Html
2026-08-31
HTML
★ 10
Asur-Rat is a powerful Android remote access tool designed for surveillance and management of Android devices. Its primary use case includes extensive control features such as SMS handling, call management, file operations, GPS location tracking, and real-time screen monitoring, along with administrative capabilities like device formatting and icon hiding. Notable features include a keylogger, live screen streaming, and comprehensive media management, making it a versatile solution for remote device administration.
2026-08-31
HTML
★ 18
VERDICT is an autonomous web and API penetration testing agent that employs AI to conduct vulnerability assessments, confirming findings through reproducible evidence. Its primary use case is for in-depth security evaluations, particularly in applications with complex authentication mechanisms, utilizing a real browser for accurate session handling and multi-step testing. Notable features include precise detection accuracy backed by recorded evidence, an ability to map and exploit unknown applications autonomously, and integration with tools like Burp, all while adhering strictly to defined testing scopes.
2026-08-30
HTML
★ 278
TorNet is a tool that automates IP address rotation through the Tor network, providing users with enhanced anonymity during internet browsing or application usage. It allows for configurable settings such as rotation intervals and the number of IP changes, and offers both command-line and Python API interfaces for integration and automation. Notable features include the ability to run indefinitely, check current IP addresses, and fix missing dependencies automatically.
2026-08-30
HTML
★ 55
The Stellar Cartographer's Atlas is a sophisticated C++ tool designed to enhance the experience of players in procedurally generated space exploration simulations by providing an external memory system for tracking exploration journeys. Its notable features include advanced data interpretation across three layers: spatial analysis for path reconstruction and resource identification, linguistic assistance for understanding alien languages, and narrative generation that composes a personalized log of discoveries and interactions. This tool aims to enrich players' exploration narratives and prevent the loss of valuable data amid vast digital environments.
2026-08-30
HTML
★ 55
DeadSpace3ResourceManager is a cross-platform tool designed for the Steam version of Dead Space 3 that facilitates efficient in-game resource management. By allowing users to inject 500 units of various resources directly into their inventory with a keystroke, it enhances the gameplay experience through instantaneous resource access while maintaining balance with features like customizable bindings and a cooldown timer. Notably, it operates non-intrusively and supports multilingual configurations, making it an ideal solution for players seeking to optimize their resource utilization ethically.
2026-08-30
HTML
★ 55
Kekropis is a cross-platform tactical overlay designed for competitive FPS games, focusing on enhancing situational awareness without altering the game’s core. It utilizes a micro-kernel visualization engine to passively observe game telemetry and displays intuitive glyphs, emphasizing minimal cognitive load and visual clarity. Notable features include a responsive user interface, support for multiple operating systems, and reliance on a read-only spatial telemetry network to maintain the integrity of the gaming experience.
2026-08-30
HTML
★ 55
AQW-Sequence Weaver is a bioinformatics-inspired toolkit designed to visualize and extract patterns from network telemetry specifically for AQW private server research. It enables users to map packet transactions, identify variable fields through heuristic analysis, and interactively explore session flows, while also supporting export to standard formats and multilingual interfaces. Notably, it offers a protocol diff engine for comparing captures across versions and a community research log for collaborative annotation of packet sequences.
2026-08-30
HTML
★ 55
ChronoVault is a sophisticated game profile management tool designed to enhance single-player narratives by allowing users to architect alternate realities within their gaming experiences. Unlike traditional save editors, it provides comprehensive features such as relationship mapping, inventory weaving, and resource flow balancing to ensure narrative coherence and immersion. Its responsive interface and multilingual support further elevate the user experience, making it accessible and intuitive for gamers at all levels.
2026-08-30
HTML
★ 55
MindForge is an educational sandbox designed for aspiring reverse engineers and memory manipulators, allowing users to explore the interactions between software and hardware within a controlled environment. It features a fictional binary target for practice, comprehensive in-app tutorials, a snapshot recovery system for experimentation, and tools like memory heatmaps and scriptable learning modules that foster understanding of memory manipulation concepts. The platform also supports multiple languages, making it accessible to a global audience of learners.
2026-08-30
HTML
★ 55
The Forge of the Wraith is an internal trainer specifically designed for the Steam GOTY edition of Middle-earth: Shadow of Mordor, enabling extensive manipulation of game mechanics through memory editing. It offers a robust suite of features such as invulnerability, infinite focus in combat, stealth enhancements, and currency maximization, allowing users to dominate gameplay and explore freely without the constraints of the original mechanics. Its internal architecture ensures stability and minimizes the risk of detection, providing a seamless and powerful gaming experience.
2026-08-30
HTML
★ 55
EchoForge is a runtime reflection framework and asset studio tailored for Unreal Engine 3 (UE3), enabling users to explore and manipulate the engine's internal object graph without altering its core. Its notable features include a comprehensive runtime reflection API, support for polyglot modding through C, C++, and Rust, and a cross-platform asset studio that allows live viewing and editing of game assets. This tool serves as a vital resource for modders and researchers aiming to enhance or reimagine existing UE3 games, providing flexibility through dynamic property discovery and event notification systems.
2026-08-30
HTML
★ 55
OrbitPilot is an advanced automation tool tailored for online betting that enhances user engagement through a context-aware decision-making layer. By utilizing a robust Selenium foundation and a modular plugin architecture, it offers intelligent action sequencing, multi-platform responsiveness, and native multilingual logging, while also providing innovative features like a 24/7 sentinel monitoring system and detailed session analytics. This tool enables users to transform repetitive tasks into strategic workflows, allowing for a more informed and efficient betting experience.
2026-08-30
HTML
★ 55
PatternScope is a predictive drift analysis tool designed for simulated probability environments, enabling users to identify and visualize behavioral patterns in outcomes that initially appear random. By leveraging features such as Sequence Archetype Extraction (SAE) and Drift Velocity Index (DVI), the tool provides a scientific approach to understanding probability landscapes, allowing analysts to build comprehensive historical profiles and observe shifts in real-time. The platform also facilitates multi-session analysis through 3D visualizations and maintains an encrypted comparative corpus to enhance predictive accuracy across varied session parameters.
2026-08-30
HTML
★ 55
The Arcade Ascension Toolkit is a modular performance enhancer designed for retro-style endless hopper games, providing real-time aids that improve gameplay without diminishing the core skill challenge. Key features include predictive pathfinding overlays to enhance spatial awareness, adaptive timing calibration for responsive controls, and session performance analytics to help players learn from their gameplay. With a game-agnostic framework and a sleek, immersive UI, it also offers multi-language support and a vibrant community for continuous support.
2026-08-30
HTML
★ 55
BlackOut: The Shadowforge Toolkit for Meteor Client is an advanced Minecraft modification designed to enhance Crystal PvP (CPVP) gameplay through a system of contextual automation and precise combat tools. Notable features include predictive combat algorithms, advanced movement mechanics tailored for aerial combat, and a customizable user interface that supports multilanguage interactions, providing players with an edge in competitive scenarios. The toolkit aims to elevate gameplay by automating critical actions with high precision, making it a vital asset for serious players in the 2026 competitive scene.
2026-08-30
HTML
★ 55
MindBridge Orchestrator is a behavioral framework for managing and interacting with external Windows processes through an event-driven architecture. It facilitates adaptive process discovery, seamless communication with GUI elements, and robust event handling, enabling applications to effectively converse with both legacy and modern systems. Notable features include dynamic enumeration of processes, a unified interaction vocabulary for UI elements, and resilience mechanisms such as process resurrection and session rehydration.
2026-08-28
HTML
★ 350
FindME is a CLI-based tool designed for discovering social media and online platform profiles associated with a specified username, enabling rapid reconnaissance across over 400 platforms. Key features include multi-threaded concurrent searching for fast results, real-time progress tracking, and no data collection to ensure user privacy. It serves multiple use cases such as cybersecurity research, digital footprint verification, and username availability checks.
2026-08-26
HTML
★ 319
QueryTool is a standalone HTML application designed for constructing and executing OSINT queries while providing access to a curated source catalogue of 178 sources. Its primary use case is to facilitate the generation of complex queries using Google-style syntax, allowing users to filter sources by various criteria and open multiple links in new tabs. Notable features include offline functionality, the ability to import and export browser sessions as JSON, and a straightforward setup with no installation required.
2026-08-26
HTML
★ 13
PageZero is a JavaScript-based browser exploitation and command-and-control (C2) framework that integrates features from both Evilginx and BeEF. It allows security professionals to deploy phishing attacks without the need for complex configurations, enabling live sessions to execute over 40 modules including credential theft, keylogging, and LAN scanning from a web admin panel. The tool is designed for authorized penetration testing and operates using a simple hook that grants persistent control over the victim's browser context.
2026-08-25
HTML
★ 10
ESP_RTK_ROVER is a DIY GNSS rover that repurposes a ComNav K803 Lite board with a Seeed Studio XIAO ESP32C6 to provide centimetre-accurate positioning via Bluetooth for mobile GIS applications. Noteworthy features include automatic configuration as a rover at boot, bi-directional data transmission, Bluetooth Low Energy communication compatibility, and a web-based dashboard for real-time diagnostics. It serves hobbyist applications such as autonomous robotics, DIY auto-steering, and educational purposes in GNSS and RTK technologies, although it is not designed for professional surveying or critical applications.
2026-08-23
HTML
★ 72
Otwarte Źródła is a Polish extension of the OSINT Framework that focuses exclusively on Polish tools and data sources for open-source intelligence (OSINT) investigations. Key features include an organized catalog of local resources, the ability to contribute new entries via GitHub pull requests, and support for various tool installation and registration requirements. This tool enhances the accessibility and functionality of open-source intelligence efforts within Poland by centralizing relevant data.
2026-08-20
HTML
★ 11
WireTapper is a tool designed for detecting and mapping nearby wireless signals, including Wi-Fi networks, Bluetooth devices, IoT devices, and CCTV cameras. Its notable features include Wi-Fi detection with detailed information, Bluetooth scanning, and signal visualization on a user-friendly map interface, enabling users to gather intelligence from their environment effectively. The tool is intended for responsible use in compliance with local privacy laws and regulations.
2026-08-20
HTML
★ 263
The Flipper Zero Evil Portal tool transforms a Wi-Fi development board into a phishing access point, serving a fake login screen to connected users. It captures user credentials and logs them onto the SD card, functioning as an educational demonstration for learning about Wi-Fi exploits and programming. Notable features include compatibility with both official and unleashed firmware, easy installation via pre-built app files, and customizable HTML login screens.
2026-08-17
HTML
★ 181
BomberCat is an advanced security tool designed for auditing banking terminals and NFC technology, integrating both NFC and magnetic stripe functionalities for comprehensive access control and identification analysis. It supports features such as card emulation, read/write capabilities, and MagSpoof for magnetic stripe interactions, all while being compatible with popular programming frameworks like Arduino and CircuitPython. Additionally, it is equipped with WiFi connectivity for remote testing and supports a wide range of RF protocols, making it a versatile solution for security professionals.
2026-08-17
HTML
★ 93
OWASP Threat Dragon is a tool designed for simplifying the threat modeling process, enabling users to identify and mitigate potential security risks in their applications. It is recognized as an OWASP Production project and adheres to established threat modeling principles. The project offers comprehensive documentation and community support, facilitating its integration into cybersecurity workflows.
2026-08-16
HTML
★ 42
Zombieland is a browser-based command and control (C2) dashboard frontend designed for educational and authorized penetration testing research. It features mock agent management with grid and list views, a global console for broadcasting commands, and a modular UI that supports customization and enhanced visual effects. The tool is currently in development for backend and agent components, aiming for cross-platform compatibility and improved user management in future releases.
2026-08-16
HTML
★ 122
Aegis Vault is an offline password, identity, and secret management tool that operates solely on the user's local machine without requiring any server or cloud connectivity. It allows users to securely store various account types, including logins, API keys, SSH keys, and database credentials, all encrypted under a master password. Notable features include a modern web-based interface, a password generator, easy installation commands for multiple platforms, and robust security measures with no third-party dependencies.
2026-08-15
HTML
★ 13
AryterLink is a self-hosted, browser-based remote control panel designed for Termux on Android devices, enabling users to manage their smartphones from any browser globally. It offers capabilities such as SMS management, call handling, access to contacts, device controls (like flashlight and screen brightness), real-time battery stats, audio recording, and secure terminal shell access, all while ensuring data protection through robust security measures. Notably, it operates without the need for root access or third-party servers, relying solely on Python and direct interactions with the device's hardware via the Termux:API.
2026-08-14
HTML
★ 46
AI-Browser-MCP is a Windows-based browser automation service that leverages AI to execute predefined tasks through natural language commands. It features 255 pre-packaged tools capable of automating data collection, reverse engineering, debugging, and form filling, all orchestrated via intuitive commands without the need for scripting. The tool integrates easily with various AI agents and utilizes a local server for API communication, emphasizing privacy and ease of use.
2026-08-14
HTML
★ 318
QueryTool is a lightweight, standalone HTML application designed for constructing OSINT queries and accessing a curated selection of 178 relevant sources. Its notable features include the ability to build complex Google-style queries, filter sources by various criteria, and simultaneously open selected links in new tabs, all without requiring any installation or configuration. The tool serves as an effective resource for users seeking to streamline their open-source intelligence tasks.
2026-08-14
HTML
★ 12
Riksdagsmonitor is a Swedish political intelligence platform that enhances democratic transparency through evidence-based analysis and AI-generated political news, utilizing official open data. It leverages structured intelligence techniques and monitors extensive data from the Swedish Parliament, Government, and public agencies, producing publication-ready intelligence articles autonomously in multiple languages. Notably, it operates a fully automated newsroom with 14 agentic workflows, generating daily content without human editors.
2026-08-13
HTML
★ 60
Bjorn Manager is a desktop application designed to facilitate the discovery and management of Bjorn devices across various network interfaces, including LAN, USB, and Bluetooth. It allows users to install, update, and control these devices from a single user interface, featuring multilingual support, smart device naming, and real-time terminal logs for installations. Key functionalities include auto-discovery, SSH installation capabilities, and configurable settings, making it a comprehensive tool for managing Bjorn devices efficiently.
2026-08-13
HTML
★ 29
Assemblyline 4 Documentation repository provides comprehensive documentation for the Assemblyline platform, facilitating user and developer understanding of its capabilities and functionalities. The primary use case is to assist in contributing to or utilizing the Assemblyline cybersecurity tool, with notable features including inline editing on GitHub and local setup instructions for developers.
2026-08-11
HTML
★ 15
Skoolkit-game-revs is a repository focused on reverse engineering classic video games, primarily for platforms like the ZX Spectrum and TI-83 Plus, utilizing the SkoolKit framework. It features multiple projects for various games, providing insights, code instruction analysis, and ongoing development status with detailed resources for each game. Notable features include extensive documentation and linked follow-up projects for users interested in further exploration of game code.
2026-08-11
HTML
★ 23
Attack Surface Toolkit is a passive reconnaissance tool designed for authorized web security assessments that maps external exposures of web targets through OSINT and non-destructive metadata collection. Its primary use case is to provide clear and actionable insights into an organization’s attack surface without engaging in invasive testing, presenting findings in a structured format suitable for both technical and non-technical stakeholders. Notable features include comprehensive subdomain enumeration, DNS analysis, SSL/TLS inspection, security header audits, technology detection, and a weighted scoring system, all culminating in professional-grade reports formatted for client deliverables.
2026-08-11
HTML
★ 28
CScorza is a personal GitHub profile showcasing various projects and stats related to the user's activity. It utilizes automated badges and visual elements to present information about the developer’s work and social connections, facilitating networking and project visibility. Notably, it emphasizes the integration of dynamic content to enhance presentation and engagement.
2026-08-10
HTML
★ 24
The Surveillance Capabilities Map is an interactive visualization tool that maps police surveillance capabilities across the United States, aggregating data from various authoritative sources, including the EFF Atlas of Surveillance and federal contracts. Key features include technology filtering across 19 surveillance categories, a search function by location or agency, and the ability to export raw data in CSV format. Additionally, users can visualize FBI and DHS aircraft flight paths, enhancing the understanding of surveillance operations at specific locales.
2026-08-09
HTML
★ 11
Let's Hack It is a web-based tool designed for penetration testing and ethical hacking. Its primary use case is to facilitate security assessments of web applications by identifying vulnerabilities. Notable features include a user-friendly interface and integration with various penetration testing methodologies.
2026-08-09
HTML
★ 18
The OSINT Roadmap is a structured educational resource designed to guide users through the principles and practices of Open Source Intelligence (OSINT) in an ethical and professional manner. It provides a comprehensive learning path that covers core skills such as source verification, documentation, and reporting, while also offering practical case studies for learners ranging from beginners to advanced practitioners. Notable features include detailed workflows, an emphasis on legal boundaries, and a focus on real-world application in fields like cybersecurity and digital forensics.
2026-08-09
HTML
★ 16
DEEP STATE is an open-source submarine intelligence map that leverages public OSINT data to visually represent the positions and statuses of 292 submarines from over 30 navies. Key features include an interactive flat map and a 3D globe showing real-time positions, automated OSINT feeds for updates, and detailed submarine specifications sortable by type and nation. The tool is bilingual (French/English) and enables users to track nuclear deployment levels while providing a comprehensive comparison of global submarine fleets.
2026-08-09
HTML
★ 11
ShadowPDF is a lightweight, privacy-focused tool that enables users to extract text from PDF documents directly in their browser without any data leakage risks. Its notable features include 100% offline processing, multi-format export options (Plain Text, Markdown, HTML), and a user-friendly drag-and-drop interface, making it ideal for developers and security-conscious individuals seeking efficient document conversions.
2026-08-08
HTML
★ 12
PE-pal is a web-based Portable Executable (PE) file analysis tool that translates the internal structure of Windows executables into a user-friendly format, making it accessible for beginners. It features entropy analysis to detect anomalies, classification of imported functions, and string flagging for suspicious elements, all while ensuring that file processing occurs locally in the user's browser for privacy. Notably, PE-pal does not function as a virus scanner but provides insights into the file's behavior and characteristics.
2026-08-05
HTML
★ 286
Assayo is a tool designed for generating detailed HTML reports that analyze git commit statistics, providing insights into work pace, overtime, team dynamics, and project costs. Notable features include the ability to evaluate developer location, release schedules, employee turnover rates, and areas in need of refactoring. The tool can be utilized through various programming libraries, allowing for flexibility in implementation within different environments.
2026-08-03
HTML
★ 383
Gigahorse is a binary lifter and toolchain designed for decompiling and analyzing Ethereum smart contracts by translating low-level EVM code into a higher-level, function-based three-address representation, akin to LLVM IR or Jimple. It provides a robust framework for contract analysis with optional feature sets for Datalog parsing and interactive visualization. The tool facilitates easy integration and deployment via Docker, along with comprehensive setup instructions for dependencies, making it accessible for various environments.
2026-08-03
HTML
★ 9595
mitmproxy2swagger is a tool designed to automate the conversion of HTTP traffic captured by mitmproxy into OpenAPI 3.0 specifications. Its primary use case is reverse-engineering REST APIs by capturing traffic during application execution, enabling developers to easily document and understand API structures. Notable features include support for merging existing schemas, handling HAR files exported from browser DevTools, and generating detailed endpoint descriptions after initial traffic capture.
2026-08-03
HTML
★ 10
SUD (Super User Do) is a lightweight UNIX tool designed for privilege escalation, enabling designated users in specific system groups (admin, wheel, sudo, or sud) to execute commands with root permissions without a password. It prioritizes simpler code and easier audits compared to traditional tools like sudo, while offering a public domain license and a literate programming approach for improved readability and maintainability. Notably, SUD features a minimalistic design with fewer dependencies and no configuration files, making it suitable for specific multi-user privilege isolation scenarios.
2026-08-03
HTML
★ 29
CVE-2026-41089 is a critical cybersecurity tool designed to assess Windows Active Directory Domain Controllers for a severe unauthenticated remote code execution vulnerability caused by a stack-based buffer overflow in the Netlogon service. It allows users to execute crafted requests to identify susceptible systems without prior authentication, making it a crucial tool for detecting and mitigating potential exploits in enterprise environments. The tool features a Python-based script that facilitates various testing techniques, including baseline checks and aggressive payload testing, all while ensuring system stability.
2026-08-03
HTML
★ 157
The repository contains a collection of writeups detailing solutions and methodologies used in various Capture The Flag (CTF) competitions, including Hack The Box (HTB). Its primary use case is to provide insights and explanations for participants looking to learn from past challenges. Notable features include links to social media for support and engagement, as well as visual representation of stargazers over time.
2026-08-03
HTML
★ 13
RedVision is a collection of custom-designed HTML user interfaces specifically intended for Command & Control (C2) systems. Its primary use case is to enhance the operational efficiency of security professionals by providing a visually appealing and functional interface for managing C2 capabilities. Notable features include an array of templates, each visually distinct, allowing for flexible customization to suit various C2 deployment scenarios.
2026-08-03
HTML
★ 12
`geol` is a Go-based command-line interface tool designed to manage end-of-life (EOL) information for software, offering an enhanced user experience compared to its Python counterpart, `norwegianblue`. It provides a terminal-based interface that facilitates safer and easier delivery while incorporating additional features for improved security management related to EOLs. Notable features include a strong focus on user experience, straightforward installation, and innovative management methods for software lifecycle tracking.
2026-08-03
HTML
★ 263
The Awesome Bootkits & Rootkits Development repository provides a comprehensive collection of resources focused on the development of bootkits and rootkits, targeting both BIOS/UEFI specifications and Windows kernel intricacies. Notable features include analysis tools, tutorials, source code examples for various operating systems, and insights into kernel security mechanisms such as Driver Signature Enforcement and Kernel Patch Protection. This repository serves as a vital resource for security researchers and developers interested in low-level malware development and analysis.
2026-08-03
HTML
★ 19
The J5 EV Dashboard is a self-hosted telematics solution designed for Jaecoo J5 EV vehicles, providing users with comprehensive insights into vehicle performance metrics such as battery status, range, efficiency, and charging sessions. This mobile-first Progressive Web App (PWA) allows users to access real-time data from their own car while also offering features like a trip planner and an interactive EV charger map. Notably, it guarantees high accuracy in charge-cost reporting, closely matching users' receipts, and is designed to operate exclusively with the owner's vehicle data.
2026-08-03
HTML
★ 199
Open Claude in Chrome is an open-source reimplementation of the official Claude in Chrome extension, providing complete web navigation without the restrictions of an allowlist. It supports any Chromium-based browser and maintains identical performance and feature parity, offering all 18 MCP tools while eliminating any blocked domains. This tool primarily enhances browser automation capabilities by allowing users to access a wider range of websites that the original extension restricts.
2026-08-03
HTML
★ 31
PyAutoRaid is a tool designed for optimizing gameplay in *Raid: Shadow Legends* by enabling players to simulate Clan Boss fights locally without using in-game keys. Its notable features include a key-free battle simulation, team and gear optimization, and detailed battle history tracking, allowing players to fine-tune their strategies before committing resources. The simulation harnesses the actual game engine for accurate results and maintains user data privacy by running entirely on the player's PC.
2026-08-03
HTML
★ 151
Torii Gateway is a middleware solution designed to provide researchers with persistent, authenticated access to advanced inference pathways of large language models (LLMs) while bypassing tiered consumption limits imposed by commercial APIs. Its notable features include protocol reflection to mimic enterprise-tier traffic, token frame rebalancing to adjust apparent consumption rates, and session entropy injection for neutralizing identifiable session fingerprints, facilitating a seamless connection to multiple inference providers without altering client-side code. This tool serves as a crucial resource for overcoming restrictions that hinder research and experimentation with frontier LLM capabilities.
2026-08-03
HTML
★ 153
Lumina Sentinel is a behavioral anomaly detection and orchestration framework designed for security researchers and threat analysts to analyze the behavior of credential stealers and remote access trojans (RATs) in a controlled environment. Its notable features include a Behavior Replay Engine that reconstructs infostealer actions with MITRE ATT&CK™ mapping, real-time process tree visualization via D3.js, and multilingual intelligence reporting to facilitate global collaboration. The framework emphasizes security and education by operating in isolated containers without affecting the host system.
2026-08-03
HTML
★ 73
Project Chisel is a comprehensive modding toolkit for Geometry Dash, enabling developers and reverse engineers to deeply analyze and modify the game through a robust framework built on full decompilation analysis. It features a precision modification engine that allows granular control over game systems, seamless integration with the Geode mod loader, and a responsive UI framework for custom in-game menus. Notable capabilities include non-destructive overrides, automated patching for version-specific binaries, and multilingual support for localized modding experiences.
2026-08-03
HTML
★ 10
PICT-CTF-WEBSITE-FRONTEND is a frontend template designed for organizing Capture the Flag (CTF) events. It features multiple static pages such as Home, Login, Register, Challenge/Quests, Leaderboard, and an About/Rules page, providing a structured layout for participants and organizers. This template serves as a foundational framework for anyone looking to host their own CTF events, though it currently lacks dynamic functionality.
2026-08-03
HTML
★ 10
The "web-ctf-labs" repository is a collection of web-based Capture the Flag (CTF) challenges designed for cybersecurity training and skill development. It features diverse challenges, including Host Header Injection, Server-Side Template Injection in Flask, and SQL Injection, among others, providing a practical environment for enhancing web security knowledge. Notable features include a variety of challenge types that cater to different aspects of web vulnerabilities and security testing.
2026-08-03
HTML
★ 36
DOM-Clobber3r is a tool designed to generate DOM clobbering attack vectors, which are used to exploit vulnerabilities in web applications that mishandle the Document Object Model (DOM). Its primary use case is to aid security researchers and developers in identifying potential attack surfaces within web applications. Notable features include automated generation of various clobbering scenarios, facilitating the testing of DOM-based security defenses.
2026-08-03
HTML
★ 21
HackMe is a Capture The Flag (CTF) tool designed for Android devices using Termux, enabling users to participate in cybersecurity challenges. Notable features include a simple setup process through bash scripts and a straightforward interface for executing CTF tasks. Primarily aimed at individuals looking to enhance their penetration testing skills in a controlled environment.
2026-08-03
HTML
★ 646
The Reversing Bits Cheatsheets repository serves as a comprehensive resource for assembly programming, reverse engineering, and binary analysis tools. It includes in-depth guides on installation, usage examples, and advanced tips for a variety of tools, such as assemblers, debuggers, disassemblers, and binary analysis frameworks, catering to different operating systems and user needs in the field of cybersecurity. Notably, it features prominent tools like Ghidra, IDA Pro, and GDB, making it a valuable reference for professionals involved in security and malware analysis.
2026-08-03
HTML
★ 20
Elite Google Dorks Search by Biscuit is a curated set of advanced Google search queries designed to uncover hidden information and vulnerabilities on the web, primarily targeting cybersecurity professionals and ethical hackers. Notable features include a selection of smart and improved dorks that enhance search effectiveness and a user-friendly interface for easy application. The tool enables users to efficiently identify security weaknesses by utilizing specific search patterns directly in Google.
2026-08-03
HTML
★ 12
Reconal is an advanced OSINT reconnaissance framework designed to streamline and automate over 70 Google dorks and detailed infrastructure analysis via a native desktop application. Key features include a zero-config experience for end users, a diverse range of recon modules covering cloud services, infrastructure configurations, and API discovery, as well as a robust command-line interface for terminal usage, ensuring no external exposure during operations.
2026-08-03
HTML
★ 49
BugBoard is an open-source web application that acts as a centralized dashboard for cybersecurity tools, enabling users to efficiently identify and report vulnerabilities such as SQL Injection, XSS, and CSRF. Its modular design allows users to focus on specific vulnerabilities while providing a user-friendly interface that caters to both novices and experienced professionals in the bug bounty process. Notable features include comprehensive vulnerability assessments and an intuitive layout for streamlined navigation.
2026-08-03
HTML
★ 104
Gerobug is an open-source, self-managed bug bounty platform designed for organizations to easily deploy their own bug bounty programs without incurring significant costs associated with third-party services. Key features include a streamlined installation process with a single command setup, robust security measures like email parsing and network segregation, and automated HTTPS configuration using NGINX and Let’s Encrypt. This solution facilitates efficient vulnerability reporting through an email parser and provides a dedicated dashboard for managing submissions.
2026-08-03
HTML
★ 13
The Frey-Rück Attack implementation allows for the extraction of the ECDSA secret key ("K") from vulnerable Bitcoin transactions. This tool is particularly useful for cryptocurrency analysts and researchers studying signature vulnerabilities in blockchain protocols, enabling them to restore Bitcoin wallets by solving the discrete logarithm problem through compromised signatures. Notable features include practical examples of vulnerable Bitcoin addresses and methodologies for conducting cryptanalysis efficiently.
2026-08-03
HTML
★ 117
The OWASP ZAP project is a leading open-source web application security scanner designed to identify vulnerabilities in web applications during development and deployment. Its primary use case involves automated security testing, providing tools for both developers and security professionals to facilitate vulnerability detection and remediation. Notable features include a user-friendly interface, extensive API support, and a variety of plugins to enhance its scanning capabilities.
2026-08-03
HTML
★ 38
ClawSecure is an independent security scanning and auditing platform designed for the OpenClaw ecosystem, which focuses on ensuring the integrity and safety of AI agent skills and workflows. It features a proprietary 3-Layer Audit Protocol that has examined over 3,000 skills against all OWASP ASI Top 10 security vulnerabilities, revealing that 41% of audited skills contain security flaws. It also offers free developer tools to enhance functionality and user experience within the OpenClaw framework.
2026-08-03
HTML
★ 51
BitDefender Total Security Ultimate Protection is a comprehensive cybersecurity suite that functions as a modular framework for fortifying network defenses against a wide array of cyber threats. Its primary use case revolves around system hardening, employing features such as vulnerability scanning, real-time threat correlation, and sandbox-based execution to protect various environments from evolving threats. Notable capabilities include automated policy enforcement, advanced heuristic analysis, and deep kernel inspection for rootkit remediation, all integrated within a responsive interface supporting multilingual operations and continuous 24/7 support.
2026-08-03
HTML
★ 21
The OSINT Toolkit is a web-based platform designed for conducting comprehensive open-source intelligence (OSINT) investigations using various tools and methodologies. Key features include GitHub profile analysis, DNS reconnaissance, WHOIS history tracking, and integrations with external resources to uncover emails, phone numbers, and compromised accounts. Built with FastAPI and TailwindCSS, it emphasizes user experience while providing extensive data retrieval and analysis capabilities.
2026-08-03
HTML
★ 28
SINARC (Sistema Integrado de Análise de Redes Complexas) is an experimental open-source program designed for data analysis of public sources by generating graphs. Its primary use case is to empower citizens to exercise social control over public administration in line with constitutional rights and the Law on Access to Information. Notable features include integration with various databases, interactive tutorials, and a command alphabet, facilitating user engagement and comprehensive data analysis.
2026-08-03
HTML
★ 272
Coeus OSINT ToolBox is a comprehensive open-source intelligence platform designed for effective information gathering from various open sources. It provides a wide range of tools for conducting background checks, investigating individuals or usernames, and accessing anonymous communication services, as well as resources for searching both the surface and deep web. Notable features include tools for web resources, social media investigation, and guides on managing personal information online, making it a versatile tool for both individuals and organizations engaged in OSINT activities.
2026-08-03
HTML
★ 23
DorkTerm is a web-based tool for security researchers that facilitates the execution of Google Dork queries to identify potential vulnerabilities in a specified domain. It automates the generation and opening of 15 predefined Google Dork searches in separate tabs, enabling quick reconnaissance of common vulnerabilities, such as login pages and exposed files. The tool is lightweight and user-friendly, providing guidance for enabling popups to enhance its functionality.
2026-08-03
HTML
★ 189
The Hacking-Social_Media-Accounts repository provides templates and configurations for the GoPhish phishing toolkit, facilitating the creation of deceptive landing pages and email templates aimed at capturing user credentials for social media platforms. Notable features include dedicated templates for Instagram login pages and security emails, along with instructions for setting up these tools effectively to simulate phishing attacks. This repository serves as a resource for security professionals and ethical hackers to test and enhance organizational security awareness.
2026-08-03
HTML
★ 15
Leadminer is a contact management tool designed to extract, clean, enrich, and manage contacts for email and SMS campaigns. Its notable features include extracting contacts from mailboxes, cleaning email lists, enriching contact data with signature extraction, and exporting to formats like CSV and Google Contacts, along with the ability to send email campaigns using the user's email while providing analytics. This tool integrates with third-party services for enhanced functionality, making it suitable for both individual and business use cases.
2026-08-03
HTML
★ 24
TIA is an autonomous AI security operations platform that utilizes 30 specialized AI agents for continuous threat detection, OSINT intelligence, and incident response without human intervention. Noteworthy features include real-time threat monitoring with a proven record of blocking over 563 attacks, zero breaches, and a cost-effective operation rate of $405 per month, making it ideal for organizations seeking robust cybersecurity solutions.
2026-08-03
HTML
★ 15
The EU Parliament Monitor is a Political Intelligence Platform designed to enhance transparency and accountability in the European Parliament. Its primary use case involves providing AI-generated news and detailed insights related to legislative activities affecting Europe’s 450 million citizens, available in 14 languages. Notable features include a comprehensive Political Intelligence Hub, an API for developers, and a site map that ensures accessibility to content across various languages.
2026-08-03
HTML
★ 153
GhostIntel v2.5 is an advanced OSINT (Open Source Intelligence) framework designed for cybersecurity professionals and digital investigators to gather and analyze public information without the need for API keys. Notable features include support for 8 countries, batch processing capabilities, breach detection, and risk scoring, along with a user-friendly web interface that allows for intuitive multi-target scans across 129+ platforms. This tool is optimized for uncovering online footprints, enhancing threat intelligence, and conducting comprehensive digital reconnaissance.
2026-08-03
HTML
★ 63
The Carding Tools Web Version is a web-based application designed for generating, checking, and validating credit card numbers and Bank Identification Numbers (BINs). Its notable features include a BIN Checker that retrieves detailed BIN information, a Card Generator for producing valid credit card numbers using the Luhn algorithm, a Card Checker that verifies card authenticity, and a BIN Generator for generating random BINs based on card types. It incorporates a responsive design for optimal usability across devices and facilitates data importing from text files.
2026-08-03
HTML
★ 620
Phishbait is a phishing tool designed to simulate phishing attacks by hosting replicas of 38 different websites, allowing users to generate luring links to target victims. Key features include easy setup through command-line instructions, the ability to create a local server using PHP, and the integration with Ngrok for tunneling, which conceals the server's presence. It is intended strictly for educational purposes, with a disclaimer against misuse.
2026-08-03
HTML
★ 76
R8HEX is a flexible Android Remote Access Tool (RAT) designed for cybersecurity professionals, students, and researchers to understand malware behaviors without the need for port forwarding. This tool offers extensive features such as SMS management, camera access, microphone recording, and device location tracking, with both free and paid versions providing varying levels of functionality. Its integration with Telegram allows for seamless remote management and control of Android devices during security assessments.
2026-08-03
HTML
★ 79
Red Team Wiki serves as a centralized public resource for information on Red Team tactics, techniques, and procedures (TTPs), with an emphasis on both the offensive and defensive elements of these methodologies. It allows users to access detailed documentation while providing options for community contributions through role assignments or pull requests. Notable features include a focus on reporting aspects of TTPs and a collaborative approach to content creation.
2026-08-03
HTML
★ 41
SQLMap Command Builder is a web-based tool designed to simplify the process of crafting SQLMap commands through an intuitive point-and-click interface, eliminating the need to memorize complex command-line switches. It features real-time command generation, a fully client-side architecture for enhanced security, and compatibility with the latest SQLMap versions, making it accessible and user-friendly for penetration testers of all skill levels. The tool requires no installation and can be used directly through any modern web browser.
2026-08-03
HTML
★ 13
WiFi-Pinapple is a tool designed to create a Wi-Fi Pineapple device using Raspberry Pi hardware, enabling users to simulate attacks such as Evil Portal for testing purposes. It incorporates features like easy setup instructions, DHCP server configuration with dnsmasq, and iptables manipulation for traffic redirection to capture credentials on a spoofed access point. This tool is particularly useful for penetration testing and educational purposes in cybersecurity.
2026-08-03
HTML
★ 50
WIFIHacker is a comprehensive WiFi penetration testing tool designed to automate various WiFi security audits and attacks, including phishing, SSID spamming, and denial of service attacks. Notable features include the ability to create fake access points for phishing, broadcast multiple fake SSIDs, and capture credentials. This tool requires a WiFi adapter that supports monitor mode to function effectively and aims to serve educational purposes while emphasizing responsible use.
2026-08-03
HTML
★ 12
H4ck3R is an open-source package designed for individuals interested in learning hacking and cybersecurity techniques. It provides a framework for educational purposes, facilitating the exploration and understanding of various cybersecurity concepts. Notable features include a comprehensive collection of tools and resources aimed at enhancing practical skills in ethical hacking.
2026-08-03
HTML
★ 1496
R4ven is a security research tool designed to demonstrate the potential risks associated with modern web browser permissions, illustrating how granting access can expose sensitive data such as location, camera inputs, IP addresses, and device information. It enables users to collect metadata in a controlled environment for educational purposes, emphasizing the importance of privacy hygiene and the dangers of social engineering attacks. Notable features include IP and GPS tracking, camera access, user-driven permission interactions, and integration with platforms like Discord for data presentation.
2026-08-03
HTML
★ 17
Tele-Trace is a local web-based OSINT tool for Telegram, designed for profile analysis and research investigations utilizing Flask and Telethon. Its key features include detailed profile scanning by username or phone number, user account age estimation, a trust score calculation based on multiple factors, and advanced username intelligence capabilities with bio analysis. This solution operates entirely on your device, ensuring data privacy without reliance on cloud services.
2026-08-03
HTML
★ 222
CyberTrace is an advanced OSINT (Open Source Intelligence) and cyber intelligence platform designed for security researchers, bug bounty hunters, and penetration testers. It consolidates various reconnaissance techniques such as IP geolocation, ISP lookup, and WHOIS information into a streamlined, cyberpunk-themed dashboard, facilitating faster and more efficient investigations. Key features include an interactive map for visualizing data and the ability to gather intelligence from public camera sources, enhancing situational awareness for security operations.
2026-08-03
HTML
★ 44
The Hacking-PenTesting-Utils repository serves as a comprehensive collection of tools, scripts, and configurations specifically designed for Internet of Things (IoT) penetration testing. It provides a variety of microcontroller options, RF modules, and essential hardware components to assist users in developing and deploying effective IoT security testing solutions. Notable features include a diverse range of compatible microcontrollers such as the ESP32, along with numerous supporting modules for enhanced functionality in various pen-testing scenarios.
2026-08-03
HTML
★ 622
NETHERCAP is a comprehensive Wi-Fi penetration testing and social engineering tool designed for deployment on ESP8266, ESP-32, and BW16 (RTL8720dn) devices. Its primary use case involves executing attacks such as deauthentication and the Evil Twin attack, offering features like multi-language support and easy installation through its GitHub releases. The tool is particularly targeted towards users in Indonesia and includes community support via Telegram and WhatsApp for enhanced user engagement.
2026-08-03
HTML
★ 48
NullPhish is an automated phishing toolkit designed for security research, featuring over 30 customizable templates with integrations for Discord and Telegram. It offers a range of notable features including multiple tunneling options, URL masking, and Docker support, making it beginner-friendly while providing advanced capabilities for simulating phishing attacks. The tool serves educational purposes to demonstrate phishing mechanisms and comes pre-loaded with the latest login page designs.
2026-08-03
HTML
★ 230
ToolHunt is an advanced search engine designed to facilitate the discovery of cybersecurity tools from a comprehensive database exceeding 3,000 entries. Its primary use case is to help security professionals, pentesters, and researchers quickly identify relevant tools through a semantic search powered by AI, which utilizes hybrid algorithms for optimal match relevance. Notable features include a cyberpunk-themed user interface, responsive design for various devices, and cloud deployment capabilities via Google Colab.
2026-08-03
HTML
★ 54
Email-Security-Auditor is a robust tool designed to enhance email authentication verification by conducting in-depth behavioral analysis across security protocols such as SPF, DKIM, and DMARC. Its notable features include policy fuzzing for automated edge-case discovery, machine-learning-based reputation scoring, and comprehensive compliance reporting capabilities, making it essential for organizations facing contemporary email threats and regulatory pressures. The architecture supports horizontal scaling and microservices isolation, ensuring reliability and effectiveness in enterprise environments.
2026-08-03
HTML
★ 60
INtrack is a multi-threaded internet crawler and security scanner focused on network reconnaissance and vulnerability detection. It supports various scanning types, including the detection of web applications, IoT devices, and exposures, while offering flexible target selection, customizable settings, and real-time progress visualization. Notable features include support for multiple scanner types based on CVEs, the ability to scan either specific IPs or subnets, and a customizable thread count for efficient scanning.
2026-08-03
HTML
★ 23
Sqlite3 Page Explorer is an Electron-based application that enables users to open and explore SQLite databases, allowing for in-depth examination of their internal structures, including schemas, tables, and indices. Its notable features include hierarchical navigation of B-Tree pages, parsing of cell content, and the ability to view both current and deleted data pages, making it an essential tool for software development, ethical hacking, troubleshooting, and academic studies related to database formats.
2026-08-03
HTML
★ 314
Infosec House is a comprehensive repository offering a wide range of cybersecurity tools and resources tailored for both offensive and defensive strategies. It features over 1,100 entries across various categories including AI, API pentesting, incident response, malware analysis, and OSINT, providing cybersecurity professionals with essential resources to enhance their operations. Users can contribute to the repository by submitting pull requests or reporting issues, facilitating a collaborative environment for continuous improvement.
2026-08-03
HTML
★ 139
The Periodic Table of Offensive Security serves as a visual reference for 118 essential tools, frameworks, and standards utilized in offensive security and red teaming. Its primary use case includes aiding penetration testing, red team training, and providing a comprehensive overview of tools for OSINT, exploitation, and post-exploitation phases. Notable features include downloadable print-friendly PDFs and an interactive clickable version that links directly to resources for each tool represented.
2026-08-03
HTML
★ 38
SecuSploitX is an advanced, modular, open-source penetration testing and cybersecurity toolkit designed for offensive security operations. It features a comprehensive suite of tools including web and network security modules, AI-driven automation for tasks like phishing simulations, and both GUI and CLI interfaces for user flexibility across multiple platforms. Notable capabilities include automated vulnerability scanning, advanced brute force tactics, and extensive documentation, making it suitable for both educational and professional use.
2026-08-03
HTML
★ 86
LOLFSaaS is a comprehensive directory of 127 Software as a Service (SaaS) platforms equipped with free tiers, focusing on their abuse potential in security contexts. It offers extensive operational intelligence, detailing abuse surface, operational security profiles, detection mechanisms, and links to Command and Control (C2) frameworks, enabling security researchers and red teamers to effectively strategize their approaches. Notably, the tool categorizes services based on various attributes, such as zero-signup services, custom domain support, and detection logics, and provides cross-references to other threat intelligence resources for enriched context.
2026-08-03
HTML
★ 23
The Malware Analysis repository serves as a comprehensive resource for the technical dissection of various malware strains, aimed at security professionals and researchers. It features in-depth analysis articles on notable malware such as AsyncRAT and SamSam Ransomware, as well as a collection of tools like Flare-VM, which is a pre-configured Windows-based virtual machine tailored for reverse engineering and malware analysis.
2026-08-03
HTML
★ 16
The Tools Installer facilitates the streamlined installation of various cybersecurity tools on Kali Linux and Ubuntu operating systems. Key features include automatic script updates, the capability to install individual tool sections, and a user-friendly menu and icon design for enhanced accessibility. This tool is ideal for cybersecurity professionals seeking quick and efficient setup of essential tools in their environments.
2026-08-03
HTML
★ 13
This repository presents a proof-of-concept for exploiting a CORS (Cross-Origin Resource Sharing) vulnerability characterized by a misconfigured policy that allows arbitrary `Origin` headers and sets `Access-Control-Allow-Credentials: true`. The primary use case involves demonstrating how such vulnerabilities can be detected and exploited to exfiltrate sensitive data, such as an API key, from a victim's browser. Notable features include detailed steps for testing the vulnerability using tools like Burp Suite and a lab walkthrough that guides users through the detection and exploitation processes.
2026-08-03
HTML
★ 12
The CORS vulnerability tool demonstrates the exploitation of a null origin CORS misconfiguration in a web application, enabling attackers to exfiltrate sensitive API keys. This GitHub repository provides a comprehensive walkthrough of a proof-of-concept (PoC) attack on a sample lab site, detailing the steps and methods used to identify and exploit the vulnerability, along with suggested mitigation techniques to enhance security. Notable features include a structured guide with practical examples and screenshots to aid in understanding the exploit and its implications.
2026-08-03
HTML
★ 44
The CS2 Real-time Demo Radar Visualizer is a tool designed to visualize player activities and game dynamics in real-time for Counter-Strike 2 demos. Notable features include automatic game path detection, detailed player statistics, real-time updates every 50ms, customizable display settings, and a mini radar interface for secondary monitors. This tool is intended for educational and personal use, and it requires specific commands to function properly in a game environment.
2026-08-03
HTML
★ 10
The tool "Tor-0day-JavaScript-Exploit" serves as a comprehensive educational resource and demonstration of the CVE-2024-9680 vulnerability, a critical use-after-free exploit in the Tor Browser's animation handling. It includes both the original exploit code used in the wild and a modified version with detailed analyses, showcasing the exploitation process through various stages such as initialization, DOM crafting, and trigger mechanisms. This repository is intended primarily for security education, defensive research, and authorized vulnerability assessments, emphasizing ethical and legal usage.
2026-08-03
HTML
★ 25
The 'vulnerability' tool catalogs known vulnerabilities for various software, with a current focus on Microsoft Internet Explorer and Apple OSX, listing specific Common Vulnerabilities and Exposures (CVEs) associated with each platform. The primary use case is to provide a reference for security professionals looking to understand and track reported vulnerabilities. Notable features include the organization of vulnerabilities by vendor and product, enabling easier identification of security concerns.
2026-08-03
HTML
★ 15
CVE-2020-10558 is a tool that documents a critical Denial of Service vulnerability in Tesla Model S, 3, and X vehicles prior to software version 2020.4.10, which allows remote attackers to crash the vehicle's Infotainment system by exploiting improper web instruction handling. The tool provides insights into the attack vector, impact on vehicle functionality, and remediation details following responsible disclosure protocols. Notably, the findings led to a fleet-wide OTA update from Tesla to mitigate the vulnerability, highlighting its significance in automotive cybersecurity.
2026-08-03
HTML
★ 42
The k8gege.org repository hosts a website that serves as a centralized platform for Kubernetes-related resources and tools. Its primary use case is to provide educational content, documentation, and best practices for Kubernetes users and developers. Notable features include curated links to tutorials, articles, and other valuable resources in the Kubernetes ecosystem.
2026-08-03
HTML
★ 13
The Wagon Site is a versatile web application that aggregates a variety of tools, including exploits, bookmarklets, games, and proxies. It serves as a centralized platform for users seeking easy access to these resources, emphasizing functionality through a bookmarklet for streamlined launching. Notable features include a diverse array of tools and a community-driven approach with a dedicated Discord channel for user engagement.
2026-08-03
HTML
★ 83
CVE-Intel is a vulnerability intelligence platform that aggregates and correlates data from GitHub CVE-tagged repositories, the National Vulnerability Database (NVD), and cybersecurity news feeds. It is aimed at security researchers, blue teams, and integrators, providing a public API and frontend to access and analyze enriched CVE information. Notable features include a robust data ingestion pipeline, real-time news updates, and an interface for querying vulnerability details with pagination and filtering capabilities.
2026-08-03
HTML
★ 61
The haval-app-tool-multimidia project is an unofficial educational tool designed for reverse engineering the Haval GWM multimedia system. Its primary use case is to facilitate learning and exploration of the system's architecture and functionality without any commercial intent. Notable features include detailed documentation for understanding the inner workings and guidance on extending the tool's capabilities.
2026-08-03
HTML
★ 80
The Security Reference Guide is a curated repository of cyber security resources tailored for SOC analysts, pentesters, DFIR practitioners, and other security-focused roles. It organizes valuable links into categories such as offensive and defensive operations, engineering fundamentals, and training resources, providing context to help users select the appropriate tools and materials quickly. Notably, the guide emphasizes legitimacy, cautioning against the misuse of tools for unethical purposes.
2026-08-03
HTML
★ 19
Z-Hound is a browser-based tool designed for visualizing attack graphs from SharpHound and AzureHound data, enabling quick and portable analysis of Active Directory and Azure AD environments without requiring any server setup or installations. It supports multiple SharpHound output formats, offers an interactive graph interface with various layout options, and allows users to upload ZIP or JSON files for analysis, making it ideal for pentesters and red teamers needing fast, offline capabilities. Notable features include automatic resolution of SIDs, customizable node visualizations, and the ability to work entirely offline after initial loading.
2026-08-03
HTML
★ 44
CyberInject is a professional browser extension toolkit focused on authorized security testing and penetration testing activities. It offers quick access to a diverse range of security payloads categorized into vulnerabilities such as XSS, SQL Injection, SSRF, and LFI, alongside features like one-click copying and an organized, user-friendly interface. Designed for compliance with legal standards, it ensures that users can efficiently execute their testing tasks while promoting responsible usage.
2026-08-03
HTML
★ 14
The iOS ClickFix Template is a red team tool designed for executing a ClickFix → WebClip social engineering attack chain on iOS devices. It creates a convincing lure page that prompts targets to install a malicious `.mobileconfig` profile, which then adds a shortcut to the attacker's designated web page on the target's Home Screen. Notable features include personalized links for each target, generating unique profiles, and easy configuration to customize the WebClip functionality.
2026-08-03
HTML
★ 233
The HTB Writeups repository is a comprehensive resource for Hack The Box enthusiasts, providing structured and searchable documentation for over 500 machines, 400 challenges, and various tools and methodologies useful for penetration testing and certification preparation. Notable features include an interactive machine finder, knowledge graph for technique exploration, and visual attack paths that illustrate complete exploitation processes. This repository serves as an essential hub for skill development aimed at OSCP, CPTS, and other security certifications.
2026-08-03
HTML
★ 14
CloudGuard Security is a browser-based demonstration tool that exploits the File System Access API to simulate file encryption and delivery attacks without requiring software installation. It operates in two modes: the 'lock' mode, which encrypts files using AES-256-GCM and displays a countdown alert, and the 'drop' mode, which silently writes a specified payload to the user's file system. The tool emphasizes social engineering techniques for permission granting, making it a practical resource for red-team exercises.
2026-08-03
HTML
★ 129
HydraSoft is an advanced open-source tool designed for detecting DLL hijacking vulnerabilities within Windows environments, facilitating privilege escalation. It automates the analysis of executable files and their associated DLLs by scanning directory structures and import tables, thus identifying specific hijacking opportunities. Notable features include a real-time graphical user interface for centralized endpoint management and a color-coded rating system to prioritize targets based on the complexity of crafting proxy DLLs.
2026-08-03
HTML
★ 136
Burp HTTP History Browser (BHHB) is a tool designed to enable users of Burp Suite Community Edition to view and manage their HTTP history after a session ends, addressing the lack of disk-based project support. It allows users to export their HTTP history in XML format, which can then be parsed and displayed in a well-structured interface. Notable features include its functionality as a Progressive Web App (PWA) that can operate offline in any Chromium-based browser.
2026-08-03
HTML
★ 54
RedConsole is an offline, single-file penetration testing tool designed for Red Team operators, OSCP/OSEP preparation, and CTF/HTB engagements. It provides an interactive attack plan generator that automatically fills commands based on target details and adapts as progress is made, while also offering features like recon autopilot, credential reuse matrix, and playbook builder for streamlined execution. Its core advantage lies in its ability to run in any browser without requiring installation or internet access, making it suitable for various environments, including locked-down VMs and air-gapped systems.
2026-08-03
HTML
★ 30
RRW (Rick Roll WiFi) is a prank tool that sets up a rogue access point designed to capture captive portal probes and serve a fake Wi-Fi login page that redirects connected devices to a rickroll video. It utilizes standard network utilities like `hostapd`, `dnsmasq`, and `iptables` to manage the AP and traffic redirection without collecting credentials or intercepting user data, making it a non-malicious tool meant for entertainment. Users can customize the SSID, video, and HTML templates, allowing for tailored rickroll experiences.
2026-08-03
HTML
★ 21
This repository provides a curated collection of detailed writeups on various cybersecurity challenges, including Bug Bounty, Hack The Box (HTB), TryHackMe, and Capture the Flags (CTFs). It serves as an educational resource for cybersecurity practitioners at all levels, featuring in-depth explanations of techniques for web exploitation, privilege escalation, and more, aimed at enhancing understanding of vulnerabilities and methodologies in cybersecurity.
2026-08-03
HTML
★ 12
ExploitHunter.app is an open-source offensive-security tool designed to enhance the cost-effectiveness of security research through intelligent orchestration of various AI models. It facilitates broad reconnaissance, inventory checks, and evidence gathering using budget-friendly or local models, while reserving expensive frontier models for deeper analysis and validation tasks. Key features include automated lab environments for running evaluations, local model capabilities without API costs, and a data explorer for tracking evaluation outcomes and expenses.
2026-08-03
HTML
★ 31
OSCP+ Complete Exam Checklist & Attack Chains (2025-26) is a comprehensive resource designed to aid candidates in navigating the OSCP exam format, emphasizing techniques for enumeration, exploitation, and lateral movement within a simulated environment. It offers structured methodologies for tackling Active Directory and standalone systems, alongside practical strategies for efficient time management during the exam. Notable features include a universal enumeration framework, a detailed breakdown of point allocation, and specific attack chains related to various scenarios, ensuring candidates are well-prepared for the challenges they will face.
2026-08-03
HTML
★ 156
JAMBOREE is a comprehensive sandbox environment designed for Android security research, integrating tools like Magisk for root access, Burp Suite for proxy interception, and Objection for runtime manipulation within a unified system. Its primary use case is to facilitate seamless penetration testing and reverse engineering of Android applications, streamlining the workflow with features such as automated module management, efficient proxy configurations, and optimized emulator settings. Notable enhancements include a self-healing configuration system and multi-version compatibility, significantly reducing setup time and improving testing efficiency.
2026-03-30
HTML
★ 771
THC-Archive is a repository that consolidates all releases from The Hacker’s Choice, a prominent security research group. This collection serves as a backup for their work, ensuring that projects are preserved despite the lack of a full web server. Notable active projects include THC-Hydra, THC-IPv6, and utilities aimed at various hacking and security tasks.
2026-03-22
HTML
★ 1079
Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.
2026-03-22
HTML
★ 972
A collection of android Exploits and Hacks
2026-03-22
HTML
★ 1045
:baby: BabySploit Beginner Pentesting Toolkit/Framework Written in Python :snake:
2026-03-22
HTML
★ 890
These are my checklists which I use during my hunting.
2026-03-22
HTML
★ 3965
有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file
2026-03-22
HTML
★ 1342
Course Repository for University of Cincinnati Malware Analysis Class (CS[567]038)
2026-03-22
HTML
★ 796
Everything needed for doing CTFs
2026-03-22
HTML
★ 8032
Gather and update all available and newest CVEs with their PoC.
2026-03-22
HTML
★ 1641
Real-time phishing & scam domain blocklist — 99,000+ curated threats, 828K+ community, free API, multiple formats
2026-03-22
HTML
★ 814
A security research site.
2026-03-22
HTML
★ 1008
GeoIntel using Google's Gemini API to uncover the location where photos were taken through AI-powered geo-location analysis.
2026-03-22
HTML
★ 1077
Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework
2026-03-22
HTML
★ 5448
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
2026-03-22
HTML
★ 794
A tool to quickly identify relevant, publicly-available open source intelligence ("OSINT") tools and resources, saving valuable time during investigations, research, and analysis.
2026-03-22
HTML
★ 909
So what is this all about? Yep, its an OSINT blog and a collection of OSINT resources and tools. Suggestions for new OSINT resources is always welcomed.
2026-03-22
HTML
★ 2190
OSINT cheat sheet, list OSINT tools, wiki, dataset, article, book , red team OSINT for hackers and OSINT tips and OSINT branch. This repository will grow every time will research, there is a research, science and technology, tutorial. Please use it wisely.
2026-03-22
HTML
★ 7479
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
2026-03-22
HTML
★ 8805
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
2026-03-22
HTML
★ 2409
RootMyTV is a user-friendly exploit for rooting/jailbreaking LG webOS smart TVs.
2026-03-22
HTML
★ 3557
Database documentation built easy
2026-03-22
HTML
★ 4870
Social engineering tool [Access Webcam & Microphone & Location Finder] With {Py,JS,PHP}
2026-03-22
HTML
★ 794
Trace Labs OSINT Linux Distribution based on Kali.
2026-03-22
HTML
★ 1715
WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.
2026-03-22
HTML
★ 2590
Web Fuzzing Box - Web 模糊测试字典与一些Payloads