templates to identify vulnerabilities across multiple targets efficiently, ensuring zero false positives. Its notable features include an intercepting proxy that allows users to dynamically test parameters as they browse web applications, along with built-in support for updating and downloading community-contributed vulnerability templates. This tool is designed for rapid scanning of large networks, making it ideal for penetration testers and cybersecurity researchers.
2026-08-03
Go
★ 12
Gopo is a proof-of-concept (PoC) framework designed for generating and executing multiple exploitation scripts compatible with XRAY V2's PoC functionality. It facilitates vulnerability scanning by allowing users to load and execute predefined or custom PoCs against specified targets, with options for proxy settings, threat management, and debugging features. Notable capabilities include the ability to handle rules with logical expressions, multi-threaded scanning, and customizable execution parameters to optimize performance and accuracy.
2026-08-03
Go
★ 31
Nessusbeat is a Beat designed to monitor a local Nessus vulnerability scanner's reports directory, facilitating the export, parsing, and output of scan results to various supported Beat outputs. Its primary use case is to enhance vulnerability management workflows by automating the reporting process. Notable features include configurable report paths and potential future enhancements to support remote polling and API-based authentication.
2026-08-03
Go
★ 36
The Harbor Scanner Adapter for Aqua Enterprise serves as a bridge between the Harbor scanning API and Aqua Enterprise's scanning capabilities, enabling vulnerability scanning of container images stored in the Harbor registry. Notable features include its implementation of the Pluggable Scanners API, which allows for ad hoc scanning and the generation of vulnerability reports, while also requiring specific version dependencies and configurations to function properly. The adapter does not provide visibility or enforcement for Aqua's image assurance policies, which must be managed via the Aqua Management Console.
2026-08-03
Go
★ 10
The network-vulnerability-scanner is a tool designed to identify vulnerabilities within networked systems by analyzing hosts and services for known security flaws. Its primary use case is to enable network administrators and security professionals to assess the security posture of their network infrastructure. Notable features include support for various network protocols, customizable scanning options, and detailed reporting on discovered vulnerabilities and recommended mitigations.
2026-08-03
Go
★ 334
Ward is a specialized security scanner for Laravel applications that performs targeted security checks by understanding the application's structure, including routes, models, and configuration files. Notable features include live vulnerability lookups against the Packagist advisory database, comprehensive checks for common misconfigurations, and the ability to generate detailed reports on security findings, making it a valuable tool for both development environments and CI/CD pipelines.
2026-08-03
Go
★ 21
wp-taint-scan is a specialized static analysis tool designed to detect genuine vulnerabilities in WordPress plugins using a native Go-based taint analysis engine. It enables users to scan multiple versions of plugins in parallel and offers features such as detailed source-to-sink dataflows, version diffs to track changes in vulnerabilities, and a thorough understanding of the WordPress security model, significantly reducing false positives. Notable vulnerability classes include SQL injections, XSS, path traversal, and missing authorization issues, making it an essential tool for enhancing WordPress security.
2026-08-03
Go
★ 20
WPRecon is an advanced WordPress reconnaissance and vulnerability scanning tool designed for security engineers to identify vulnerabilities, misconfigurations, and information disclosure in WordPress installations. It utilizes a YAML-driven template architecture that facilitates easy extensibility, rapid deployment as a single binary, and features such as high-performance parallel scanning, a diverse library of over 150 templates, and multi-format output options. Notable capabilities include automatic retries for failed requests, comprehensive HTTP operations, and a variety of matchers and extractors for efficient data retrieval and analysis.
2026-08-03
Go
★ 14
AIROM is a tool designed for scanning filesystems, git repositories, container images, and Kubernetes workloads to identify and document AI components in software. It generates an AI Bill of Materials that includes models, datasets, and frameworks used in the code, providing line-by-line evidence for each entry. Notable features include support for various scan targets, output formats like CycloneDX and SPDX, and the ability to gate builds based on identified risks.
2026-08-03
Go
★ 721
ChYing is an open-source penetration testing tool designed to provide an interactive platform for security professionals, facilitating the capture, modification, and replay of HTTP/HTTPS traffic. Its notable features include a lightweight UI, built-in scanning capabilities from the Jie tool, automated attack testing with multiple payload types, and an intuitive workflow for JWT parsing, which makes it an alternative to heavier tools like Burp Suite. The tool aims to offer a modern and customizable solution for active and passive web vulnerability assessments.
2026-08-03
Go
★ 420
CSCAN is an enterprise-level distributed network asset scanning platform designed for comprehensive asset management and vulnerability detection. Its notable features include a distributed architecture for flexible scalability, automated scanning pipelines, customizable password dictionaries, periodic task scheduling, and real-time notification subscriptions, supporting extensive data isolation across multiple workspaces. This tool is ideal for organizations seeking to efficiently monitor and secure their network infrastructure.
2026-08-03
Go
★ 175
Drogonsec is an open-source security scanner designed to perform comprehensive security assessments through Static Application Security Testing (SAST), Software Composition Analysis (SCA), and secret detection, aligning with the OWASP Top 10:2025 framework. It supports over 20 programming languages and various deployment strategies, including local or cloud-based AI remediation for findings. Key features include the ability to scan for vulnerabilities, identify misconfigurations in Infrastructure as Code (IaC), and integrate with CI/CD pipelines for automated security reporting.
2026-08-03
Go
★ 618
Eraser is a tool designed for Kubernetes administrators that facilitates the removal of non-running images from all nodes within a cluster. Its primary use case is to help optimize storage and resources by cleaning up unused images, thereby improving cluster efficiency. Notable features include easy integration with Kubernetes environments and a user-friendly quick start guide for rapid deployment.
2026-08-03
Go
★ 13
Observer is a command-line tool designed to analyze codebases and generate a comprehensive production health report, all from a single, offline binary with no dependencies or account requirements. It combines various analysis methods—such as static analysis, dependency checks, and runtime error detection—into a unified report that includes a security rating and suggested fixes for identified issues. The tool is aimed at developers seeking to efficiently identify and remediate production problems without navigating complex code and server logs.
2026-08-03
Go
★ 40
The Harbor Scanner Adapter for Anchore Engine/Enterprise facilitates the integration of Harbor's scanning capabilities with the Anchore API, enabling vulnerability assessments on Docker images stored within Harbor. It offers TLS/HTTPS protection for API communications, supports authentication through Bearer tokens and Basic authentication, and can be configured via environment variables or configuration files. This tool is essential for users seeking to leverage Anchore's scanning features directly from Harbor, enhancing their image security posture.
2026-08-03
Go
★ 30950
Nuclei is a high-performance vulnerability scanner that utilizes YAML-based templates for customizable vulnerability detection, aiming to reduce false positives by mimicking real-world attack scenarios. Its notable features include ultra-fast parallel scan processing, support for multiple protocols such as HTTP and DNS, and seamless integration into CI/CD pipelines as well as various issue tracking and logging systems. The tool is designed for security professionals to stay ahead of trending vulnerabilities while conducting thorough regression testing.
2026-08-03
Go
★ 30
PenHunter is a modular web vulnerability scanner designed for penetration testers, bug bounty hunters, and security researchers, focused on identifying a wide range of web vulnerabilities, including XSS, SQL Injection, and RCE. It features advanced detection methods, such as boolean and time-based techniques, as well as built-in WAF evasion capabilities, and can integrate with external tools like sqlmap and dalfox. The tool supports concurrent scanning, interactive CLI usage, and provides organized output in multiple formats, enhancing workflow efficiency in security assessments.
2026-08-03
Go
★ 197
SEC-AF is an AI-native security auditing tool that confirms exploitability of vulnerabilities in codebases by providing a detailed data flow trace and verifiable evidence for each finding. It allows users to initiate audits via a single API call or command line interface, returning comprehensive reports that include severity, exact location, and a verdict on each vulnerability. Notably, SEC-AF offers a cost-effective solution for thorough security assessments, typically costing about $1.40 per full audit.
2026-08-03
Go
★ 36
Synapse is a governed control plane designed for comprehensive software composition analysis, vulnerability detection, and reporting, facilitating security assessments in a controlled environment. Its primary use case revolves around automating security workflows, ensuring tamper-evident evidence collection, and allowing for deterministic scanning across various ecosystems with multiple built-in scanners. Notable features include a robust SBOM generation, risk-based prioritization of findings, and strict adherence to authorization and scope constraints before tool execution.
2026-08-03
Go
★ 11
Terraview is an open-source security analysis tool designed for Terraform plans that integrates static scanners like Checkov, Trivy, and Terrascan with AI contextual analysis, executing these processes in parallel. It inspects infrastructure provisioned with Terraform to identify security misconfigurations and compliance issues while enriching results through multi-provider contextual insights. Notable features include built-in security scanner capabilities, seamless configuration management, and native policy-as-code support, all without external dependencies.
2026-08-03
Go
★ 1055
Vigolium is a high-fidelity vulnerability scanner that offers two distinct scanning modes: Native Scan for fast and flexible multi-phase assessments, and Agentic Scan for autonomous, AI-driven code auditing. It features 317 scanner modules covering a wide array of vulnerabilities, including OWASP Top 10, and employs out-of-band testing to enhance accuracy. The tool is designed for both manual and automated security assessments, enabling comprehensive coverage of web applications and codebases.
2026-08-03
Go
★ 12248
Vuls is an agent-less vulnerability scanner designed for Linux, FreeBSD, and macOS systems, written in Go, that automates the detection of vulnerabilities by continuously monitoring installed software against a variety of vulnerability databases. It generates regular reports that inform users about affected systems and related vulnerabilities, mitigating the risks of human oversight in the management of software updates. Notable features include high-quality scanning capabilities across major operating systems and integration with multiple security advisories and vulnerability databases.
2026-08-03
Go
★ 712
wscan is a comprehensive web security scanner designed for active, passive, and AI-driven penetration testing, addressing a wide range of vulnerabilities from the OWASP web vulnerability landscape. Key features include a browser-based WebUI for scan management, support for multiple scanning modes, an extensive library of built-in detection plugins, and integration with external POC engines like Nuclei, Xray, and Goby. Additionally, it offers an AI agent mode for automated testing and a reverse-connect platform for exploiting blind vulnerabilities.
2026-08-03
Go
★ 944
Xalgorix is an open-source AI-driven penetration testing platform that autonomously conducts comprehensive pentesting methodologies and verifies each finding through an independent verification process, ensuring the delivery of proven vulnerabilities rather than uncertain results. It is designed for self-hosting and supports a "bring-your-own-LLM" model, allowing integration with user-defined language models, while catering to both Linux environments and containerized implementations through Docker. Notable features include its autonomous execution, independent verification of findings, and the ability to run in a secured Docker container.
2026-08-03
Go
★ 14967
OWASP Amass is a comprehensive tool for network mapping and external asset discovery aimed at enhancing cybersecurity through the use of open source information gathering and active reconnaissance techniques. Its primary use case is to identify and map attack surfaces, enabling security professionals to assess the security posture of the networks they oversee. Notable features include its ability to aggregate data from various sources and integrate with existing tools, providing a robust framework for comprehensive threat assessment.
2026-08-03
Go
★ 221
Certstream Server Go is a high-performance server written in Go that aggregates, parses, and streams real-time data from multiple certificate transparency logs to clients via WebSocket connections. It serves as a drop-in replacement for the original Certstream server, enabling users to analyze newly issued TLS certificates with more reliability and ease of use. Key features include support for custom configuration of monitored CT logs, straightforward setup via precompiled binaries or Docker images, and multiple endpoints for data connection.
2026-08-03
Go
★ 20
Cloud Data is a repository designed to collect and parse cloud-related data from multiple supported cloud providers, including AWS and GCP, to extract useful information about specified targets. Users can define their targets in a `targets.txt` file, and the tool automates data fetching every seven days using GitHub Actions, with outputs saved for easy access. Notable features include customizable scheduling through cron jobs and integration with multiple data sources for comprehensive analysis.
2026-08-03
Go
★ 172
GoTor is a concurrent web crawler designed for robust web scraping through the Tor network, utilizing SOCKS5 support for anonymity. Its primary use case is to crawl websites while providing a JSON crawl report and a local HTTP API for job control, making it suitable for integration with applications like TorBot. Notable features include customizable crawl depth, worker count, and the ability to randomize headers, along with built-in diagnostics for Tor connectivity and health checks.
2026-08-03
Go
★ 3044
Uncover is a Go-based tool designed to automate the discovery of exposed hosts on the internet by leveraging the APIs of multiple search engines like Shodan, Censys, and FOFA. Its primary use case centers around efficiently querying these services in tandem, allowing for input via standard input and stdout, while supporting multiple API keys and automatic key randomization for enhanced security and operational efficiency. Notable features include the ability to utilize awesome search queries and a broad array of supported search engines, making it versatile for cybersecurity professionals.
2026-08-03
Go
★ 13
Watson is a tool designed for searching social media accounts across various platforms by checking for availability of specified usernames. Its primary use case is to assist users in verifying the existence of usernames on multiple sites simultaneously, utilizing features such as custom output folders, timeout settings for requests, and adjustable request speeds. Additionally, it supports querying multiple usernames and provides options for detailed output management and configurations.
2026-08-03
Go
★ 11
BannerGrapV2 is an advanced network reconnaissance and vulnerability discovery tool designed for both offensive and defensive security operations, making it suitable for Red and Blue Teams, bug bounty hunters, and security auditors. Notable features include multi-threaded banner grabbing, extensive service fingerprinting, a robust vulnerability detection engine, and flexible reporting options in multiple formats, all powered by a performance-focused architecture enabling concurrent scans of up to 10,000 hosts.
2026-08-03
Go
★ 588
Leaker is a passive leak enumeration tool that identifies valid credential leaks through various online sources, allowing searches by email, username, domain, keyword, and phone number. Notable features include support for multiple leak databases, deduplication of results, JSONL output for integration with pipelines, and built-in rate limiting with proxy support.
2026-08-03
Go
★ 14344
Subfinder is a fast passive subdomain enumeration tool designed to discover valid subdomains for websites by leveraging curated online sources. Its primary use case is for penetration testers and bug bounty hunters who require stealthy and efficient subdomain discovery, featuring modules for resolution and wildcard elimination, multiple output formats, and resource optimization. Subfinder supports STDIN/OUT integration and offers customizable source selection, filtering options, and rate-limiting to enhance its performance and adaptability in various workflows.
2026-08-03
Go
★ 40
go-fasttld is a high-performance module designed for the extraction of effective top-level domains (eTLD) and subcomponents from various URL formats, including hostnames and IP addresses (both IPv4 and IPv6). Utilizing the Mozilla Public Suffix List, it supports private domains and offers a command-line interface (CLI) for easy extraction, while also providing functionality to handle internationalized label separators. Notable features include the ability to pretty-print results and robust handling of different URL structures.
2026-08-03
Go
★ 165
kafSIEM is an edge-ready operations intelligence tool that monitors Kafka agent traffic and OSINT feeds to build an evidence-linked entity graph stored in SQLite. It provides an analyst workflow through a web desk and a typed OpenAPI, facilitating the tracking of unmanned systems and SCADA infrastructures. Notable features include a configurable analyst desk, domain-specific ontology packs, and a streamlined deployment via Docker without the need for a cluster database.
2026-08-03
Go
★ 30
URLInsane is a command-line tool designed for detecting domain typosquatting and facilitating OSINT (Open Source Intelligence) investigations across multilingual target domains. It generates and scans for potential typosquatting variants of a specified domain, allowing users to identify threats such as phishing and brandjacking, with features that include customizable variant generation, reporting options in various formats, and a focus on multiple target types beyond just domains.
2026-08-03
Go
★ 14
SubFors is a modular subdomain discovery tool designed for rapid enumeration of subdomains, integrating various techniques for comprehensive attack surface analysis. Notable features include multi-engine enumeration, API support for services like VirusTotal and GitHub, certificate transparency monitoring, and bulk domain processing with customizable wordlists. This tool is particularly beneficial for security professionals seeking to enhance their reconnaissance capabilities and automate the discovery process.
2026-08-03
Go
★ 37
uCVE is a cybersecurity tool developed in Go that facilitates the extraction of Common Vulnerabilities and Exposures (CVE) associated with specific software and version numbers. It generates reports in HTML format and supports exporting data in various formats, including text, JSON, and CSV, offering customizable search parameters such as risk levels and vendor inclusion/exclusion. The tool is designed for penetration testing and vulnerability management, streamlining the process of identifying security risks in software dependencies.
2026-08-03
Go
★ 26
Enraijin is a robust web brute-force framework designed for automating credential testing against HTTP(S) web forms. Its primary use case is to facilitate long-term brute-force runs with a focus on readability and easy configuration via a YAML file, while also supporting reliable proxy management and token crawling to enhance its effectiveness. Notable features include customizable settings for form fields, the ability to handle multiple configurations, and integration with notification systems for real-time feedback during tests.
2026-08-03
Go
★ 273
Fleex is a tool designed for orchestrating distributed workload execution across cloud-based VPS fleets, enabling rapid scaling of various security tools like masscan and nuclei. Its notable features include multi-provider support, user-friendly fleet management commands, distributed scanning capabilities, and result aggregation functionalities. Additionally, Fleex encompasses a build system for provisioning tools with pre-configured recipes and provides cost estimation before running tasks.
2026-08-03
Go
★ 388
lit-bb-hack-tools is a command-line toolkit specifically designed for bug bounty hunters and penetration testers, focusing on web application security assessments. It includes a variety of tools that analyze URLs to extract critical information such as unique extensions, headers, status codes, and potential security vulnerabilities like DOM XSS sinks. Noteworthy features include processing input from standard input, producing comprehensive outputs, and supporting various common web testing scenarios.
2026-08-03
Go
★ 1741
emp3r0r is an advanced, zero-trust post-exploitation framework and command & control (C2) system designed for secure operations on both Linux and Windows environments. Its notable features include autonomous gossip mesh networking, fileless memory execution of Starlark-scripted agents, and robust cryptographic identity pinning, ensuring high levels of stealth, operational control, and security against impersonation attacks. The framework facilitates seamless integration and execution without relying on host-based interpreters, making it highly suitable for high-security scenarios.
2026-08-03
Go
★ 24
The Dark Mark is a command and control (C2) framework designed for efficient management of cybersecurity operations, enabling real-time command execution and secure client communication. It supports scalability, facilitates monitoring of client activities, and is user-friendly for both small and large-scale deployments. Key features include an intuitive command set for module management and easy setup, making it a versatile tool for cybersecurity professionals and researchers.
2026-08-03
Go
★ 15
The cisco-snmp-pwner tool facilitates the exploitation of Cisco devices with read-write SNMP access by enabling users to dump the running configuration or add new users. It operates a local TFTP server to manage these configurations and supports SNMP versions 1, 2c, and 3, with customizable community strings and user roles. Notable features include the ability to merge configurations and streamline user management, while requiring root access to function properly.
2026-08-03
Go
★ 654
Goop is a robust tool designed for extracting complete Git repositories from websites, emphasizing comprehensive dumps and accommodating various edge cases often overlooked by other tools. It utilizes multiple strategies to recover files and objects from .git directories, even in the absence of directory listings. Notable features include directory management options, handling of rate limits, and the ability to process a list of domain names for batch operations.
2026-08-03
Go
★ 51
indextree is a tool designed for analyzing and filtering directory listing pages of web servers, allowing users to focus on specific files or directories based on various criteria such as file extensions or keyword matching. Its notable features include options for displaying directory or file mode, a configurable output tree structure, and protection against infinite loops during recursive scans. The tool is intended for educational and research purposes within the cybersecurity domain.
2026-08-03
Go
★ 532
Ligolo-MP is a sophisticated pentesting tool that facilitates collaborative pivoting through a client-server architecture, allowing multiple concurrent tunnels with automated TUN management. Its notable features include SOCKS and HTTP proxy support, cross-platform compatibility, and dynamic mTLS-enabled agent generation, all while providing a user-friendly terminal-based GUI for efficient monitoring and management.
2026-08-03
Go
★ 33
Lurker is a cross-platform implant designed to function as a companion tool for Cobalt Strike, implemented in Go. It facilitates various commands such as file upload, download, and remote shell execution, enabling comprehensive control over target systems across multiple operating systems including Windows and Linux. Notably, it emphasizes security research and authorized penetration testing, providing a flexible and customizable platform for security assessments.
2026-08-03
Go
★ 525
csprecon is a reconnaissance tool designed to discover new target domains by leveraging Content Security Policy (CSP) data. Its primary use case is for security professionals conducting reconnaissance in order to identify potential attack surfaces across multiple domains, with features such as concurrent requests, domain filtering, output options in JSON format, and the ability to handle CIDR input. The tool can also be configured for rate limiting and proxy usage, making it versatile for various operational environments.
2026-08-03
Go
★ 14
frameseven is a CLI-oriented offensive web security scanner designed for authorized security testing, capable of mapping a target's attack surface while executing active checks for prevalent web vulnerabilities and misconfigurations. Key features include extensive reconnaissance capabilities, support for authenticated scans, and structured reporting options, along with a dedicated MCP server for AI agents to utilize the same framework tooling. The tool emphasizes a standard-library-centric Go codebase, enhancing readability and extendability.
2026-08-03
Go
★ 965
goshs is a versatile, single-binary file server designed for file transfer and capture tasks during penetration testing engagements. It supports multiple protocols including HTTP/S, WebDAV, FTP/SFTP, SMB, and LDAP, and offers features such as hash capturing, basic authentication, self-destructing payloads, and a TUI for interactive operations. Notable functionalities include token-based link sharing, DNS and SMTP server capabilities, and advanced collaboration tools for CTF scenarios.
2026-08-03
Go
★ 20
Kentra is a Kubernetes-based offensive security framework designed for orchestrating penetration testing, red teaming operations, and large-scale security scans, both within and outside Kubernetes clusters. It allows users to define security tests as declarative YAML manifests, automating orchestration, scheduling, and logging through its native Kubernetes resources. Notable features include integration with Helm for deployment, a customizable dashboard for command output aggregation, and the use of a ConfigMap to manage tool specifications.
2026-08-03
Go
★ 305
knary is a canary token server designed to alert users via messaging platforms like Slack, Discord, and Teams when specific HTTP(S) or DNS requests are made to designated domains. Its primary use case is to enhance offensive security by notifying teams of interactions with their controlled servers, thereby revealing potential vulnerabilities and providing insights into unauthorized access attempts. Notable features include subdomain allow/denylisting, integration with Burp Collaborator, and automatic TLS certificate management through Let's Encrypt.
2026-08-03
Go
★ 2403
Pentest Swarm AI is an open-source penetration testing tool that leverages a swarm architecture for coordinated multi-agent operations, enabling efficient vulnerability assessment. Its primary use case is facilitating authorized security testing through live integration with popular offensive tools like nmap, sqlmap, and Metasploit, while incorporating AI models for advanced analysis. Notable features include a stigmergic blackboard for agent coordination, automated evidence capture, and the ability to generate submission-ready reports.
2026-08-03
Go
★ 103
XMT (eXtensible Malware Toolkit) is a versatile command and control (C2) framework written in Golang, designed for malware analysis and control functions, including data exfiltration. It features advanced process control for Windows, efficient networking resources, and compatibility with older Windows systems, while maintaining a minimal file size of approximately 5MB. Additionally, XMT supports various utility functionalities and aims for continuous enhancements, making it suitable for researchers and security professionals exploring cybersecurity threats.
2026-08-03
Go
★ 270
grafanaExp is a tool designed to exploit the CVE-2021-43798 vulnerability in Grafana, enabling automated detection of vulnerable instances, extraction of keys, and decryption of server database files. Its primary use case is to assist in the security assessment of Grafana installations by providing the capability to reveal sensitive configuration data and datasource information. Notable features include an 'exp' command for vulnerability detection and information retrieval, and a 'decode' command for local decryption of large database files.
2026-08-03
Go
★ 280
Padre is an advanced tool designed for conducting Padding Oracle attacks against CBC mode encryption, enabling the decryption of tokens and encryption of arbitrary data. It features automatic fingerprinting of padding oracles, detection of cipher block lengths, and provides hints for overcoming failures during operations, all while supporting various encoding rules for enhanced flexibility. Particularly useful for security researchers and penetration testers, Padre can effectively exploit vulnerabilities to disclose encrypted session information or bypass authentication mechanisms.
2026-08-03
Go
★ 18
SeTcbPrivilege Local Privilege Escalation (LPE) is a tool implemented in Go that leverages the SeTcbPrivilege privilege escalation technique to allow users to execute arbitrary commands with elevated permissions on Windows systems. Its primary use case is for gaining administrative access by manipulating service configurations, and it features automatic service deletion post-execution, with a manual clean-up option available. This tool provides a streamlined method for executing commands that would normally require higher privileges.
2026-08-03
Go
★ 116
AKILT is an open-source botnet framework designed for security enthusiasts and malware analysts to facilitate the study of botnet operations. Written in Go, it supports both client and server functionalities with advanced features such as screen capture, remote command execution, DDOS attacks, and a keylogger, while aiming to remain undetectable. The tool provides a valuable resource for understanding the implementation and behavior of botnets in a controlled environment.
2026-08-03
Go
★ 264
Bluebox is a collection of exploits tailored for various VoIP products, primarily designed for penetration testing and the exploitation phase of VoIP environments. It utilizes the Go Exploit Framework and features a Docker Compose file that includes an Asterisk server for testing purposes, facilitating a streamlined approach for security professionals to assess vulnerabilities in VoIP systems.
2026-08-03
Go
★ 274
Octoscan is a static vulnerability scanner designed for GitHub action workflows, enabling users to identify potential security issues within their CI/CD pipelines. Its primary use case is analyzing workflows for various vulnerabilities, including dangerous actions, credentials exposure, and expression injection. Notable features include the ability to download workflows from remote repositories, customizable rule sets for scanning, and support for multiple output formats, ensuring flexibility in vulnerability reporting.
2026-08-03
Go
★ 68
OnlyShell is a Go-based reverse shell handler designed for penetration testers and security researchers, enabling the management of multiple reverse shell connections concurrently. Key features include automatic shell type detection, background shell management, command broadcasting across active shells, and the option for encrypted communications with TLS support. The tool offers an intuitive command-line interface and allows for real-time interaction and status monitoring of all connected sessions.
2026-08-03
Go
★ 12
Prober is a pentesting framework designed to simplify the management of GitHub repositories by eliminating the complexities of git submodules. Its primary use case is to allow penetration testers to easily download and clone necessary tools with straightforward commands, enhancing usability in security assessments. Notable features include a clean execution script and a focus on user-friendly setup processes.
2026-08-03
Go
★ 26
CVE-2025-32463 is a Go-based exploit tool designed to exploit a critical local privilege escalation vulnerability in sudo versions 1.9.14 to 1.9.17. The tool manipulates the `--chroot` option to load a malicious shared library, allowing unauthorized users to gain root access. Notable features include the ability to run the exploit in both normal and silent modes, and it supports building from source or using a pre-built binary.
2026-08-03
Go
★ 26
Capsaicin is a next-generation web directory and asset discovery engine designed for red teamers, bug bounty hunters, and DevSecOps. It employs advanced evasion techniques, including TLS fingerprint spoofing and human-like delay simulations, to bypass modern web application firewalls and effectively uncover hidden paths, secrets, and misconfigurations. Notable features include smart auto-calibration to eliminate false positives, stateful fuzzing for misconfigured APIs, and the ability to detect over 16 different WAFs.
2026-08-03
Go
★ 44
CyberMind CLI v6.0 is a powerful AI-driven offensive security tool designed for a diverse range of users including bug bounty hunters, red teamers, penetration testers, and security researchers. It offers 22 autonomous attack modes, a unique OMEGA brain orchestration feature, and support for exploiting Web3, mobile, and cloud environments, while integrating seamlessly with Kali tools. Key features include manual and automated execution options, real-time alerting via Telegram, and a VSCode extension for enhanced usability.
2026-08-03
Go
★ 10
NightCloak is a statically-linked Go binary designed for metadata steganography and string obfuscation, allowing users to embed encrypted payloads into various file formats through a sophisticated multi-layer pipeline involving obfuscation, authenticated encryption, and binary injection. It supports distributed resiliency via Reed-Solomon erasure coding and enables discovery through CRC64 algebraic beacons, making it highly effective for covert data storage and transmission. The tool modernizes and ports previous versions while preserving core functionalities and operational models.
2026-08-03
Go
★ 475
PingRAT is a command and control (C2) tool that utilizes ICMP payloads to stealthily transmit C2 traffic through firewalls, making it largely undetectable by most antivirus and endpoint detection and response solutions. It is implemented in Go and offers features such as server-client architecture for communication, allowing for flexible network interface configuration. This tool is primarily aimed at facilitating covert operations in environments with strict traffic monitoring.
2026-08-03
Go
★ 453
Arachne C2 is a decentralized Command & Control framework leveraging libp2p for peer-to-peer communication, eliminating reliance on a central server or fixed IP addresses. Its notable features include self-contained binaries for cross-platform implant generation, encrypted messaging, interactive operator consoles, and built-in NAT traversal techniques, all designed to maintain operational continuity and enhance resilience against detection and takedown. This framework is particularly suited for secure, covert operations requiring dynamic connectivity amid adversarial environments.
2026-08-03
Go
★ 621
arsenal-ng is a modern pentest command launcher developed in Go, designed to enhance the efficiency of security assessments by providing instant access to a vast library of tools and commands. Notable features include a smart search with fuzzy matching, syntax highlighting for improved command readability, an intuitive terminal user interface for easy navigation, and support for global variables that streamline command usage. This tool prioritizes simplicity and speed, making it a valuable asset for cybersecurity professionals.
2026-08-03
Go
★ 40
`git-fire` is a command-line interface (CLI) tool designed for efficiently checkpointing multiple Git repositories simultaneously. Its primary use case is to facilitate the safe backup of local changes across numerous repos by discovering repositories, optionally auto-committing uncommitted changes, and pushing backup branches with added recovery safety. Notable features include the ability to perform dry-run previews for safety and a streamlined emergency mode for quick execution under pressure.
2026-08-03
Go
★ 12
GoFenrir is an Active Directory enumeration and attack framework developed in Go, leveraging the Manticore protocol backend for efficient operations without dependency complexities. It supports various protocols, including LDAP/LDAPS for full enumeration, Kerberos for advanced credential attacks, and has a plan to support SMB v2/v3, providing a robust suite of enumeration and exploitation features ideal for penetration testing. Notable functionalities include user and group enumeration, domain controller discovery, and advanced Kerberos attack capabilities like Kerberoasting and AS-REP roasting.
2026-08-03
Go
★ 34
Lain C2 is a command-and-control framework designed to facilitate secure communication between compromised hosts and operators across multiple platforms including Windows, Linux, macOS, and Android. It supports various communication protocols such as HTTP/1, 2, and 3, and integrates third-party libraries for enhanced functionality, making it a versatile tool for conducting remote management and operations. Notable features include cross-platform compatibility and efficient handling of system metrics and processes.
2026-08-03
Go
★ 21
Maldev is a comprehensive Go library designed for malware engineering, providing tools for syscall manipulation, evasion techniques, code injection, credential harvesting, and persistence mechanisms. Its capabilities include a variety of syscall calling methods, extensive evasion techniques against detection mechanisms, and robust injection methods, all integrated through a unified syscall caller for enhanced stealth and flexibility. The library is aimed at authorized security research, red teaming, and penetration testing, ensuring a modular approach to malware development with an emphasis on cross-compilation without CGO dependencies.
2026-08-03
Go
★ 227
PromptZero is a natural-language operator designed for the Flipper Zero device, enabling users to generate, deploy, and execute various payloads through simple text commands. It primarily facilitates tasks related to RF, NFC, RFID, and HID payload creation while offering an intuitive interface for both offensive and defensive cybersecurity scenarios. Notable features include end-to-end integration with Claude AI for payload generation, a read-only operational mode for safe usage, and real-time querying of connected devices.
2026-08-03
Go
★ 55
Sopa is a Golang-based client for the Active Directory Web Services (ADWS) protocol, facilitating comprehensive directory management operations. It supports object search and retrieval, lifecycle management, attribute editing, account management, and custom actions while leveraging WS-Enumeration, WS-Transfer, and other protocols. Notable features include the ability to create, delete, and modify objects, as well as manage account passwords and group memberships.
2026-08-03
Go
★ 47
Zscan is a fast and customizable service detection tool designed to identify services, APIs, and network configurations within infrastructure using a flexible fingerprint system. Key features include high-performance concurrent port scanning, intelligent service detection capabilities (such as MAC vendor identification and OS fingerprinting), precise proof of concept (POC) targeting, and versatile output formats including JSON and human-readable options. This tool enhances scanning accuracy and speed compared to traditional methods, making it valuable for network security assessments.
2026-08-03
Go
★ 36
Geiger is a read-only blast-radius triage tool designed for assessing the impact of leaked credentials by identifying what resources they can access. It excels in incident response and penetration testing scenarios by running dry-run recon against credentials to evaluate their reach without altering any systems. Notable features include the ability to process various input formats, integration with other security tools like TruffleHog and Nuclei, and the option for live testing to provide impact assessments while preserving a read-only modality.
2026-08-03
Go
★ 170
ASHIRT is an automated adversary simulation documentation tool designed to centralize the capture, indexing, and searchability of evidence collected during operations. Its primary use case is to streamline the process of documenting activities by providing a non-intrusive methodology that reduces manual steps and enhances sharing across teams. Notable features include support for high-fidelity data synchronization and a dedicated frontend and backend architecture for improved usability and deployment flexibility.
2026-08-03
Go
★ 318
Brutus is an advanced, multi-protocol authentication testing tool designed for penetration testers and red team operators, enabling efficient credential validation across a diverse range of network services such as SSH, RDP, and databases. Built in Go as a single binary with no external dependencies, it offers features like SOCKS5 proxy support, aggressive mode tuning, and seamless integration with tools like Nerva and naabu for automated workflows. Notably, it includes a library of known bad keys and supports account enumeration, making it a versatile asset for modern offensive security practices.
2026-08-03
Go
★ 251
pphack is an advanced client-side prototype pollution scanner designed to identify vulnerabilities in web applications. It offers a variety of features including the ability to scan single or multiple URLs, configure concurrency levels, set timeouts, and conduct automatic exploitation. The tool utilizes Chrome or Chromium for its operations, allowing for custom JavaScript execution and flexible output options such as JSON format.
2026-08-03
Go
★ 25
Sandbox Probe is a static Go binary designed to evaluate the boundaries of sandbox environments used by AI coding agents and other applications. By performing a comparative analysis between a baseline scan on a host and a scan within the sandbox, it identifies potential security gaps, such as unauthorized access to sensitive paths or network resources. Notable features include customizable task sets for various types of actions, JSON report generation for findings, and the ability to track sandbox policy changes over time.
2026-08-03
Go
★ 11763
Sliver is an open-source adversary emulation and red team framework designed for security testing in organizations of all sizes. It features dynamic code generation, multiple secure command and control (C2) communication methods including mTLS and WireGuard, and supports a wide range of platforms while allowing for advanced tactics like process injection and in-memory execution. The framework is highly scriptable in Python and offers functionalities like compile-time obfuscation and multiplayer-mode for enhanced testing scenarios.
2026-08-03
Go
★ 376
SmokedMeat is a CI/CD post-exploitation framework designed to analyze, exploit, and validate security vulnerabilities within continuous integration and deployment pipelines. It automates the identification of injection vulnerabilities in GitHub Actions workflows, facilitates the deployment of malicious payloads, and allows attackers to pivot across cloud environments to extract secrets and permissions. This tool is primarily intended for red teams, penetration testers, and security researchers to demonstrate and assess the resilience of CI/CD systems against advanced supply chain attack techniques.
2026-08-03
Go
★ 27
SubdomainX is an advanced subdomain discovery and security reconnaissance tool that integrates over twelve enumeration tools and six API services into a single command-line interface (CLI). Its primary use case is to facilitate comprehensive subdomain enumeration, vulnerability detection, and monitoring, featuring capabilities such as HTTP probing, technology fingerprinting, subdomain takeover detection, and notifications via various platforms. Notable features include the ability to generate detailed reports in multiple formats, an interactive terminal user interface (TUI), and support for resuming interrupted scans, making it a robust solution for security assessments.
2026-08-03
Go
★ 687
Titus is a high-performance secrets scanner designed to detect credentials, API keys, and tokens within source code, files, and git history. Targeted at security engineers and DevSecOps teams, it features accelerated regex matching, live secret validation, broad coverage with 487 detection rules, and multiple scanning interfaces including CLI, Go library, and browser extensions. Notably, Titus also supports container image scanning and binary file extraction for enhanced security assessments.
2026-08-03
Go
★ 10
Emailfinder is an open-source OSINT tool designed to extract email addresses from various search engines and platforms, including Google, DuckDuckGo, Bing, Yahoo, Yandex, and GitHub. It operates via a command-line interface, supporting batch processing of domains and offering flexibility through its command structure, allowing users to customize their searches for specific engines and exact matches. Notable features include the ability to fetch results from multiple sources and provide an autocompletion script for enhanced usability.
2026-08-03
Go
★ 210
`fileless-xec` is a penetration testing tool that enables stealthy execution of remote binary files directly in memory, avoiding disk write operations. It utilizes the `memfd_create` and `fexecve` system calls for secure execution, supports customizable program names, and can bypass network restrictions through ICMP and HTTP3. Notable features include self-removal after execution and the capability to execute binaries without prior installation dependencies on the target system.
2026-08-03
Go
★ 391
GoLinkFinder is a minimalistic JavaScript endpoint extractor designed for security professionals such as bug hunters and red teamers. It efficiently extracts endpoints from both HTML sources and embedded JavaScript files by processing a specified domain, and outputs the results to a file or standard output. Notable features include seamless integration with command-line tools like grep, enhancing its utility in automated security assessments.
2026-08-03
Go
★ 83
gubble is a security auditing tool specifically designed to analyze Google Workspace group settings, identifying potential risks associated with group configurations such as membership permissions, visibility, and messaging capabilities. Its primary use case is to facilitate penetration tests by automating the detection of misconfigurations that could lead to privilege escalation or data exposure. Notable features include the ability to assess various permission settings, including who can join groups, post messages, and view membership, enabling security assessments of Google Groups effectively.
2026-08-03
Go
★ 14
r3conwhal3 is a multifunctional reconnaissance tool designed for web application data collection and analysis, employing a concurrency-based approach to enhance performance and resource efficiency. Its primary use case includes performing both passive and active reconnaissance, with capabilities to enumerate subdomains, conduct vulnerability scans, and manage custom configurations through an environment file. Notable features include a comprehensive execution chain, support for Docker deployment, and the ability to save output results for future reference.
2026-08-03
Go
★ 313
SmuggleFuzz is a configurable HTTP downgrade smuggling scanner designed to identify overlooked smuggling vulnerabilities in web applications. Its notable features include customizable gadget lists, multiple scanning options with support for various HTTP methods and headers, and the ability to filter responses by specific criteria. The tool enables deeper insights into failed attacks, making it a powerful resource for security professionals aiming to enhance their vulnerability assessments.
2026-08-03
Go
★ 54
Supernova_CN is an open-source shellcode encryption tool developed in Golang, designed to facilitate the encryption of raw shellcode using various algorithms such as XOR, RC4, AES, and CHACHA20. It allows users to convert the encrypted shellcode into compatible formats for multiple programming languages, and provides corresponding decryption code as guidance for implementation. Notably, the tool includes a comprehensive command-line interface and supports encryption in Base64 formats for added versatility.
2026-08-03
Go
★ 27
AndroSecTest is a security auditing tool designed for static analysis of Android applications to identify vulnerabilities and insecure behaviors. It utilizes a Docker container for easy setup and includes functionalities such as unpackaging APK files, examining application signatures, and checking for sensitive data within the application's file system. Notably, the tool facilitates interaction with connected Android devices via ADB commands, though results are currently not persisted outside the Docker environment.
2026-08-03
Go
★ 12
certinfo is an SSL certificate scraping tool designed to extract domain names from SSL certificates across multiple hosts. Its primary use case includes both basic certificate data extraction and recursive enumeration of subdomains through Certificate Subject Alternative Names (SANs), offering features like multi-threaded processing, support for varied input formats, and real-time output. Users can choose from multiple output formats, including JSON and CSV, and customize the number of concurrent workers for efficiency.
2026-08-03
Go
★ 43
haktrailsfree is a command-line tool designed to extract up to 10,000 subdomains from SecurityTrails using user-provided cookies instead of an API key, effectively bypassing the limitations of the free API tier. Key features include the ability to handle both single and multiple domains, configurable cookie input, and options for silent or verbose output. This tool facilitates extensive subdomain enumeration, making it valuable for security assessments and research.
2026-08-03
Go
★ 11
hidden_fuzzer is a command-line tool designed for rapid web content discovery, specifically targeting hidden paths and directories in web applications. Leveraging Jaro and Jaro-Winkler similarity algorithms, it automatically filters out false positives without the need for complex configurations. Notable features include multi-threaded scanning, recursive directory fuzzing, and support for various customizations such as proxy routing and parameter fuzzing.
2026-08-03
Go
★ 82
HTTPUploadExfil is a simple HTTP server designed in Go for exfiltrating files and information from a machine using HTTP, particularly suited for low-stakes offensive scenarios like Capture The Flag (CTF) competitions. It offers an interface that allows users to upload files, uses basic GET requests to log data, and supports multiple endpoints for file management and retrieval. Notable features include customizable bind addresses, support for SSL/TLS, and a straightforward build process.
2026-08-03
Go
★ 17
ipfinder is a command-line tool designed to efficiently extract IP addresses and other data from Shodan search queries, catering to both advanced users and beginners through its support of complex query syntax and simple domain-based filtering. Key features include flexible facet selection, options for filtering query types, handling of HTTP errors with retry logic, and the ability to control output verbosity, making it suitable for robust cybersecurity investigations and data extraction tasks.
2026-08-03
Go
★ 13
Nucleihub is a tool designed for organizing and managing Nuclei templates from various community sources, enabling users to consolidate template files efficiently. It features auto-flattening of directory structures, duplicate handling, smart filtering, and validation of downloaded templates, with optimizations for low-resource environments. The tool supports URLs ending in `.git`, `.yaml`, or `.zip` formats, enhancing flexibility in template retrieval.
2026-08-03
Go
★ 25
OpenShell is an open-source reverse shell management server developed in Go, enabling users to establish and manage reverse shell connections through a web-based graphical user interface. Its primary use case is for educational and research purposes in cybersecurity, featuring a lightweight server architecture, WebSocket interaction, and support for multiple terminal tabs within the GUI. Notable features include easy command generation for reverse shells, session management, and an emphasis on security practices through the use of certificates.
2026-08-03
Go
★ 50
OriginipHunter is a Go-based tool designed to identify the origin IP addresses of domains by leveraging multiple security APIs, including Shodan and SecurityTrails. Its notable features include support for concurrent validations, parallel execution for improved performance, and customizable settings through a configuration file. The tool outputs results in various formats and allows users to easily manage API keys for different services, enhancing its flexibility in domain reconnaissance.
2026-08-03
Go
★ 11
ParamFinder is a tool designed for security assessment that crawls input and textarea tags on web pages to identify and manipulate parameters for testing vulnerabilities, particularly in the context of web applications. It allows the user to input single or multiple URLs, automatically generating modified URLs with specified parameters for ease of testing, while offering features such as concurrency options, output file configurations, and the ability to operate in silent or verbose modes. Notably, it facilitates the identification of potential security issues like XSS by transforming input parameters with preset values, ensuring a streamlined approach to parameter analysis.
2026-08-03
Go
★ 11
portmap is a high-speed port scanning tool that leverages Shodan's public data to identify open ports associated with specified IP addresses or CIDR ranges. Its primary use case is to quickly ascertain accessible services on remote hosts using Shodan's APIs, featuring commands for basic port scans and enhanced details retrieval, including ASNs and organization details. Notable functionalities include JSON output options, support for multiple IP inputs, and a user-friendly command-line interface.
2026-08-03
Go
★ 21
pvreplace is a robust URL parameter and request fuzzing tool designed to enhance security assessments by processing URLs or Burp Suite raw requests, substituting values with custom payloads while preserving unique parameter combinations. Notable features include multiple fuzzing types (replace, prefix, postfix), various fuzzing modes (single, multiple), and the ability to target specific components such as parameter names, values, path segments, and headers. The tool facilitates a comprehensive fuzzing approach to identify vulnerabilities within web applications.
2026-08-03
Go
★ 17
SocialFinder is an efficient username enumeration tool built in Go, designed to verify the availability of usernames across multiple social media platforms and websites. It offers real-time output, customizable URL lists, and smart matching for URL variations, allowing for rapid enumeration with clear, colored terminal results. The tool is optimized for performance using httpx, and it supports options like inclusion of NSFW sites and silent mode for discreet checks.
2026-08-03
Go
★ 68
subdog is a comprehensive subdomain enumeration tool designed to aggregate subdomains from over 17 different data sources, providing cybersecurity professionals with extensive lists of root subdomains. Notable features include parallel processing for expedited results, output options for saving to files while displaying terminal output, and automatic duplicate removal along with normalization to filter unwanted entries. By supporting external tools and allowing flexible source selection, subdog enhances the efficiency and effectiveness of subdomain discovery tasks.
2026-08-03
Go
★ 35
tldscan is a high-performance domain scanner designed to identify active domains by testing various Top-Level Domains (TLDs) against user-specified domain names. It features customizable concurrency levels, wordlist options for domain generation, and the ability to output results to a specified file, making it suitable for domain reconnaissance tasks in cybersecurity. Notably, users can choose between small and large wordlists and utilize silent or verbose modes for streamlined operation or detailed debugging.
2026-08-03
Go
★ 168
Turbo-attack is a pentesting tool designed to generate random network traffic with variable MAC and IP addresses, enhancing testing capabilities for network resilience against traffic-based attacks. It supports both IPv4 and IPv6 on various Linux architectures (ARM64 and AMD64), and is optimized for environments such as Kali Linux using native syscalls for improved performance. This tool is intended for educational use and emphasizes responsible usage to prevent unauthorized access to networks.
2026-08-03
Go
★ 17
unew is a high-performance command-line utility designed for efficiently processing and managing unique lines from input streams, offering functionalities similar to `sort`, `uniq`, and `tee`. Its primary use case is deduplication and data organization, featuring advanced capabilities such as case-insensitive processing, file splitting, shuffling, and the ability to append new unique lines to existing files. Benchmarked against similar tools, unew demonstrates superior speed and memory efficiency, making it suitable for handling large datasets.
2026-08-03
Go
★ 66
The Venera Framework is a Lua-based tool designed for automating customizable tests and attacks across various protocols. Its primary use case lies in vulnerability scanning and exploitation, allowing users to create and manage scripts that target specific vulnerabilities or conduct general verification tasks. Notable features include a built-in package manager, the ability to import and export scripts, and a flexible scripting environment that supports user-defined modules for tailored security testing.
2026-08-03
Go
★ 20
vulntechfinder is an automated vulnerability scanning tool that utilizes technology stack detection to execute targeted scans using tools like Nuclei and httpx. It supports features such as automated tech stack identification, configurable parallel processing, smart filtering for technology inclusion, and crash-safe resume capabilities, making it versatile for various scanning needs. The tool is compatible with any security tool that accepts technology tags, thereby enhancing its utility in security assessments.
2026-08-03
Go
★ 13
WaybackURLsX is a Go-based tool designed to extract archived URLs from the Wayback Machine, emphasizing performance and user-configurable features. It offers smart filtering for sensitive files, adaptive rate limiting to comply with Wayback Machine constraints, and automatic retry mechanisms with exponential backoff for robust error handling. Notable features include detailed logging, support for domain-specific searches, and the capability to filter results based on custom regex patterns.
2026-08-03
Go
★ 10
Cokmap is a high-speed network scanner developed in Go that detects services and products on open ports using probes formatted according to the nmap-service-probes schema. Notable features include rapid product detection through a plugin architecture, support for flexible configuration, and the ability to generate detailed statistics. It is compatible with both Linux and macOS systems and offers a straightforward command-line interface for input and output handling.
2026-08-03
Go
★ 341
Crawley is a web crawling tool that efficiently parses HTML pages to discover and print links, including resources like images, audio, and video. It features a fast SAX-parser, customizable scan depth, compliance with `robots.txt`, support for subdomain crawling, and options for ignoring certain URLs or scanning specific tags. Additionally, Crawley allows for the use of user-defined cookies and headers, making it adaptable for various crawling scenarios.
2026-08-03
Go
★ 24
DirRunner is a Go-based command-line tool designed for DNS enumeration, directory discovery, virtual host identification, FUZZ payload testing, and basic HTTP fingerprinting. With features such as worker pools for concurrent processing, streaming result output, and customizable HTTP requests via command-line flags, it is optimized for performance and flexibility without relying on third-party dependencies. The tool supports multiple modules for specific tasks and offers options for JSON output, deterministic exports, and the ability to route traffic through Tor for added anonymity.
2026-08-03
Go
★ 35
emailextractor is a high-speed email scraping tool developed in Go that enables concurrent crawling of websites to extract email addresses for purposes such as reconnaissance and sales intelligence. Key features include fast concurrent processing, fallback to headless Chrome for JavaScript-rendered content, smart URL normalization, and optional JSON output for easy integration.
2026-08-03
Go
★ 10
Gitar is a sophisticated Python-based HTTP server designed for simple and efficient file exchange during penetration tests and capture the flag (CTF) competitions. It enables users to quickly upload and download files and directories to and from a target machine without requiring installation, while also offering features such as HTTP webhook logging and secure container deployment options. Notable functionalities include minimal command shortcuts for file transfers and additional modes for logging and secure sending.
2026-08-03
Go
★ 19
gosqli is a specialized tool designed for the rapid and accurate detection of blind SQL injection vulnerabilities using time-based techniques. It can scan both URLs and HTTP request files with user-defined payloads, ensuring zero false positives through sequential testing and real-time verification of results. Notable features include automatic exploitation integration with tools like sqlmap, configurable output options, and support for proxy routing, making it suitable for comprehensive security assessments.
2026-08-03
Go
★ 10334
httpx is a versatile and high-performance HTTP toolkit designed for probing web services effectively. Its primary use case focuses on conducting a variety of HTTP-based checks such as status codes, content length, and various headers, equipped with features like smart fallback from HTTPS to HTTP, multi-threading, and error handling for WAFs. With a modular code base and customizable flags, httpx allows users to efficiently gather information from URLs, IPs, or CIDR networks while automatically managing retries and backoff strategies.
2026-08-03
Go
★ 17
LLMrecon is an advanced security testing framework specifically designed to identify and exploit vulnerabilities in Large Language Models (LLMs), adhering to the OWASP Top 10 2025 guidelines. It features a variety of novel attack techniques such as FlipAttack and DrAttack, along with machine learning-optimized attack selection, comprehensive defense detection capabilities, and support for testing models from multiple platforms, making it suitable for enterprise-level deployment.
2026-08-03
Go
★ 38
PentLog is an evidence-first pentest logging tool designed to capture high-fidelity terminal output during penetration testing engagements. Its primary use case includes providing searchable logs, compliance-ready reports, and interactive timelines for real-world auditing and engagements such as OSCP and HackTheBox. Notable features include automatic organization of commands, AI analysis for summarization, real-time session sharing, and AES-256 encryption for secure archives, addressing the common challenges faced in traditional logging methods.
2026-08-03
Go
★ 168
QueenSono is a Golang package designed for data exfiltration utilizing the ICMP protocol for both IPv4 and IPv6. Its primary use case is to bypass network monitoring systems that do not actively inspect ICMP traffic, making it effective in environments with limited oversight, such as public Wi-Fi networks. Notable features include the ability to send and receive files using ICMP packets, and its implementation of acknowledgment mechanisms to confirm data reception.
2026-08-03
Go
★ 33
Tacos is a tool designed to facilitate the creation of interactive reverse shells with minimal prerequisites, specifically targeting environments lacking the socat utility. It leverages containerization for easy deployment while offering advanced configuration options, automatic detecting of default shells, and a built-in multi-handler listener feature. Notably, Tacos allows users to obfuscate connections and easily expose listeners to the internet, enhancing accessibility and stealth during penetration testing activities.
2026-08-03
Go
★ 13
Techfinder is a high-performance technology detection tool developed in Go, designed to identify web technologies and frameworks—including dynamically loaded JavaScript frameworks—using a headless browser with a reusable browser pool for enhanced scanning speeds. It features multi-threaded processing, various output formats (plain text, JSON, CSV), Discord integration for real-time alerts, and robust configuration options for large-scale scans. Key capabilities include a fast static detection mode, crash-safe resume functionality, and automated downloading of necessary fingerprint data on first use.
2026-08-03
Go
★ 152
WordList is a comprehensive tool for generating custom wordlists intended for web application fuzzing and reconnaissance tasks. It supports the creation of various specialized wordlists, including those for DNS enumeration, default credentials, and parameters extracted from URLs, while also offering integrations for use with the Nuclei vulnerability scanner. Notable features include the ability to aggregate wordlists from multiple sources, classifies output by size, and efficiently prepares tailored wordlists based on specific URL patterns and application technologies.
2026-08-03
Go
★ 55
XSSRecon is an automated tool designed for the discovery of reflected XSS vulnerabilities in web applications by testing URL parameters for reflection of a specified payload. It features a dual detection method for assessing input reflection in both HTTP responses and DOM, as well as support for concurrent processing and customizable testing of special characters. Additional capabilities include smart optimizations for testing efficiency, flexible output formats, and integration with external tools like `pvreplace` for precise parameter injection.
2026-08-03
Go
★ 14
Arsenic is a tool designed to establish standard conventions for organizing penetration testing data, primarily focusing on directory structures and file naming conventions. Its notable features include the ability to create custom operation setups, a dedicated structure for storing host information and reconnaissance data, and integration capabilities with other tools like arsenic-hugo to enhance the offensive operations process. Arsenic aims to streamline and augment the workflow of penetration testers by making data management more systematic and enjoyable.
2026-08-03
Go
★ 3632
Cariddi is a domain crawling and scanning tool designed to identify sensitive information such as endpoints, secrets, API keys, and various file extensions from a list of provided URLs. Notable features include intensive crawling of subdomains, options for hunting specific secrets and errors, and customizable scanning parameters, making it particularly useful for penetration testing and bug bounty hunting. The tool can be easily installed across various platforms, supporting both single-target and bulk scanning configurations.
2026-08-03
Go
★ 16611
ffuf is a high-performance web fuzzer developed in Go, designed for conducting security testing by discovering hidden resources on web applications. Its primary use cases include directory and virtual host discovery, as well as fuzzing GET and POST parameters, allowing users to efficiently identify vulnerabilities and misconfigurations. Notable features include customizable wordlists, support for interactive mode, and the ability to filter responses based on their size, enhancing both speed and effectiveness in identifying potential security flaws.
2026-08-03
Go
★ 11997
Hetty is an open-source HTTP toolkit designed for security research and penetration testing, serving as an alternative to commercial tools like Burp Suite Pro. Its notable features include a machine-in-the-middle (MITM) HTTP proxy with logging capabilities, an HTTP client for crafting and replaying requests, request and response interception for manual review, organized project-based database storage, and a user-friendly web-based interface. Hetty is continually under development, aiming to meet the needs of the infosec and bug bounty communities effectively.
2026-08-03
Go
★ 126
RUDY (R-U-Dead-Yet?) is a Denial of Service tool designed for executing low-rate "slow and low" attacks that target web servers by sending long form data in small packets at a slow rate. Its interactive console facilitates user-friendly operation, allowing users to simulate concurrent POST requests with customizable parameters such as request intervals, payload sizes, and the ability to use a TOR proxy for anonymity. This tool is primarily intended for educational and testing purposes to analyze server behavior under resource-saturation attacks.
2026-08-03
Go
★ 95
Secbutler is a utility tool designed for penetration testers, bug bounty hunters, and security researchers, streamlining common tasks in cybersecurity assessments. It includes features such as generating reverse shell commands, setting up proxies, downloading payloads, and managing wordlists, thus enhancing productivity during security audits. The tool aims to cater to community needs, welcoming suggestions and contributions for continuous improvement.
2026-08-03
Go
★ 24
urlX is a high-performance reconnaissance tool for bug bounty hunters, penetration testers, and security researchers, facilitating passive URL discovery from over 11 intelligence sources, live host probing, and active web crawling for hidden endpoints. Its key features include smart file and extension filtering, concurrent processing using Go routines, and optional integration with various API keys to enhance results. Designed for swift and effective attack surface identification, urlX requires minimal setup and is built for real-world reconnaissance workflows.
2026-08-03
Go
★ 343
AgentHound is an open-source offensive security framework designed for AI agent infrastructures, capable of conducting comprehensive reconnaissance, asset fingerprinting, credential harvesting, model inventorying, and active exploitation. It integrates findings into a Neo4j graph to visualize attack paths, addressing every layer of the agentic stack, including model gateways and inference servers. Notable features include credential inventorying, model inversion capabilities, and the ability to perform active exploitation through tool and instruction poisoning.
2026-08-03
Go
★ 244
AutoAR is an automated security reconnaissance and vulnerability hunting platform designed for bug bounty hunters and penetration testers, built in Go. It facilitates the entire recon-to-report pipeline by offering features such as subdomain enumeration, DNS takeover detection, automated vulnerability scanning with Nuclei templates, and multi-platform mobile app analysis. Notable functionalities include automatic result uploads to Cloudflare R2 storage, comprehensive monitoring for subdomain and URL changes, as well as integrated AI capabilities for enhanced searching and vulnerability detection.
2026-08-03
Go
★ 248
favirecon is a reconnaissance tool that utilizes favicon.ico files to enhance the target information gathering phase. It allows users to quickly identify technologies, web application firewalls, exposed panels, and known services associated with a given domain or list of domains. Notable features include configurable output options, support for concurrency, and the ability to filter results based on favicon hashes.
2026-08-03
Go
★ 14058
Gobuster is a high-performance brute-forcing tool written in Go, primarily used for web directory/file enumeration, DNS subdomain discovery, and virtual host detection. It features multi-threaded scanning, multiple operational modes including support for cloud storage enumeration, and extensibility with custom wordlists. Its design is tailored for security professionals, providing a reliable and efficient means to conduct penetration testing and security assessments.
2026-08-03
Go
★ 20
hackenv is a command-line tool designed for managing hacking environments based on Kali Linux and Parrot Security, enabling users to quickly create, configure, and control short-lived virtual machines. Notable features include instant download of official live images, simple SSH access via public-key authentication, shared directories between host and guest, and unified keyboard layouts. This tool streamlines the setup of secure pentesting environments directly from the terminal, emphasizing efficiency and ease of use.
2026-08-03
Go
★ 306
Packémon is a terminal user interface (TUI) tool designed for packet generation and monitoring across any network interface, with compatibility for Windows, macOS, and Linux. It enables users to create arbitrary packets, including DNS queries, and observe real-time responses, whilst offering features like detailed packet inspection and filtering options. The tool is developed from scratch utilizing raw sockets, providing flexibility but also carries a warning for potential bugs.
2026-08-03
Go
★ 192
Phatcrack is a distributed hash cracking tool built on Hashcat, aimed at information security professionals. It facilitates efficient management of cracking projects through a modern web interface, supports various hash types and attack methods, and allows for the synchronization of wordlists and rule files across multiple worker agents. Notable features include multi-user support, project-based access control, and automated distribution of cracking tasks.
2026-08-03
Go
★ 623
sif is a comprehensive recon and exploitation scanner that integrates various scanning capabilities—including subdomain enumeration, port scanning, crawling, vulnerability detection, and more—into a single binary. It leverages a shared connection-pool architecture for efficiency, allowing seamless execution of over 25 scan types from one command, while eliminating the need for external dependencies. Notable features include support for continuous monitoring with change detection, scanning configuration through command-line flags, and integration with notification services like Slack and Discord.
2026-08-03
Go
★ 13
VSAT (Volumetric Socket Artillery) is an advanced multi-layer network traffic generation framework designed for comprehensive stress testing and benchmarking of network infrastructure. The tool integrates Layer 3, Layer 4, and Layer 7 traffic engines, enabling high-throughput traffic simulation across various protocols while offering features such as HTTP/2 multiplexing, TLS JA3 fingerprinting, and raw packet crafting. Its multiprocessing architecture facilitates concurrent traffic generation, making it suitable for defensive security research and protocol analysis.
2026-08-03
Go
★ 356
Nerva is a high-performance command-line interface (CLI) tool for fast service fingerprinting, capable of identifying over 170 network protocols across various transport layers including TCP, UDP, and SCTP. It is designed for use in network reconnaissance, providing features such as rich metadata extraction, security misconfiguration detection, and support for various output formats. Notably, Nerva integrates seamlessly with other security tools like Naabu, enabling automated workflows and robust scanning capabilities.
2026-08-03
Go
★ 374
RF Swift is a versatile tool designed to quickly set up a comprehensive hardware and RF security lab using containerized applications, allowing security professionals to utilize over 200 tools without altering their primary operating system. It supports multiple platforms, including Linux, Windows, and macOS, across various architectures while offering the ability to run specialized images for different engagement types. Notable features include rapid deployment, host OS preservation, and the ability to run on x86_64, ARM64, and RISC-V64 systems.
2026-08-03
Go
★ 12
Rosemary is a cross-platform tool for transparent network pivoting and tunneling over QUIC, enabling seamless traffic interception on remote hosts without the need for proxies or special configurations. Its key features include kernel-level interception of TCP, UDP, ICMP, and DNS traffic, a comprehensive web dashboard for real-time monitoring, and support for multi-hop connections through multiple agents. This tool is designed for scenarios where secure and efficient access to remote networks is required without altering client configurations.
2026-08-03
Go
★ 42
go-appsec/toolbox is a collaborative security testing tool designed for application security assessments through the Model Context Protocol (MCP). It enables users to interact with web applications via a proxy while an agent analyzes and manipulates the traffic, facilitating complex testing scenarios and more thorough identification of vulnerabilities. Notable features include built-in HTTP proxy capabilities, support for wire-fidelity and various protocols, and the ability to seamlessly integrate with existing tools like Burp Suite for enhanced testing workflows.
2026-08-03
Go
★ 268
aiscan is an AI-driven penetration testing tool that integrates traditional security scanning with large language model (LLM) capabilities. It operates in three primary modes: a deterministic scanning pipeline, an autonomous natural language assessment agent, and multi-agent distributed collaboration for comprehensive security evaluations. Notable features include a single-binary architecture, a web console for management, and support for both standard and full editions that offer additional reconnaissance capabilities.
2026-08-03
Go
★ 53
bgscan is a high-performance, modular multi-protocol network scanner implemented in Go, designed for host discovery and validation across various protocols including ICMP, TCP, HTTP, and DNS. Notable features include a fully keyboard-driven terminal user interface (TUI) for real-time monitoring, the ability to chain scan stages into pipelines for efficient scanning workflows, and robust data handling capabilities with options for output to CSV and integration with existing IP lists.
2026-08-03
Go
★ 177
The rix4uni/medium-writeups repository aggregates recent articles and write-ups focused on cybersecurity, penetration testing, and security awareness from Medium. Its primary use case is to provide users with timely content related to various security topics, including the OWASP Top 10 vulnerabilities and advanced pentesting techniques. Notable features include categorization by tags such as "security," "hacking," and "infosec," allowing for easy navigation and discovery of relevant materials.
2026-03-30
Go
★ 807
Caddy WAF is a customizable middleware for the Caddy web server that functions as a Web Application Firewall, designed to provide advanced protection against a wide range of web-based threats. Key features include regex-based filtering, IP blacklisting, geo-blocking, rate limiting, anomaly scoring, and detailed monitoring capabilities, all aimed at securing applications while ensuring high performance through techniques like zero-copy networking and wait-free concurrency. The tool also supports seamless dynamic configuration reloads and offers precise insights into traffic and security events, making it a robust solution for safeguarding web applications.
2026-03-30
Go
★ 728
DllShimmer is a tool designed to facilitate DLL hijacking by allowing users to backdoor any function in a DLL without disrupting the normal operation of the host program. It generates proxy DLLs through a boilerplate C++ file and a corresponding .def file, ensuring that all exported functions maintain their original names and ordinal numbers, thus avoiding detection. Key features include support for both dynamic and static linking, the option to prevent multiple executions of the backdoor, and comprehensive debug logging capabilities.
2026-03-30
Go
★ 882
Fridare is an automation tool for modifying the Frida server on iOS, Android, Linux, and Windows platforms, designed to enhance security and flexibility by allowing users to change server names and ports while bypassing jailbreak detection. The tool features a dual-mode interface, offering both a robust command line and a modern graphical user interface (GUI) based on the Fyne framework, facilitating intuitive server modifications and visual feedback. Notable functionalities include cross-platform support, binary replacement, custom packaging, and dependency management, making it a comprehensive solution for Frida users across different environments.
2026-03-30
Go
★ 748
GobyVuls is a collection of exploitation scripts specifically designed for vulnerabilities identified by the Goby scanning tool. The primary use case is to facilitate the exploitation of detected vulnerabilities, allowing users to perform actions such as command execution or establishing reverse shells. Notable features include a user-friendly interface for scanning and verification, as well as a collaborative framework for contributing new vulnerabilities and enhancing existing exploitation methods.
2026-03-30
Go
★ 726
NMAP-Formatter is a versatile tool designed to convert NMAP XML output into various formats such as HTML, CSV, JSON, Excel, and more, facilitating the analysis and reporting of network scan results. Notable features include support for output via stdin, the ability to generate diagrams using Graphviz, and options to skip down hosts, enhancing usability for security professionals and network administrators. This tool can also be utilized as a library in Golang for integration into other applications.
2026-03-30
Go
★ 760
Seekr is a multi-purpose toolkit designed for gathering and managing Open Source Intelligence (OSINT) data, featuring a streamlined web interface for data collection, organization, and analysis. Key functionalities include integration with popular OSINT tools, account discovery, customizable themes, and the absence of API keys for any features, making it suitable for researchers and investigators seeking to enhance their OSINT workflows. It is currently in beta development and allows for easy setup on various platforms including Windows, Linux, and Docker.
2026-03-22
Go
★ 4375
A Security Tool for Bug Bounty, Pentest and Red Teaming.
2026-03-22
Go
★ 1210
apk加固特征检查工具,汇总收集已知特征和手动收集大家提交的app加固特征,全网最全开源加固特征,支持40+厂商的加固检测,欢迎大家提交无法识别的app
2026-03-22
Go
★ 959
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
2026-03-22
Go
★ 882
Extract endpoints from APK files
2026-03-22
Go
★ 1122
Go CLI and Library for quickly mapping organization network ranges using ASN information.
2026-03-22
Go
★ 1100
↕️🤫 Stealth redirector for your red team operation security
2026-03-22
Go
★ 2529
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 28 protocols.
2026-03-22
Go
★ 5176
Cameradar hacks its way into RTSP videosurveillance cameras
2026-03-22
Go
★ 4741
📦 Make security testing of K8s, Docker, and Containerd easier.
2026-03-22
Go
★ 1039
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
2026-03-22
Go
★ 8797
🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
2026-03-22
Go
★ 770
An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
2026-03-22
Go
★ 2781
:fire: CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.
2026-03-22
Go
★ 4317
🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.
2026-03-22
Go
★ 1146
Awesome cloud enumerator
2026-03-22
Go
★ 3073
ContainerSSH: Launch containers on demand
2026-03-22
Go
★ 1703
🧵 CLI tool for directly patching container images!
2026-03-22
Go
★ 3038
A powerful browser crawler for web vulnerability scanners
2026-03-22
Go
★ 1560
A fast tool to scan CRLF vulnerability written in Go
2026-03-22
Go
★ 6573
60 Cybersecurity Projects | Certification Roadmaps |Everything you need to build your cybersecurity portfolio
2026-03-22
Go
★ 6077
CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, role-based testing with predefined security roles, a skills system with specialized testing skills, and comprehensive lifecycle management capabilities.
2026-03-22
Go
★ 1576
DarkFlare Firewall Piercing (TCP over CDN)
2026-03-22
Go
★ 1709
DetectDee: Hunt down social media accounts by username, email or phone across social networks.
2026-03-22
Go
★ 2139
Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
2026-03-22
Go
★ 3287
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
2026-03-22
Go
★ 797
去中心化远程控制工具(Decentralized Remote Administration Tool),通过ENS实现了配置文件分发的去中心化,通过Telegram实现了服务端的去中心化
2026-03-22
Go
★ 4264
一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入
2026-03-22
Go
★ 14479
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)
2026-03-22
Go
★ 1262
Practice Go programming and implement CobaltStrike's Beacon in Go
2026-03-22
Go
★ 890
A tool to fastly get all javascript sources/files
2026-03-22
Go
★ 1411
Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
2026-03-22
Go
★ 828
Find subdomains on GitHub.
2026-03-22
Go
★ 1598
🔪 :octocat: Leak git repositories from misconfigured websites
2026-03-22
Go
★ 29034
Find secrets with Gitleaks 🔑
2026-03-22
Go
★ 767
Load shellcode into a new process
2026-03-22
Go
★ 2226
WhatsApp Web API
2026-03-22
Go
★ 1537
一款适用于红蓝对抗中的仿真钓鱼系统
2026-03-22
Go
★ 2028
面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams
2026-03-22
Go
★ 1038
Interactive Network Scanner
2026-03-22
Go
★ 3643
🔍 Search anyone's digital footprint across 300+ websites
2026-03-22
Go
★ 8937
Go security checker
2026-03-22
Go
★ 1772
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses
2026-03-22
Go
★ 1754
Database anonymization and synthetic data generation tool
2026-03-22
Go
★ 14476
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
2026-03-22
Go
★ 2321
The Swiss Army knife for automated Web Application Testing
2026-03-22
Go
★ 4257
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
2026-03-22
Go
★ 2371
无状态子域名爆破工具
2026-03-22
Go
★ 994
Tool for building Kubernetes attack paths
2026-03-22
Go
★ 1705
Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBanner/HttpTitle/TcpBanner/Weblogic/Oxid多网卡主机,端口扫描服务识别PortScan。
2026-03-22
Go
★ 2155
Run any Linux process in a secure, unprivileged sandbox using Landlock. Think firejail, but lightweight, user-friendly, and baked into the kernel.
2026-03-22
Go
★ 4901
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
2026-03-22
Go
★ 1737
OSINT tools and more but without API key
2026-03-22
Go
★ 910
Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!
2026-03-22
Go
★ 5396
Modlishka. Reverse Proxy.
2026-03-22
Go
★ 5759
An automated e-mail OSINT tool
2026-03-22
Go
★ 1047
Idiomatic nmap library for go developers
2026-03-22
Go
★ 2087
A secure, efficient TCP/UDP tunneling solution that delivers fast, reliable access across network restrictions using pre-established TCP/QUIC/WebSocket or HTTP/2 connections.
2026-03-22
Go
★ 1555
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
2026-03-22
Go
★ 3094
Rockyou for web fuzzing
2026-03-22
Go
★ 1104
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
2026-03-22
Go
★ 6541
A Modern Orchestration Engine for Security
2026-03-22
Go
★ 10948
Vulnerability scanner written in Go which uses the data provided by https://osv.dev
2026-03-22
Go
★ 2903
Open source vulnerability DB and triage service.
2026-03-22
Go
★ 22195
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
2026-03-22
Go
★ 17714
Information gathering framework for phone numbers
2026-03-22
Go
★ 1636
:hammer: A modern multiple reverse shell sessions manager written in go
2026-03-22
Go
★ 1273
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
2026-03-22
Go
★ 5934
Monitor linux processes without root permissions
2026-03-22
Go
★ 1454
SSH based reverse shell
2026-03-22
Go
★ 2058
Reverse Shell as a Service
2026-03-22
Go
★ 1036
Statically-linked ssh server with reverse shell functionality for CTFs and such
2026-03-22
Go
★ 2301
A tool to abuse Exchange services
2026-03-22
Go
★ 867
SatIntel is an OSINT tool for Satellites 🛰. Extract satellite telemetry, receive orbital predictions, and parse TLEs 🔭
2026-03-22
Go
★ 6171
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
2026-03-22
Go
★ 1264
Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration
2026-03-22
Go
★ 1595
ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes
2026-03-22
Go
★ 3274
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
2026-03-22
Go
★ 1634
ServerScan一款使用Golang开发的高并发网络扫描、服务探测工具。
2026-03-22
Go
★ 1132
An IIS short filename enumeration tool
2026-03-22
Go
★ 1050
安全服务集成化工具集
2026-03-22
Go
★ 7003
Open Source, Google Zanzibar-inspired database for scalably storing and querying fine-grained authorization data
2026-03-22
Go
★ 996
最好用最智能最可控的目录Fuzz工具 | The most powerful, user-friendly, intelligent, and precise HTTP Fuzzer.
2026-03-22
Go
★ 3412
👻Stowaway -- Multi-hop Proxy Tool for pentesters
2026-03-22
Go
★ 862
Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.
2026-03-22
Go
★ 2110
DNS Takeover tool written in Go
2026-03-22
Go
★ 962
A Powerful Subdomain Takeover Tool
2026-03-22
Go
★ 883
A cross-platform desktop client for the jailbroken New Bing AI Copilot (Sydney ver.) built with Go and Wails (previously based on Python and Qt).
2026-03-22
Go
★ 2355
Reads from existing public and private cloud providers (reverse Terraform) and generates your infrastructure as code on Terraform configuration
2026-03-22
Go
★ 996
This repository contains a simple vulnerability scanner for the Terrapin attack present in the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation".
2026-03-22
Go
★ 7165
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
2026-03-22
Go
★ 1932
Kubernetes-native security toolkit
2026-03-22
Go
★ 905
A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.
2026-03-22
Go
★ 1662
a recon tool that allows searching on URLs that are exposed via shortener services
2026-03-22
Go
★ 2152
Venom - A Multi-hop Proxy for Penetration Testers
2026-03-22
Go
★ 1201
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
2026-03-22
Go
★ 1171
Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.
2026-03-22
Go
★ 1185
Program to reverse Docker images into Dockerfiles
2026-03-22
Go
★ 1099
a file-sharing tool that allows you to find the responsible person in case of a leakage
2026-03-22
Go
★ 938
A fast WordPress plugin enumeration tool
2026-03-22
Go
★ 3174
微信小程序反编译工具,.wxapkg 文件扫描 + 解密 + 解包工具
2026-03-22
Go
★ 1390
渗透测试C2、支持Lua插件扩展、域前置/CDN上线、自定义profile、前置sRDI、文件管理、进程管理、内存加载、截图、反向代理、分组管理