> cat /dev/github | grep security-tools

Python

netsentinel

2026-08-31 Python ★ 16
NetSentinel is a comprehensive network management tool designed for discovering devices, diagnosing connectivity issues, and monitoring network health. It features rogue device detection, detailed device inventory, bandwidth monitoring, a root cause correlator, and automated reporting capabilities, all while ensuring complete data privacy with a fully local, open-source architecture. With its extensive functionality, NetSentinel serves as a powerful aide for network administrators and users seeking to enhance both security and reliability in their network environments.

mole

2026-08-31 Python ★ 84
Mole is a Binary Ninja plugin that facilitates the identification of significant execution paths within binaries through backward slicing of variables, leveraging the Medium Level Intermediate Language (MLIL) in Static Single Assignment (SSA) form for static taint analysis. Its primary use case lies in vulnerability detection, where it allows users to define source and sink functions, visualize paths, and analyze them using AI integration for classifying potential vulnerabilities. Notable features include operational flexibility, extensive path exploration options, customizable path grouping strategies, persistence of analysis progress, and inter-procedural variable slicing.

CTFlearn-Writeups

2026-08-31 Python ★ 171
CTFlearn-Writeups is a compilation of detailed solutions for various Capture The Flag challenges across multiple domains such as Cryptography, Forensics, and Web security. The tool serves as a reference for practitioners and enthusiasts looking to enhance their skills in cybersecurity challenge-solving. Notable features include categorized writeups that cover a range of problem types, providing structured insights into methodologies and techniques used in each challenge.

cwv-scanner

2026-08-31 Python ★ 27
cwv-scanner is a Python-based tool designed to identify common web application vulnerabilities by scanning specified URLs or IP addresses. It checks for 36 types of vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), and Remote Code Execution, facilitating website owners and security researchers in enhancing their application's security posture. Notable features include a straightforward installation and usage process, allowing for quick deployment in vulnerability assessments.

snatch

2026-08-31 Python ★ 36
Snatch is a Python-based tool designed for OSINT (Open Source Intelligence) tasks, aimed at cybersecurity and hacking practitioners. It utilizes AI to automate the generation of resources such as password lists, email identification, and social media profiling based on user-defined prompts. Notable features include a ports scanner, website/video/data downloader, and a robust directory and subdomain listing module, although many features are still in development or forthcoming.

funny-virus

2026-08-31 Python ★ 10
Funny-virus is a collection of harmless, fun scripts designed to simulate playful "virus-like" behaviors for entertainment and educational programming experimentation. Notable features include the generation of random pop-up windows, playful text color changes, and fake system messages, allowing users to safely explore humorous programming concepts without causing any actual harm. The project emphasizes responsible use and is intended solely for non-malicious purposes.

IKONA-Security

2026-08-31 Python ★ 115
**IKONA Security** is a comprehensive cybersecurity tool designed for research and auditing, featuring modules for penetration testing, bug bounty payloads, and security audits of various web frameworks such as Laravel and Next.js. Notable features include a collection of web exploitation payloads, curated wordlists for API endpoints and directory traversal, and both automated and manual bug hunting methodologies. This tool emphasizes responsible usage, intended strictly for educational and authorized testing purposes.

pxethiefup

2026-08-31 Python ★ 10
PXEThiefUp is an advanced tool for extracting sensitive data from SCCM/MECM environments using PXE boot protocols, building upon the original PXEThief functionality with enhanced features. It supports automatic and manual targeting of PXE servers, various media formats for data extraction, and has capabilities for decrypting media files and organizing output, making it suitable for cybersecurity professionals engaged in network security assessments. Notable features include interface selection, folder scanning, basic password cracking, and compatibility with both Windows and Linux platforms.

BCA-Phantom

2026-08-30 Python ★ 104
Phantom is a multi-platform HTTP(S) reverse shell server and client implemented in Python 3, designed for securely establishing remote connections over HTTP or HTTPS. It features automatic certificate generation for HTTPS, bundled dependencies for seamless execution on Linux and Windows, and provides a user-friendly shell script for rapid certificate creation. The tool is tailored for penetration testing and remote administration scenarios, allowing quick setup and deployment for secure command execution.

Simple-Async-Port-Scanner

2026-08-30 Python ★ 95
Simple-Async-Port-Scanner is a Python 3-based asynchronous TCP port scanner that utilizes the asyncio framework to efficiently connect to multiple ports on specified IP addresses within a user-defined timeout. It features a straightforward command-line interface for scanning specified ports, supports both IP addresses and domain names, and can filter results to display only open ports. This tool is particularly notable for its speed, capable of scanning the first 1000 TCP ports on a target in under two seconds, while maintaining minimal dependencies.

subdosec

2026-08-30 Python ★ 63
Subdosec is a specialized scanner for identifying potential subdomain takeovers, designed to deliver fast and accurate results with zero false positives. Its primary use case involves scanning subdomains for vulnerabilities and providing detailed reconnaissance data, including relevant metadata such as IP addresses and CNAME records. Notable features include a public database of vulnerable subdomains, support for both public and private scanning modes, and an option for local result saving alongside AI analysis capabilities for undetected subdomains.

pyfunda

2026-08-30 Python ★ 190
pyfunda is a Python API wrapper specifically designed for interacting with Funda.nl, the leading Dutch real estate platform, utilizing its reverse-engineered mobile JSON API to fetch property listings without the need for HTML scraping or browser automation. This library provides clean, typed objects for listings, prices, media, and brokers, allowing users to perform detailed searches, retrieve listing information, view price history, and monitor new listings. Notably, pyfunda is an open-source solution that acts as the only functioning Python client for accessing Funda’s endpoints, making it a valuable tool for developers seeking a reliable alternative to proprietary scraping services.

CredStalker-

2026-08-30 Python ★ 10
CredStalker is a Python-based credential and sensitive data scanner that automatically crawls websites to identify exposed credentials, API keys, and other sensitive information. It features multi-type detection capabilities, deep content analysis of HTML and JavaScript, and customizable crawling with detailed reporting and export functionality for further analysis. Ideal for security audits and penetration testing, it also includes options for verbose logging and same-domain crawling to ensure scope compliance.

gitcolombo

2026-08-30 Python ★ 94
Gitcolombo is an OSINT tool designed to extract identities such as names and emails from git repositories and GitHub, establishing connections between seemingly unrelated accounts. It features a Python CLI for repository cloning and analysis, alongside a web version that allows direct querying of the GitHub API without installation. Notable functionalities include detailed per-person identity analytics, correlation of authorship and commit data, and support for batch scanning across public repositories of users or organizations.

jsrip

2026-08-30 Python ★ 24
jsrip is an advanced JavaScript analysis tool designed for bug bounty hunters and penetration testers, capable of crawling web applications to extract and analyze JavaScript files for security vulnerabilities, such as secrets and endpoints. It features a sophisticated detection mechanism that identifies over 1700 patterns related to various cloud services, maps API routes and internal paths, and generates detailed interactive reports in multiple formats. Notable functionalities include subdomain enumeration, false positive mitigation, and scoping for shared-hosting environments.

exc

2026-08-29 Python ★ 16
EXC Analyzer is a command-line tool designed for advanced intelligence gathering, security auditing, and content analysis of GitHub repositories. It enables users to assess repository security, audit GitHub Actions workflows, and locate sensitive information through dork scanning, with features such as user profiling and smart rate limiting for efficient API management. Notable for its professional-grade capabilities, it's aimed at security researchers and penetration testers looking to derive actionable insights from repository data.

Argus

2026-08-29 Python ★ 11
Argus is an open-source tool designed for aggregating and visualizing over 229,000 traffic and CCTV camera feeds globally on a real-time interactive map. It features both 2D and 3D globe views, live feed playback, and a sophisticated data pipeline that scrapes metadata from various sources, allowing users to explore live streams and static images in an easy-to-navigate dashboard. Key functionalities include data synchronization, customizable filters, and a user-friendly interface built with React and TypeScript.

scanner

2026-08-28 Python ★ 13
inspect-scanner is a command-line interface tool that audits public GitHub repositories or organizations, generating structured JSON and HTML reports focused on health, maintainability, quality, security, and dependency signals. It exclusively utilizes public GitHub API data and raw manifest files for analysis, ensuring no code is executed or cloned, and incorporates customizable scan configurations to enable or disable specific metrics or categories. Notably, it integrates with OpenSSF Scorecard for security assessment, emphasizing broad security practices over vendor-specific configurations.

pulsar-mouse-linux

2026-08-28 Python ★ 10
The pulsar-mouse-linux tool enables Linux users to configure various Pulsar gaming mice through a user-friendly interface, supporting models with distinct protocols. Key features include plugin architecture for different mouse drivers, customization options for performance and lighting, button remapping, and a system tray icon for easy access. This tool is reverse-engineered from USB HID captures and provides comprehensive support for both wired and wireless models.

DelphiReSym

2026-08-28 Python ★ 35
DelphiReSym is a reverse engineering tool that recovers fully qualified Delphi symbol names from the metadata in Delphi executables, facilitating the analysis of Delphi malware and legacy applications. Integrated with Ghidra, it not only restores human-readable context for functions and types but also automatically populates virtual table structures in Ghidra's Data Type Manager. This tool supports multiple Delphi versions, enabling detailed reconstruction of metadata for effective reverse engineering.

hcaptcha-hsj-reverse

2026-08-28 Python ★ 21
The hcaptcha-hsj-reverse tool is designed to reverse engineer hCaptcha's hsj.js to extract encryption keys used in its operations. It provides functionality to hook into the AES key schedule of hsj.js and dump encryption keys from memory, utilizing various cryptographic algorithms such as AES-GCM. Notable features include a KeyFetcher class for retrieving these keys and a comprehensive set of helper classes for encryption, hashing, and encoding processes.

n64-decomp-workbench

2026-08-28 Python ★ 13
N64 Decomp Workbench is a diagnostic tool designed to identify and analyze discrepancies in late-stage MIPS decompilation, particularly for near-matched functions. Its primary use case is for developers working with MIPS assembly code, allowing them to efficiently isolate functions, understand the reasons behind mismatches, and generate hypotheses for resolution without requiring extensive setup or external tools. Notable features include a guided workflow, exhaustive documentation, and commands like `diagnose-dumps` and `compare-dumps` that enable users to comprehensively compare and troubleshoot decompiled outputs.

r3ngine

2026-08-28 Python ★ 10
r3ngine v3.7.4 is an advanced web reconnaissance and vulnerability scanning tool that facilitates comprehensive security assessments through its Target Report Generation feature, allowing users to generate detailed multi-scan PDF reports with historical vulnerability tracking. Key features include an Attack Path Modeling Engine aligned with MITRE ATT&CK, integration with WPScan/WPTaint for static analysis, and enhanced infrastructure for scalability and reliability using Django and PostgreSQL. This enterprise-grade platform is designed for thorough and efficient security analysis while ensuring operational security and ease of use.

VeltCLI

2026-08-28 Python ★ 15
VeltCLI is a terminal-based OSINT and defensive security research toolkit that consolidates multiple reconnaissance and analysis tasks into a single interface. Its primary use case includes vulnerability assessment, DNS checks, web security analysis, and various research workflows across social media, emails, IP intelligence, and more, all while supporting data export in formats such as JSON, CSV, and Markdown. Notable features include comprehensive vulnerability scanning, domain and cloud analysis, and detailed reporting capabilities, streamlining the security research process for users.

digital-footprint-cleaner

2026-08-28 Python ★ 13
Digital Footprint Cleaner is an open-source web application designed for identifying and managing personal information exposure online by facilitating the generation of data-removal requests. It features a multi-pass search mechanism, match confidence scoring, and provides an exposure report categorized by source, alongside a comprehensive data-broker opt-out checklist for 30+ sites. Additional functionalities include a removal tracker, scan coverage reporting, and optional passcode protection to enhance user security.

Huntable-CTI-Studio

2026-08-28 Python ★ 11
Huntable CTI Studio is an advanced Cyber Threat Intelligence (CTI) tool designed to automate the collection, extraction, and generation of detection rules from over 38 OSINT sources. Its notable features include AI-driven relevance scoring, sigma rule generation, and a comprehensive workflow management system using LangGraph and Celery, which facilitates extensive threat intelligence aggregation while ensuring duplicate prevention through community rule comparisons. The tool also supports hardened deployments for secure operation in sensitive environments.

tomcter

2026-08-28 Python ★ 96
Tomcter is a Python-based tool designed for brute-forcing Apache Tomcat manager logins using default credentials. It supports targeting single or multiple instances, integrates with ProxyChains for enhanced anonymity, and is optimized for minimal resource usage. The tool is open-source and easily deployable via Docker, making it suitable for penetration testing scenarios.

YetAnotherPentestParser

2026-08-28 Python ★ 10
YAPP (Yet Another Pentest Parser) is a robust Python library and CLI tool designed to parse and process outputs from multiple penetration testing tools, including Nessus, Nmap, and BloodHound, into actionable results. Notable features include comprehensive multi-tool support, an extensible framework for adding new parsers, dual interface options (CLI and TUI), in-memory processing, and advanced Active Directory analysis capabilities without the need for a Neo4j server. This allows for efficient vulnerability management and streamlined workflows, aiding penetration testers in reducing processing time and improving overall productivity.

csp_toolkit

2026-08-28 Python ★ 10
csp-toolkit is a Python library and command-line interface designed for parsing, analyzing, generating, and identifying bypasses in Content Security Policy (CSP) headers. Primarily aimed at security researchers and bug bounty hunters, it features automated CSP generation through website crawling, policy analysis with 21 vulnerability checks, and the ability to find potential bypasses against a database of known exploit vectors. Notable functionalities include the ability to score CSPs, detect nonce reuse, batch scan URLs, and generate output in various formats such as JSON and SARIF for integration with CI/CD workflows.

JScanner2

2026-08-27 Python ★ 13
JScanner2 is an AI-powered JavaScript security analysis tool that utilizes AST parsing for detecting vulnerabilities and sensitive information in JavaScript files. Unlike traditional regex-based scanners, it intelligently extracts API parameters, provides context-aware analysis for hardcoded secrets, and offers exploit suggestions, enabling more accurate and efficient vulnerability assessments. Notable features include resumable scanning and automatic parameter discovery, making it suitable for red team and blue team exercises.

flarevm-mcp

2026-08-27 Python ★ 11
FlareVM MCP is a Model Context Protocol server that facilitates remote access to a suite of over 48 Windows malware analysis tools within an isolated FlareVM environment, allowing seamless integration for AI agents and security analysts. Its notable features include remote file operations, comprehensive static and dynamic analysis capabilities, debugger integration, and a standardized interface for automatized workflows. This architecture enables enhanced malware examination while maintaining the security of the analysis environment.

navimow_pro

2026-08-27 Python ★ 20
Navimow is an unofficial integration for Home Assistant that facilitates control and monitoring of Segway Navimow robot mowers using the vendor's private cloud protocol. Key features include customizable mowing schedules, real-time status updates through various sensors, a visual mapping interface, and a set of Lovelace cards for an enhanced user experience. This integration allows users to execute mowing commands and manage mower settings while maintaining oversight of the mower's operational status and performance.

Ryuumonbuchi

2026-08-27 Python ★ 45
Ryuumonbuchi is a headless Model Context Protocol (MCP) server that integrates with Ghidra to facilitate reverse engineering through direct interaction with its APIs via typed tool calls, eliminating the need for GUI automation and manual scripts. This tool supports a persistent PyGhidra and JVM backend, allowing multiple program session analyses including decompilation, disassembly, and patching, while maintaining efficient use of resources by reusing the backend across requests. With 216 distinct functions available to users, Ryuumonbuchi streamlines reverse engineering tasks within a robust and flexible architecture.

SimpleReconDorking

2026-08-27 Python ★ 10
SimpleReconDorking (SRDorking) is a Python-based tool for URL scraping using dorking techniques across multiple search engines, facilitating OSINT and reconnaissance operations. It accepts user-defined or categorized dorks and processes them in parallel, differentiating itself from other tools by focusing solely on search engine indices without a crawling mechanism. Notable features include asynchronous execution, no external shell dependencies, and an integrated dork catalog for efficient asset exposure audits.

Project-Eyes-On

2026-08-26 Python ★ 231
Project Eyes On is a multi-threaded reconnaissance tool designed for the global scanning and identification of open IP cameras by leveraging both web dorking and directory scraping techniques. Notable features include support for multiple search engines, anti-rate limiting, path probing to locate hidden streams, and interactive TUI for user-friendly operation. This tool aims to serve educational and security auditing purposes but highlights the importance of device security for camera owners.

RPC-Triage

2026-08-26 Python ★ 12
RPC-Triage is a static analysis tool designed to assess the Windows RPC attack surface by analyzing compiled PE binaries to identify registered RPC servers and their corresponding method signatures, security flags, and transport bindings. It uniquely ranks interfaces based on a composite score of reachability and danger, providing detailed receipts for transparency in scoring. Notably, the tool operates without the need for symbol files, making it effective on stripped binaries found in production environments.

patchbot

2026-08-26 Python ★ 19
Patchbot is a comprehensive vulnerability scanning tool that integrates with existing scanners and threat feeds to automate the patching process in software repositories. It specializes in inventorying packages, identifying vulnerabilities, and applying fixes—either through version bumps or more complex code changes—while ensuring that each change is verified and re-scanned prior to the creation of pull requests. Notable features include the ability to utilize custom threat feeds and scanners, as well as the capability to operate independently of CI environments, thereby providing flexibility in deployment and usage.

Ordo

2026-08-26 Python ★ 10
Ordo is an OSINT investigation toolkit designed to trace scam operations from a single website or app to the underlying network of operators. Its primary features include two data collection methods (WebPivot and BinaryPivot) that extract identifying artifacts, followed by a robust analysis and visualization capability to correlate data points and create interactive network graphs and professional reports. Additionally, Ordo focuses on maintaining operational security by ensuring that investigation data remains local and secure within an ignored directory.

theory

2026-08-26 Python ★ 10
THEORY is an open-source tool designed to produce comprehensive threat actor intelligence dossiers by aggregating data from various cybersecurity sources, including MITRE ATT&CK and AlienVault OTX. It leverages a large language model to synthesize information into easily digestible executive summaries and detailed intelligence reports, which feature TTP tables, detection opportunities, and enriched IoCs. Key functionalities include the generation of IR playbooks and export options in multiple formats, making it suitable for threat intelligence analysts, detection engineers, and security researchers.

awesome-osint-repos

2026-08-26 Python ★ 20
Awesome OSINT Repositories is a comprehensive catalog that organizes open-source investigative tools into 12 distinct categories, each tailored to specific input types such as usernames, domains, and IP addresses. The repository features a diverse range of projects, with additional sections highlighting emerging tools and AI-agent integrations, providing users with a robust resource for enhancing their open-source intelligence capabilities. It emphasizes only publicly accessible source-code repositories, ensuring a focused selection of actionable tools for investigations.

GMapsScraper

2026-08-26 Python ★ 70
GMapsScraper is a Python-based tool designed for scraping business data from Google Maps without requiring an API key. It offers features such as multi-threaded querying, extraction of over 15 fields including contact details and GPS coordinates, and the ability to crawl business websites for additional information. Users can export data in formats like CSV, Excel, or JSON, making it a versatile solution for lead generation and data enrichment.

spotlight

2026-08-26 Python ★ 38
Spotlight is an OSINT investigation orchestrator designed to convert leads into structured case files, integrating methodologies, sourced findings, and independent fact-checking. It features a client-driven workflow with explicit approval gates, allows for multiple research cycles, and maintains a separate knowledge vault for proven materials, ensuring that only verified data is published. Notable capabilities include drafting investigation briefs, running bounded research, and generating detailed reports with provenance records, making it suitable for rigorous investigative journalism and research.

Ingram-Pro

2026-08-26 Python ★ 12
Ingram-Pro is an enhanced network camera vulnerability scanner that builds upon the original Ingram framework, providing extensive coverage of over 40 proof of concept (POC) exploits for CVEs from 2017 to 2024, alongside brand-specific weak-password detection for more than 15 camera brands. Key features include authenticated and unauthenticated remote code execution (RCE), high concurrency scanning using gevent, and the ability to capture live snapshots from vulnerable devices. The tool is designed for authorized security assessments and facilitates rapid vulnerability detection across large IP ranges.

pi-recon

2026-08-26 Python ★ 17
PI Recon is a lightweight AI red teaming harness designed for authorized agent security challenges, facilitating a streamlined workflow of task acquisition, reconnaissance, validation, and summarization. It features continuous scheduling, bounded execution, multi-stage reconnaissance, structured summaries, and secure builds that do not expose sensitive information. This tool emphasizes simplicity and efficiency, making it an ideal choice for users looking to optimize their red teaming processes without the overhead of a heavier framework.

Project-Deep-Focus

2026-08-26 Python ★ 244
Deep Focus is a high-performance asynchronous network reconnaissance tool designed for security researchers and network administrators to discover and fingerprint services across IP ranges. It features intelligent probing of common network services, detailed authentication detection, and structured export of actionable intelligence, all while managing system resources to prevent overheating on passively-cooled devices. Its notable capabilities include comprehensive scanning for services like HTTP, FTP, SSH, and more, along with robust thermal management to ensure optimal performance.

RedAgent

2026-08-26 Python ★ 12
RedAgent is an offensive security tool designed for authorized security teams to conduct adversary-grade testing across various surfaces, including web, API, cloud, and identity. It operates within strict authorization boundaries, enabling controlled and precise engagements while leveraging supervised AI to enhance expert workflows. Notable features include comprehensive auditing of operations, policy-gated engagements, and a focus on ensuring all actions remain within authorized scopes.

ZeroBurst

2026-08-26 Python ★ 17
ZeroBurst is an advanced command-line application security testing framework designed for ethical hacking and vulnerability assessment. With over 55 specialized modules, it enables users to conduct thorough reconnaissance, injection testing, and auditing of web applications, focusing on various attack vectors such as server-side request forgery and SQL injection. Notable features include automated vulnerability detection across multiple tiers, advanced auditing capabilities, and comprehensive mapping tools for application infrastructure.

guardana

2026-08-25 Python ★ 116
Guardana is an open-source AI security verification tool designed to assess AI artifacts and deployed models for security vulnerabilities from the build stage to production. It features 51 configurable security checks, deterministic evidence collection, and graded verdicts for attack impact assessment, ensuring comprehensive reporting on model behavior and security weaknesses. Notably, it maintains user privacy by avoiding telemetry and streamlines grading through swappable components, offering detailed outcomes and confidence metrics for its findings.

search_vulns

2026-08-25 Python ★ 93
search_vulns is a modular tool designed for searching known vulnerabilities, exploits, and other related information across various data sources. Its primary use case is to facilitate vulnerability assessments by allowing users to query a local database with inputs such as product titles or vulnerability IDs, while supporting integration of additional data sources through its modular architecture. Notable features include a command-line interface for automated workflows, a web server for enhanced functionality, and the ability to accommodate diverse input formats.

Network-Scanner

2026-08-25 Python ★ 22
Network Scanner is an open-source security tool designed for vulnerability assessments and penetration testing, enhancing traditional methodologies with AI capabilities for intelligent analysis and detailed reporting. Tailored for a diverse user base including beginners and professionals, it offers functionalities such as automated reconnaissance, various scan types (subdomain, port, DNS), and an AI assistant for context-sensitive support. Notable features include report generation in PDF/HTML formats, an educational learning mode, and API readiness for seamless integration.

assemblyline_client

2026-08-25 Python ★ 23
The Assemblyline Client Library is a Python library designed to simplify the process of issuing requests to the Assemblyline API. Its primary use case is to enable developers to efficiently interact with Assemblyline's services, facilitating integration and automation of cybersecurity-related tasks. The library is notable for its comprehensive documentation and ease of use, streamlining the interaction with the Assemblyline platform.

logitech-ipc-protocol

2026-08-25 Python ★ 17
logitech-ipc-protocol is a tool that provides reverse-engineered documentation and programmatic control of Logitech multi-host devices through the Logi Options+ agent IPC protocol, addressing limitations in macOS regarding raw HID access. This tool enables seamless device switching and input monitoring on both macOS and Windows platforms, featuring scripts for automated switching, hotkey configurations, and enhanced integration for multi-device setups. Notably, it includes a monitor-follow daemon that automatically switches monitor inputs based on keyboard activity, thereby enhancing user experience in multi-host environments.

tiktok-msddk-info-fully-reversed

2026-08-25 Python ★ 11
The TikTok X-Mssdk-Info Reverse Engineering & Decrypter is a comprehensive Python tool designed to analyze and decrypt the X-Mssdk-Info telemetry header used by TikTok for device fingerprinting and security measures. It operates without external dependencies, enabling users to generate and decrypt the header payloads for API verification and device registration processes. Notable features include a complete implementation of the XXTEA encryption algorithm used by TikTok, alongside detailed instructions for payload generation and decryption.

vo_patch

2026-08-25 Python ★ 44
vo_patch is a tool designed to optimize and facilitate the installation of *Cyber Troopers Virtual-On* on modern systems, primarily by addressing compatibility issues such as crashes and frame rate problems. Notable features include XInput gamepad support for two players, internet play functionality without the need for port forwarding, and the ability to run the soundtrack from files instead of the disc, thereby enhancing the overall gaming experience.

public-skills-builder

2026-08-25 Python ★ 225
Public Skills Builder is a tool designed to generate Claude Code bug bounty skills from publicly available HackerOne reports and GitHub writeups, specifically without requiring access to private reports. It processes over 500 disclosed reports to create 18 structured skill files for various vulnerability classes, each containing real-world techniques, payloads, and bypass patterns, thereby providing users with resourceful training data for vulnerability hunting. Notable features include support for multiple sources, including public feeds, and the ability to customize output based on specified vulnerability types.

awesome-osint-repos

2026-08-25 Python ★ 11
Awesome OSINT Repositories is a comprehensive catalogue of open-source tools for Open Source Intelligence (OSINT) investigations, organized into 12 distinct categories based on concrete input types such as usernames, domains, and IP addresses. The repository features a total of 447 projects, including views for emerging tools and AI-based integrations, and excludes closed-source or incomplete resources. It provides easy navigation and documentation to facilitate the discovery and utilization of investigative software in various OSINT applications.

CyberLeaks

2026-08-25 Python ★ 12
CyberLeaks is an OSINT tool designed to assess email compromise through data breaches by utilizing dual API engines from Apify and RapidAPI. It features an interactive command-line interface for user-friendly operations, integrates risk scoring and detailed breach reporting, and supports batch processing of multiple emails. Additional capabilities include secure API key management, password leak lookups, and report generation in various formats.

HTTP-Security-Scanner

2026-08-25 Python ★ 19
Web Security Analyzer Pro is an advanced web security analysis tool designed for system administrators, developers, and security professionals to audit their websites efficiently. It conducts comprehensive assessments of HTTP headers, cookies, and SSL/TLS configurations, as well as identifying common vulnerabilities and generating a security score with remediation recommendations. Notable features include offline CVE searches using the FKIE-CAD database, interactive visual reporting, and detailed cookie analysis for security flags.

CVE-2026-18963-Exploit

2026-08-25 Python ★ 37
The CVE-2026-18963-Exploit tool allows users to test for a critical security vulnerability in Keycloak versions 26.0.0 to 26.7.1, which enables unauthenticated attackers to reset passwords without victim interaction. It features a safe detection mode that requires only the base URL and realm settings, avoiding any impact on the target system. Additionally, it includes a lab environment for practical demonstration of the exploit and its remediation.

Phishlets-Build

2026-08-25 Python ★ 10
The Phishlet Generator is an automated tool designed to streamline the creation of `.yaml` phishlet files for Evilginx3 by leveraging real browser automation with Playwright. Its primary use case is to eliminate the manual reverse-engineering of website login flows by capturing live network traffic during a simulated login process, which includes handling complex scenarios like CAPTCHA and 2FA challenges. Notable features include smart classification of fields and tokens, integration of anti-detection scripts, and the capability to generate production-ready configurations compatible with Evilginx3.

ruoyi-scan

2026-08-25 Python ★ 19
Ruoyi-Scan is a specialized vulnerability scanning tool designed for RuoYi applications, featuring a plugin-based architecture and three-state assessment (CONFIRMED / SAFE / UNKNOWN) for vulnerability status. It supports bulk scanning, multiple report formats, WAF bypass techniques, and offers enterprise-level functionalities such as API integration and a robust plugin ecosystem for various common vulnerabilities. Noteworthy capabilities include automated AI-based POC generation, extensive reporting options, and compatibility with various operating environments.

ctfbridge

2026-08-24 Python ★ 10
CTFBridge is a unified Python interface designed for seamless interaction with multiple Capture The Flag (CTF) platforms. Its notable features include auto-detection of platform types from URLs, a clean authentication flow, challenge enrichment capabilities, persistent session management, and an async-first architecture for efficient scripting and automation. The tool simplifies accessing and managing CTF challenges, submissions, and leaderboards across various platforms.

Agentic-Bug-Hunter

2026-08-24 Python ★ 4634
BugHunter is an AI-powered bug bounty toolkit designed for effective vulnerability assessment and reporting directly from the terminal. It automates the processes from reconnaissance to reporting, generating submission-ready documents for various platforms while utilizing an intelligent session management feature that retains discovered patterns across targets. This tool can operate independently without a subscription, enhancing accessibility for users in the cybersecurity domain.

hackwifi

2026-08-24 Python ★ 12
Hackwifi is a modular Python-based Wi-Fi penetration testing toolkit designed for automating tasks such as network scanning, packet capturing, deauthentication attacks, and Wi-Fi password cracking. It facilitates the identification of target networks and the extraction of handshake packets for offline password cracking, while requiring a Linux environment and necessary tools like Aircrack-ng. The tool emphasizes ethical use, necessitating proper authorization before any testing.

PwnRM

2026-08-24 Python ★ 87
PwnRM is an advanced WinRM post-exploitation tool designed for conducting authorized security assessments in Windows Active Directory environments. It features an interactive PowerShell runspace, support for various authentication methods, stealthy payload delivery, and a built-in Active Directory triage engine, enabling users to perform a wide range of assessment tasks through a command-line interface as well as via a Python library. Notable functionalities include file transfer capabilities, remote command execution, and comprehensive AD enumeration and session management features.

redteam-skill

2026-08-24 Python ★ 36
The 'redteam-skill' tool facilitates a semi-automated workflow for red teaming engagements, allowing operators to select modules that assist in penetration testing while recording findings in a `notes.md` file. It features a modular architecture encompassing various attack and reconnaissance techniques, with an emphasis on human oversight to ensure critical judgment and decision-making during operations. Notable functionalities include the automatic retrieval of previous notes and detailed process references for each module, enhancing the efficiency of security assessments.

DorkAgent

2026-08-24 Python ★ 320
DorkAgent is a LLM-powered tool designed for automated Google Dorking to assist in bug hunting and penetration testing. It allows users to retrieve and customize search results through various LLM APIs, streamlining the process of exploiting Google search vulnerabilities. Notable features include automatic package installation, dynamic model selection at runtime, and extensive customization options for search parameters.

bosectl

2026-08-23 Python ★ 41
bosectl is a command-line tool designed for controlling Bose headphones on Linux and macOS without the need for an app or cloud services. It utilizes the Bose BMAP protocol over Bluetooth RFCOMM, providing users direct access to manage features such as noise cancellation, equalization, spatial audio, button mapping, and device profiles. The tool supports various Bose devices, ensuring comprehensive customization options and functionalities.

DanyAPI

2026-08-23 Python ★ 22
DanyAPI is an OpenAI-compatible HTTP API implemented using Python and FastAPI, designed to interact with the internal APIs of free web clients, enabling users to bypass the need for paid API keys. It utilizes server-side accounts created from user-supplied tokens for chat services, allowing seamless API consumption without requiring additional authentication from end users. Notable features include ease of integration with existing fast API setups and support for multiple Python versions.

shodan_rtsp

2026-08-23 Python ★ 10
The Camera Scanner is a Python command-line tool that facilitates the discovery and assessment of publicly accessible or vulnerable cameras via integration with Shodan and Nmap scanning. Key features include command-line options to initiate searches, check a database of cameras, and perform scans over specified IP ranges, with user-configurable settings for API keys and credential wordlists. This tool is intended for educational purposes, emphasizing responsible use in cybersecurity assessments.

ip-radar

2026-08-23 Python ★ 15
IP Radar is a self-hosted threat intelligence tool that aggregates data from 29 public threat feeds to provide comprehensive IP lookups, returning a conclusive verdict with evidence, confidence scores, geographic information, and ASN details. It features a streamlined setup process requiring minimal configuration, allows for rapid deployment via Docker, and complements its user interface with real-time data updates while ensuring all queries remain local and private. Notably, it supports STIX 2.1 export for further integration with threat analysis workflows.

oxide

2026-08-23 Python ★ 10
Oxide is a cross-platform remote access trojan (RAT) framework designed for security research and detection engineering, allowing users to demonstrate and analyze threat actor tactics, techniques, and procedures (TTPs) at the code level. It includes an implant written in Rust, a C2 panel implemented in Python, and provides comprehensive detection capabilities with paired YARA rules, Sigma rules, and incident response playbooks. The framework facilitates purple team exercises through a structured approach to understanding implant-panel communications and establishing effective detection strategies.

HTLogin

2026-08-23 Python ★ 32
HTLogin is a security testing tool designed to inspect and identify vulnerabilities in login forms and authentication APIs across web applications. It comprehensively tests for common weaknesses, including default credentials, injection vulnerabilities, and rate-limiting issues, while supporting HTML forms, JSON/GraphQL APIs, and JavaScript-rendered SPAs. Notable features include confidence-based detection with detailed reporting, a CLI interface for streamlined usage, safe operational modes, and extensive integration support with proxies and testing frameworks.

cratos-fastapi

2026-08-22 Python ★ 13
Cratos FastAPI serves as a proxy API for the MISP Threat Sharing Platform, enabling the seamless extraction of threat indicators in various formats for consumption by security tools such as SIEMs, firewalls, and EDRs. Key features include tag-based feed classification, scoped access tokens for enhanced security, multi-tenancy support, and flexible output formats tailored to specific consumer requirements, facilitating efficient integration of threat intelligence into security workflows without exposing MISP credentials.

TraceTree

2026-08-22 Python ★ 42
TraceTree is an advanced autonomous security tool designed to enhance development workflows with robust detection and protection capabilities. Its primary use case revolves around analyzing packages for malicious intent through sandbox isolation, syscall parsing, and machine learning-based anomaly detection, enabling developers to maintain security before package installations. Notable features include a multi-agent coordination server, a web dashboard for monitoring, and a behavioral receipt export for summarizing observed behaviors without compromising syscall logs.

caterpillar

2026-08-22 Python ★ 39
Caterpillar is a Python library designed for the efficient packing and unpacking of structured binary data, building upon Python's native `struct` capabilities. Its primary use case is facilitating the declaration of custom data structures through Python class definitions, enabling features like dynamic endian configuration, inheritance-based struct adaptation, and the implementation of bitfields and unions. Notable functionalities include memory optimization via `__slots__`, type compliance for static checking, and extensibility for custom parsing logic written in C or C++.

ansible-security-scanner

2026-08-22 Python ★ 10
The Ansible Security Scanner is a static analysis tool designed for evaluating Ansible playbooks, roles, and related files to identify security vulnerabilities including malicious code and unauthorized access risks. It features a comprehensive reporting mechanism that generates outputs in various formats such as SARIF and CycloneDX SBOM, while providing remediation guidance and mapping findings to established security frameworks like OWASP and MITRE ATT&CK.

SimpleReconDomain

2026-08-22 Python ★ 12
Simple Recon - Domain (SRDomain) is a comprehensive tool designed for passive and active domain enumeration, primarily aimed at OSINT workflows and reconnaissance. This Python-based application incorporates 50 data sources, offering advanced features such as DNSSEC zone walking, wildcard detection, TLS certificate SAN extraction, and HTML/JS crawling, enabling users to perform thorough domain assessments with parallel processing and no external shell dependencies.

CRIMENET

2026-08-22 Python ★ 11
CRIMENET is an open-source knowledge graph that documents relationships among criminal organizations globally, leveraging multi-language Wikipedia data through a sophisticated LLM pipeline. It features a comprehensive dataset with over 4,500 organizations and nearly 11,000 relationships, all traceable to specific Wikipedia revisions, allowing for in-depth queries about criminal networks and history via a natural language interface called Ask CRIMENET AI. This tool offers the ability to explore organizational connections, historical contexts, and activity periods while ensuring information integrity through auditable sourcing.

XeroDay-APISniffer

2026-08-22 Python ★ 33
XeroDay's API Sniffer is a comprehensive toolkit designed for the discovery of exposed API keys, tokens, and other sensitive information in public GitHub repositories. It features an AI-driven workflow orchestration for natural-language requests, alongside manual execution options that enable users to conduct multi-stage discoveries and scans. Key functionalities include live scanning dashboards, adaptive query strategies for new repositories, and support for detailed querying of findings through a robust AI search engine.

BirdShot

2026-08-22 Python ★ 31
BirdShot is an offline-first CLI and local web UI tool designed to streamline and standardize hardware research workflows for lab-owned Flock devices. It enables users to organize device states, work orders, logs, and evidence collection across various research phases, ensuring repeatable and authorized testing in controlled environments. Notable features include integration with local service checks, media validation, and seamless management of related evidence within a structured framework tailored for comprehensive device and deployment research.

IndustrialXPL-Forge

2026-08-22 Python ★ 10
IndustrialXPL-Forge (IXF) is an extensive Python-based security assessment and exploitation framework designed specifically for Operational Technology (OT), Industrial Control Systems (ICS), and related environments. It encompasses the entire attack lifecycle from reconnaissance to reporting, and it features over 1,190 modular tools, support for more than 50 protocols, and extensive integration with the MITRE ATT&CK for ICS framework, along with a significant library of vulnerabilities, offering a comprehensive resource for cybersecurity professionals in the industrial sector.

lldp

2026-08-22 Python ★ 21
The lldp tool is a Mythic C2 profile designed for peer-to-peer communication utilizing IEEE 802.1AB (LLDP), allowing covert data transmission within Organizationally Specific TLVs. It operates at Layer 2, requiring agents to be within the same broadcast domain, and features customizable OUI settings for blending with vendor-specific LLDP traffic. Key functionalities include HTTP/HTTPX agent egress for bridging to the Mythic server and enhanced security through configurable encryption modes and key exchange mechanisms.

bountyforge

2026-08-22 Python ★ 405
Bountyforge is a comprehensive pentesting tool designed to facilitate automated vulnerability assessments across various platforms, including web APIs, smart contracts, and infrastructure. It employs eight parallelized security agents that systematically evaluate different attack vectors, generating deduplicated and CVSS-scored findings formatted into submission-ready reports for popular bug bounty platforms. Notable features include local tooling orchestration, multi-chain smart contract auditing, and isolated cloud pentesting environments, providing flexibility and efficiency for security professionals.

NetWatch

2026-08-21 Python ★ 11
NetWatch is a local-first visibility tool designed for IT admins and small security teams to monitor and assess changes within their authorized local networks. This tool provides a dashboard for asset discovery, TCP service exposure review, and maintaining context around significant changes, while emphasizing the importance of operating within authorized boundaries. Notable features include a repeatable workflow for local asset awareness, integration with Docker for easy deployment, and a focus on defensive visibility rather than exploitation.

anyrun-sdk

2026-08-21 Python ★ 14
The ANY.RUN SDK is a Python client library designed to interact with the ANY.RUN REST API, facilitating automated malware analysis and threat intelligence workflows. It provides features for file and URL submissions to an interactive sandbox, real-time monitoring of analysis progress, and access to comprehensive threat intelligence, including IOC searches and feeds. Notable functionalities include support for both synchronous and asynchronous operations, along with built-in exception handling and detailed reporting capabilities.

IDA-Skill

2026-08-21 Python ★ 222
IDA Skill is an AI-powered tool that enables automated malware analysis using IDA Pro, mimicking the capabilities of human security analysts. It features automatic identification of malicious behavior, code functionality understanding, key information extraction, and threat indicator localization, enhancing malware investigation efficiency. Notable components include REAI for AI function analysis and FindCrypt for detecting encryption algorithms, facilitating comprehensive and advanced threat assessment.

Arkana

2026-08-21 Python ★ 208
Arkana is a comprehensive malware analysis tool that streamlines the investigation process by integrating 308 specialized analysis tools through a single AI-driven interface. It allows users to submit natural language prompts to conduct extensive malware evaluations, including decompilation, vulnerability detection, and real-time data enrichment without switching between multiple applications. Notable features include automated risk scoring, MITRE ATT&CK mapping, and interactive debugging capabilities, all designed to enhance efficiency in analyzing PE, ELF, and other binary formats.

CyberSeek

2026-08-21 Python ★ 15
Cyberseek is a comprehensive, local threat intelligence and defensive analysis tool designed for security teams, integrating asset visibility, reconnaissance, and indicator enrichment into a unified workspace. Key features include continuous monitoring of domains and IPs, email exposure checks, and robust reporting capabilities, while it also enables the mapping of observed behaviors to the MITRE ATT&CK framework and utilizes AI for evidence-bound summaries. The tool aims to facilitate investigation workflows by preserving local task history and analyst context, enhancing operational efficiency in cybersecurity tasks.

hostagram

2026-08-21 Python ★ 145
Hostagram is an OSINT tool designed to extract and monitor extensive information from public Instagram accounts. Its primary use case is for research and analysis in the realm of social media intelligence, offering features such as user verification, email and phone number checks, and insights into follower activity. Currently in version 1.4, the tool is under active development with plans for future enhancements.

meta_scan

2026-08-21 Python ★ 47
Meta Scan is an OSINT tool designed to extract comprehensive public profile data from Facebook pages, leveraging the RapidAPI Facebook Pages Scraper. Key features include the ability to retrieve detailed information such as profile and business details, transparency data, and generate JSON reports, all while ensuring secure API key handling and a user-friendly CLI interface. The tool is intended for educational purposes and supports batch processing of usernames, enhancing its usability for researchers.

osintgpt

2026-08-21 Python ★ 525
`osintgpt` is a Python package that utilizes large language models (LLMs) to perform text analysis tasks relevant to open-source intelligence (OSINT), such as calculating text embeddings and searching for similar documents. Key features include an interactive mode for dynamic user interaction with the GPT model, SQLite database integration for efficient data management, and connectivity to the Qdrant vector similarity search engine for high-performance embedding storage and retrieval.

XingDumper

2026-08-21 Python ★ 39
XingDumper is a Python 3 script designed to extract employee data from the XING social networking platform via its unofficial API. The tool facilitates the retrieval of essential employee information such as name, position, and location using just two API calls, and it includes a feature for auto-generating email addresses based on specified formats. Users must provide a valid XING login cookie and the company URL to initiate the data dump.

Web-Security-Analizer-Pro

2026-08-21 Python ★ 19
Web Security Analyzer Pro is an advanced web security analysis tool designed for system administrators, developers, and security professionals, providing detailed examination of HTTP headers, cookies, common vulnerabilities, and SSL/TLS configuration. It operates without external queries, generating comprehensive security reports using only HTTP responses, and includes features such as CVE detection from a vast offline database, automated security scoring, and an interactive visual interface. Notable capabilities include in-depth analysis of security headers, cookie security flags, and the identification of technologies used in web applications.

SearchToolkit

2026-08-21 Python ★ 32
SearchToolkit is an advanced collection of resources designed for penetration testers, red teamers, blue teamers, and forensic analysts. It includes tools, hardware, cheatsheets, and references across various cybersecurity domains such as geolocation tracking, OSINT, malware analysis, and bug bounties. Notable features include a comprehensive navigation system for quick access to specific areas of cyber defense and offense, highlighting its utility in diverse cybersecurity tasks.

wifi-deauther

2026-08-21 Python ★ 157
The wifi-deauther tool is a Python-based application that automates deauthentication attacks to help users understand 802.11 management frame injection. Primarily intended for testing on networks with proper authorization, it allows users to select a wireless interface and target access points for deauthentication. Notable features include support for Linux systems, the necessity for a wireless card with monitor mode, and the recommendation to use two wireless cards for optimal performance.

core_net_scanner

2026-08-20 Python ★ 89
Core Net Scanner is a cross-platform Python tool designed for network discovery and open port detection on local IPv4 subnets, applicable for both personal and organizational purposes. Notable features include LAN detection, custom scanning of specific IPs or ranges, HTTP service scanning, real-time traffic inspection, and a comprehensive logging system for detailed output. This tool is specifically intended for lawful use with explicit permission from network owners, ensuring ethical and responsible operation.

yuri

2026-08-20 Python ★ 19
Yuri is a decompiler and compiler specifically designed for the Yu-Ris engine, featuring support for parallel processing. Its primary use case is facilitating the decompilation and compilation of game files from various versions of the engine, including both public and commercial releases. Notable features include tools for text extraction and translation, such as `patch_text.py` for editing dialogue in .yuri files and `gbk.py` for modifying text encoding to support Chinese translations.

metawarc

2026-08-20 Python ★ 37
Metawarc is an indexing tool that catalogs WARC collections into a versioned DuckDB database equipped with Parquet sidecars, enabling structured querying, metadata extraction, and payload export. Notable features include support for immutable source archives, atomic publication processes, typed queries accessible via CLI and REST API, and local replay capabilities similar to the Wayback Machine. The tool is designed for efficient analysis and manipulation of web archive datasets, facilitating incremental updates and recovery operations.

Consortium

2026-08-20 Python ★ 328
Consortium is a modern, extensible command and control (C2) framework that supports both asynchronous multi-client interactions and language-agnostic listener-agent designs, enabling users to develop custom agents and listeners efficiently. Key features include a robust REST API for automation, role-based access control for user management, and modular architecture that allows for extensive customization and collaboration among users. Currently in the alpha phase, the framework emphasizes a high degree of flexibility while still under rapid development.

Cybermes

2026-08-20 Python ★ 674
Cybermes is an advanced autonomous security research framework designed for offensive security tasks, including bug bounty hunting and red teaming. It features over 50 specialized modules for in-depth reconnaissance, attack surface analysis, and vulnerability validation, leveraging a unique integration of modern LLM reasoning and automated workflows. Notable capabilities include dynamic attack planning, multi-source knowledge retrieval, and programmatic validation of findings to ensure zero false positives.

safer-dependencies

2026-08-19 Python ★ 33
Safer Dependencies is a security tool designed to enhance the integrity of package installations in AI-assisted coding environments like Claude. It automatically intercepts package addition requests to perform checks for known vulnerabilities, maintainability, and risks such as typosquats, while ensuring that only safe versions are installed across multiple ecosystems including npm, PyPI, and Maven. Notable features include its proactive blocking of vulnerable installations, automatic correction of risky dependencies, and a streamlined integration that operates in the background without user intervention.

Wazuh-MCP-Server

2026-08-19 Python ★ 51
Wazuh-MCP-Server is a defensive blue team framework designed to integrate with Claude Desktop or any MCP client, serving as a complement to offensive security tools. It provides access to over 100 SOC tools, including multi-provider threat intelligence, alert enrichment, and advanced threat correlation capabilities using the MITRE framework. Notable features include a modular architecture, a variety of transport options for communication, and extensive configuration options for integrating with Wazuh SIEM and various threat intelligence sources.

agentmetry

2026-08-19 Python ★ 12
Agentmetry is an open-source endpoint flight recorder specifically designed for AI coding agents, capturing detailed logs of tool calls, approvals, and denials to provide visibility into agent actions. Its primary use case is enhancing incident response by generating a comprehensive JSONL trail and correlating events with MITRE ATT&CK tactics, issuing critical alerts when a series of actions could signify an attack. The tool can function locally on Windows and Linux machines, with optional forwarding to SIEM solutions like Loki, Elastic, Splunk, or Google SecOps for centralized monitoring.

ps-fuzz

2026-08-19 Python ★ 704
Prompt Fuzzer is an interactive security assessment tool designed for GenAI applications, evaluating the robustness of system prompts against a variety of dynamic attacks, including jailbreak and prompt injection. It adapts its testing methodology to the specific characteristics of the application, allowing for iterative improvement through a Playground chat interface. Notable features include support for multiple LLM providers, a command-line interface, and multi-threaded testing capabilities.

yaramail

2026-08-19 Python ★ 23
Yaramail is a Python tool designed for scanning emails using YARA rules, primarily aimed at automating the triage process of phishing reports. It offers comprehensive functionality that allows users to analyze all components of an email, including headers, body content in various formats (Markdown conversion), and various attachment types, while also providing customizable password options for encrypted ZIP files. Notably, Yaramail categorizes emails systematically and parses authentication results for enhanced analysis.

assemblyline-service-overpower

2026-08-19 Python ★ 10
The Assemblyline Overpower service is designed to de-obfuscate and profile PowerShell files for analytical purposes. It utilizes modified open-source tools like PSDecode and PowerShellProfiler to statically analyze scripts and extract behavioral indicators. Key features include configurable submission parameters and integration within the Assemblyline framework for streamlined deployment and operation.

helm-d

2026-08-19 Python ★ 32
helmd is a comprehensive security analysis plugin designed for the DeepSeek Harness, integrating capabilities across six domains: Android, Web, Native, Protocol, Malware, and AI-Security. This tool facilitates a streamlined installation with ten independently released bundles, enabling users to access all essential functionalities with minimal configuration while maintaining a modular architecture for on-demand knowledge and tool utilization. Notable features include first-round tool anchoring for user queries, specialized routing for domain-related tasks, and a focused referencing system that supports autonomous model decision-making.

Grok-Api

2026-08-19 Python ★ 314
Grok-Api is a deprecated Python API wrapper for Grok AI that enables users to interact with the conversational AI without needing official API credentials or accounts. This tool features a FastAPI server for RESTful access, supports HTTP proxies, and allows for high-performance, concurrent requests with streaming response capabilities. Notably, it provides both automatic and expert processing modes, though it is rendered obsolete due to changes in Grok's access policy.

DeNuitkanizator

2026-08-19 Python ★ 18
DeNuitkanizator is a utility designed for analyzing .exe files compiled with Nuitka and other packagers such as PyInstaller. Its primary use case is for reverse engineers and malware analysts, providing detailed extraction of metadata, strings, modules, and PE structure information, while also disassembling machine code and identifying potential suspicious patterns. Notably, it distinguishes between different packagers, retrieves network-related data, and analyzes the executable's PE structure, although it does not function as a decompiler.

lucasartsifier

2026-08-19 Python ★ 47
The Sierra softlock analyzer is a static analysis tool designed for decompiling and enhancing Sierra SCI adventure games by identifying and mitigating softlocks—game states where players can input commands but cannot win. It effectively derives, verifies, and installs protective guards against these non-winnable scenarios without requiring any game-specific code, allowing for seamless integration and the preservation of original game content. Notable features include automated trap detection, comprehensive scripting alterations, and customizable guard behaviors, ensuring gameplay remains normal while safeguarding against progression-blocking states.

GridSetup

2026-08-19 Python ★ 10
GRID v2 is a comprehensive local intelligence dashboard that integrates multiple capabilities for OSINT, network reconnaissance, satellite tracking, IoT, and automation, all within a single conversational interface. Its notable features include a sophisticated layered memory engine that retains knowledge across sessions, enabling efficient recall and context management, alongside over 68 built-in tools for various operational tasks, making it a versatile solution for cybersecurity professionals. Unlike competing tools, GRID uniquely combines a wide range of functionalities while operating entirely offline, ensuring user autonomy and data security.

instagrapi

2026-08-19 Python ★ 6730
instagrapi is an unofficial Instagram API wrapper for Python that facilitates fast and effective automation of various Instagram functionalities, including user interactions, media management, direct messaging, and insights retrieval. It supports session persistence and challenge handling while allowing extensive integration with both public web and private mobile API flows, making it suitable for testing, research, and controlled automation. Notable features include optional TLS impersonation support, built-in video upload capabilities, and comprehensive documentation for effective usage.

adsbtrack

2026-08-19 Python ★ 10
adsbtrack is a Python tool designed to retrieve and structure historical ADS-B flight data for any aircraft using its ICAO hex code. It facilitates comprehensive analysis by extracting individual flights, correlating takeoff and landing coordinates with airports, and evaluating flight data quality over specified date ranges, making it particularly useful for OSINT and aviation enthusiasts seeking detailed insights into aircraft travel patterns. Notable features include multi-network data retrieval, flight quality classifications, and the ability to analyze signal gaps and generate routing fingerprints.

PhantomTap

2026-08-19 Python ★ 18
PhantomTap is a machine learning-enhanced tool for the Flipper Zero, specifically designed for RFID/NFC fuzzing and access-control auditing. It utilizes active learning to intelligently generate test credentials, significantly reducing the number of reader queries required for effective security assessments, and produces an explainable audit report for identifying vulnerabilities in badge systems. Notably, it features efficient characterization, Bayesian population sizing, and integrates detection mechanisms to monitor real-time security threats.

py-gitguardian

2026-08-18 Python ★ 89
py-gitguardian is a Python client library for the GitGuardian API, designed to detect over 200 types of secrets and potential security vulnerabilities in various text contents. It enables developers to integrate scanning capabilities into their applications, whether scanning individual files, entire codebases, or content from chat applications. Notable features include the ability to perform multi-file scans, handle API responses, and easily convert results to JSON or dictionaries for further processing.

smbscan

2026-08-18 Python ★ 50
SMBScan is a tool designed for enumerating file shares on internal networks, allowing users to scan either a single target or a range of targets. Notable features include the capability to identify potentially sensitive files, support for guest and domain user authentication, and tactics to minimize detection by security teams. Additionally, it generates log files for comprehensive output analysis following scans.

xrefer

2026-08-18 Python ★ 321
XRefer is a Python plugin for the IDA Pro disassembler that enhances binary analysis through a custom navigation interface. It clusters related functions, highlights execution paths, and integrates external data sources to provide context-rich path graphs, significantly speeding up manual static analysis. Notable features include LLM integration for generating natural language descriptions of code relationships and the ability to incorporate API traces and custom xrefs for improved insights.

discord-badge-spoofer

2026-08-18 Python ★ 46
The Discord Badge Spoofer is a tool designed to artificially inflate the "hours played" and "games played" badges on Discord profiles by sending spoofed game events to Discord's analytics endpoint. This experimental Python application requires user authentication, including an account token and a cookie, to simulate playtime through commands for claiming hours and marking games as played. Notably, while the tool can track playtime without additional setup, the games-played count necessitates a legitimate executable fingerprint obtained from the user's own client, emphasizing its experimental nature and potential violation of Discord's terms of service.

beosound5c

2026-08-18 Python ★ 25
BeoSound 5c is a software tool that modernizes the Bang & Olufsen BeoSound 5 experience by utilizing web technologies on a Raspberry Pi 5. It features a circular arc-based touch UI and integrates with various music services and devices, offering seamless remote control, configuration options, and support for legacy hardware like the original BS5 rotary encoder and display. Additionally, it incorporates a security model that ensures a trusted home network environment and protects sensitive configuration data.

IG-Detective

2026-08-18 Python ★ 154
IG-Detective is a Python-based Open Source Intelligence (OSINT) tool designed for in-depth analysis of Instagram accounts, enabling users to extract location history, map social interactions, and generate automated reports. Notable features include advanced evasion techniques for stealthy data collection, interactive geospatial mapping, and various forensic modules such as account recovery enumeration and engagement audits. The tool optimizes performance with asynchronous data export and intelligent caching for efficient query handling.

MetaView

2026-08-18 Python ★ 10
MetaView is a web-based interface for the Metasploit Framework that provides multi-user support and an intuitive user interface built on Vue3. Its primary use case is to facilitate project management and data visualization within penetration testing, enabling users to manage workspaces, visualize database entries such as hosts and vulnerabilities, and generate live dashboards. Notable features include integration with external tools (like MaxPatrol and Nmap), role-based access control, and task management functionalities.

getsploit

2026-08-18 Python ★ 1815
Getsploit is a tool designed for searching and downloading public exploits from the Vulners database, facilitating both online searches and fully offline operations via a local SQLite index. Its notable features include a comprehensive query capability across multiple exploit collections, local query support without internet connectivity, and robust JSON and tab-separated output formats, all while maintaining data privacy and integrity. The tool is compatible with Python 3.11 and above, ensuring reliable performance across various platforms.

certi

2026-08-17 Python ★ 10
Certi is a Python-based tool designed for monitoring SSL Transparency logs, aiding users in tracking their issued certificates across multiple domains. Its primary features include domain monitoring with alert notifications through various channels (enabled by Apprise), and a REST API for managing domains, thus enhancing the security and oversight of SSL certificates. Utilizing frameworks like FastAPI and Loguru, Certi provides a structured approach to certificate log analysis for both organizations and individuals.

codescan

2026-08-17 Python ★ 65
CodeScanAI is a security analysis tool that leverages AI models to scan codebases for vulnerabilities and offers actionable remediation suggestions. It supports multiple AI providers, including OpenAI and Google Gemini, and integrates seamlessly into CI/CD pipelines, allowing for full directory scans, targeted scans on changed files, and inline PR review comments. Notable features include diff-aware analysis for pull requests and flexible scanning options to enhance security throughout the development process.

xaidr

2026-08-17 Python ★ 26
`xaidr` is a runtime security tool designed for AI agents that operates in-process with zero dependencies. It inspects agent interactions—input, tool calls, output, and inter-agent communications—to detect and prevent various security threats like prompt injection and unauthorized actions in real-time. The tool features a monitoring mode for assessment, a blocking mode for enforcement, and can emit structured telemetry to existing systems without requiring a network connection.

Galaxy-Book4-Edge-linux

2026-08-17 Python ★ 72
The Galaxy-Book4-Edge-linux repository focuses on reverse-engineering and providing Linux support for the Samsung Galaxy Book4 Edge, particularly enhancing features such as battery reporting and thermal management through the ENE KB9058 embedded controller. Notable features include the development of a custom battery driver and tools for fan control, alongside pre-built ISOs for easier setup and manual driver installations for existing Linux users. The project offers comprehensive documentation on the reverse-engineering process, making it a valuable resource for developers working with this ARM64 platform.

hik-qr-export

2026-08-17 Python ★ 27
HikVision QR Export is a tool designed to decode and renew QR code data associated with Hik-Connect applications, specifically for extracting metadata and stored device information from QR codes generated for HikVision cameras. Its notable features include the ability to read QR code images directly from the macOS clipboard and the option to recover forgotten export passwords without the need for a static encryption key. This utility is valuable for users seeking access to their camera configurations after password loss.

steam-osint

2026-08-17 Python ★ 98
Steam OSINT is an open-source intelligence tool specifically designed for analyzing public Steam profile data. It facilitates the discovery of mutual friends, identifies hidden relationships, and retrieves historical account information like previous usernames and URLs, making it a valuable resource for OSINT researchers and cybersecurity professionals. Notable features include a command-line interface, cross-platform support, and capabilities for uncovering connections beyond the Steam platform.

cc-tree

2026-08-17 Python ★ 161
cc-tree is a Claude Code plugin designed to transform open-ended thinking tasks into structured phylogenetic trees for easier auditing and exploration. It features a universal radial-tree exploration engine with four distinct presets—divergent brainstorming, adversarial critique, design-space exploration, and code audit—utilizing a disciplined approach where every generated node includes detailed evidence for its derivation. The tool emphasizes substantive convergence over arbitrary thresholds, ensuring that only high-value findings are further explored and represented in the tree structure.

tiktok-signature

2026-08-16 Python ★ 11
The TikTok Signature Generator is a Python tool designed to create valid signatures for TikTok Web API requests, specifically **X-Gnarly**, **X-Bogus**, and **X-Dynosaur** signatures. It features support for SDK version 5.1.2 and employs advanced encryption and hashing algorithms, including ChaCha20 and RC4, to ensure secure and dynamic signature generation. This lightweight and production-ready implementation is tailored for developers seeking to interact with the TikTok API effectively.

MassAcre

2026-08-16 Python ★ 10
MassAcre is a tool designed to exploit a zero-day vulnerability in the masscan banner scanning utility, causing it to enter an infinite loop and consume 100% CPU by sending a specially crafted TLS handshake record. Its primary use case is to demonstrate a remote, unauthenticated Denial of Service (DoS) attack that stalls the banner processing of masscan, leading to lost scan results. Notably, the attack is executed with a minimal payload and targets a specific flaw in masscan's certificate handling logic.

MikuCffHelper

2026-08-16 Python ★ 42
MikuCffHelper is a Binary Ninja plugin designed to deobfuscate binaries that utilize OLLVM-style control flow flattening (CFF). It employs static analysis techniques to identify dispatcher subgraphs and simulates state variables, offering two primary deobfuscation paths: a recommendation for the 'synthesize_switch' approach that preserves the dispatcher as a switch-case structure and an alternative 'deflate_hard' method that bypasses the dispatcher entirely. The tool significantly reduces High-Level Intermediate Language (HLIL) line counts, with half of the tested functions showing a decrease of 20-59% without losing any side effects.

CLI-Anything-WEB

2026-08-16 Python ★ 214
CLI-Anything-Web is a tool that transforms any website into a production-ready command-line interface (CLI) by capturing its live HTTP traffic. It is primarily used for generating Python CLIs for web applications that lack public APIs, featuring capabilities such as authentication handling, a REPL mode, JSON output, and built-in tests. Designed for prototyping and automation, this tool eliminates the need for manual reverse-engineering by automatically generating CLI interactions based on live traffic data.

medc17-checksum-tool

2026-08-16 Python ★ 47
The MEDC17 Checksum Tool is a specialized software designed to analyze and correct checksums for Bosch MED17 and EDC17 ECU firmware binaries, supporting CRC32, ADD32, and ADD16 algorithms. Notable features include automatic block detection, instant CRC32 solving via GF(2) matrix algebra, RSA signature forging, and calibration verification number (CVN) correction, all while ensuring safe operation by preserving original files. The tool is implemented in Python and offers both command-line and web-based usage options for convenience.

revula

2026-08-16 Python ★ 72
Revula is a production-grade MCP server designed for universal reverse engineering automation, facilitating connections between various compatible IDEs and custom tooling to an extensive reverse engineering backend through the Model Context Protocol. Its primary use case focuses on both static and dynamic analysis, featuring a robust suite of over 70 tools including binary parsing, disassembly, decompilation, and exploit development, alongside comprehensive support for Android reverse engineering and traffic interception capabilities. Additionally, Revula offers integration with numerous clients, enhanced debugging support, and a versatile configuration model, making it suitable for advanced security analysis and vulnerability research.

insta-dl

2026-08-16 Python ★ 14
insta-dl is an asynchronous command-line tool designed for downloading Instagram content, such as profiles, posts, reels, stories, and comments, while preserving the original timestamps. It features two backend options, HikerAPI for safe use without a login and an optional private API, along with capabilities for incremental updates, JSON metadata storage, and versatile input formats. This tool is optimal for users seeking to archive Instagram content without the risk of account bans associated with traditional scraping methods.

OSINT-NEXUS

2026-08-16 Python ★ 42
OSINT-Nexus is an open-source intelligence platform designed for security researchers, penetration testers, and intelligence analysts, integrating passive reconnaissance tools with AI-driven analysis. Notable features include advanced graph analytics, interactive visualizations, and AI-powered insights using Google Gemini, along with robust reporting capabilities in multiple formats. This cross-platform tool supports Windows and Linux, making it a versatile resource for gathering actionable intelligence from publicly available data.

whatslookup

2026-08-16 Python ★ 130
WHATS LOOKUP is an OSINT tool designed for gathering various types of user information from WhatsApp accounts, including profile pictures, business account verification, user status, linked device analysis, and privacy settings. It supports six API endpoints and features an interactive terminal interface, automated image saving, and international number format validation. This tool is intended for legitimate cybersecurity investigations and requires integration with the WhatsApp OSINT API on RapidAPI.

world-intel-mcp

2026-08-16 Python ★ 596
The World Intelligence MCP Server provides real-time global intelligence across over 30 domains by integrating 120 tools compatible with the Model Context Protocol. It features a live ops-center dashboard and a Qdrant vector store for efficient semantic search, allowing users to query historical data on various subjects such as military activity, cyber threats, and economic indicators using natural language. This tool is particularly beneficial for AI agents requiring comprehensive world awareness without reliance on paid data subscriptions.

CVE-2026-9830

2026-08-16 Python ★ 394
The CVE-2026-9830 tool is a Python-based proof of concept designed for assessing the unauthenticated exposure of the BookingPress Pro REST API in WordPress installations. It enables authorized users to validate potential vulnerabilities by normalizing target URLs, checking API endpoints for sensitive data exposure, and providing configurable options such as timeouts and filtering. Notable features include the ability to save API responses to JSON files while emphasizing the responsible handling of personal data in compliance with authorized assessment protocols.

HEAVEN-Autonomous-Penetration-Testing

2026-08-16 Python ★ 88
HEAVEN is an autonomous penetration-testing framework designed to streamline and automate various stages of the penetration testing process, including reconnaissance, vulnerability detection, exploitation, risk scoring via machine learning, and reporting. It features a robust interface with 55 CLI commands, 77 API routes, and multiple scan modes, facilitating comprehensive assessments while allowing users to focus on critical decision-making tasks. Notably, it incorporates a CVSS machine learning predictor with a high correlation score, ensuring accurate risk evaluation.

ExploiterX

2026-08-16 Python ★ 16
ExploiterX 3.0 is an enterprise-grade web vulnerability scanner designed for security professionals and developers, capable of detecting a wide range of vulnerabilities including XSS, SQL Injection, and CSRF. Its notable features include advanced scanning capabilities with over 20 XSS payload variants, concurrency support for parallel scanning, intelligent HTML form parsing, and comprehensive reporting in multiple formats. Additionally, the tool emphasizes resilience with built-in retry mechanisms, robust error handling, and secure reporting to prevent common security vulnerabilities in output.

trustsight

2026-08-15 Python ★ 14
TrustSight is a security auditing tool designed for Arch Linux that inspects AUR PKGBUILD updates prior to installation. It identifies structural changes, malicious commands, and typosquatting while generating a deterministic evidence report that traces findings to specific diffs, URLs, or novelty records. Notable features include local analysis without executing commands, a reputation-based novelty detection model, and a structured output to enhance transparency in the auditing process.

Aivist-Verify

2026-08-15 Python ★ 13
Aivist Verify is an access-control confirmation engine designed to eliminate false positives in testing for Broken Object Level Access (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities. It utilizes a dual approach where an AI model proposes potential vulnerabilities based on traffic analysis, while deterministic code gates decisively validate these findings, ensuring that only fully verified threats are reported. Notably, Aivist Verify guarantees zero false positives, supported by a reproducible evidence chain that enhances the reliability of its outcomes.

docker-packing-box

2026-08-15 Python ★ 66
Packing Box is a Docker container that offers a command-line interface (CLI) environment designed for the static detection of executable packing. It integrates various executable analyzers, packing detectors, and tools for generating datasets, specifically tailored for evaluating detection techniques and automating machine learning pipelines involving packed and unpacked executables across different formats such as PE, ELF, and Mach-O. The toolkit features a user-friendly YAML configuration system, enabling straightforward customization for research evaluations and model training.

VSphereRansomwareRecovery

2026-08-15 Python ★ 10
The VSphereRansomwareRecovery tool provides a recovery solution for virtual machines affected by Babuk-family ransomware on ESXi hosts. It facilitates the restoration of virtual disks ending in `.babyk` through partition table rebuilding and file system recovery, ensuring minimal data loss in the process. Notable features include the capability to leverage AI agents for automated recovery steps and the assurance of recovering readable data from the majority of affected disk space.

SYNINT

2026-08-15 Python ★ 58
SYNINT: Agentic OSINT & Intelligence Framework – Modular, Stealthy, API-Free, Multi-Agent System for Automated Intelligence Collection & Analysis.

wmn-docker

2026-08-15 Python ★ 19
WMN-Docker is a containerized API wrapper for the WhatsMyName (WMN) tool, designed to facilitate username discovery on websites within an OSINT framework. Notable features include JWT authentication for secure access, the ability to perform individual or batch username lookups, cached job results for performance, and built-in API documentation. This tool aims to enhance integration, modularity, and scalability for users involved in online investigative tasks.

vulnerability-poc

2026-08-15 Python ★ 59
The Vulnerability PoC Repository offers curated Proof-of-Concept code, test labs, and prevention rules targeting high-severity CVEs for authorized security testing, penetration testing, CTF challenges, and security research. Key features include detection-only PoC scripts, Docker test labs with both vulnerable and patched applications, and bilingual documentation in English and Korean, ensuring comprehensive resources for cybersecurity professionals.

Auto_JB_APE

2026-08-15 Python ★ 13
jb_ape is an automated red-team engine designed to perform security assessments by probing target defenses, generating and mutating attack payloads through browser or API interfaces. It features a unique three-tier judgment system that ensures machine-verified outcomes for every attempt, employs a controlled submission budget to enhance efficiency, and utilizes reinforcement learning techniques to optimize the attack strategy while avoiding guessing. This tool is intended strictly for authorized use in sanctioned environments such as penetration testing or capture-the-flag competitions.

nexus-redfox

2026-08-14 Python ★ 12
NEXUS REDFOX is a local-first codebase intelligence and security analysis tool designed to assist developers and security teams in understanding software projects by inspecting source code and dependencies without cloud reliance. It features comprehensive deterministic security scanning, architecture graph generation, and detailed reporting capabilities, enabling users to identify vulnerabilities, map project structures, and generate software bills of materials effectively. Notable functionalities include a local web dashboard, deterministic analysis, and integration with an optional AI analysis component, all aimed at enhancing developer security and project integrity.

dewolf

2026-08-14 Python ★ 235
dewolf is a research-oriented decompiler designed as a plugin for Binary Ninja, allowing users to decompile binaries into a more understandable format using its Medium-Level intermediate language. Primarily targeted at software researchers and security analysts, dewolf offers both GUI and command-line interfaces for inspecting decompiled code. Notable features include caching of decompiled code, function navigation within the GUI, and automatic decompilation toggling, though it remains a prototype with potential bugs and optimization limitations.

openqore

2026-08-14 Python ★ 33
OpenQore is an open-source toolkit designed for patching, modifying, and enhancing the firmware of Soundcore Q-series headphones, with plans to extend support to additional models. The project encompasses a patcher for the stock firmware and an SDK tailored for headphones utilizing the bes2300p SoC, featuring functionalities such as unlocking audio support and implementing customizable firmware patches. It is a work in progress, reflecting a personal learning journey in hardware reverse-engineering and embedded systems, with community contributions encouraged.

Naminter

2026-08-14 Python ★ 48
Naminter is a Python-based tool designed for asynchronous OSINT username enumeration utilizing the extensive WhatsMyName dataset. Its primary use case is to efficiently enumerate usernames across a multitude of websites with features such as browser impersonation and customizable filtering options, functioning seamlessly as both a command-line interface and a library for integration in Python applications.

stellar-threatnet-app

2026-08-14 Python ★ 10
Stellar ThreatNet is an open-source, decentralized threat intelligence platform designed for the Stellar blockchain ecosystem, focusing on enhancing Web3 security. It addresses threats such as phishing domains and malicious tokens by providing a robust reputation scoring system, community-driven moderation, and real-time validation of threat indicators, all anchored on the Stellar ledger for zero-trust validation. Notable features include a high-performance automated threat ingestion system, comprehensive developer SDK integrations, and community engagement functionalities.

A-Pythonic-Keylogger

2026-08-14 Python ★ 28
The A-Pythonic-Keylogger is a Python-based keylogger designed for educational purposes that captures keystrokes, logs them to a local file, and can send the logs via email. Notable features include robust email retry handling, automatic session restart after key capture, and platform compatibility with both Linux and Windows. The tool incorporates local log management by clearing logs after the session ends, ensuring data retention only during active capture.

redcell

2026-08-14 Python ★ 75
REDCELL is an advanced penetration testing platform that utilizes AI agents to execute automated tests and generate comprehensive reports. It features a multi-agent orchestration system, real-time execution of offensive tools within a Dockerized Kali environment, and integrates pluggable language models for enhanced automation. Notable capabilities include live monitoring of agent activity, interactive terminal access to reverse shells, structured tool outputs, and seamless network pivoting for deeper exploitation.

assisted-log-enabler-for-aws

2026-08-13 Python ★ 276
Assisted Log Enabler for AWS automates the activation of logging for various AWS services to aid customers in maintaining compliance and troubleshooting. It identifies resources without logging enabled and facilitates the setup of essential logs including Amazon VPC Flow Logs, AWS CloudTrail, and others, thus eliminating the need for users to have in-depth expertise in log management. Key features include support for both single and multi-account setups using AWS Organizations, the creation of necessary S3 buckets, and the capability to enable logging during security incidents.

PyPCAPKit

2026-08-13 Python ★ 264
PyPCAPKit is an open-source Python library designed for comprehensive network packet parsing and analysis, enabling users to extract, construct, and analyze PCAP files with detailed insights into packet structures. Its notable features include support for various extraction engines, a user-friendly interface, and a modular design that encompasses interface management, protocol handling, and utility functions, making it a robust tool for network analysis. While it operates with moderate extraction speed compared to some competitors, its comprehensiveness and extensibility position it as a powerful option for network specialists.

assemblyline-docker-compose

2026-08-13 Python ★ 17
Assemblyline Docker Compose is a tool that facilitates the deployment of the Assemblyline 4 framework using Docker Compose, allowing users to easily set up a scalable and customizable environment for malware analysis. Its primary use case includes providing varied deployment profiles such as minimal, full, and archive setups, enabling users to tailor the system's capabilities according to specific requirements, including metrics collection and logging. Notable features include flexibility in configuring profiles, self-signed certificate generation for secure communication, and comprehensive documentation for streamlined installation and setup.

reverse-engineering-agent

2026-08-13 Python ★ 10
Reverse Engineering Agent is an autonomous system designed to analyze and reverse engineer binary challenges using both static and dynamic analysis techniques. It features a multi-agent architecture for executing tasks and self-correcting mechanisms to refine the analysis process, along with support for various large language model providers for enhanced reasoning capabilities. The tool integrates GDB for dynamic program inspection and utilizes `pexpect` for interactive binary analysis, making it suitable for effectively tackling complex crackme challenges.

metaai-api

2026-08-13 Python ★ 92
metaai-api is an unofficial Python SDK and API server designed to interact with Meta AI, enabling users to generate images from text prompts, engage in chat conversations using Llama, and manage their interactions. This tool leverages cookie-based authentication, eliminating the need for API keys, and incorporates browser automation for image generation and prompt submissions, while also providing REST API server capabilities for broader integration. Notable features include support for multiple chat modes, media fetching by card ID, and a straightforward setup process.

binsync

2026-08-13 Python ★ 745
BinSync is a collaborative decompiler tool that integrates with Git to facilitate fine-grained reverse engineering across multiple decompilers, enabling users to share and synchronize Reverse Engineering Artifacts (REAs) such as function headers, stack variables, structs, enums, and comments. Notable features include support for multiple decompilers, installation via Python, and enhanced functionalities for chat and artifact syncing, tailored for environments like IDA Pro, Binary Ninja, angr-management, and Ghidra. The tool's design fosters seamless collaboration among reverse engineers, making it easier to maintain consistency in shared analysis.

bitwig-nitro-tools

2026-08-13 Python ★ 22
Bitwig Nitro Tools is an offline reverse-engineering toolchain specifically designed for the Nitro DSP format used in Bitwig Studio. It facilitates the decryption, decompilation, parsing, editing, and re-serialization of native devices and Grid modules, allowing users to comprehensively analyze and modify the digital signal processing behind each module. Key features include the ability to extract keys from the user's Bitwig installation, decompile modules into readable pseudo-source format, and repack modified modules without altering their byte structure, ensuring a seamless editing experience.

game-patches

2026-08-13 Python ★ 600
Game patches for the Xenia emulator

LTSDM_hack

2026-08-13 Python ★ 34
The LTSDM hack repository provides a framework for reverse engineering the Little Tikes Story Dream Machine cartridges, enabling users to create custom stories through extensive cartridge data analysis and extraction techniques. Key features include cartridge dumping workflows, audio pipeline experiments, and detailed hardware documentation to facilitate the modification process. This project is currently a work in progress aimed at legal modding and educational use only.

McAFuse

2026-08-13 Python ★ 19
McAFuse is an open-source utility designed for the Digital Forensics and Incident Response (DFIR) community to handle encrypted disk images created with the McAfee Full Disk Encryption (FDE) toolset. The tool provides a static read-only FUSE filesystem, allowing users to access both a plain FAT partition and the encrypted disk image, facilitating the analysis of encrypted data during digital investigations. Notable features include the ability to specify a keyfile for decryption, options for verbose output, and functionality to expose all disk contents beyond just the encrypted volumes.

redteam-ai-benchmark

2026-08-13 Python ★ 17
Red Team AI Benchmark is a command-line interface tool designed to evaluate large language models (LLMs) in terms of their understanding and response quality regarding red-team-related questions and scenarios. It employs a rubric-based dataset for comprehensive assessment over 60 domain-specific questions, providing detailed metrics such as refusal rate and lexical coverage to ensure robust evaluation without executing any model outputs or engaging in any red-team activities. This tool primarily aids researchers and practitioners in assessing LLM capabilities in security contexts, with results intended for authorized use only.

pentestkit

2026-08-13 Python ★ 40
Pentestkit is a sophisticated, multi-agent penetration testing framework that utilizes the Claude Agent SDK to orchestrate a team of specialized agents. The tool excels in automating the penetration testing process by exploiting vulnerabilities, scoring them using CVSS v3.1, and generating comprehensive client-ready reports, all while accumulating knowledge in a shared database. Notable features include its ability to perform real exploitation of findings and a robust scoring system that achieved a perfect 104/104 on the XBOW benchmark suite.

A_Pythonic-Keylogger

2026-08-13 Python ★ 24
This tool is a Python-based keylogger designed for educational purposes, capable of capturing keystrokes and sending the recorded logs via email. It features local log management, an email retry mechanism for reliable delivery, and automatic startup configurations for both Linux and Windows systems. Users are cautioned to run the script only on systems they own or have explicit permission to test, as it demonstrates sensitive functionality.

HunterX

2026-08-13 Python ★ 13
HunterX is an AI-assisted offensive security engine designed for conducting authorized security assessments, integrating tools for reconnaissance, hypothesis-driven investigation, vulnerability validation, and professional reporting into a unified workflow. Unlike traditional vulnerability scanners, HunterX emphasizes thorough investigation and validation, ensuring that findings are evidence-based and report-ready. Notable features include AI-assisted reasoning, proof of concept engineering, and capabilities for reproducibility and impact assessment, enhancing the reliability of security assessments.

gakido

2026-08-12 Python ★ 23
Gakido is a high-performance CPython HTTP client designed for browser impersonation, anti-bot evasion, and enhanced speed. It supports multiple protocols including HTTP/1.1, HTTP/2, and HTTP/3 (QUIC), and includes notable features such as 96 browser profiles, automatic content compression, TLS overrides, and both synchronous and asynchronous operation modes, along with multipart upload capabilities and proxy support. Additionally, Gakido offers built-in retry functionality with exponential backoff to handle transient failures effectively.

secpipw

2026-08-12 Python ★ 14
secpipw is an open-source Python package designed to enhance supply-chain security during package installation by acting as a safer wrapper around the standard pip command. It analyzes and mitigates supply-chain risks when installing packages, allowing users to use `spip install` as a drop-in replacement for `pip install` while still supporting additional package managers like pipx and poetry. This tool does not require configuration, aiming for ease of use while providing comprehensive checks against potentially malicious packages.

TerraSecure

2026-08-12 Python ★ 10
TerraSecure is an ML-powered Infrastructure as Code (IaC) security scanner designed to identify cloud misconfigurations in Terraform and HCL files at build time, effectively preventing potential breaches. It employs a pre-trained XGBoost model that delivers 92.45% accuracy with a significantly lower false positive rate of 10.71%, offering context and remediation guidance based on real-world breach data. Notable features include a hybrid detection approach that integrates a rules engine, machine learning, and AI analysis to provide actionable insights for developers.

DeepSafe

2026-08-12 Python ★ 53
DeepSafe is an all-in-one safety evaluation toolkit designed specifically for large language models (LLMs) and multimodal language models (MLLMs), integrating over 25 safety datasets along with the ProGuard evaluation model for comprehensive assessments. Its modular architecture allows for extensive customization and rapid integration of new components, promoting a streamlined, automated evaluation process that generates detailed reports to enhance AI safety research. Key features include a configuration-driven approach, facilitating user-friendly YAML-based execution and in-depth analysis capabilities, aimed at positioning itself as a significant tool in the construction of trustworthy AI systems.

ai_for_the_win

2026-08-12 Python ★ 158
AI for the Win is a hands-on training platform designed for security practitioners to develop AI-powered tools specifically for threat detection, incident response, and security automation. It features over 50 labs, including capstone projects and CTF challenges, focusing on practical applications such as phishing detection and security log analysis using advanced algorithms like Random Forest and LLMs. The platform also offers a Docker lab environment, sample datasets, and solution walkthroughs to facilitate immersive learning experiences.

assemblyline-core

2026-08-12 Python ★ 21
Assemblyline 4 - Core is a foundational service suite designed to manage and process submissions in cybersecurity workflows. Its primary use case lies in orchestrating various tasks such as alerting, archiving, dispatching, and managing service loads dynamically. Notable features include a scalable architecture, automated expiry handling, and comprehensive metrics generation to ensure effective monitoring and management of cybersecurity operations.

assemblyline-ui

2026-08-12 Python ★ 21
Assemblyline UI is a component of the Assemblyline 4 framework that provides a user interface along with various APIs and SocketIO endpoints for interaction and data retrieval. Its primary use case is to facilitate real-time information exchange about system alerts, submissions, and overall health through a consistent JSON output format. Notable features include a comprehensive set of APIs for data access and live updates via SocketIO for seamless user notifications.

assemblyline-v4-service

2026-08-12 Python ★ 16
Assemblyline 4 - Service Base provides the foundational functionality for developing services within the Assemblyline 4 framework, facilitating the creation of new services via a provided template. Notable features include various image variants for stable and development builds, along with comprehensive documentation to guide service development. This tool is primarily utilized by developers looking to extend the capabilities of the Assemblyline platform in cybersecurity contexts.

malzoo

2026-08-12 Python ★ 95
MalZoo is a mass static malware analysis tool designed to catalog malware samples by storing metadata in a MongoDB database and organizing samples into a directory structure based on their MD5 hashes. Its primary use cases include analyzing large sets of malware for insights (such as identifying compilation languages and packers) and monitoring emails for malicious attachments. Notable features include support for Docker and AWS Serverless deployment, extensive data collection capabilities, and integration options with tools like Splunk for enhanced analysis and visualization.

melitta-barista-ha

2026-08-12 Python ★ 12
The Melitta Barista & Nivona for Home Assistant is a custom integration that enables the control of Melitta Barista T/TS Smart and various Nivona coffee machines via Bluetooth Low Energy (BLE) within the Home Assistant ecosystem. It allows users to monitor machine status, manage brewing recipes, adjust settings, and perform maintenance tasks through a unified dashboard, with additional features like an AI Coffee Sommelier for recipe generation accessible via conversation agents. The tool supports multiple languages and is designed to streamline the coffee-making experience through automation and integration with smart home setups.

Noctyra

2026-08-12 Python ★ 17
Noctyra is an AST-based Python framework for code transformation and deobfuscation, offering a modular pipeline that simplifies complex expressions and logic in Python source code. Key features include the ability to resolve static values, unroll dynamic execution blocks, and optimize obfuscated constructs through a sequence of pluggable transformers. Designed for flexibility, it facilitates the analysis and processing of Python code while emphasizing the importance of running untrusted code in isolated environments for security.

room-server

2026-08-12 Python ★ 37
room-server is a server implementation designed to facilitate connectivity for the Wii no Ma platform. It primarily serves as a backend solution for users seeking to self-host the service, enabling enhanced multiplayer interaction and community features. Notable features include flexible self-hosting options and an open contribution policy that promotes collaborative development.

AIDebug

2026-08-12 Python ★ 10
AIDebug is a command-line interface and terminal UI tool designed for malware reverse engineering, emphasizing evidence collection and analysis. Its primary use case involves deterministic offline triage of PE and ELF files, whole-file hex inspection, and in-depth structure analysis with features such as Ghidra-backed reconstruction and local ELF debugging, while also offering optional integration with large language models for enhanced review capabilities. Notable functionalities include paged hex viewing, customizable output formats for analyst reviews, and a robust history tracking system for SHA-256 indexed analyses.

blackbox-re-agent

2026-08-12 Python ★ 35
Revagent is a black-box program analysis agent that leverages natural language processing to automate reverse engineering tasks across various file formats, including APKs, firmware, and executable binaries. Users can query the agent directly for insights, bypassing manual command inputs, while it dynamically assembles the necessary tools for tasks like unpacking, disassembly, and reporting findings. Notable features include support for Android and automotive firmware analysis, as well as a unified interface for interacting with different artifact types through a single command.

CanLab

2026-08-12 Python ★ 79
CanLab is a comprehensive reverse-engineering workstation for CAN bus data, designed to facilitate the analysis, diagnostics, and modification of automotive communication protocols. It features a user-friendly PyQt6 interface that supports loading and inspecting CAN frames, running offline analyses, and utilizing AI assistance for interpreting IDs. Notable capabilities include DBC building and export, diagnostic protocol support, signal injection and fuzzing, as well as built-in safety mechanisms to prevent accidental misuse in live vehicle environments.

UtechSmart-Venus-Pro-Linux-MMO-Mouse-Utility

2026-08-12 Python ★ 20
The UtechSmart Venus Pro Config utility is a reverse-engineered configuration tool for the UtechSmart Venus Pro MMO gaming mouse, specifically designed for Linux users. It allows for comprehensive device configuration, including button remapping, macro management, DPI adjustment, and RGB lighting customization, all without the need for Windows software. Notable features include a macro engine, battery monitoring, and a user-friendly interface that adapts to connected devices, ensuring effective management of mouse functionalities.

floss-toolbox

2026-08-12 Python ★ 27
The FLOSS Toolbox is a multi-language utility designed to assist developers in maintaining clean projects within GitHub organizations. It features a variety of scripts for automating tasks such as data scraping from Git logs, interfacing with GitHub and GitLab APIs, managing license inventories, and generating documentation. The primary use case is to enhance code quality and streamline project management through efficient file processing and automation using Shell, Ruby, Python, and PHP.

ghost

2026-08-12 Python ★ 11
GHOST is an AI-powered OSINT investigation platform designed for automated intelligence gathering using various data vectors such as names, emails, and images. It offers notable features like AI-driven correlation, extensive reporting capabilities in HTML/PDF formats, and a web dashboard with graphical representations of data, enabling users to conduct thorough investigations efficiently. GHOST supports multiple platforms and provides tools for dark web monitoring, social media analysis, and entity resolution, all while being open source and cost-free.

Spiderfoot-local-data-module

2026-08-12 Python ★ 11
The Spiderfoot-local-data-module enhances the Spiderfoot reconnaissance tool by enabling it to search through locally stored databases for leaked and breached data. It allows users to specify the full paths of datasets and automatically scans for relevant information during Spiderfoot operations, reporting any findings with file names and content. Notable features include support for multiple data files and the ability to configure what types of data to search for, with potential performance improvements suggested through integration with tools like ripgrep.

findcdn

2026-08-12 Python ★ 123
findcdn is a Python-based tool designed to scan domains to identify the Content Distribution Network (CDN) they utilize. Its primary use case includes providing actionable insights regarding CDN usage for security assessments or operational purposes, with features that allow output to files, invocation as a module, and customizable processing options such as threading and user-agent specification. The tool supports multiple domains and offers verbose output for enhanced monitoring and analysis.

web-of-flaws

2026-08-12 Python ★ 18
Web of Flaws is a Markdown-based catalog that identifies vulnerable web patterns alongside safer alternatives, aimed at both developers and automated tools. Its primary use case is to educate users on exploitable vulnerabilities and provide concrete code examples for remediation, organized by security topics and vulnerability families. Notable features include detailed guides that explain risky patterns and their fix implementations.

ai-scraping-defense

2026-08-11 Python ★ 12
AI Scraping Defense is a robust microservice-based system designed to protect web applications from advanced AI-driven scrapers and bot attacks. It features a layered defense approach utilizing Nginx, Lua, and Python microservices, along with tools for intelligent traffic analysis and machine learning integration, allowing for flexible defense mechanisms. Notable features include adaptive rate limiting, active countermeasures like a Tarpit API, optional CAPTCHA verification, and a community blocklist service, making it a versatile solution for modern web security challenges.

precli

2026-08-11 Python ★ 27
Precli is a command line interface designed for performing static code analysis on source code, primarily focusing on detecting vulnerabilities within the standard library of various programming languages. Its capabilities include predefined rules for analysis, and it offers an upgrade option to Precaution Professional for deeper inspection of third-party libraries. Notable features include easy installation via pip, and the ability to analyze specific code examples for potential security risks.

macos-re

2026-08-11 Python ★ 16
MacRE is a suite of scripts and tools designed for reversing macOS applications, focusing on security analysis and malware investigation. Notable features include the App Security Passport for extracting and simplifying macOS app metadata, MachoEntropy for detecting packed or encrypted Mach-O sections, and various analysis scripts for malware datasets. This toolkit facilitates security assessments and research on macOS applications through effective data extraction and entropy analysis.

Hellhound-Spider

2026-08-11 Python ★ 12
Hellhound Spider is a fully autonomous web crawler designed for security testing that efficiently maps endpoints, parameters, and potential security issues in traditional and single-page applications (SPAs). It features concurrent crawl engines using async HTTP workers and headless Chromium for JavaScript interrogation, outputting a structured JSON report that categorizes endpoints by confidence level and is ready for integration with security assessment tools like Burp Suite. The tool also includes capabilities for automated CORS audits, sensitive file detection in Capture the Flag (CTF) environments, and dynamic parameter extraction, enhancing its utility in penetration testing and vulnerability assessments.

CVE-2023-51467

2026-08-11 Python ★ 12
CVE-2023-51467 Scanner is a Python-based command-line tool designed to identify a specific vulnerability in the Apache OfBiz ERP system that allows unauthorized access due to an authentication bypass flaw. It enables users to scan individual URLs or lists of URLs for the vulnerability, supporting multiple concurrent threads for efficient scanning and providing output files for vulnerable targets. Notable features include customizable thread counts and flexible input options for URL scanning.

Threat-Patrol

2026-08-11 Python ★ 10
Threat-Patrol is a lightweight Python script designed for web application security testing, enabling users to scan websites for vulnerabilities such as SQL injection, XSS, CSRF, SSRF, LFI, and RCE. Its notable features include an easy-to-use command line interface, automatic scanning capabilities, and instant results, making it suitable for quick vulnerability detection.

Web_Vulnerability_Scanner-AI

2026-08-11 Python ★ 31
The Learning Grade AI Web Vulnerability Scanner is a non-destructive tool designed for identifying common web security issues such as unauthorized security headers, insecure cookie flags, and potential SQL injection vulnerabilities. It features a queue-based crawling mechanism for polite scanning, an AI-assisted report viewer for enhanced analysis, and requires explicit user confirmation for ethical scanning practices. This tool is particularly suited for educational purposes and authorized security assessments.

Detection-Labs-for-Palantir-Style-Activity

2026-08-11 Python ★ 16
Detection Labs for Palantir-Style Activity is an educational resource designed for blue team practitioners focusing on detection engineering and threat hunting. It leverages open-source tools and Sigma rules within SIEM environments to enhance competencies in cybersecurity operations, incident response, and threat intelligence analysis. Notable features include a flexible simulation environment, advanced jitter analysis for continuous monitoring, and comprehensive learning resources for SOC management.

SimpleReconURL

2026-08-11 Python ★ 18
SimpleReconURL is an OSINT tool designed for the extraction and discovery of URLs from a given seed URL, enabling reconnaissance workflows. It fetches HTML content to identify all reachable URLs, with options for deeper crawling of the same origin and enrichment through various external sources like the Wayback Machine and VirusTotal. The tool is built in asynchronous Python, ensuring efficiency and ease of use without external shell dependencies.

NmapScanningTool-V1

2026-08-11 Python ★ 28
The Nmap Scanning Tool is an interactive wrapper for Nmap that simplifies the execution of common scans and enhances readability of results. It supports multiple scan profiles, including SYN, aggressive, and vulnerability scans, along with an optional output filter to highlight open ports. The tool requires Python and Nmap to be installed on the user's system and aids in providing helpful error messages regarding user permissions and installation checks.

CVE-2023-22515

2026-08-11 Python ★ 154
The CVE-2023-22515 exploit script is designed to target and exploit the critical Broken Access Control vulnerability in Confluence Server and Data Center instances, enabling unauthorized access. It offers two operational modes: Normal for single-target exploitation via a provided URL, and Mass for bulk processing using a list of target URLs from a file, with output detailing the success of the exploitation attempts. Notable features include real-time logging of the exploitation process and clear output indicating whether unauthorized access was achieved.

CVE-2025-55182

2026-08-11 Python ★ 68
The tool exploits the vulnerability CVE-2025-55182 to achieve remote code execution through prototype pollution in Next.js React Server Components. Its primary use cases include executing arbitrary commands or establishing a reverse shell on a target server, with features for specifying various listener and payload options. Additionally, a lab environment is provided for testing the exploit in a controlled Docker setup.

xsscan

2026-08-11 Python ★ 11
XSScan is a Playwright-based automated tool designed for bug bounty hunters and security researchers to detect executed cross-site scripting (XSS) vulnerabilities. Key features include real browser execution using Chromium, intelligent form submission, recursive crawling, and auto-generated reports of confirmed XSS findings, ensuring focus on vulnerabilities that are genuinely executed rather than merely reflected.

CVE-2026-21858

2026-08-11 Python ★ 260
The CVE-2026-21858 tool demonstrates a full exploitation chain involving unauthorized arbitrary file read (AFR) and remote code execution (RCE) in the n8n automation platform. By leveraging content-type confusion and expression injection vulnerabilities, it allows an attacker to forge admin tokens and execute commands with critical impact. Key features include automated exploitation via a Python script and specific exploit requirements, such as vulnerable configurations of n8n workflows.

ai-red-teaming

2026-08-11 Python ★ 26
Red-Team AI is a white-box red teaming tool designed specifically for agentic AI applications, capable of reading source code to identify vulnerabilities that are unique to a particular technology stack. Its primary use case involves generating tailored attacks based on an application's specific implementation, rather than relying on generic adversarial prompts. Notable features include a modern React dashboard for scan management and compliance tracking, as well as integrations with popular agent frameworks, facilitating extensive security assessments and risk assessments for AI systems.

ShadowRAT

2026-08-11 Python ★ 13
ShadowRAT is a Telegram-based Remote Access Trojan designed for Windows that provides complete remote control of a machine using Telegram bot commands with password authentication. Primarily targeted at cybersecurity professionals, security researchers, and educators, it serves to demonstrate RAT functionalities, enhance malware detection techniques, and facilitate authorized penetration testing in controlled environments. The tool emphasizes responsible use solely for educational and research purposes, providing insights into attacker methodologies and improving defensive security measures.

NoiseHound

2026-08-11 Python ★ 63
NoiseHound is a detection-aware Active Directory attack-path scoring tool that enables cybersecurity operators to identify the quietest routes to administrative control within a network, leveraging BloodHound graph data. Its primary use case is for operational security (OPSEC) planning in authorized engagements, providing better risk assessments by incorporating expected detection costs instead of just hop counts. Notable features include support for multiple detection tiers, a calibration harness to measure edge effectiveness, and the ability to ingest various data formats for comprehensive path analysis.

Malware-Sandbox-mcp

2026-08-10 Python ★ 23
Malware-Sandbox-mcp is a cloud-based tool designed to detonate suspicious files and URLs within multiple third-party malware sandboxes, providing normalized reports with threat intelligence data such as verdicts, indicators of compromise (IOCs), and MITRE ATT&CK techniques. It offers a streamlined asynchronous submission and polling mechanism, allowing users to efficiently manage and analyze malware reports while integrating with nine backend services and twenty analytical tools. Key features include a uniform report schema, customizable API key management for backends, and safety mechanisms to prevent exposure of sensitive data.

Auto-Android-App-Modding-Tool

2026-08-10 Python ★ 18
UAMT (Ultimate Auto Android App Modding Toolkit) is a Termux-based toolkit for modifying Android APKs without requiring root access. Its primary use case includes injecting Frida Gadget and custom native libraries, alongside features such as a full APK rebuild pipeline, smart detection of injection methods, and an interactive TUI for user-friendly operation. Notable functionalities include automatic dependency management, safe modding practices, and optimized performance for Android security research and reverse engineering tasks.

GM2Godot

2026-08-10 Python ★ 29
GM2Godot is a conversion tool designed to facilitate the migration of GameMaker LTS 2026 source projects to Godot 4.7.1, utilizing both a graphical user interface and a headless command line interface. Key features include GML transpilation into GDScript, comprehensive diagnostics and compatibility reporting, and support for multiple platform settings, along with a robust asset conversion process for various GameMaker resources. The tool also incorporates customizable conversion options and detailed validation processes, ensuring a reliable transition while preserving project integrity.

Rein-Ai

2026-08-10 Python ★ 10
Rein is a Python library designed to serve as a runtime governor for autonomous AI agents, ensuring their actions are monitored and controlled based on real-time performance rather than just adhering to content guidelines. It features capabilities such as regime classification, Bayesian scoring of actions, a tamper-evident audit log, and a natural-language policy compiler, making it suitable for scenarios where costly or harmful actions could occur without adequate oversight. Rein is framework-agnostic, compatible with various AI platforms, and is particularly valuable in environments requiring dynamic decision-making under uncertainty.

C1ZX

2026-08-09 Python ★ 10
C1ZX is a professional dual-table Unicode substitution cipher tool that uses two independent substitution tables to encrypt printable ASCII characters, enhancing security by reducing simple repetition patterns. It features fully reversible encryption, extensive validation, automated self-testing, and supports terminal Unicode compatibility detection, making it robust for various platforms including Windows, Linux, and macOS.

U92

2026-08-09 Python ★ 30
U92 is a specialized steganography tool that facilitates the embedding of files and directories into PNG images utilizing a Least Significant Bit (LSB) embedding method. It features continuous bitstream processing, integrated archive management for ZIP file creation, and robust integrity validation processes, ensuring accurate data recovery and minimal visual distortion during extraction. The utility supports command-line interaction for easy file embedding and extraction, making it a versatile solution for secure data concealment.

HackMeGPT

2026-08-09 Python ★ 14
HackMeGPT is a CTF-style laboratory designed for practicing LLM prompt injection, where users must extract a secret "favorite item" through a series of increasingly difficult levels and unlock subsequent stages using a command-based interface. This tool features a unique level board with various defenses and secrets, an independent browser session for tracking player progress, and customizable settings for different LLM providers. Notable functionalities include environmental configuration, flag injection for each level, and restrictions on client access to settings APIs, enhancing the challenge and security aspects of the training tool.

RAMBreaker

2026-08-09 Python ★ 13
RAMBreaker is a modular memory-forensics framework that simplifies the analysis of RAM images using Volatility 2 and 3. It automatically detects the operating system and the appropriate Volatility engine to generate a self-contained, interactive HTML report, supporting Windows, Linux, and macOS environments. Notable features include the ability to extract Linux kernel symbols from the RAM image itself, minimizing reliance on external resources, and clear communication of limitations when analysis cannot be completed.

CDMW-Full

2026-08-09 Python ★ 12
Crimson Desert Mod Workbench (CDMW) is a comprehensive Windows desktop application designed for modding the game **Crimson Desert**. It allows users to browse and extract game archives, preview and edit meshes using a native D3D11 renderer, author DDS textures, and create material and mesh replacement packages, all while providing extensive controls and tools for texture editing and model manipulation. Notable features include an Archive Browser with filtering and preview options, a Mesh Editor with advanced selection and editing tools, and various workflows for texture manipulation.

ubi-gs

2026-08-09 Python ★ 14
The Ubisoft Game Service (GS) is a software development kit that facilitated online features such as user authentication, matchmaking, in-game chat, and CD key validation for Ubisoft games released between 2000 and 2005. It integrates with a dedicated network protocol for game server communication and includes components for both web service operations and specific game server implementations, exemplified by its integration with 'Heroes of Might and Magic V'. Notably, the project comes with a structured directory for common services, game-specific implementations, and testing scripts, requiring Python 3.11 or higher for execution.

re-docs

2026-08-09 Python ★ 582
The repository provides comprehensive guidance on setting up environments for security researchers across multiple operating systems, including macOS, Windows, Ubuntu, and Fedora. It also offers detailed analyses of Lua program reverse engineering, covering topics such as Luac file format, bytecode disassembly, and developing IDA Pro loaders and processors for Luac. Notably, it serves as a practical resource for those looking to enhance their skills in reverse engineering Lua applications.

revkit

2026-08-09 Python ★ 13
Revkit is a comprehensive reverse-engineering toolkit designed for analyzing and modifying iOS and Android applications. It facilitates iOS tweak development through Theos/Orion, enables dynamic instrumentation with Frida, and incorporates HTTP traffic interception using mitmproxy, alongside binary analysis tools like Ghidra and radare2. Its modular structure supports a variety of scripting and disassembly functionalities, making it suitable for both dynamic and static analysis of mobile apps.

x-tweet-fetcher

2026-08-09 Python ★ 951
x-tweet-fetcher is a tool designed for retrieving tweets, replies, timelines, and articles from X/Twitter without requiring login or API keys. Its primary use case involves fetching data efficiently through three backend options—FxTwitter for single tweets, Nitter for timelines, and a browser driver for comprehensive user interaction—automatically switching between them as needed. Notable features include monitoring for mentions, archiving query results in a SQLite database, and flexible output formats, allowing users to adapt data retrieval for various AI applications.

xorcise

2026-08-09 Python ★ 12
XORCISE is a cybersecurity tool designed to run AI agents against real-world missions in a controlled environment, monitoring and grading their actions through detailed evidence collection. It utilizes OpenTelemetry for real-time tracking of commands and actions while providing a scoring system based on pre-defined mission criteria. Notably, XORCISE supports various AI models and generates comprehensive reports, allowing users to evaluate and compare the performance of different agents in a secure, isolated network.

Auto-IDOR

2026-08-09 Python ★ 15
IDOR-Auto is an advanced testing tool designed specifically to identify Broken Object-Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR) vulnerabilities by employing differential access testing rather than relying on simple HTTP status codes. It distinguishes itself by utilizing multiple identity responses to determine if one user can access another user's data, while effectively minimizing false positives through robust response comparison, identifier analysis, and support for various input formats. Key features include canary detection, injection point flexibility, identification of encoded IDs, method tampering, and direct raw request importation, making it suitable for authorized security testing in penetration tests and bug bounties.

Analyst-Tool

2026-08-08 Python ★ 19
The Analyst-Tool is a Python-based scripting tool designed to automate digital investigation and intelligence gathering across various indicators such as domains, URLs, IP addresses, and hashes. Notable features include concurrent lookups from multiple security services, result caching for efficient API usage, multi-user tracking, and the ability to annotate and tag indicators for collaborative work. The tool emphasizes passive data retrieval, ensuring that no new data is added to the monitored services during investigations.

apotrope

2026-08-08 Python ★ 12
Apotrope is a portable Windows security posture auditing tool that performs a comprehensive assessment of Windows systems against CIS Microsoft Windows Benchmarks, providing a score from 0 to 100 along with detailed remediation recommendations. It operates as a standalone executable or via pip installation, requiring no network connection or user account for operation, and it returns results in both terminal output and self-contained HTML reports. With over 50 audit controls across 14 categories, Apotrope distinguishes itself by being read-only, user-friendly, and capable of generating actionable PowerShell commands for each identified issue.

pocket-libre

2026-08-08 Python ★ 10
Pocket Libre is a tool designed to replace the vendor app for the Pocket AI voice recorder, allowing users to extract recordings locally via Bluetooth. It features local transcription using Whisper, speaker identification, and optional summarization through API calls, ensuring that user audio data remains on their personal devices. The tool operates without reliance on cloud services and offers a web interface for managing recordings and transcripts, enhancing control over audio processing and data privacy.

gamesir-linux-tools

2026-08-08 Python ★ 14
Deadband is a Linux GUI application designed for configuring gaming input devices such as controllers and mice through their vendor-specific interfaces. It features live input monitoring, extensive customization options for profiles, lighting effects, and button remapping, as well as diagnostic tools to troubleshoot device connectivity issues. Additionally, the tool supports multiple devices with potential for extension to others, offering a user-friendly interface and customizable themes.

openremap-core

2026-08-08 Python ★ 23
OpenRemap is a Python library and CLI tool designed for ECU binary identification, diffing, and patching, enabling users to automate workflows or integrate it into applications without reliance on the internet. Its key features include accurate identification of binary files, batch processing for multiple binaries, generation of detailed diff recipes, and secure patching with complete verification. The tool provides a comprehensive, open-source solution for automotive software analysis, eliminating the need for costly commercial software.

hackerone-cli

2026-08-08 Python ★ 10
The HackerOne CLI utility is an unofficial command-line client for the HackerOne platform, enabling users to interact with their account through various modules. Notable features include accessing user profiles, reports, program information, and earnings status, all powered by the official HackerOne API for seamless integration. The tool supports multiple operations suitable for both Windows and Unix environments, allowing easy installation and execution.

phishtank-lookup

2026-08-08 Python ★ 12
phishtank-lookup is a web API that leverages the hourly public dump from Phishtank, facilitating queries against a Redis database of valid phishing URLs. Key features include automatic updates every hour, a straightforward installation process, and access to a web interface for API interaction, which enhances phishing detection capabilities by providing quick access to real-time data on known malicious sites.

Kryon

2026-08-08 Python ★ 29
Kryon is an autonomous, local-first cybersecurity agent designed for comprehensive offensive security tasks including compliance audits, penetration testing, vulnerability hunting, digital forensics, and incident response from a single command. It features a skill-based architecture that dynamically loads over 110 playbooks and employs deterministic pre-hooks for critical detections, ensuring that it provides both a thorough assessment and actionable outputs without reliance on external APIs. Additionally, it supports a wide range of compliance frameworks across multiple sectors, making it adaptable for various organizational needs.

wifi-jammer

2026-08-08 Python ★ 18
WiFi Jammer is an advanced educational penetration testing tool designed for WiFi security assessments, utilizing Python for 802.11 frame injection. It facilitates multiple attack types, including deauthentication, disassociation, and various flooding attacks, while offering rich interfaces through CLI, TUI, and GUI across multiple platforms. Notable features include channel hopping automation, PMKID and WPA handshake capture, and an architectural design grounded in SOLID principles.

pymsi

2026-08-07 Python ★ 71
pymsi is a pure Python library designed for reading and manipulating Windows Installer (MSI) files, utilizing the rust msi crate and msitools utilities. Its primary use case is to facilitate the extraction, analysis, and modification of MSI file contents, offering features such as command line operations for listing tables, dumping contents, checking file validity, and decoding custom actions. Additionally, it provides a client-side MSI viewer and file extractor accessible through a web interface.

repro-evidence-kit

2026-08-07 Python ★ 14
`repro-evidence-kit` is a command-line interface designed for maintainers to effectively review artifact-heavy pull requests and automate release processes by generating comprehensive hash manifests and evidence bundles. Its notable features include the creation of SHA-256 manifests, manifest diffs to identify changes, sandbox output verification against specified allowlists, and the ability to validate and tamper-proof evidence bundles, all while preserving command context for comprehensive review without revealing sensitive data. This tool is particularly beneficial for CI, security research, and data processing contexts, ensuring that artifact reviews are manageable and secure.

attackgen

2026-08-07 Python ★ 1237
AttackGen is an advanced incident response testing tool designed for cybersecurity professionals, utilizing large language models and the MITRE ATT&CK and ATLAS frameworks to generate customized incident response scenarios. Key features include tailored scenarios based on threat actor groups, organization-specific parameters, a chat-based assistant for scenario updates, and integration with multiple AI APIs for enhanced scenario generation. It also provides user feedback mechanisms and downloadable scenarios in Markdown format, facilitating effective training and assessment of incident response capabilities.

cookidoo-api

2026-08-07 Python ★ 145
The Cookidoo API is an unofficial Python package designed to facilitate access to the Cookidoo platform. It utilizes the `aiohttp` library for asynchronous requests, requiring OAuth2 login through stored credentials, and handles various exceptions related to API interactions. Notable features include support for cross-domain cookies and detailed usage documentation with example scripts.

ERPLibre

2026-08-07 Python ★ 22
ERPLibre is a versatile CRM/ERP platform designed for managing Odoo modules, supporting multiple Odoo versions (12.0 to 18.0) within a single workspace using independent Python environments. Key features include a guided interactive CLI for module management, automated module code generation, Selenium-driven web testing, and production-ready Docker deployment options, ensuring ease of installation and robust functionality in a local environment. The integration of pre-trained Generative Transformers enhances data management and automation capabilities.

PeAR

2026-08-07 Python ★ 17
PeAR is a versatile binary instrumentation tool leveraging the GTIRB framework, designed to add AFL++ or WinAFL instrumentation to x64 Linux and x86/x64 Windows binaries, as well as coverage tracing for x64/ARM64 Linux binaries. Key features include multiplatform support, preservation of original binary properties, the ability to import Ghidra function names into stripped binaries, and advanced fuzzing options such as persistent and shared memory modes. PeAR is particularly effective for real-world binaries, even those that are stripped, enabling practical application in binary fuzzing and tracing.

OwlTrack

2026-08-07 Python ★ 263
OwlTrack is a multifaceted tracking tool designed for investigation purposes, capable of gathering detailed information about phone numbers, email addresses, and IP addresses using various scanning methods. Key features include phone number identification with location data, email validation and finding capabilities, and a DDoS attack option for stress testing websites. Built with Python, Bash, and JavaScript, it operates on platforms including Android and Linux, catering to diverse cybersecurity needs.

FTPBuster

2026-08-07 Python ★ 10
FTPBuster is a command-line brute-forcing tool engineered for testing the security of FTP, SFTP, and explicit FTPS servers through dictionary-based attacks. Its notable features include support for single username/password and wordlist attacks, real-time progress tracking, multithreading capabilities with a maximum of 50 threads, and automatic handling of UTF-8 encoded wordlists, making it suitable for penetration testing and ethical hacking scenarios.

dirracuda

2026-08-06 Python ★ 29
Dirracuda is a graphical user interface (GUI) tool designed for discovering and categorizing open directory listings across various protocols, facilitating audits on accessible resources. Key features include a user-friendly dashboard for launching scans, integration with the Shodan API for candidate discovery, and support for file viewing and malware scanning post-download. It emphasizes security measures for scanning unknown hosts, recommending the use of VPNs and virtual machines.

npm-shai-hulud-scanner

2026-08-06 Python ★ 15
The NPM Supply Chain Security Scanner is a robust tool designed to identify vulnerabilities in NPM and PyPI dependencies, specifically targeting known compromised packages associated with significant supply chain attacks from 2025 to 2026. Key features include comprehensive detection of transitive dependencies, integration with multiple programming ecosystems, and careful analysis of installation scripts and entangled dependencies for malicious patterns, alongside automated script options for continuous security monitoring and reporting.

codex5.6-coldbrew

2026-08-06 Python ★ 73
Codex 5.6 ColdBrew is a sophisticated tool designed for advanced task routing and processing across multiple domains, employing a dual-engine framework named MAX. Its notable features include Armor Break configurations for enhanced target prioritization and integrity checks, as well as Mature M5 for adult-oriented content generation, all supported by a comprehensive command set for session management and task execution. The tool is tailored for users seeking to leverage versatile interactions for technical and creative applications within a structured environment.

jadx-mcp-server

2026-08-06 Python ★ 764
JADX-MCP-SERVER is an automated server designed for analyzing Android APKs through the connection with the JADX-AI-MCP Plugin, utilizing large language models like Claude to facilitate reverse engineering. Its primary use case involves uncovering vulnerabilities and parsing APK manifests, streamlining the reverse engineering process for security professionals. Notable features include seamless integration with LLMs for advanced analysis and fully automated operations to enhance efficiency in vulnerability detection.

ONUS

2026-08-06 Python ★ 11
ONUS is a locally-hosted vulnerability assessment and penetration testing tool designed for conducting comprehensive scans on authorized target domains. It features eight parallel scanning modules that assess various security aspects, employs deterministic CVSS v3.1 scoring for findings, and optionally utilizes AI for generating user-friendly remediation instructions, delivering results in both a PDF report and an interactive web dashboard. This air-gapped solution prioritizes simplicity and security, requiring no external dependencies or user accounts for self-hosted deployments.

SentinelDeck

2026-08-06 Python ★ 22
SentinelDeck is a passive attack-surface assessment tool designed for small businesses, agencies, and security consultants, which evaluates the public-facing posture of a specified domain or IP without intrusive scanning. It generates a risk score, provides an A to F grade, and offers prioritized findings along with actionable remediation steps. Key features include easy installation via pip, command-line scanning, and an interactive web dashboard for visualizing results.

D0x-K1t-v2

2026-08-06 Python ★ 82
D0x-K1t-v2 is a portable web application designed for active reconnaissance, information gathering, and Open Source Intelligence (OSINT) tasks. Its notable features include a user-friendly Bootstrap-based admin dashboard, capabilities for saving data in a database, and tools for conducting WhoIs lookups, phone scans, port checks, and GeoIP lookups. The tool is designed for ease of installation and deployment on various platforms, including serverless environments.

CVE-2026-60004-POC

2026-08-06 Python ★ 17
The CVE-2026-60004-POC tool provides a proof-of-concept for exploiting a pre-authentication remote code execution vulnerability in Gitea versions 1.17 through 1.27.0, with a CVSS score of 9.8. This exploitation occurs via the `diffpatch` API endpoint, allowing attackers to inject malicious Git hooks that execute arbitrary commands by manipulating Git's patch processing. Notable features include two operational modes for automation and the ability to retrieve command output directly from the target server after exploitation.

dheater

2026-08-05 Python ★ 217
D(HE)ater is a proof-of-concept tool that demonstrates the D(HE)at denial-of-service attack, which targets servers by saturating their CPU through enforced Diffie-Hellman ephemeral (DHE) or elliptic-curve Diffie-Hellman ephemeral (ECDHE) key exchanges over TLS and SSH. It allows users to specify protocols and various settings like key exchange type, socket timeout, and the number of threads for executing the attack, making it suitable for defensive security testing and research purposes. The tool is built on Python 3.9+ and relies on the CryptoLyzer library for traffic generation and DHE/ECDHE support validation.

JoySafeter

2026-08-05 Python ★ 304
JoySafeter is an AI-native platform designed to automate and orchestrate security agents at scale, facilitating rapid security operation deployments from concepts to production in minutes. With capabilities such as autonomous APK vulnerability detection and dynamic penetration testing through adaptable DeepAgents, it eliminates the need for extensive manual coordination and integrates seamlessly with over 200 security tools via the MCP Protocol. Its focus on multi-agent collaboration and cognitive memory redefines traditional security methodologies, enabling efficient analysis and reporting with minimal human intervention.

mailgoose

2026-08-05 Python ★ 207
Mailgoose is a web application designed to verify the correct configuration of SPF, DMARC, and DKIM for email domains, thus enhancing email security and reducing the risk of spoofing. It underpins the service provided by CERT PL at bezpiecznapoczta.cert.pl, which assists Polish institutions in domain configuration. Notable features include integration with checkdmarc and dkimpy for comprehensive validation checks.

plecost

2026-08-05 Python ★ 381
Plecost is a professional security scanner specifically designed for WordPress installations, capable of detecting vulnerabilities in the core, plugins, and themes while referencing a daily-updated local CVE database. It offers various scanning modes, such as deep and fast scanning, along with features like asynchronous scanning, extensive configuration options, and compatibility with task queues like Celery, making it suitable for automated security assessments without any external API dependencies or data sharing.

secuditor-lite

2026-08-05 Python ★ 63
Secuditor Lite is a Python-based diagnostic security tool designed for Windows environments, facilitating endpoint security assessments through a user-friendly graphical interface. Its primary use case involves identifying vulnerabilities, suspicious activities, and misconfigurations across systems and networks, while providing features like SSL/TLS interception analysis, operational security evaluations, and the generation of structured audit reports. The tool supports comprehensive security checks covering system hardware, network configurations, shared folder permissions, and a variety of security controls.

SkillSpector

2026-08-05 Python ★ 15401
SkillSpector is a security scanner designed for evaluating AI agent skills, identifying vulnerabilities and malicious patterns prior to their installation. It features multi-format input support, a two-stage analysis combining static and semantic evaluations, and live vulnerability lookups with real-time CVE data. The tool generates comprehensive reports and risk scores, making it integral to ensuring the safety of AI skill deployments.

Java-Triage

2026-08-05 Python ★ 15
Java Triage is a static analysis tool designed for examining suspicious Java codebases, decompiled JARs, and Minecraft mods. It features extensive capabilities including decompilation with CFR, advanced string recovery, and detection of malicious indicators and behaviors, all while producing comprehensive reports in various formats. Notable functionalities include runtime command and control resolution, detailed scoring for findings, and support for detecting obfuscation tactics commonly used in malware.

crackmesone_python

2026-08-05 Python ★ 10
Crackmes.one is a Python and Flask-based platform designed for sharing and solving reverse engineering challenges, enabling users to upload crackmes and their corresponding solutions. Key features include user registration and authentication, a content moderation system, a rating feature, notifications, and search functionality, making it a comprehensive tool for collaboration in reverse engineering. The application integrates with MongoDB for data storage and supports deployment configurations for both development and production environments.

gemini-python-api

2026-08-05 Python ★ 27
The Gemini Chat API is an automated browser wrapper framework that serves as a programmatic interface to Google's Gemini web platform, enabling users to synchronize session states and interact with Gemini's conversational capabilities. Notable features include session-based automation using persistent cookies, structured data extraction for integration with downstream projects, and automated handling of media payloads generated during interactions. This open-source tool is intended for educational and research applications within controlled environments, rather than commercial use.

RESim

2026-08-05 Python ★ 194
RESim is a dynamic analysis tool designed for reverse engineering and vulnerability assessment on simulated networked systems, utilizing the Simics platform for high-fidelity emulation of hardware. Its key features include tracing process execution, integrated debugging with IDA Pro and Ghidra, reverse execution, and a custom AFL fuzzer for direct memory injection, all while offering external observation without altering the state of the simulated environment. This tool is particularly effective for analyzing processes and data flow in both Linux and Windows systems without requiring kernel-level knowledge.

Tools

2026-08-05 Python ★ 209
This repository offers a collection of tools and scripts specifically designed for reverse engineering computer and console games using Python 3 and MexScript. The scripts are ready to run without compilation, requiring only appropriate interpreters such as Python or quickBMS, making them accessible for game modding projects. Notable features include the variety of tools developed over years of expertise in game reverse engineering, providing practical support for modders.

hbkit

2026-08-05 Python ★ 61
`hbkit` is a command-line tool designed to extract files from Synology Hyper Backup (`.hbk`) archives without requiring Synology software, offering a robust alternative for recovering backups. It operates seamlessly on Linux and macOS, supporting interactive browsing via a text-based user interface (TUI) and ensuring data integrity by validating every file against the archive's MD5 and CRC32 checksums. Notable features include handling encrypted backups, a variety of command options for probing and extracting data, and the ability to recover files while preserving their directory structure and modification times.

Patcherex2

2026-08-05 Python ★ 58
Patcherex2 is an advanced patching tool designed for binary analysis and modification across multiple platforms, extending the capabilities of the original Patcherex project. It enables users to insert, remove, and modify instructions and data within binaries, supporting a wide range of architectures including x86, ARM, and PowerPC. Notable features include detailed documentation, installation via PyPI and Docker, and extensive support for various patch types, enhancing its utility for cybersecurity researchers and developers.

Unpacker

2026-08-05 Python ★ 27
Unpacker is a modular tool designed for malware analysts to detect and unpack various malware packers such as UPX, ASPack, Themida, and VMProtect, facilitating static analysis. It leverages multiple detection methods including section names, entropy, and heuristics, allowing users to unpack multi-layer packed samples through a streamlined command pipeline. The tool outputs an unpacked file along with validation notes, enhancing the analyst's ability to perform further examinations and providing outputs suitable for integration with other analysis tools.

py-sdk

2026-08-05 Python ★ 19
The Noimosiny Python SDK is a client library designed to interact with the Noimosiny API, which specializes in OSINT and reverse-lookups. Its primary use case includes performing reverse email lookups to retrieve associated social media profiles and online records while managing account credit balances for API usage. Notable features include session management via a context manager, simplified method calls for API interactions, and built-in rate limiting for request handling.

The-Black-Tiger

2026-08-05 Python ★ 206
The Black Tiger is an advanced OSINT (Open Source Intelligence) tool designed to automate the collection and organization of information across various domains, including people, social networks, emails, phone numbers, web pages, public IPs, and images. Its key features include a comprehensive suite for web page and domain analysis, social media profile exploration, and detailed metadata extraction for images and videos, all accessible with minimal user interaction. The tool also offers specialized search capabilities for verifying email existence and identifying information from public records.

modelfuzz

2026-08-05 Python ★ 14
ModelFuzz is a runtime guardrails tool designed to intercept and prevent unsafe tool calls made by AI agents due to prompt injection attacks. It checks each argument against defined policies before execution, ensuring that only permitted actions, such as API calls to whitelisted domains, are executed, effectively blocking any malicious attempts. Notable features include support for both synchronous and asynchronous function wrapping, configurable policies, and logging of blocked actions for auditing purposes.

SquidC5

2026-08-05 Python ★ 51
SquidC5 is a cybersecurity team server designed for authorized red team operations and penetration testing, featuring AI-integrated capabilities for enhanced collaboration and task management. Notable features include scoped API tokens, dual AI operational modes, malleable C2 profiles, and a comprehensive engagement console, making it suitable for secure and efficient offensive security operations. The tool emphasizes secure defaults, including TLS encryption and robust auditing features, to ensure a safety-first approach to red teaming.

exploitbot

2026-08-05 Python ★ 10
ExploitBot is an AI-powered penetration testing toolkit designed for autonomous operation on Apple Silicon, enabling users to conduct comprehensive pentests without cloud dependency. Notable features include local LLM inference, three distinct interaction modes (Autopilot, Copilot, Manual), integration with major penetration testing tools, and automatic report generation in multiple formats. Additionally, it supports cross-engagement artifact sharing, a local CVE database, and multilingual interfaces, enhancing efficiency in vulnerability discovery and reporting.

generate-api-key

2026-08-04 Python ★ 23
The `generate-api-key` GitHub Action automates the generation of secure API keys, enhancing security in CI/CD workflows. It features key masking in logs and the ability to set the generated key as an output variable, with customizable key length defaulting to 32 characters. This tool is particularly useful for developers seeking to manage sensitive credentials without exposing them in build logs.

hermes-katana

2026-08-04 Python ★ 48
Hermes Katana is a defense-in-depth security tool designed for AI agents, providing mechanisms for tracking input provenance, scanning content for prompt injections, and enforcing YAML policies before tool execution. Notable features include configurable human-in-the-loop escalation, purpose-trained injection classifiers, and a tamper-evident audit trail for decision-making, all aimed at enhancing the security posture of AI applications. This tool is particularly useful for developers looking to safeguard AI systems from potential vulnerabilities and malicious inputs.

jddlab

2026-08-04 Python ★ 22
jddlab is a comprehensive tool designed for decompiling and deobfuscating Java and Android APKs through a Docker image, providing a robust command-line interface for users. Its primary use case is to simplify the process of accessing various decompilation tools while ensuring system safety via Docker's isolation. Notable features include easy installation with a single Docker pull command, quick updates through container versions, and accessibility of all files within the current working directory during operation.

DracoLure

2026-08-04 Python ★ 15
DracoLure is a dragon vector honeypot designed to deceive and analyze attackers by serving realistic fake web assets, thereby enticing them to interact. It features real-time detection and classification of probing attacks, assigns threat scores from 0–100, and automatically quarantines malicious sources when they exceed predefined threat thresholds. With its comprehensive signature library for various attack vectors and real-time response mechanisms, it provides a robust defense mechanism for cybersecurity environments.

iocx

2026-08-04 Python ★ 29
IOCX is a deterministic static IOC extraction engine designed for modern security pipelines, specifically focusing on malware analysis and incident response. It ensures zero execution risk by performing pure static analysis on Portable Executable (PE) files, delivering stable and reproducible outputs while effectively handling adversarial input. Key features include a binary-aware parser, high-performance extraction, and compatibility with CI/CD environments, positioning IOCX as a reliable tool for automated threat detection and defense.

ida-minsc

2026-08-04 Python ★ 333
IDA-minsc is a plugin for IDA Pro designed to streamline the scripting of the IDAPython plugin, allowing reverse engineers to execute scripts with minimal effort. It introduces a simplified structure for the IDAPython API, featuring a tagging system, support for multicased functions, and filtering capabilities, enabling users to perform search and annotation tasks efficiently with concise code. The installation process is straightforward, requiring the user to clone the repository and install necessary Python dependencies before utilizing its enhanced functionality directly within IDA Pro.

ida-sigmaker

2026-08-04 Python ★ 217
SigMaker is a cross-platform plugin for IDA Pro 9.0+ that enables the creation of binary signatures with zero dependencies, supporting x86, x64, ARM, and MIPS architectures. It offers optional SIMD optimizations for improved performance and aims to remain compatible with future IDA versions without requiring SDK recompilation, facilitating community contributions. Noteworthy features include processor-aware operand wildcarding, a straightforward installation process, and batch search capabilities for efficient signature management.

playdate-reverse-engineering

2026-08-04 Python ★ 305
The cranksters/playdate-reverse-engineering repository provides a collection of unofficial documentation and tools for reverse-engineering the Playdate handheld console's game files and file formats. Key features include a range of conversion tools for proprietary file types, an API for server interaction, and utilities for evaluating Lua scripts over USB, enabling in-depth analysis and manipulation of Playdate games and applications.

sigmatcher

2026-08-04 Python ★ 13
Sigmatcher is an automation tool tailored for matching Java classes and methods across various application versions, utilizing signatures from smali code for accurate correlation. It serves as a vital asset in long-term reverse engineering projects by enabling users to create customizable signature files in YAML format and analyze multiple types of Android package inputs efficiently. Notable features include the ability to decode APK files, apply specified signatures, and produce detailed analysis results that highlight matched classes, methods, and fields.

UnpackThemida

2026-08-04 Python ★ 194
ThemidaUnpacker is a Python 3 tool designed for dynamically unpacking executables protected by Themida and WinLicense versions 2.x and 3.x. It supports unpacking both 32-bit and 64-bit portable executables (PEs) and .NET assemblies, automatically recovering the original entry point and import table. Notable features include a user-friendly drag-and-drop interface, command-line options for advanced control, and specific handling for executables requiring license files.

pymodhook

2026-08-04 Python ★ 122
`pymodhook` is a Python library designed for recording function calls within Python modules, facilitating reverse engineering and analysis tasks. It operates across major platforms and allows users to hook into arbitrary method calls of module classes alongside tracking invocation arguments and return values, providing features akin to the Xposed framework for Android. Notable functionalities include customizable hooking parameters, support for specific module imports, and detailed logging of the raw and optimized code paths of executed functions.

lol_monitor

2026-08-04 Python ★ 22
lol_monitor is a sophisticated tool designed for real-time tracking of League of Legends (LoL) players' activities, offering detailed statistics such as match outcomes, champion performance, and team dynamics. Key features include customizable HTML-formatted email notifications for various gaming events, CSV export of gaming activities, and extensive configuration options supporting multiple methods for customization. This tool is particularly suited for users seeking to analyze and monitor gaming performance actively while maintaining flexibility through various integration options.

xbox_monitor

2026-08-04 Python ★ 28
xbox_monitor is a real-time monitoring tool for Xbox Live player activities, enabling users to track online status, game play history, and comprehensive player statistics. Key features include detection of gaming activity even for users with an "Appear Offline" status, email notifications for status changes, and the ability to log user activity into CSV files. The tool offers extensive user information displays and supports various configuration methods, allowing for customizable monitoring experiences.

Mr.SIP

2026-08-04 Python ★ 431
Mr.SIP is a console-based SIP security framework designed for auditing and penetration testing of SIP-based systems. It includes three primary modules for network scanning, user enumeration, and Denial of Service (DoS) attack simulations, all leveraging high-performance multithreading and IP spoofing. The tool serves both as a research platform for SIP DDoS attacks and as a practical utility for assessing the security of VoIP infrastructures.

androguard

2026-08-03 Python ★ 6218
Androguard is a comprehensive Python tool designed for analyzing Android files, including DEX, ODEX, and APK formats. Its notable features include disassembling DEX/ODEX bytecodes, a basic decompiler, dynamic analysis support via Frida, and the capability to handle Android's binary XML and resources. The tool is aimed at developers and security researchers looking to assess Android applications for vulnerabilities or conduct reverse engineering.

Moriarty-Project

2026-08-03 Python ★ 2076
The Moriarty Project is a web-based phone number investigation tool that facilitates the identification of phone number owners, assesses spam risk, and gathers associated information from social media platforms. With features that allow users to search for comments and links related to the given number, it aims to assist in digital investigations without supporting any intrusive actions such as tracking or hacking. Notably, it offers a customizable feature set and focuses solely on investigative purposes rather than mobile compatibility.

Photon

2026-08-03 Python ★ 13156
Photon is a high-performance web crawler designed specifically for Open Source Intelligence (OSINT) purposes. It excels at extracting a variety of data types—including URLs, emails, social media accounts, files, and secret keys—while offering extensive customization options for crawls, such as timeout control and regex URL exclusions. Notable features include smart thread management, support for plugins, and a simple deployment via a lightweight Docker image.

socialscan

2026-08-03 Python ★ 1825
socialscan is a high-performance tool designed for accurate checks of email address and username availability across various online platforms. Utilizing asynchronous querying methods via asyncio and aiohttp, it ensures 100% accuracy while executing bulk queries rapidly, making it suitable for both individual and large-scale checks. The tool supports both email and username queries, can be utilized through a command-line interface or as a Python library, and includes a wide range of platforms for comprehensive user availability assessments.

BinAssistMCP

2026-08-03 Python ★ 49
BinAssistMCP is a comprehensive Model Context Protocol (MCP) server designed to enhance Binary Ninja's binary analysis capabilities with AI-powered reverse engineering tools. It facilitates AI-assisted tasks through dual transport support and offers an extensive suite of 44 tools, streamlining the analysis process while managing multiple binaries concurrently and providing features like guided prompts and efficient caching for improved performance.

Clippy

2026-08-03 Python ★ 15
PrivEsc-Clippy is a Windows privilege escalation enumeration script designed to assist users in identifying potential vulnerabilities for privilege escalation. Key features include various command options for enumeration, report generation, file downloading, and administrative task execution, making it particularly useful in Capture The Flag (CTF) scenarios. The tool operates independently of Python installation, allowing easy packaging into a standalone executable.

dirty_sock

2026-08-03 Python ★ 681
Dirty Sock is a privilege escalation tool for Linux systems that exploits a vulnerability in the snapd API, allowing unauthorized user creation and root access. It provides two versions: the first requires an internet connection and SSH service to create a local user using Ubuntu SSO, while the second operates without these requirements, leveraging the installation of a "devmode" snap to execute arbitrary commands and bypass access controls. Notably, the tool can be used on both Ubuntu and other distributions with the snapd package installed, making it versatile in various environments.

exploit

2026-08-03 Python ★ 185
The "am0nsec/exploit" repository serves as a collection of exploit scripts and related resources, although the majority of the artifacts are not original contributions from the maintainer. Its primary use case is to provide a centralized resource for penetration testers and security researchers seeking various exploits. Notably, it includes links to the maintainer's social media and personal website for further engagement.

IAM-Deescalate

2026-08-03 Python ★ 98
IAM-Deescalate is a security tool designed to mitigate privilege escalation risks within AWS identity and access management (IAM) by identifying IAM users and roles susceptible to escalation. It utilizes NCC Group's PMapper to model relationships in an AWS account and provides commands to audit risks, plan remediation, apply policies, and revert changes. Notable features include the ability to dynamically manage inline policies and the use of explicit denies to break risky permissions paths between non-administrative and administrative principals.

uptux

2026-08-03 Python ★ 301
Uptux is a specialized tool for conducting privilege escalation checks on modern Linux systems, focusing on vulnerabilities in systemd units, D-Bus settings, and Unix socket files. Notable features include the ability to identify writable executables, broken symlinks, and overly permissive service configurations without requiring installation, making it convenient for use in restricted environments. The tool runs entirely from a single Python script and provides options for logging and debugging output.

EPScalate

2026-08-03 Python ★ 19
EPScalate is a proof-of-concept exploit that targets an elevation of privilege vulnerability (CVE-2023-31497) in QuickHeal's Seqrite Enterprise Endpoint Security solution. The tool leverages weak permissions on directory and file installations, enabling low-privilege users to escalate privileges to root by overwriting executable files or manipulating startup scripts. Notable features include the ability to perform privilege escalation via either daemon binary overwrites or injecting reverse shell commands into system initialization scripts.

eviltree

2026-08-03 Python ★ 412
EvilTree is a Python3 tool that serves as a standalone remake of the classic "tree" command, enhanced with the capability to search for user-defined keywords or regex patterns within files. Its primary use case is to assist in identifying sensitive information within complex directory structures during post-exploitation enumeration. Notable features include the ability to highlight matches in search results, support for both keyword and regex searches, and an option to filter results to show only files containing matching content.

GCP-Attack-Defense

2026-08-03 Python ★ 60
The GCP-Attack-Defense project provides comprehensive documentation of attack and defense vectors specifically in the Google Cloud Platform (GCP), aiding users in understanding security threats and mitigation strategies. It features detailed research on various aspects of cloud security, including privilege escalation and defense evasion, as well as tools like gLess and GATOR for practical application. The project serves both as an educational resource and a reference for cybersecurity professionals studying GCP vulnerabilities.

Lucifer

2026-08-03 Python ★ 378
Lucifer is a Python-based tool designed for shell manipulation and module management within cybersecurity frameworks. Its primary use case involves automating and simplifying the interaction with different shells and related modules, allowing users to set variables, run exploits, and manage options efficiently. Notable features include dynamic module indexing, the ability to spawn alternate shells, and a comprehensive set of commands for module interaction.

PayloadsAllTheThings

2026-08-03 Python ★ 11
Payloads All The Things is a comprehensive repository offering a curated list of payloads and techniques specifically designed for web application security testing. It includes detailed documentation on various vulnerabilities and how to exploit them, alongside resources for tools like Burp Intruder. Notable features include structured chapters with vulnerability descriptions, applicable payloads, and a collection of methodologies for diverse security scenarios, making it an essential toolkit for penetration testers and security professionals.

pwncat

2026-08-03 Python ★ 2915
pwncat is a versatile post-exploitation platform designed primarily for Linux targets, though it now includes alpha support for Windows. It enhances red team operations by automating interactions with remote shells, enabling functionalities like enumeration, implant installation, and privilege escalation. Notable features include the ability to spawn pseudo-terminals, synchronize shell environments, and streamline the management of remote connections for more efficient exploitation.

pytmipe

2026-08-03 Python ★ 123
PYTMIPE is a Python 3 library that facilitates Windows token manipulation and impersonation for privilege escalation, allowing users to gain elevated access within Windows environments. The tool features various methods for managing tokens and privileges, including token creation, impersonation, and access to additional escalation techniques like parent PID spoofing and service management. Additionally, it provides capabilities to retrieve comprehensive information about selected tokens and supports both local and remote token operations.

SUIDump

2026-08-03 Python ★ 18
SUIDump is an automated tool for identifying potential privilege escalation vectors in Linux systems by analyzing setuid binaries. It leverages the GTFOBins database to assess known exploitation methods, allowing users to conduct both standard and verbose scans for security auditing purposes. Key features include automated discovery of SUID binaries, a customizable command-line interface, and handling of rate limiting for checks against GTFOBins.

windows-coerced-authentication-methods

2026-08-03 Python ★ 602
This repository provides a comprehensive list of methods to coerce Windows machines into authenticating to an attacker-controlled machine, leveraging vulnerabilities in the authentication process. It includes 15 tested functions across 5 protocols, with functionalities for communicating through distributed file systems and encrypting file systems, ultimately facilitating unauthorized access to resources. The tool is intended for penetration testing and security audits, enhancing the capabilities of security professionals in assessing Windows environments.

copy-fail-CVE-2026-31431-IOC

2026-08-03 Python ★ 31
copyfail-detect is a detection toolkit designed to identify exploitation attempts of CVE-2026-31431, a local privilege escalation vulnerability in the Linux kernel that alters page-cache data without modifying the actual disk file. It features multiple detection layers, including real-time eBPF monitoring of suspicious activities, auditd rules for syscall tracking, and a page-cache comparison tool for post-exploitation analysis, enabling proactive defense and investigation against the vulnerability. The toolkit also provides mitigation scripts and documentation for responders to safely address incidents involving the Copy Fail exploit.

CVE-2024-32019-Netdata-ndsudo-PATH-Vulnerability-Privilege-Escalation

2026-08-03 Python ★ 14
This tool provides a Python-based exploit for the CVE-2024-32019 vulnerability in the Netdata Agent, specifically targeting the misconfigured `ndsudo` SUID binary that incorrectly handles the `PATH` environment variable. Its primary use case is for users with authorized access to demonstrate local privilege escalation (LPE) by executing a malicious binary with root privileges. Notable features include both manual and automated exploitation methods, aimed for educational purposes to assess potential risks in affected versions of the software.

kosty

2026-08-03 Python ★ 272
Kosty is a comprehensive CLI tool designed for AWS cost optimization and security auditing, capable of scanning over 30 AWS services. Its key features include external attack surface mapping, IAM privilege escalation detection, and specific audits for GenAI workloads like Bedrock and SageMaker, alongside actionable insights on cost savings and security gaps. The tool facilitates organization-wide scanning with parallel processing and offers an interactive visual dashboard for in-depth report analysis.

PayloadsAllTheThings

2026-08-03 Python ★ 80526
Payloads All The Things is a comprehensive repository that provides a collection of useful payloads and techniques for web application security testing. It offers structured documentation on various vulnerabilities, including exploitation methods and payload examples, and is designed to assist penetration testers in identifying and utilizing attack vectors effectively. Notable features include templates for adding new vulnerabilities, integration with Burp Suite Intruder, and a community-driven approach to enhancing its content.

Pentest-Service-Enumeration

2026-08-03 Python ★ 118
Pentest-Service-Enumeration (PSE) is a terminal-based tool designed for penetration testers, providing a quick-reference library of commands organized by service and enabling interaction with AI/LLM endpoints. Its primary use case is to facilitate service enumeration during penetration testing, while also incorporating fingerprinting and chat functionalities for AI services, aiding both practical application and certification preparation. Notable features include customizable command tracking, multi-technique extraction capabilities, and session isolation for enhanced security during testing operations.

SUID3NUM

2026-08-03 Python ★ 678
SUID3NUM is a standalone Python script designed to identify and exploit SUID binaries on Linux systems, distinguishing between default and custom binaries. Its primary use case is in penetration testing, particularly for scenarios like Capture The Flag (CTF) challenges, where it automates the exploitation of non-default SUID binaries while providing a clear overview of potentially exploitable binaries from the GTFO Bins repository. Notable features include the ability to auto-exploit custom binaries without impacting the system, as well as color-coded output for improved readability.

Windows-Kernel-Exploitation

2026-08-03 Python ★ 20
Windows Kernel - Exploration is a repository that provides a collection of notes, tools, and code snippets for exploiting Windows kernel drivers, aimed at both research and offensive security applications. It covers both legacy driver vulnerabilities and modern exploitation techniques, including Bring Your Own Vulnerable Driver (BYOVD) methods, while offering resources for kernel debugging, PDB analysis, and understanding core primitives related to kernel exploits. Notable features include detailed discussions on essential exploit techniques, kernel mitigations, and various tools for PDB parsing and debugging.

Apollo

2026-08-03 Python ★ 16
Apollo is a lightweight Remote Access Tool (RAT) developed in Python, designed for post-exploitation tasks, enabling remote code execution and system information retrieval across multiple platforms including Windows, Linux, FreeBSD, and macOS. Key features include AES-256 encrypted communication, support for handling multiple clients simultaneously, basic port scanning capabilities, and functionality to eradicate traces of its presence on the client system.

Auto-PostXploit

2026-08-03 Python ★ 16
Auto-PostXploit is a Windows post-exploitation tool designed for Red Team operations, facilitating immediate system reconnaissance following an exploit. Its primary use case involves executing post-exploitation actions on compromised systems using Meterpreter, enabling security professionals to gather critical system information efficiently. Notable features include the ability to upload and execute scripts on target systems and automate information gathering, aiding in the assessment of security postures.

MacOS-WPA-PSK

2026-08-03 Python ★ 30
MacOS-WPA-PSK is a proof-of-concept script that demonstrates how macOS stores the wireless network key in plaintext within NVRAM, rendering it accessible without root privileges. This tool highlights the risks associated with the management of sensitive credentials in macOS, serving as a reminder that users should be aware of the non-secure treatment of such information. The script operates using Python and has been tested across specific versions of macOS.

poet

2026-08-03 Python ★ 181
Poet is a post-exploitation tool that facilitates remote control and management of compromised machines through a client-server architecture. It allows attackers to perform various operations on the target, such as reconnaissance, file exfiltration, remote execution, and self-destruction of the client. Notable features include a control shell for executing commands, automatic reconnection capabilities, and the ability to remove traces post-exploitation.

punk.py

2026-08-03 Python ★ 143
punk.py is a post-exploitation tool designed for network pivoting from compromised Unix systems, facilitating the collection of usernames, SSH keys, and known hosts to establish SSH connections across discovered combinations. It supports both Python 2 and 3, features options for custom execution, password bypass, command execution with sudo, and the capability to crack hashed known hosts, making it versatile for penetration testing and exploitation scenarios.

RSPET

2026-08-03 Python ★ 263
RSPET (Reverse Shell and Post Exploitation Tool) is a Python-based framework designed for executing remote commands and facilitating post-exploitation activities in penetration testing scenarios. Notable features include TLS encryption for secure server-client communication, built-in file and binary transfer capabilities, support for managing multiple hosts, and a modular code design that allows for extensive customization and plug-in management through a RESTful API.

soapy

2026-08-03 Python ★ 15
Soapy is a post-exploitation tool designed to facilitate stealthy operations within a compromised system by creating a container that hosts a root terminal shell while monitoring and scrubbing log files. Its primary use case involves executing commands to extract sensitive information such as hashes and IP addresses, map the network, and perform other tasks without detection. Notable features include the ability to specify custom log file paths, delete files from specified directories post-session, and operate with minimal user prompts.

AdbNet

2026-08-03 Python ★ 435
AdbNet is an exploitation tool designed for identifying and compromising vulnerable Android devices across the globe. Key features include post-exploitation modules, device scanning functionalities, IP address management, and integration with APIs from Censys and Shodan for discovering susceptible devices. Users can connect to these devices through common ports, execute commands, and utilize various exploits to gain control over the target systems.

AWS-Attack

2026-08-03 Python ★ 46
AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.

Bella

2026-08-03 Python ★ 205
Bella is a potent post-exploitation and remote administration tool designed specifically for macOS, leveraging Python for high-level automation and ease of use. Its primary use case involves establishing SSL/TLS encrypted reverse shells to facilitate comprehensive data extraction, including passwords, system information, and iCloud services, while offering features like multi-user support, reverse VNC connections, and extensive logging capabilities. Notably, Bella can gain root access to expand its functionalities and maintain persistent control over the target system, all while operating undetectably.

Bifrost

2026-08-03 Python ★ 50
Bifrost is an open-source command and control (C2) tool implemented as a Discord bot, allowing users to manage and communicate with compromised clients through the Discord API. It supports multiple platforms and provides features such as keylogging, antivirus enumeration, real-time encrypted communication, and file management capabilities. Designed for educational and authorized security testing purposes, Bifrost leverages the Discord infrastructure to maintain a stealthy connection with clients.

C2_Server

2026-08-03 Python ★ 58
The C2 Server is a Command and Control framework that enables attackers to manage compromised target machines through a reverse shell connection. It supports various commands for file management, directory navigation, and even malicious functions like keylogging and credential spoofing, enhancing the attacker's ability to interact with the victim's system. Written in Python, it provides a user-friendly interface for executing predefined commands and extracting sensitive information from infected devices.

Crowbar

2026-08-03 Python ★ 47
Crowbar is a comprehensive Windows post-exploitation tool designed to facilitate various tasks such as privilege escalation and system command execution via PowerShell. It includes an extensive range of scripts and utilities, notably the 'Hail Mary' feature for launching multiple scripts simultaneously, and checks for the presence of Windows Subsystem for Linux on the target machine. The tool is actively maintained, with regular updates that introduce new scripts and enhancements to improve functionality.

DeathNote

2026-08-03 Python ★ 36
DeathNote is a penetration testing cheat sheet tool that provides a collection of resources and techniques essential for conducting security assessments. Its primary use case is to streamline the penetration testing process by offering organized references for various attack vectors, including reverse shells, PowerShell exploits, Active Directory, brute-forcing, and persistence methods. Notable features include compatibility with both Python 2.7 and 3.7, straightforward installation, and customizable configurations.

FudgeC2

2026-08-03 Python ★ 253
FudgeC2 is a PowerShell-based command and control (C2) platform that enhances collaborative red teaming by providing an organized structure for managing campaigns and implants. It features a web-based interface that allows operators to easily deploy and control various implants, execute commands, and gather system information, with support for custom modules and a range of built-in commands such as persistence and file manipulation. Designed for active development, FudgeC2 aims to improve understanding of adversarial techniques through detailed reporting and campaign timelines.

HackingComm

2026-08-03 Python ★ 78
HackingComm is a user-friendly penetration testing tool designed for individuals with limited terminal command knowledge. It simplifies common pentesting tasks on Kali Linux through a straightforward interface, allowing users to easily input required parameters while executing commands. Notable features include an installation script, guided prompts for user inputs, and reliance on Python for functionality, making it accessible for beginners in cybersecurity.

iPwn

2026-08-03 Python ★ 233
iPwn is a framework specifically designed for the exploitation of jailbroken iOS devices, enabling users to gain access and extract sensitive information. It incorporates a post-exploitation tool named 'iSteal', which offers various modules for information harvesting and management, including SSH brute-forcing capabilities using common credential wordlists. Notably, the framework is still under development, with ongoing enhancements for easier payload management and integration with existing iOS tweaks.

rpc2socks

2026-08-03 Python ★ 194
rpc2socks is a client-server solution designed to establish a SOCKS5 proxy tunnel through a custom RPC and SMB connection for remote execution and communication between Unix or Windows hosts and Windows targets. The tool leverages a dedicated named pipe for communication, supports DNS resolution, and operates without authentication by default, making it suitable for establishing secure tunnels on networks where direct connectivity may be restricted. Notably, the client is a Python package while the server is a statically-linked C++ console application compatible with both 32-bit and 64-bit Windows environments.

shennina

2026-08-03 Python ★ 557
Shennina is an automated host exploitation framework that leverages Artificial Intelligence for comprehensive scanning, vulnerability analysis, and exploitation of target systems. Integrated with Metasploit and Nmap, it features a self-learning AI engine for identifying exploits, supports post-exploitation capabilities, and automates data exfiltration while covering over 40 techniques from the MITRE ATT&CK framework. Notable features include heuristics mode for exploit recommendations, high concurrency performance, and cross-platform support for various operating systems.

ghost

2026-08-03 Python ★ 162
Ghost Framework is an Android post-exploitation tool that leverages the Android Debug Bridge for remote device administration. It provides a user-friendly interface to execute various remote management tasks such as accessing the device shell, installing applications, capturing screenshots, and managing device settings. Notable features include password removal capabilities and comprehensive system information retrieval.

Ant

2026-08-03 Python ★ 17
Ant is a post-exploitation tool designed to automate the deployment of tunnels and port forwarding over a specified network topology using configuration files. Key features include support for WMI, WinRM, and SMB protocols, along with four main commands—deploy, desinfect, redeploy, and probe—that facilitate topology management. The tool also includes validation for configuration file accuracy and allows comments for better user guidance.

dfex

2026-08-03 Python ★ 45
DFEX is a tool designed for DNS-based data exfiltration, leveraging the DNS protocol to transmit files across networks while circumventing traditional firewalls. Its primary use case is in post-exploitation scenarios, employing unique tactics to outsmart advanced firewalls, including techniques that disguise data transfers in plain sight. Notable features include a dual-client and server architecture, and compatibility with Python environments to facilitate easy installation and setup.

DNS-Tunnel-Keylogger

2026-08-03 Python ★ 280
DNS Tunnel Keylogger is a post-exploitation tool designed to covertly exfiltrate keystrokes via DNS tunneling, allowing for lightweight and persistent data exfiltration while minimizing detection risks. The tool features separate components for Linux and Windows, employing bash scripts and a compiled executable respectively, along with a server setup that listens on UDP port 53 by default. Notably, it can send keystrokes silently and can be configured for automatic startup in interactive shells to maintain persistence.

ExtractBitlockerKeys

2026-08-03 Python ★ 403
ExtractBitlockerKeys is a post-exploitation script designed for system administrators to automate the extraction of BitLocker recovery keys from a domain. It features multithreaded LDAP connections to retrieve data from domain controllers, supports pagination for large domains, and allows for exporting results in various formats, including JSON, XLSX, and SQLite3. This tool is essential for managing BitLocker recovery information in a secure and efficient manner.

GOD-OF-RAT

2026-08-03 Python ★ 22
GOD-OF-RAT is an advanced Python Remote Access Trojan (RAT) framework designed for authorized penetration testing, offering extensive control over compromised systems. Its notable features include live screen controlling, credentials harvesting from various sources, an interactive agent builder with encryption capabilities, and advanced evasion techniques. The framework also supports remote shell access, file system management, and a suite of fun modules for additional functionalities.

gtfobins-cli

2026-08-03 Python ★ 145
GTFOBins CLI is a command-line tool designed for security professionals to quickly access and search for Unix binary exploitation techniques. It features capabilities such as fuzzy searching, filtering exploitation types, and an interactive mode for ease of navigation, all while providing an offline database for fast, local access. The tool supports cross-platform usage and enhances readability with syntax highlighting, allowing for efficient identification of security bypass methods.

MsfMania

2026-08-03 Python ★ 516
MsfMania is a Python-based payload obfuscation framework primarily aimed at evading endpoint detection and antivirus systems on Windows platforms. It boasts notable features such as dynamic code generation, multi-layer encryption using RC4, local memory injection, and extensive metadata spoofing, making it suitable for authorized security testing and research activities.

PivotSuite

2026-08-03 Python ★ 459
PivotSuite is a network pivoting toolkit designed for Red Teamers and penetration testers, enabling the movement within a compromised network using either forward or reverse connections. Notable features include support for TCP tunneling, SOCKS5 proxies, and various network enumeration functions, all without requiring administrative access on the compromised host. The tool operates independently of installation requirements, utilizing only Python's standard libraries, making it versatile across different platforms and environments.

PyADRecon

2026-08-03 Python ★ 67
PyADRecon is a Python-based tool designed for gathering comprehensive information from Microsoft Active Directory environments, catering to the needs of penetration testers and blue teams. It supports NTLM and Kerberos authentication methods, can generate XLSX reports, and offers an HTML dashboard for visualizing collected data, making it a versatile resource for Active Directory reconnaissance. Additionally, it provides options for standalone report generation from CSV files, enhancing its usability in various assessment scenarios.

PyExfil

2026-08-03 Python ★ 809
PyExfil is a Python-based tool designed for stress testing the detection capabilities of security systems against various exfiltration and communication techniques employed by threat actors. It allows users to deploy multiple experimental and stable exfiltration methods, such as DNS queries, HTTP cookies, and ICMP packets, enabling organizations to evaluate their defenses. Notable features include a wide array of techniques for data exfiltration and communication, with the ability to configure and run tests across different operating systems.

PyIris

2026-08-03 Python ★ 326
PyIris is a modular remote access trojan (RAT) toolkit implemented in Python, designed for the dynamic creation, encoding, and encryption of RAT payloads to facilitate the remote control of compromised systems. Its notable features include cross-platform compatibility for both Windows and Linux, robust error handling, dynamic payload generation, and advanced functionalities such as keylogging, webcam access, and file manipulation, making it a versatile tool for malicious actors. The ongoing development aims to enhance its capabilities further with improved encryption methods and operational persistence techniques.

python-remote-session-lab-poc

2026-08-03 Python ★ 175
PythonRAT is a Command and Control (C2) server that orchestrates multiple machines infected with a Remote Administration Trojan (RAT), enabling the formation of a botnet cluster. Its primary use case is for educational purposes in cybersecurity training, allowing users to remotely control, monitor, and manipulate target sessions. Notable features include an integrated keylogger, screenshot and webcam capture, file transfer capabilities, privilege checking, and the ability to issue commands to all active sessions simultaneously.

reave

2026-08-03 Python ★ 50
Reave is a post-exploitation framework developed for hypervisor endpoints, designed to facilitate automated penetration testing in heavily virtualized environments. This Python-based tool operates on a listener/agent model, offering features such as real-time interactive terminal sessions, automatic hypervisor enumeration, and modular payloads for tasks including exfiltration and persistence. Notably, Reave supports versatile configurations for agents, enabling comprehensive control over operations and network interactions.

SeaShell

2026-08-03 Python ★ 721
The SeaShell Framework is a post-exploitation tool designed for iOS and macOS that facilitates remote access to devices, allowing for control and extraction of sensitive data. Its notable features include a powerful payload named Pwny which supports custom post-exploitation modules, encrypted communication via TLS 1.3, and a basic set of modules for exfiltrating user data such as SMS, voicemail, and browsing history. Actively updated, it supports a wide array of iOS versions susceptible to specific vulnerabilities, enhancing its utility in security assessments and penetration testing.

sshimpanzee

2026-08-03 Python ★ 294
Sshimpanzee is a tool for creating a static reverse SSH server that initiates connections from the victim machine to an attacker's IP, bypassing the need for incoming connection requests. It provides all standard SSH functionalities, including port forwarding and dynamic SOCKS proxies, while also offering advanced tunneling methods like DNS Tunneling, ICMP Tunneling, and HTTP encapsulation to facilitate communication in restrictive network environments. Notable features include customizable build configurations, support for multiple tunneling mechanisms, and the ability to generate new SSH keys upon build.

venus

2026-08-03 Python ★ 76
Venus is a VS Code extension designed to serve as an agent for the Mythic C2 framework, enabling operators to create and deliver payloads to target systems. This tool automates the packaging of VS Code extensions and supports various commands for interacting with the system environment, although it currently lacks support for encrypted payloads. Notably, Venus is cross-platform compatible and requires manual installation on target machines after preparation.

byob

2026-08-03 Python ★ 9499
BYOB is an open-source post-exploitation framework designed for educational purposes that facilitates command and control operations following a system compromise. It features a comprehensive web GUI for managing post-exploitation tasks, customizable payload generation for multiple platforms, and the ability to dynamically load third-party packages without leaving traces on the disk. The framework is optimized for ease of use, allowing students, researchers, and developers to extend its capabilities with minimal effort.

ShellOrd

2026-08-03 Python ★ 17
ShellOrd is a cross-platform Command & Control (C2) framework designed for authorized penetration testing and educational purposes, implemented in Rust and Java. It supports Windows, MacOS, and Linux, and features a modular architecture with extensions, secure memory handling, and encrypted data transmission over TCP or UDP. The framework enables users to build and automate workflows, serving as an alternative to Trickest, while emphasizing speed and security.

agentic-threat-hunting-framework

2026-08-03 Python ★ 364
The Agentic Threat Hunting Framework (ATHF) is a markdown-based tool that structures and preserves threat hunting investigations, enhancing their accessibility and utility through automation. It utilizes the LOCK pattern for documentation, providing a framework that integrates with any SIEM/EDR platform while incorporating AI-driven research and hypothesis generation capabilities. By retaining context and enabling AI assistants to leverage past hunts, ATHF aims to enrich and streamline the threat hunting process.

chipsec

2026-08-03 Python ★ 3297
CHIPSEC is a comprehensive platform security assessment framework designed to analyze the security of PC platforms, focusing on hardware, system firmware (BIOS/UEFI), and associated components. It features a variety of security tests, access tools for low-level interfaces, and forensic capabilities, and supports operation across Windows, Linux, and UEFI shell environments. This tool is particularly geared for security professionals seeking to identify vulnerabilities in firmware, hypervisors, and hardware configurations.

compose-lint

2026-08-03 Python ★ 53
compose-lint is a security-focused linter designed to analyze Docker Compose files for dangerous misconfigurations and enforce best practices. It conducts static analysis to identify issues such as privilege flaws, network exposure, and supply chain vulnerabilities, and can automatically fix unambiguous findings. Grounded in OWASP guidelines and the CIS Docker Benchmark, it serves as a pre-merge gate for infrastructure-as-code, making it essential for production environments and CI/CD workflows.

cortado

2026-08-03 Python ★ 29
Cortado is a Python-based framework designed for executing Red Team Automations (RTAs) which emulate attacker behaviors or reference specific binary samples to evaluate detection rules in Elastic's security products. It features a command-line interface for running RTAs in a minimal dependency environment, as well as utilities for assessing RTA coverage against defined detection rules. The tool facilitates seamless integration and deployment within security operations, enhancing the verification process of alert generation.

cryptolyzer

2026-08-03 Python ★ 48
CryptoLyzer is a comprehensive security auditing tool that analyzes various cryptographic protocols, including TLS, SSL, SSH, IKE, and DNSSEC. It uniquely identifies over 400 cipher suites and cryptographic algorithms using a custom implementation that operates independently of OpenSSL, enabling the detection of vulnerabilities often missed by traditional tools. With both command-line and API interfaces, CryptoLyzer offers versatile output formats and a unified approach, making it an essential solution for security assessments across multiple cryptographic attack surfaces.

ExtensionShield

2026-08-03 Python ★ 99
ExtensionShield is a Chrome extension security scanner and governance platform that audits browser extensions, producing comprehensive, evidence-linked reports focusing on security, privacy, and governance. It operates in an open-source mode using SQLite, allowing scans of extensions from the Chrome Web Store or local files, with features such as manifest and permission reviews, SAST findings, entropy checks, and integration with VirusTotal for enhanced analysis. Notably, it offers a customizable scoring system to evaluate extensions across critical security and governance dimensions.

masscan_as_a_service

2026-08-03 Python ★ 29
Masscan as a Service is a Python-based tool designed to facilitate rapid port scanning across whole IPv4 ranges using the high-speed masscan utility, allowing users to quickly identify open TCP or UDP ports on their servers. Its primary use case is for security monitoring, alerting users when previously unseen ports become active, thus helping to mitigate the risk of unauthorized access or malicious activity. Notable features include seamless integration into deployment pipelines via scheduling systems, easy installation as a Python package, and upcoming support for nmap to enhance its scanning capabilities for IPv6.

openshield

2026-08-03 Python ★ 55
OpenShield is an open-source Cloud Security Posture Management (CSPM) tool designed specifically for Azure environments, enabling users to detect misconfigurations and improve security compliance by mapping issues to frameworks like CIS, NIST, and ISO 27001. Notable features include a comprehensive misconfiguration scanner, which evaluates over fifty security rules across various Azure services, and the ability to identify classical cryptographic assets that require migration to quantum-safe alternatives. The tool facilitates remediation through a single command, providing a user-friendly approach to enhancing cloud security for startups and small to medium-sized enterprises.

stride-gpt

2026-08-03 Python ★ 1111
STRIDE GPT is an AI-driven threat modeling tool that utilizes Large Language Models to create detailed threat models and attack trees based on the STRIDE methodology. It offers features such as agentic codebase analysis, a user-friendly CLI and interactive REPL, integration with OWASP guidelines, and the capability to generate and edit architecture diagrams directly within the tool. Additionally, STRIDE GPT supports multi-modal input, allowing users to incorporate various diagram types into the threat modeling process.

argus

2026-08-03 Python ★ 28
Argus is a comprehensive security scanning tool that integrates Static Application Security Testing (SAST), container security, Infrastructure as Code (IaC) scanning, and dynamic application security testing (DAST) into a single command-line interface (CLI) or GitHub Actions workflow. It supports various scanners such as Bandit, Gitleaks, and Trivy, enabling users to detect vulnerabilities, secrets, and security weaknesses across code, containers, and cloud configurations. Notable features include an interactive terminal UI for triaging scan findings, customizable integration with CI pipelines, and export options for results.

AutoFyn

2026-08-03 Python ★ 101
AutoFyn is a long-horizon agent designed to find vulnerabilities in software by utilizing a clean context and verifiable feedback mechanism. It operates by proposing exploits against live systems, ensuring objective outcomes that enhance its learning through expert iteration across multiple domains, including security audits and mathematical research. Notable features include its ability to conduct thorough security audits on popular repositories, yielding significant vulnerability reports, and effectively managing context to avoid the pitfalls of accumulating errors.

Commander

2026-08-03 Python ★ 251
Keeper Commander serves as a versatile command-line interface for managing access to the Keeper® Password Manager and KeeperPAM, facilitating tasks such as user and role administration, password rotation, and session management. Notably, it offers an interactive terminal UI, supports REST service operations, and enables features like biometric authentication and persistent login sessions, making it suitable for both individual users and enterprises seeking to integrate secure password management within their workflows. As an open-source tool, it encourages community contributions, enhancing its capabilities and usability.

FinalThreatFeed

2026-08-03 Python ★ 13
FinalThreatFeed is a high-performance automated threat intelligence aggregation engine designed for continuous collection and fusion of global open-source intelligence. Its architecture supports asynchronous operations to enhance data throughput, while features such as intelligent cleaning, deduplication, and full lifecycle management ensure high-quality, relevant threat data. The tool also offers flexible extension configurations and advanced IOC identification, making it suitable for enterprise security defense systems.

humble

2026-08-03 Python ★ 373
Humble is a fast and security-oriented HTTP headers analyzer designed to assess the presence and efficacy of security headers in web applications. Its primary use case is to enhance security by identifying missing or misconfigured headers, making it a valuable tool for cybersecurity professionals and web developers. Notable features include compatibility with Python 3.11 or higher, integration with the DefectDojo platform for result parsing, and inclusion in Kali Linux, making it readily accessible for penetration testing workflows.

pwpush-cli

2026-08-03 Python ★ 28
pwpush CLI is a command-line tool designed for securely sharing sensitive information such as passwords and files via self-destructing links. Its primary use case is to facilitate the secure transmission of secrets without relying on traditional communication methods like email or Slack, and it provides notable features including automatic expiration controls, integration for file uploads, and a secured request feature for soliciting sensitive data from others in a protected manner.

RA3G-Agent

2026-08-03 Python ★ 12
RA3G-Agent is a policy-aware RAG (Retrieval-Augmented Generation) multi-agent AI system designed for document querying without the need for external APIs. It features a robust architecture comprising a Retriever, Reasoning, and Governance agents, enabling automatic filtering of sensitive information and maintaining session memory for context. Key capabilities include a user-friendly web interface, real-time logging, automatic PDF uploads for vector storage, and full programmatic access through a REST API built with FastAPI.

ShareClean

2026-08-03 Python ★ 17
ShareClean is a Python CLI tool designed for sanitizing developer outputs such as logs, configuration snippets, and terminal outputs before sharing them in public or semi-public environments. Notable features include local processing without the need for network calls, customizable redaction patterns, and a robust detection system that identifies and replaces sensitive information like API keys and passwords while preserving useful context. This enhances security by ensuring that potentially sensitive data is adequately managed prior to publication.

sigwood

2026-08-03 Python ★ 104
sigwood is a local-first command-line tool designed for threat hunting by analyzing existing log files from sources such as Zeek, DNS servers, and syslogs. Its primary use case is to detect anomalies, including beaconing, suspicious DNS queries, and unusual activity within a user’s network, without requiring any external deployment or configuration. Notable features include its simple installation process, a suite of detectors for various events, and the ability to run directly on logs without needing to send data to the cloud.

tracehound

2026-08-03 Python ★ 13
Tracehound is a Linux DFIR tool designed to parse host artifacts and compile them into a unified, UTC-normalized timeline, facilitating the analysis of attacker behavior during forensic investigations. It processes log files, mounted images, and evidence folders, employing detection rules with MITRE ATT&CK mappings to convert raw events into actionable findings. Notable features include exporting results in various formats such as JSON, HTML, or CSV, and capabilities for maintaining a timeline in SQLite for extensive datasets.

Yoda

2026-08-03 Python ★ 37
Yoda is a passive RF monitoring tool designed for home environments, capable of tracking Bluetooth (BLE) devices and WiFi access points and clients in real time. It features a terminal user interface (TUI) that displays live data, push notifications for device and connection events via ntfy.sh, and advanced jamming detection using an asymmetric exponentially weighted moving average (EWMA). Users benefit from the ability to customize alert topics and monitor device stability, making it an effective solution for managing home network security and device presence.

zizmor-pre-commit

2026-08-03 Python ★ 64
The `zizmor-pre-commit` tool integrates the `zizmor` linter with the pre-commit framework, allowing users to enforce code quality checks before commits. Its notable features include easy configuration via `.pre-commit-config.yaml`, support for running the linter with autofix capabilities, and distribution as a standalone repository for seamless installation through prebuilt wheels from PyPI.

AntiScamBot

2026-08-03 Python ★ 13
The ScamGuard AntiScam Bot is a Discord bot designed to identify and ban scammers who target users with unsolicited commission offers. Its primary use case is to safeguard Discord communities by leveraging a shared ban list of verified scammers, supported by community reporting and a transparent operational framework. Notable features include the ability to configure the bot for local use with essential environment variables and the option to activate a publicly accessible API endpoint for custom bot instances.

AutoCVE

2026-08-03 Python ★ 1386
AutoCVE is an automated tool designed for end-to-end CVE discovery, encompassing project screening, source code auditing, vulnerability verification, and report generation. Its notable features include a multi-agent collaborative auditing system and flexible auditing modes tailored for different objectives, enabling efficient management of vulnerability assessment through structured automated workflows. The tool simplifies the CVE reporting process, allowing users to easily submit their findings after a comprehensive auditing experience.

h1domains

2026-08-03 Python ★ 529
h1domains is a Python tool that retrieves and lists domains approved for bug bounty programs on HackerOne, focusing specifically on those marked as "in-scope." Its primary use case is to assist security researchers in identifying valid targets for vulnerability testing while providing a regularly updated repository of domains. Notable features include an automated script to fetch the latest data and a comprehensive list of domains across various companies and services.

scapy-usbbluetooth

2026-08-03 Python ★ 23
Scapy UsbBluetooth is a Python library that integrates Bluetooth communication capabilities into Scapy, enabling it to interact with Bluetooth controllers through UsbBluetooth. Its primary use case is for network and device analysis, providing functionality to list devices, establish sockets, and send command packets, like HCI commands. Notable features include easy installation via pip and support for specific platform requirements, facilitating access on Windows and Linux systems.

findmytakeover

2026-08-03 Python ★ 178
Findmytakeover is a specialized tool designed to detect dangling DNS records within multi-cloud environments, scanning all DNS zones and associated infrastructure in cloud service providers. Its primary use case is to identify potential subdomain takeovers by pinpointing DNS records without existing infrastructure, enhancing security against unauthorized access and malicious activity. Notable features include configurable cloud provider support, comprehensive reporting, and dependencies tailored to different cloud environments, ensuring effective operational capability across major platforms.

oxo

2026-08-03 Python ★ 581
OXO is a security scanning framework designed for modularity and scalability, enabling users to efficiently combine various specialized agents to conduct comprehensive vulnerability assessments across a wide range of assets, including IPs, domains, mobile applications, and APIs. Key features include an extensible agent store for community and official tools, a Python-based framework for creating custom agents, and an API-first design that facilitates integration into CI/CD workflows. The tool supports Docker for containerized execution, simplifying deployment and management of security scans.

pcap-hunter

2026-08-03 Python ★ 157
PCAP Hunter is an AI-enhanced threat hunting workbench designed for SOC analysts, enabling seamless integration of manual packet analysis with automated security monitoring. It features a user-centric interface for geographic flow aggregation, linked visual analysis, and a durable analysis workflow, while also providing optional Large Language Model assistance for enriched analysis. The tool supports visualization and investigation of packet captures through advanced filtering and responsive dashboard capabilities, ensuring comprehensive threat detection and evidence management.

prismor

2026-08-03 Python ★ 277
Prismor is a runtime security tool designed for AI coding agents like Claude Code and Codex, providing features to block dangerous commands, prevent prompt injections, and avoid secret leaks. It also recommends safe supply chain packages and offers an observe mode to monitor agent session activities through a growing self-serve dashboard. Its primary use case is enhancing the security and reliability of AI coding interactions by addressing potential vulnerabilities.

QuicDrawH3

2026-08-03 Python ★ 23
QuicDraw is a security research tool focused on fuzzing and race-condition testing of HTTP/3 servers using the Quic-Fin-Sync technique over the QUIC transport layer. It supports advanced features such as custom HTTP headers, multiple request fuzzing with wordlists, and TLS decryption for packet analysis, making it suitable for testing the resilience of HTTP/3 applications against race conditions and security vulnerabilities. The tool is built on the aioquic library, offering a robust implementation for developers and security professionals engaged in network protocol research.

repo-forensics

2026-08-03 Python ★ 168
Repo Forensics is a security tool designed to audit untrusted repositories before their integration with AI-agent plugins, skills, and MCP servers. It features a fully local and self-updating detection mechanism with zero dependencies and telemetry, ensuring a secure audit process. The tool supports live scanning against CVEs, incorporates over 800 patterns and 41 correlation rules, and operates effectively in offline environments.

rust-in-peace

2026-08-03 Python ★ 17
Rust-in-Peace is an autonomous security review tool specifically designed for Rust programming, facilitating the detection and remediation of vulnerabilities related to memory safety and panic handling in unsafe contexts. It integrates various detectors such as Miri and AddressSanitizer into a comprehensive pipeline that automates the process of finding, grading, and reporting vulnerabilities while also enabling targeted fuzzing. This tool emphasizes a structured approach by utilizing a machine-readable threat model and supports a recall-first strategy to improve detection accuracy through multiple scanning runs.

sbomify

2026-08-03 Python ★ 59
sbomify is a comprehensive Software Bill of Materials (SBOM) management tool that allows users to upload, manage, and share SBOMs and related documentation through a centralized platform, either self-hosted or via the provided web application. It supports multiple formats including CycloneDX and SPDX, integrates with GitHub Actions for automatic SBOM generation, and features robust compliance plugins while offering document management capabilities with version control and configurable access settings. Notably, it enables vulnerability scanning and employs workspace-based organization for efficient access and permission control.

SecObserve

2026-08-03 Python ★ 295
SecObserve is an open source vulnerability and license management tool designed for software development teams and cloud environments, enabling efficient assessment and reporting of vulnerabilities across multiple scanning tools. It features a centralized dashboard for viewing and filtering scan results, as well as easy integration into CI/CD pipelines through pre-defined GitLab CI templates and GitHub Actions for streamlined vulnerability scanning. This tool aims to simplify the vulnerability management process, allowing teams to focus on addressing significant security issues.

vulnerablecode

2026-08-03 Python ★ 699
VulnerableCode is an open-source database designed to catalog software package vulnerabilities, accessible through a Web UI and a comprehensive API. Its primary use case is to provide detailed information on vulnerabilities affecting software packages, including upstream and downstream impact analysis, thereby facilitating better vulnerability management. Notable features include its focus on Package URLs (PURLs) for easy identification of packages, along with the ability to build custom instances of the database.

wildbox

2026-08-03 Python ★ 132
Wildbox is a self-hosted, open-source security operations platform designed for comprehensive threat monitoring, analysis, and automated responses, allowing users to maintain full control over their data. It features aggregated threat intelligence from over 50 sources, cloud security posture management for major providers, and utilizes YAML-based playbooks for incident automation, alongside advanced LLM capabilities for enhanced threat analysis and reporting. The architecture is built on microservices, providing flexibility and scalability through a robust API gateway, identity management, and integrated data management tools.

assemblyline

2026-08-03 Python ★ 532
AssemblyLine 4 is an open-source automated malware analysis framework designed to support both manual analysis and large-scale enterprise security operations through scalable file triage. Built on Kubernetes and Docker, it offers extensive integration capabilities with various security tools and provides a REST API for customizable extensions. Notable features include deep file analysis, interoperability with threat knowledge bases, and the ability to create additional analysis services via Python.

assemblyline-base

2026-08-03 Python ★ 73
Assemblyline Base is a foundational package for the Assemblyline suite, providing essential libraries, cachestore, datastore, filestore, and remote datatypes necessary for operational functionality. It is specifically designed for environments running Python 3.11 on Linux systems, with support for both stable and development builds. Key features include robust dependency management and compatibility with containerized deployment via Docker images.

assemblyline-service-cape

2026-08-03 Python ★ 14
The Assemblyline CAPE Service integrates with CAPEv2 to facilitate the submission of files for automated malware analysis, utilizing a REST API to manage task distribution across virtual victim machines. It retrieves and summarizes analysis reports, providing users with both summarized results and full report access through the Assemblyline UI. This service requires a private CAPE deployment and additional configuration for optimal functionality and reporting.

capa

2026-08-03 Python ★ 6162
Capa is an advanced tool designed to analyze executable files, specifically PE, ELF, .NET modules, and shellcode, by detecting their operational capabilities. It provides detailed insights into potential functionalities, such as backdoor activities and methods of communication, while allowing interactive exploration of results via a web interface. Notable features include the ability to respond to custom rules, integration with the MITRE ATT&CK framework, and multiple output options for comprehensive analysis.

drakvuf-sandbox

2026-08-03 Python ★ 1333
DRAKVUF Sandbox is an automated black-box malware analysis system that operates without requiring agents on the guest operating system, utilizing the DRAKVUF engine for its core functionality. It features a user-friendly web interface for uploading and analyzing suspicious files, along with an installer that simplifies the setup process for beginners while allowing for advanced configuration by experienced users. This tool is designed to facilitate the identification of malicious files efficiently, though it requires specific hardware and software setups for optimal performance.

flare-floss

2026-08-03 Python ★ 4143
The FLARE Obfuscated String Solver (FLOSS) is a static analysis tool designed to automatically extract and deobfuscate strings from malware binaries, enhancing the traditional `strings.exe` utility. It effectively identifies and extracts various types of obfuscated strings, including static, stack, and decoded strings, thereby improving the analysis of potential malware artifacts. Notable features include support for language-specific string formats and the ability to interface with other tools like Binary Ninja and IDA Pro through additional scripts.

ioc-finder

2026-08-03 Python ★ 184
IOC Finder is a tool designed to extract indicators of compromise (IOCs) such as URLs and email addresses from textual data. Its primary use case is enhancing threat detection and analysis by parsing relevant observables from various text sources. Notable features include interactive documentation and a focus on community support for ongoing improvements.

lenspect

2026-08-03 Python ★ 199
Lenspect is a lightweight security threat scanner that utilizes VirusTotal to analyze potential threats. Its primary use case is to provide users with quick and efficient scans for security vulnerabilities within their systems. Notable features include support for installation via Flatpak and AppImage, providing accessibility across various Linux distributions, as well as a user-friendly interface for enhanced usability.

macaron

2026-08-03 Python ★ 210
Macaron is a software supply chain security analysis tool developed by Oracle Labs, designed to verify the build integrity of software artifacts and their dependencies across various ecosystems such as PyPI and npm. Notable features include attestation verification for provenance validation, detection of malicious packages, identification of vulnerable GitHub Actions, and support for reproducible builds through static analysis of build scripts, enhancing the security and traceability of software development workflows.

mobileAudit

2026-08-03 Python ★ 228
MobileAudit is a Django web application designed for static analysis and malware detection in Android APKs. It provides a comprehensive dashboard that aggregates SAST findings, app metadata, security vulnerabilities, and malware checks, while integrating with VirusTotal and optional tools like DefectDojo. Key features include customizable SAST rules, export capabilities for scan reports, and a token-based API with user management for secure access.

mwdb-core

2026-08-03 Python ★ 399
MWDB Core is a malware repository component designed for automated malware collection and analysis systems, facilitating the management and examination of malware binaries and their configurations. Notable features include a robust storage solution, relationship tracking and visualization between objects, a user-friendly interface for querying datasets, and integration capabilities through webhooks and plugins. The tool is aimed at enhancing the effectiveness of malware analysis by providing comprehensive data sharing and user management mechanisms.

PseudoNote

2026-08-03 Python ★ 49
PseudoNote is an AI-enhanced plugin for IDA Pro that streamlines malware reverse engineering by automating tasks such as function renaming, code explanation, and generating human-readable C code. Its key features include a markdown editor for analyst notes, customizable AI prompts for specific functions, and the capability to produce detailed forensic reports, with all generated data saved directly to the IDB file for persistent access. This tool is particularly beneficial for malware analysts seeking efficiency in their analysis workflows.

speakeasy

2026-08-03 Python ★ 2038
Speakeasy is a Windows malware emulation framework designed to execute binaries, drivers, and shellcode within a modeled Windows runtime environment, rather than a full virtual machine. Its primary use case is to provide realistic execution paths for malware analysis by emulating various system behaviors, including APIs, file systems, and network activity. Notable features include the ability to run from a command-line interface for quick triage and the option to integrate as a Python library that generates structured JSON reports.

stringsifter

2026-08-03 Python ★ 759
StringSifter is a machine learning tool designed for ranking strings to enhance malware analysis efficiency. It mimics GNU binutils' `strings` functionality while providing additional capabilities like ranking strings based on relevance, supporting batch processing, and offering customizable output options. Notably, it integrates with various input sources, making it adaptable for extracting insights from memory dumps and obfuscated binaries.

ThreatIntel-Reports

2026-08-03 Python ★ 172
ThreatIntel-Reports is a comprehensive repository designed for the extraction and search of content from numerous threat intelligence reports, enabling users to automatically gather data from various feeds. Its primary use case is to facilitate the exploration of threat intelligence through keyword-based searches in both a web interface and command-line interface, with capabilities to store results in JSON format for integration. Notable features include a custom search bar for predefined results and Python scripts that allow users to perform keyword searches and manage output flexibly.

triager

2026-08-03 Python ★ 22
Triager is a DFIR automation platform designed for Windows triage collections, facilitating the processing and organization of various digital artifacts into investigation-ready CSV files. It features a command-line interface (Triager CLI) for parsing and searching processed results, as well as a web console for multi-case management, enabling centralized evidence analysis, role-based access, and collaboration across multiple machines. Notable capabilities include built-in support for integrating various forensic tools, cross-machine correlation, and advanced features such as AI assistance for generating reports and findings.

ai-reverse-engineering

2026-08-03 Python ★ 154
Rev·Deck is a localized static-analysis workstation that integrates Ghidra with an AI-driven web interface for reverse engineering binaries. It allows users to browse deterministic evidence from analyzed binaries without executing them, while an AI assistant provides fact-based responses citing specific evidence. This tool supports various LLM backends and enables secure, efficient analysis with a user-friendly interface.

awesome-game-file-format-reversing

2026-08-03 Python ★ 207
The "Awesome Game File Format Reversing" repository is a curated collection of tools, documentation, and resources aimed at developers and modders for reverse engineering and manipulating various video game file formats. It encompasses a wide range of asset types, including models, textures, audio, and scripts, providing essential tools for extraction, conversion, and analysis. The repository also encourages community contributions, fostering a collaborative environment for enhancing game modding and development practices.

ghidra-hexagon-sleigh

2026-08-03 Python ★ 41
The Ghidra Hexagon SLEIGH tool provides an implementation of the Qualcomm Hexagon "QDSP6" architecture for the Ghidra reverse engineering framework, enabling comprehensive disassembly of multiple Hexagon instruction versions and HVX support. Notable features include support for hardware loops, constant extenders, and Pcode for numerous operations, alongside specialized scripts for decompression and log message annotation. While modern Ghidra versions offer native Hexagon support, this plugin maintains unique functionalities and caters to specific disassembly needs for advanced users.

IDACLI

2026-08-03 Python ★ 42
IDA-CLI is a command-line interface for IDA Pro and Hex-Rays that allows AI agents to interact with IDA databases directly via a low-latency JSONL protocol, bypassing traditional GUI and middleware constraints. Its primary use case is to facilitate unrestricted execution of IDAPython code for enhanced analysis capabilities, featuring persistent session management, built-in caching, and integration with agent frameworks, enabling features like parallel analysis and dynamic database modifications. Notable functionalities include the ability for agents to execute arbitrary IDAPython commands, simplified installation of agent skills, and support for effective multi-agent collaboration.

mcrit

2026-08-03 Python ★ 103
The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework designed to streamline the implementation of the MinHash algorithm for code similarity analysis, specifically targeting disassembled function comparisons. It integrates with disassembly reports from SMDA and features both a REST API for server interaction and a command-line interface (CLI) for user operations, with persistent data storage facilitated by MongoDB. Notably, MCRIT allows for easy deployment through Docker, ensuring compatibility across its components.

MoovitPatcher

2026-08-03 Python ★ 16
A patcher for the moovit application to unlock premium features and removed ads.

nge_2_re

2026-08-03 Python ★ 15
The EVA-zh-Hans/nge_2_re project is focused on creating a comprehensive and reproducible Chinese localization patch for the PSP game "Neon Genesis Evangelion 2: The World Created." It includes notable features such as text structure parsing, translation management, and automated patch building, enabling it to successfully replicate the game's intricate internal mechanics and narrative elements. The project leverages advanced technologies like machine translation and relational database storage for efficient handling of translation tasks.

openskp

2026-08-03 Python ★ 34
OpenSKP is an open-source, cross-platform parser for SketchUp (`.skp`) binary files that allows developers to access and manipulate 3D model data programmatically without the need for the SketchUp application or its SDK. It supports both modern and legacy file formats, offering features such as 3D geometry extraction, dynamic component handling, scene baking, and export capabilities to various formats including GLB and OBJ. Built in multiple programming languages, it emphasizes low-memory parsing and includes comprehensive observability for error management.

Pyamoto

2026-08-03 Python ★ 12
Pyamoto is an enhanced level editor for the game Super Mario Maker, designed as an advanced fork of the original Miyamoto editor, primarily aimed at improving functionality and user experience. It features a streamlined installation process, supports automated releases and Homebrew installation for macOS, and includes comprehensive usage documentation on its wiki. Notably, Pyamoto encourages community contributions and offers a dedicated environment for developers to collaborate and contribute to the project.

pylabview

2026-08-03 Python ★ 147
Pylabview is a set of Python tools designed for extracting, modifying, and recreating LabVIEW RSRC files, such as VIs and CTLs. Its primary use case involves enabling batch processing of these files, allowing users to make bulk modifications outside the LabVIEW GUI, and facilitating the recovery of files that LabVIEW cannot read. Notable features include the capability to extract RSRC files into a structured format for easier manipulation, support for binary and text extraction, and the generation of outputs that aim for binary-level fidelity to the originals, despite some known exceptions.

quokka

2026-08-03 Python ★ 226
Quokka is a binary exporter that facilitates the manipulation of binary files without the need for ongoing disassembly after the initial export, supporting disassembly backends like IDA Pro, Ghidra, and Binary Ninja. It provides a clean interface by abstracting the APIs of various disassemblers and generates .quokka files, which can be loaded for further processing. Notable features include the ability to export in LIGHT mode for block-level data export and the upcoming FULL mode for comprehensive instruction and operand exporting.

Reversecore_MCP

2026-08-03 Python ★ 194
Reversecore MCP is an AI-powered server designed to facilitate reverse engineering and security analysis by integrating 120 analysis tools into a unified interface. It utilizes natural language processing to allow AI assistants to perform tasks like malware analysis, vulnerability research, and source code auditing, significantly simplifying the interaction with complex command-line tools. Notable features include structured tool results that AI can reason about and chain into follow-up queries, making it highly efficient for rapid security assessments and investigations.

HBC-Tool

2026-08-03 Python ★ 28
HBC-Tool is a Hermes bytecode disassembler and assembler specifically designed for React Native bundles, facilitating reverse engineering, inspection, and patching of applications that utilize the Hermes engine. Key features include the ability to disassemble bytecode into a human-readable format (HASM), modify the contents, and reassemble valid Hermes bundles, with options for enhanced performance through native C++ acceleration and fast JSON processing. The tool supports multiple Hermes bytecode versions and offers a command-line interface for various operations such as disassembly and assembly.

llm4free

2026-08-03 Python ★ 357
LLM4Free is a versatile Python toolkit that provides access to over 40 AI models, web search capabilities, and image and voice generation, all through a unified interface that mimics the OpenAI SDK. Its notable features include a built-in free tier for various models, multi-provider support with automatic failover, and an OpenAI-compatible server, allowing for seamless integration and development. The tool is fully typed and documented, making it user-friendly for developers.

skyrim_vr_address_library

2026-08-03 Python ★ 25
The Skyrim VR Address Library is a specialized tool that facilitates the conversion of Skyrim Special Edition (SSE) mod addresses to their corresponding Virtual Reality (VR) addresses, enabling modders to adapt existing mods for use in Skyrim VR. It provides a collection of CSV files that serve as a community resource for identifying and mapping addresslib IDs, along with automated and manual verification of addresses to ensure compatibility. Notable features include a comprehensive database for address mapping, release CSV generation for plugin integration, and analysis CSVs to assist in tracking changes and maintaining accurate mappings across various Skyrim versions.

xiaomi-hyperos-bootloader-unlock

2026-08-03 Python ★ 26
Xiaomi MTK Bootloader Unlock is a tool designed to bypass the Dual-Layer Lock Verification for Xiaomi MTK devices running HyperOS or MIUI14+. It enables the unlocking of the bootloader by erasing a specific magic string stored in the Replay Protected Memory Block (RPMB), thus allowing the device to revert to the seccfg unlock state. The tool requires specific hardware conditions and careful execution to prevent common pitfalls associated with USB connections during the unlocking process.

AGaMEMnon

2026-08-03 Python ★ 46
AGaMEMnon is an SDK that facilitates the synthesis and generation of flashable bitstreams for the AG32 microcontroller and its integrated FPGA fabric, enabling users to leverage a fully open toolchain without vendor binaries. It allows for Verilog-based development, providing functionalities such as synthesis, placement, routing, and programming, effectively serving as an IceStorm-like solution tailored to this unique RISC-V and FPGA combination. Notable features include support for real hardware peripherals and flexible integration of custom logic on the FPGA, making it a versatile tool for embedded systems development.

d810-ng

2026-08-03 Python ★ 293
D-810 ng is an IDA Pro plugin designed to enhance reverse engineering by deobfuscating code during the decompilation process. It integrates seamlessly into the IDA workflow and allows for the rapid creation and configuration of deobfuscation rules, significantly simplifying complex expressions and restoring natural control flow. Notable features include a wide array of instruction-level optimizations, such as mixed Boolean arithmetic and constant folding, as well as control-flow unflatteners that tackle various obfuscation techniques, making it a comprehensive tool for malware analysis.

DeepZero

2026-08-03 Python ★ 626
DeepZero is an automated vulnerability research pipeline engine that allows users to define and orchestrate data processing workflows using YAML configuration files. Notable features include support for parallel execution, resumable runs, integration with language model providers, and extensibility for custom processing components, making it ideal for analyzing and assessing vulnerabilities in a target corpus of files. The tool is built to enhance efficiency in vulnerability research while ensuring fault tolerance and state management during execution.

digital-fauxice

2026-08-03 Python ★ 40
Digital Fauxice is an open-source tool that emulates the infrared dust and scratch removal functionality of Nikon's Digital ICE, producing identical image outputs without utilizing Nikon's code. Its primary use case is to process scanned film images by leveraging a four-channel input (RGB and infrared) to accurately identify and repair surface defects, while an optional hybrid mode enhances defect handling by integrating modern inpainting techniques for severe damage. Notable features include a validation mechanism that ensures output fidelity to Nikon's original processing and a CUDA-backed implementation for accelerated processing times.

gpmc

2026-08-03 Python ★ 320
GPMC is a cross-platform Python library and CLI tool designed for uploading media files to Google Photos using a reverse-engineered mobile API. Its notable features include unlimited uploads in original quality, automatic detection of existing files to prevent duplicates, album creation based on directory structure, and configurable multithreaded uploads for enhanced performance. The tool supports individual file and entire directory uploads with real-time progress tracking and optional JSON output for programmatic consumers.

open-reverselab

2026-08-03 Python ★ 1094
ReverseLab is an open-source reverse engineering lab designed for capturing and analyzing various attack scenarios across multiple domains, including CTF pentesting, APK reverse engineering, and PE binary analysis. Its notable features include a comprehensive knowledge base organized into specialized categories, over 100 automation tools for rapid execution, and a modular architecture that supports various signal types and attack chains. Users can easily set up the tool on multiple platforms with provided scripts, ensuring a streamlined onboarding experience.

reverseloom

2026-08-03 Python ★ 41
reverseloom is a tool designed to automate the extraction of data from websites protected by advanced bot detection systems, such as Akamai Bot Manager. It employs a unique approach by interacting directly with the browser using a headless environment to reverse engineer the site's protocol, enabling it to generate standalone crawlers that function without a browser. Notable features include complete exposure of the website's DOM, network traffic, and JavaScript debugger, along with the ability to create fully operational, browser-free crawlers that are capable of executing tasks autonomously.

BinNexus

2026-08-03 Python ★ 16
BinNexus is a binary analysis tool designed for Windows binaries (DLL/EXE) that generates an interactive web portal, providing a comprehensive dependency graph and export exploration capabilities. Its primary use case is to facilitate the understanding of binary structures through visualizations of relationships between components, supported by features like global search and noise filtering to enhance analysis precision. The tool is modular, allowing for easy expansion and integration of new analysis engines while offering both static and experimental runtime analysis of dependencies.

r2morph

2026-08-03 Python ★ 51
r2morph is a metamorphic mutation engine that enables tracked binary transformations, operating with structured validation and reporting. It supports various architectures and binary formats, offering 18 diverse mutation passes along with multiple validation modes and comprehensive reporting capabilities in formats such as SARIF and JSON. Key features include session management for rollback, a detection suite for various signatures, and the ability to analyze virtual machine handlers for devirtualization.

ReverseProxyDLL

2026-08-03 Python ★ 41
ReverseProxyDLL is a tool designed to create compatibility scaffolds for legacy x86 Windows DLLs, facilitating reverse engineering by automating the generation of proxy DLL projects. Its notable features include runtime loading of original DLLs, export resolution using `GetProcAddress`, call forwarding, and support for structured logging, all aimed at facilitating a more efficient workflow during the reverse engineering process. This tool stands out from conventional DLL proxy generators by being export and ABI aware, allowing for a more nuanced approach to dealing with complex legacy binaries.

TooGoodToGo-CLI

2026-08-03 Python ★ 27
TooGoodToGo-CLI is a command-line interface tool that automates the checkout process for the Too Good To Go service, allowing users to monitor and reserve magic bags before they sell out. Its notable features include passwordless account login, automatic handling of the checkout flow including 3DS challenges, an interactive menu for ease of use, and customizable notifications for item availability. Designed for simplicity, the tool can be easily configured and used directly from the command line without requiring additional software.

asmtransformers

2026-08-03 Python ★ 15
ASMTransformers is a machine learning tool designed for analyzing ARM64 assembly functions by comparing them to a database of known functions to facilitate reverse engineering tasks. Its architecture includes a training and inference module, a FastAPI backend for service management, and a Ghidra frontend for user interaction, with models available on Hugging Face. Notable features include dynamic similarity scoring and an integration framework for seamless use within Ghidra.

chomper

2026-08-03 Python ★ 621
Chomper is a lightweight emulation framework designed for security algorithm testing in iOS executables and libraries, with limited support for Android native libraries. It supports the emulation of ELF and Mach-O binaries and integrates with the Unicorn engine for dynamic analysis, allowing users to engage with Objective-C runtime and directly manipulate security algorithms. Notable features include automatic loading of iOS system libraries and comprehensive API support for invoking functions and managing memory.

Kreo-Hive65-Rgb-Linux

2026-08-03 Python ★ 31
Kreo Hive 65 is a Linux utility for controlling the RGB lighting of the Kreo Hive 65 keyboard without requiring Windows software. It allows users to set individual key colors, create gradients, and utilize an audio-reactive mode that transforms the keyboard's lighting into a dynamic visualizer synchronized with sound output. Notable features include the ability to run complex lighting effects based on audio input, with customizable options via command-line parameters.

P2-FR-IS-PSP

2026-08-03 Python ★ 54
The repository provides a comprehensive French translation patch for the PSP game "Persona 2: Innocent Sin" (ULES01557), enabling users to play the game entirely in French. Key features include a fully playable main storyline, modifications to dialogue formatting, and ongoing updates to enhance the patch, which is built alongside custom romhacking tools tailored for the game. The project emphasizes legal use, requiring users to obtain their original game disc to apply the patch.

PCM-Forge

2026-08-03 Python ★ 29
PCM-Forge is an open-source activation code generator and diagnostic toolkit specifically designed for Porsche PCM 3.1 infotainment systems, utilizing a fully cracked RSA-64 encryption algorithm to generate activation codes for any vehicle identification number (VIN) at no cost. The tool features a web application that includes functionalities for creating activation codes, building USB sticks for installation, and providing modular diagnostic utilities tailored for various Porsche models, ensuring compatibility with different hardware revisions.

TryHackMeWriteups

2026-08-03 Python ★ 17
TryHackMeWriteups is a comprehensive repository that curates free TryHackMe rooms, providing organized resources for cybersecurity enthusiasts to learn and practice various skills. Notable features include categorized rooms across diverse topics, detailed notes and summaries, step-by-step writeups for Capture The Flag challenges, and continuous updates, making it an ideal starting point for beginners in cybersecurity and ethical hacking.

defcon-2017-tools

2026-08-03 Python ★ 96
The DEFCON CTF 2017 repository features a collection of tools developed for the DEFCON 25 Capture The Flag competition. It includes an assembler with custom macros, a binary patcher, flag encryption utilities, IDA plugins for disassembly viewing, and PCAP analysis tools. Notable features include enhanced disassembly capabilities and various utility scripts aimed at improving offensive security techniques.

AleJndCTF

2026-08-03 Python ★ 10
AleJndCTF is an open-source Capture The Flag (CTF) platform designed for competitive cybersecurity training, specifically in jeopardy-style formats as well as attack and defense scenarios. This tool enhances CTF event organization with features inherited from various forks of the original tinyctf-platform, enabling easy setup and customization for users. Notably, it supports scalable deployments via Flask and includes simple documentation for user guidance.

ancypwn

2026-08-03 Python ★ 154
Ancypwn is a CTF pwnable challenges environment helper that leverages Docker to provide a modular and isolated setup for debugging and exploiting vulnerabilities. It includes pre-packaged tools such as pwndbg, pwntools, and various disassemblers, with a flexible plugin system for backend and terminal options, facilitating seamless integration and execution of complex commands within a contained environment. Its primary use case is to streamline the process of interacting with CTF challenges while maintaining a consistent and manageable workspace.

Auto-AWD

2026-08-03 Python ★ 30
Auto AWD is a tool designed to automate the execution of payloads and submission of flags to a platform during competitive scenarios. Its primary use case is in automated gameplay for challenges or competitions, allowing users to configure game rules through a YAML file. Notable features include cross-platform compatibility (Windows, Linux, macOS) and an easy setup process using Python and pip.

awd-frame

2026-08-03 Python ★ 87
awd-frame is a Capture The Flag (CTF) framework designed to automate manual tasks during competitions, aiming to improve efficiency and maintain focus. It allows for batch SSH logins, password modifications, and command executions, along with semi-automated attack capabilities utilizing specified payloads and webshells for deploying backdoors. The tool supports both GET and POST methods for payload submission, although flag submission integration varies depending on competition configurations.

beard

2026-08-03 Python ★ 14
Beard is a tool designed to facilitate the tracking of progress for teams participating in Attack/Defense Capture The Flag (CTF) competitions, providing real-time insights into scoreboard data. It features parsing capabilities for various scoreboard types (specifically hackerdom and forcad), performance graphs for all teams with automatic scaling, and alerts via Telegram for significant events like flag loss and position changes. Additionally, it offers predictive analytics for scoring trends based on past performance and can be easily deployed using Docker.

bitspec

2026-08-03 Python ★ 15
Bitspec is a bit pattern mini-language tool designed for specifying instruction encodings, converting byte input into an intermediate representation (IR). Its primary use case is in reverse engineering or developing code for architectures like Z80, allowing users to define bit patterns and corresponding operations easily. Notable features include the ability to parse bytecode and generate structured output, as well as comprehensive documentation and example usage provided for developers.

blackhat-python

2026-08-03 Python ★ 30
The "blackhat-python" repository provides resources for a workshop focused on quick-prototyping scripts and tools for ethical hacking using Python. It emphasizes the development of custom hacking tools when existing solutions are insufficient, targeting beginners with basic programming concepts and practical exercises. The workshop content is inspired by the "Black Hat Python" book and aims to enhance participants' programming skills within the legal framework of cybersecurity.

blizzardwrap

2026-08-03 Python ★ 16
BlizzardWrap is a command-line interface (CLI) tool developed in Python for encoding and decoding data in various formats, including URL, Morse Code, and Base64 among others. Its primary use case is to facilitate quick and versatile transformations of text representations, making it useful for developers and cybersecurity professionals. Notable features include support for multiple encoding types, ease of installation, and a user-friendly help system.

brutelist

2026-08-03 Python ★ 13
Brutelist is a Python script that automates the creation of seed-based dictionary attack files, primarily used during Capture the Flag (CTF) competitions or penetration testing. It allows users to generate customized password lists by combining seed phrases from a seed list with common patterns specified in a template file. Notable features include support for customizable template patterns and the ability to output the generated dictionary to a specified file.

Cannon

2026-08-03 Python ★ 19
Cannon is a post-exploitation framework developed in Python, designed primarily for Unix-based systems to facilitate post-access tasks on compromised machines. Its functionalities include uploading and downloading files, executing pre-defined modules, and harvesting reverse shells, making it a powerful tool for security professionals and penetration testers. The framework also offers some compatibility with Windows systems, expanding its utility across different platforms.

cryptz

2026-08-03 Python ★ 21
cryptz is an advanced encryption and decryption tool designed for secure data handling. Its primary use case involves encrypting sensitive information to prevent unauthorized access, and it features a user-friendly command-line interface to facilitate easy implementation. The tool is built using Python, with dependencies managed via a requirements file.

CTF-RSA-tool

2026-08-03 Python ★ 521
CTF-RSA-tool is a Python and Sage-based utility designed to assist CTF participants in efficiently solving basic RSA challenges during competitions. It automates the identification of input parameters, selects appropriate attack methods, and provides multiple functionalities for generating public keys, dumping key details, and decrypting encrypted messages. Notable features include a variety of implemented attack methods, such as Fermat's factorization, Wiener's attack, and support for input via text files, enhancing usability for quick solutions to common RSA problems.

CTFsubmitter

2026-08-03 Python ★ 71
CTFsubmitter is a centralized flag submission service designed for use in Capture The Flag (CTF) competitions, which filters and manages flag submissions to prevent flooding with invalid entries. It features a REST API for submitting flags, stores submission statistics in a MongoDB database, and requires both a submitter and a worker instance for functionality. The tool operates using bottle.py and cherrypy, with an additional stats service built on tornado, allowing for real-time monitoring and management of flag submissions.

etherblob-explorer

2026-08-03 Python ★ 43
EtherBlob Explorer is a tool designed for the extraction and analysis of blob files from the Ethereum blockchain, leveraging the Etherscan API. It allows users to search for various human-generated data types across multiple Ethereum networks, using diverse methods such as embedded file detection, ASCII string extraction, and entropy-based searches. Notable features include support for five Ethereum test networks, user-defined search parameters, and the ability to log search results for further analysis.

firstblood

2026-08-03 Python ★ 37
FirstBlood is a Python 3 library designed to extend built-in objects and enhance utility functions, primarily for rapid development in Capture The Flag (CTF) scenarios. Notable features include method chaining for easier function calls, advanced manipulation of strings and bytes, and integrated cryptographic functions such as XOR and various hashing algorithms. However, users should exercise caution, as the library may alter standard Python behavior and is not intended for production environments.

flagWarehouse

2026-08-03 Python ★ 13
FlagWarehouse is a Flask-based flag submission system designed for Attack/Defense Capture The Flag (CTF) competitions, utilizing SQLite for data management. It allows teams to submit flags to a verification server while providing a user-friendly web interface to display statistics and manage flag submissions efficiently. Key features include customizable configurations for flag formats and submission intervals, automatic flag extraction from exploits, and real-time feedback on submissions.

jwtXploiter

2026-08-03 Python ★ 291
jwtXploiter is a security testing tool designed to assess the vulnerabilities of JSON Web Tokens (JWTs). It enables penetration testers and developers to exploit known CVEs, manipulate token payloads, verify JWTs, and perform key confusion attacks by retrieving public keys from SSL connections. Notable features include support for all JWT algorithms, automated generation of JSON Web Keys (JWK), and the ability to tamper with vulnerable header claims like kid, jku, and x5u.

karkinos

2026-08-03 Python ★ 197
Karkinos is a comprehensive library database tool designed for binary exploitation on Linux, facilitating the identification of unknown libraries and their associated symbols. It provides capabilities to locate library packages, dump useful symbols and gadgets for return-oriented programming (ROP), and supports various architectures, including x86, ARM, and more, by indexing a wide range of libraries like glibc and libstdc++. Key features include commands to find libraries by offsets, dump detailed library information, and update the internal database autonomously.

KeyboardTraffic

2026-08-03 Python ★ 17
KeyboardTraffic is a tool designed for analyzing keyboard traffic packets, primarily used in CTF (Capture The Flag) competitions. It allows users to process and interpret captured keyboard data through a straightforward command-line interface. Notable features include the capability to handle various packet formats, facilitating post-analysis of keystroke data for security assessments.

LCGHack

2026-08-03 Python ★ 17
LCGHack is a command-line tool designed for generating pseudo-random numbers using the Linear Congruential Generator (LCG) algorithm. It allows users to input known values and customize parameters such as modulus, multiplier, and increment, facilitating easy calculations of the next values in the sequence. Notable features include customizable parameters and straightforward usage through a command-line interface.

magnetos

2026-08-03 Python ★ 25
Magnetos is a tool designed to enhance problem-solving efficiency in Capture The Flag (CTF) competitions by automating various tasks related to digital forensics and steganography. It features several command-line utilities, including a steganography solver, file format identifier, encoding detector, and automated resource downloader, enabling users to quickly analyze files, detect flags, and handle common challenges encountered in CTF events. Notable integrations include dependencies on tools like zsteg and stegdetect for comprehensive analysis capabilities.

MT19937-Symbolic-Execution-and-Solver

2026-08-03 Python ★ 40
The MT19937 Symbolic Execution and Solver tool provides a mechanism for symbolic execution of the MT19937 pseudorandom number generator, alongside a solver for GF(2) matrices, enabling cloning of the generator based on known outputs. Notable features include a Python-only solver for faster performance without dependencies and a wrapper for Cryptominisat, which enhances speed with proper compilation. The tool also facilitates state reversal of the MT19937 generator to predict prior outputs, despite some current limitations in functionality.

Nosql-MongoDB-injection-username-password-enumeration

2026-08-03 Python ★ 176
The Nosql-MongoDB-injection-username-password-enumeration tool is designed to enumerate usernames and passwords from NoSQL (MongoDB) injection vulnerable web applications. Its primary use case is to facilitate the exploitation of NoSQL injection vulnerabilities by allowing users to specify various parameters and methods for form submission and enumerating user credentials. Notable features include customizable parameters for targeting specific username and password fields, as well as flexibility in defining the HTTP method for the exploitation process.

NullCTF

2026-08-03 Python ★ 144
NullCTF is a Discord bot built with discord.py that facilitates collaboration for Capture The Flag (CTF) events within Discord servers by providing tools for team management and CTF participation. Notable features include commands for creating and archiving CTFs, managing challenges, and integrating with the CTFd platform for challenge data retrieval. The bot also supports commands for accessing CTFtime information, allowing users to track CTF countdowns and time left for ongoing competitions.

overflow-checker

2026-08-03 Python ★ 19
Overflow Checker is a utility designed to assess the vulnerability of simple binaries to basic buffer overflow attacks. It allows users to specify the program for analysis and the maximum number of bytes to test, making it customizable for different scenarios. Notable features include an easy-to-use command-line interface and the ability to demonstrate functionality with provided demo binaries.

patsac

2026-08-03 Python ★ 10
`patsac` is a Python toolkit designed to assist users in solving cryptography challenges, particularly in Capture The Flag (CTF) competitions. The toolkit includes functionalities for various cryptographic attacks, such as RSA decryption using Fermat's method and Linear Congruential Generators (LCG) cracking, making it a practical resource for cryptographic analysis and experimentation. It relies on several external libraries for enhanced computational capabilities, although it is still under development and may lack comprehensive documentation.

PHPFun

2026-08-03 Python ★ 20
PHPFun is a code obfuscation tool that allows developers to write and execute PHP code using only six specific characters, inspired by techniques in other programming languages. Its primary use case is to create compact and obfuscated PHP scripts that maintain functionality while obscuring their logic. Notable features include support for PHP 7 and higher, and the ability to transform conventional PHP code into a highly condensed format without losing execution capability.

pwn-server

2026-08-03 Python ★ 17
pwn-server is an automated deployment tool designed for pwn challenges, utilizing containerization to isolate each challenge environment. It features token-based connection management, supports multiple flags per challenge, and automatically logs traffic and flag access while preventing resource exhaustion through fork bomb protection. The tool also allows customization of Docker images per challenge, facilitating diverse runtime requirements.

PwnSandboxForCTF

2026-08-03 Python ★ 97
PwnSandboxForCTF is a ptrace-based sandbox designed specifically for Capture The Flag (CTF) challenges operating in an AWD mode. It restricts child processes from performing certain actions, particularly those involving files with 'flag' in their name, and illegal system calls, providing support for both ELF32 and ELF64 binaries including Position Independent Executables (PIE). Notable features include its simple installation via pip, the generation of a sandboxed binary, and built-in support for the pwntools library.

pwntools-r2

2026-08-03 Python ★ 22
pwntools-r2 integrates the `radare2` reverse engineering framework with `pwntools`, allowing for streamlined debugging of exploits in a Python2 environment. Its primary use case is to facilitate the development of exploits by automating interactions with `radare2` commands, particularly within a `tmux` session. Notable features include support for executing `radare2` commands within Python scripts and handling process arguments via temporary payload files.

revshfuzz

2026-08-03 Python ★ 17
A tool for fuzzing for ports that allow outgoing connections

RSA-Common-Modulus-Attack

2026-08-03 Python ★ 41
RSA-Common-Modulus-Attack is a Python 3 script designed to exploit the common modulus vulnerability in RSA encryption by recovering plaintext messages from two ciphertexts encrypted with the same modulus but different exponents. The tool requires the public keys of both ciphertexts and operates under the condition that the greatest common divisor of the two exponents is 1. Notable features include a simple command-line interface for inputting ciphertexts and public keys, as well as dependency management through a requirements file for easy installation.

SSH-BruteForce

2026-08-03 Python ★ 16
SSH Brute-Force is a simple Python script designed for brute-forcing SSH credentials against an OpenSSH server. Its primary use case is for ethical hacking and penetration testing, specifically within environments like HackTheBox. Notable features include the ability to execute commands upon successful authentication and the requirement of the pwntools library, though it is advised that users enhance its functionality to mitigate potential defenses against brute-force attacks.

Stegall

2026-08-03 Python ★ 13
Stegall is an automation tool designed to facilitate the use of popular steganography tools, primarily targeted towards participants in Capture The Flag (CTF) challenges. It encompasses a suite of 12 key tools, including Steghide and Exiftool, and provides streamlined commands for tasks such as extracting hidden text, analyzing metadata, and detecting concealed data within various file formats. The tool requires Python 2.7 and simplifies the steganographic process by automating tool suggestions, installations, and executions based on user inputs.

tankigen

2026-08-03 Python ★ 14
Tankigen is a command-line tool for generating a variety of reverse shell payloads, drawing from established cheat sheets by PayloadsAllTheThings and Pentestmonkey. It supports multiple scripting languages such as Bash, Python, and PowerShell, allowing users to easily create reverse shells for capture the flag (CTF) challenges and penetration testing scenarios. Notable features include the capability to list available shell types and generate all shells simultaneously, enhancing the tool's flexibility for security professionals.

vulnlab

2026-08-03 Python ★ 23
vulnlab is a tool designed to manage an OSCP-like lab environment by providing a web control panel for resetting virtual machines. Utilizing Flask and the pyvmomi library, it allows users to easily reset configured VMs through a simple web interface, with output accessible via HTTP requests. Notable features include the ability to configure VM settings for non-persistent disk changes and web-based controls for VM lifecycle management.

web-ctf-help

2026-08-03 Python ★ 20
Web-CTF-Help is a set of Python scripts designed for assisting participants in web Capture The Flag (CTF) competitions by scraping relevant information from target websites. Its primary use case involves extracting HTML comments, JavaScript sources, image sources, and interesting HTTP headers, with features allowing for selective output based on user-defined parameters, including cookie management for authenticated requests. Future enhancements may include functionality for downloading extracted resources.

wiz-search

2026-08-03 Python ★ 10
Wiz-search is a Python-based offline search tool designed for the Mac version of Wiz Note, enabling full-text search capabilities even without internet access. It analyzes the application's data storage structure, which uses SQLite for metadata and ZIP compression for notes, and employs Whoosh and Jieba for indexing and searching. Key features include the ability to create and update an index, facilitating seamless offline access to notes during situations such as offline CTF competitions.

0xTwin

2026-08-03 Python ★ 23
0xTwin is a Python-based tool for encoding and decoding text using the Twin-Hex Cipher, which transforms original text into a hex format, encoding two characters at a time. Its primary use case is for participants in Capture The Flag (CTF) events who need an offline utility to handle this specific cipher without relying on online resources. Notable features include simple command-line options for encoding and decoding, making it straightforward to use in various cybersecurity challenges.

basecrack

2026-08-03 Python ★ 583
BaseCrack is a Python-based decoding tool that supports a wide range of alphanumeric base encoding schemes, allowing for the rapid decoding of both single and multi-encoded inputs. Notable features include the ability to decode bases embedded in image EXIF data, perform OCR on images, and process multiple encodings from files, making it particularly useful for tackling complex Capture The Flag (CTF) challenges and steganography tasks.

bug-bounty-tips

2026-08-03 Python ★ 37
The bug-bounty-tips repository provides a comprehensive collection of resources and tools tailored for bug bounty hunters. It includes a curated list of required scripts and tools like Amass, SQLMap, and Fuff, facilitating efficient reconnaissance and vulnerability assessment. The repository emphasizes community engagement through platforms like Telegram and Twitter, aiming to enhance knowledge sharing among cybersecurity professionals.

cryptosploit

2026-08-03 Python ★ 31
Cryptosploit is a module-based cryptographic tool designed to streamline the process of decryption, decoding, and cracking through an organized library of scripts. It automates common cryptographic tasks, allowing users to easily search and execute various cryptographic modules without the need for extensive command-line flags or multiple tools. Key features include a user-friendly console interface for module selection, variable management, and the ability to search for modules using regular expressions.

CTF-CryptoTool

2026-08-03 Python ★ 68
CTF-CryptoTool is a Python-based utility designed for deciphering encrypted text encountered in Capture The Flag (CTF) challenges by employing brute-force techniques across a comprehensive array of known ciphers, encodings, and obfuscators. It allows users to input cipher text and optional keys to facilitate decoding, making it particularly useful for cryptanalysis tasks where keys may be unknown. Notable features include support for multiple ciphers such as Caesar, Vigenere, and various encoding formats like Base64 and Hex.

CTF-nc-docker

2026-08-03 Python ★ 40
CTF-nc-docker is a Dockerized environment designed for hosting Capture The Flag (CTF) challenges, supporting various challenge types including Python, Node.js, and binary challenges. The tool facilitates easy configuration through `global.json` and challenge-specific `config.json`, allowing users to manage resources, ports, and dependencies effectively. Key features include a download server for challenge files, a web-based netcat service, and logging capabilities for monitoring challenge execution.

CTF-Tools

2026-08-03 Python ★ 18
CTF-Tools is a Python-based suite designed for Capture The Flag (CTF) competitions and penetration testing practice, offering functionality for repeating HTTP requests and robust password cracking. Its notable features include a versatile password cracker that supports brute force and dictionary attacks across various hashing algorithms (MD5, SHA-1, SHA-256, SHA-512, NTLM, and bcrypt), with the ability to generate custom hash dictionaries and a Cascade option for iterating through hash types.

CTF-Writeup

2026-08-03 Python ★ 10
The CTF Writeup repository compiles a series of challenge write-ups primarily for web and miscellaneous categories within Capture The Flag (CTF) competitions. It serves as a resource for participants looking to understand solutions and methodologies applied in various CTF events, featuring detailed documentation for each specific competition. Notable features include links to individual event pages on Ctftime for further exploration.

ctfhub

2026-08-03 Python ★ 82
CTFHub is a collaborative platform designed for Capture The Flag (CTF) teams to manage and engage with challenges efficiently. It features a Docker-based setup, integration with HedgeDoc for markdown note-taking, private CTF capabilities for individual learning, and additional tools like Discord notifications and Jitsi for video chats, facilitating enhanced team communication and project management.

DailyCTFRobot

2026-08-03 Python ★ 11
DailyCTF Robot is a Python-based Discord bot designed for hosting and managing Capture The Flag (CTF) challenges, providing an organized platform for both organizers and participants. It features dynamic bot presence, role-based management, an intuitive user interface, versatile command options, event logging, and security protocols, ensuring a tailored and secure experience for different servers. Additionally, the bot facilitates continuous improvement through user feedback after challenge submissions.

dfuf

2026-08-03 Python ★ 19
dfuf is a tool designed to extract files from the request and response dumps generated by ffuf, which is primarily used for exploiting Local File Inclusion (LFI) and Directory Traversal vulnerabilities. Notable features include the ability to specify output directories and handle various file extraction scenarios, such as extracting common Linux files and accessing files in webroot through URL double encoding. This tool enhances the data exfiltration process when shell access is not feasible.

example-ctf-challenge

2026-08-03 Python ★ 34
The Example Ethereum CTF Challenge repository provides a framework for creating and hosting Capture The Flag (CTF) challenges related to Ethereum, utilizing the underlying architecture developed by Paradigm. It allows users to deploy private blockchain instances for various challenges and includes features for interacting with these instances via network connections. Notable functionalities include Docker integration for easy setup and configuration, as well as tools for administering challenge instances and obtaining flags.

Flask-Unsign-Wordlist

2026-08-03 Python ★ 45
Flask Unsign Wordlist is a lightweight Python package designed to provide standalone access to a collection of wordlists used for unsigning Flask cookies. Its primary use case is to assist developers and security professionals in recovering secret keys without having to download the entire flask-unsign library. Notable features include easy installation via pip, command-line access to wordlists, and straightforward Python integration for obtaining lists programmatically.

grepaddr

2026-08-03 Python ★ 68
GrepAddr is a versatile command-line tool designed to extract a wide variety of address types from standard input, including URLs, IP addresses, e-mail addresses, and MAC addresses, utilizing regular expressions for processing. Its primary use case is for penetration testing and bug bounty hunting, where users need to quickly identify multiple address formats in data streams. Key features include support for filtering by address type, options to reduce false positives, and the ability to save results in CSV format, making it a comprehensive solution compared to similar tools that focus on single address types.

Hack-Tool

2026-08-03 Python ★ 50
Hack-Tool is a comprehensive all-in-one hacking tool tailored for cybersecurity professionals, providing a suite of utilities for various hacking tasks, including information gathering, web attacks, and post-exploitation analysis. Notably, the tool enhances functionality with recent updates that incorporate new features such as reverse engineering tools, remote administration tools (RAT), and advanced web crawling capabilities. Operating on Linux-based systems like Kali Linux and Parrot OS, it supports a wide range of offensive security operations.

haipy

2026-08-03 Python ★ 11
Haipy is a command-line interface (CLI) tool designed for identifying over 500 types of hash algorithms. This Python port of the original "haiti" tool includes support for modern hashing algorithms such as SHA3 and Keccak, can be utilized as a Python library, and provides references to Hashcat and John the Ripper, making it a flexible option for cybersecurity professionals. Notably, Haipy aims to be hackable, allowing users to extend its functionality as needed.

hash-length-extension

2026-08-03 Python ★ 39
The length-extension-tool is a Python library that implements hash length extension attacks and supports multiple hashing algorithms, including MD5, SHA1, and SHA256. Its primary use case is to exploit vulnerabilities in hashing algorithms that utilize the Merkle-Damgård construction, allowing an attacker to append data to a hashed message without knowing the original input. Notable features include a straightforward API for computing hashes and performing extension attacks, as well as built-in tests to validate the implementation against standard Python hashing libraries.

hydrogen

2026-08-03 Python ★ 18
Hydrogen is a versatile tool designed for Capture The Flag (CTF) competitions, offering functionalities like encoding conversions, file transformations (to hexadecimal/Base64), and classical cipher decoding. Notable features include an HTTP proxy for traffic analysis and request replay capabilities, as well as built-in decryption tools for AES and RSA, all integrated within a user-friendly web interface utilizing Vue and Tornado in a Python environment.

NoSQL-Attack-Suite

2026-08-03 Python ★ 66
NoSQL-Attack-Suite provides automated scripts designed to exploit vulnerabilities in NoSQL databases, specifically targeting authentication bypass and credential enumeration. The tool features two primary scripts: one for identifying NoSQL authentication bypass vulnerabilities in login forms, and another for character-by-character credential dumping from the database when such vulnerabilities are present. Both scripts are tailored for testing against specific configurations, such as those found in HackTheBox challenges.

padding_oracle.py

2026-08-03 Python ★ 39
The `padding_oracle.py` tool automates padding oracle attacks in Python, enabling efficient decryption and encryption of vulnerable tokens. It features multi-threaded execution for improved performance, customizable logging options, and includes additional functionalities for URL and base64 encoding/decoding. This tool is particularly useful in penetration testing scenarios where padding oracle vulnerabilities are present.

png-parser

2026-08-03 Python ★ 102
png-parser is a Python tool designed for analyzing PNG files by displaying their various chunks, such as header, palette, and textual content. Its primary use case includes inspecting the integrity and structure of PNG images through features like chunk data retrieval, CRC validation, and hex output. The tool offers command-line options for printing specific chunk information, displaying images, and saving corrected versions of PNG files, making it valuable for developers and analysts dealing with image processing.

pwndra

2026-08-03 Python ★ 708
Pwndra is a collection of utilities designed to enhance the Ghidra reverse engineering environment, specifically for pwn and Capture the Flag (CTF) challenges. Key features include the ability to replace constants with human-readable counterparts, annotate system calls and their arguments, conveniently convert character representations, and quickly navigate to the main function of binaries. This toolset streamlines the analysis workflow, improving usability for cybersecurity practitioners working with various CPU architectures.

python4pentesters

2026-08-03 Python ★ 10
The `python4pentesters` repository provides a toolkit designed for automating various tasks related to penetration testing, inspired by TryHackMe's "Python for Pentesters" room. Key features include tools for subdomain discovery, directory enumeration, network scanning, port scanning, file downloading, and password cracking, all of which can be modified for specific security engagement needs. The package serves as a foundational codebase for developing hacking scripts with improved console output and usability.

recursive-compression

2026-08-03 Python ★ 11
The recursive-compression tool facilitates the recursive compression and decompression of nested archive files utilizing multiple algorithms supported by the Patool library. It offers customizable options for character sets, rounds of compression, and progress tracking, while notably lacking support for password-protected archives. This tool can be particularly useful in scenarios requiring the management of complex archive structures in batch processing or automation tasks.

Reverge

2026-08-03 Python ★ 18
Reverge is a Python-based tool designed for extracting and converting hexadecimal data from files, primarily utilized in Capture The Flag (CTF) competitions within the forensic category. Key features include support for file extraction and conversion between hexadecimal and binary formats, making it a valuable asset for digital forensics practitioners and enthusiasts.

RTB-CTF-Framework

2026-08-03 Python ★ 110
The RTB-CTF Framework is a lightweight, efficient Capture The Flag (CTF) management tool built with Flask, designed to facilitate the organization and execution of CTF events. It offers notable features including real-time scoreboard tracking, configurable settings for customization, user account management, and robust administrative controls, making it suitable for scalable CTF deployment in various environments like Heroku and Railway. The framework is user-friendly, providing a simple user registration process and extensive logging capabilities, ensuring a comprehensive management experience for CTF organizers.

ShellValley

2026-08-03 Python ★ 13
ShellValley is a user-friendly reverse shell generator tool designed for Capture The Flag (CTF) enthusiasts who require quick shell generation directly from the terminal. It supports multiple reverse shell types, including bash, php, python, and many others, allowing users to specify the shell type, IP address, and port easily through a command-line interface. The tool emphasizes educational use, warning against illegal activities and ensuring adherence to regulations.

webgrep

2026-08-03 Python ★ 114
WebGrep is a versatile command-line tool designed to search web pages and their associated resources for specified patterns, enhancing traditional grep functionality by incorporating advanced features such as JavaScript deobfuscation, CSS unminifying, and image OCR. It allows users to grep through HTML, scripts, and stylesheets, offering various regex options and resource download capabilities, while also emphasizing efficiency with support for temporary file management. This tool is particularly useful for cybersecurity professionals and developers conducting web security assessments or searching for specific content across multiple web resources.

xorhunx

2026-08-03 Python ★ 17
xorhunx is a cryptography tool that implements the XOR cipher, featuring capabilities for encoding, decoding, and brute-forcing encrypted data. It is designed for multi-platform use, with installation instructions available for Linux, Windows, and Termux. Notable features include a straightforward command-line interface to manage the ciphering processes efficiently.

avala

2026-08-03 Python ★ 10
Avala is a tool designed for the rapid development, execution, and monitoring of exploits in attack-defense capture the flag (CTF) competitions. It simplifies the process for teams by allowing them to focus on exploiting vulnerabilities and implementing patches without being bogged down by technical complexities. Notably, Avala is informed by the practical experiences of the Serbian National ECSC Team and provides functionality for integrating with various services to facilitate quick exploit deployment.

AYO

2026-08-03 Python ★ 10
AYO is an efficient Capture The Flag (CTF) environment manager designed to simplify the setup and management of critical variables such as remote hosts, domains, and URLs. Its notable features include the ability to create and manage multiple "boxes," easily configure essential data, and retrieve specific information through simple command-line operations. AYO streamlines the CTF process, making it accessible for users to handle environment variables and configurations quickly.

brutalkeepass

2026-08-03 Python ★ 31
brutalkeepass is a Python tool designed to brute force passwords of KeePass database files, particularly useful when other conversion methods to supported formats fail. It utilizes the pykeepass library, supports command-line argument input for specifying the database and wordlist, and can produce verbose output and entry dumps upon successful password retrieval.

capture_the_flag

2026-08-03 Python ★ 18
Capture The Flag (CTF) is a comprehensive resource repository aimed at facilitating the learning of cybersecurity techniques through hands-on challenges and tools. It includes curated educational links for fundamental Linux skills, web exploitation techniques, and cryptography, while also providing access to various cryptographic tools for encoding and decoding. Notable features include links to prominent learning platforms, video channels for continued education, and tools for steganography and hash cracking, essential for engaging with CTF competitions.

CTF-Heaven

2026-08-03 Python ★ 298
CTF-Heaven serves as a resource hub for CTF (Capture The Flag) participants, offering a collection of security lists, cheatsheets, and wordlists that aid in penetration testing and security assessments. Notable features include organized links to essential tools like SecLists and PayloadsAllTheThings, as well as a dedicated section for esoteric programming languages, which adds a unique element for enthusiasts exploring unconventional coding challenges.

Dragoman--The-Decoder

2026-08-03 Python ★ 16
Dragoman is a versatile decoding tool designed specifically for tackling cryptography challenges in Capture The Flag (CTF) competitions, providing a comprehensive suite of decoding scripts. It includes functionalities for a wide range of ciphers and encoding schemes, such as Base64, Caesar cipher, Morse code, and more, streamlining the process of flag extraction. This tool enhances efficiency by consolidating multiple decoding methods into a single framework, allowing users to quickly switch between different decoders.

Flask-Unsign

2026-08-03 Python ★ 661
Flask Unsign is a command-line tool designed for extracting, decoding, and manipulating Flask session cookies by brute-forcing secret keys. Its primary use case revolves around security testing of Flask applications, enabling users to obtain and decode session data either through direct input or automatic server interactions. Notable features include session cookie decoding, secret key brute-forcing, and the ability to create custom signed session data if the secret key is known.

HackSynth

2026-08-03 Python ★ 316
HackSynth is a sophisticated LLM-based agent designed for autonomous penetration testing using a dual-module architecture comprising a Planner and a Summarizer. Its primary use case is to conduct security assessments, and it is benchmarked against two extensive CTF-based datasets derived from PicoCTF and OverTheWire, featuring 200 diverse challenges. Notable features include its iterative command generation and feedback processing capabilities, enabling comprehensive evaluation of LLM penetration testing agents.

liveexploit

2026-08-03 Python ★ 12
Live Exploit is a comprehensive Python-based tool tailored for Capture The Flag (CTF) challenges, exploit development, and vulnerability research. It offers a rich feature set including buffer overflow payload generation, ROP chain creation, fuzzing, and interactive command execution, all presented through an intuitive command-line interface. This all-in-one toolkit is designed for both novice and advanced users, streamlining numerous exploit-related tasks while being cross-platform compatible.

mkctf

2026-08-03 Python ★ 117
mkCTF is a framework designed to facilitate the creation and management of jeopardy-style Capture The Flag (CTF) challenges, employing a configurable structure for streamlined integration and deployment on CTF infrastructure. Its notable features include the mkctf-cli tool for repository manipulation and challenge management, as well as the mkctf-monitor for regular health checks and reporting, enhancing automation in the challenge deployment process. The framework is tailored for Python environments and emphasizes security protocols for handling challenge data.

S4DFarm

2026-08-03 Python ★ 152
S4DFarm is a modified version of the DestructiveFarm tool designed for automated server management and orchestration in a competitive environment. Its primary use case involves facilitating multiplayer game server deployments, leveraging Docker for containerization, with notable features including customizable configurations for server settings and secure password management.

Vigenere-Decoder

2026-08-03 Python ★ 41
The Vigenère Cipher Decoder is a Python tool designed to decrypt Vigenère cipher text efficiently, utilizing known plaintext or flag formats to significantly reduce decryption time. Key features include an interactive menu for input, command line argument support for flexibility, and a brute force capability for discovering possible keys. This decoder is particularly useful for cybersecurity professionals engaged in cryptanalysis and CTF (Capture The Flag) challenges.

zio

2026-08-03 Python ★ 395
zio is a versatile I/O library designed for exploitation development, offering a unified interface for interacting with local processes and remote TCP sockets. Its notable features include support for both Python 2 and 3, a self-contained single-file installation without external dependencies, and simplified interaction with processes and networks, making it easy to switch between local and remote exploitation workflows.

ataka

2026-08-03 Python ★ 126
Ataka is a command-line tool designed for running exploits in competitive Capture The Flag (CTF) hacking environments, allowing players to create, manage, and test their exploits efficiently. Notable features include the ability to set up exploits with specified target IPs, hot-reload configurations, and a templating system for easy exploit creation. The tool operates within a Docker container, providing a flexible and isolated environment for users to conduct their attacks and tests.

axion

2026-08-03 Python ★ 14
Axion is a versatile toolkit designed for Capture The Flag (CTF) competitions that allows users to control various input/output operations of its integrated tools, streamlining the CTF experience. It is compatible with several popular Linux distributions and requires Python 2.7, enhancing accessibility for cybersecurity practitioners. Notable features include easy installation via a script and a user-friendly command-line interface for launching functionalities.

cheb3

2026-08-03 Python ★ 45
cheb3 is a web3 Capture the Flag (CTF) tool built on the web3.py library, designed to simplify interactions with Ethereum smart contracts. Its primary use case is to facilitate the development of exploits and solutions for blockchain-based challenges, featuring streamlined transaction operations and the ability to load compiled smart contract ABIs efficiently. Notable features include a user-friendly connection interface and utility functions for managing account and contract interactions, making it suitable for both novice and experienced CTF participants.

CloverSec-CTF-Build-Dockerizer-skill

2026-08-03 Python ★ 30
CloverSec-CTF-Build-Dockerizer is a specialized tool designed for generating Docker containers tailored for Capture The Flag (CTF) competitions and vulnerability assessment environments. Its primary use case focuses on automating the conversion of challenge attachments, source codes, and specific directories into Docker images that comply with validated competition platforms, utilizing a structured workflow that significantly reduces manual intervention and uncertainty in the build process. Notable features include stage-specific document handling, improved token efficiency, and automated validation checks, which collectively enhance the operational flow and maintain the quality of deliverables.

Common-CTF-Challenges

2026-08-03 Python ★ 144
Common-CTF-Challenges is a comprehensive resource for Capture the Flag (CTF) competitions, providing categorized notes, command references, and ready-to-use Python scripts for various exploitation techniques including cryptography, binary exploitation, web vulnerabilities, and forensics. Notable features include a structured directory for easy navigation and search functionality using tools like `grep` and `ripgrep` to quickly locate relevant resources during challenges. This tool serves as a practical aid for participants by consolidating essential techniques and scripts in a single, accessible repository.

ctf-dl

2026-08-03 Python ★ 20
ctf-dl is a versatile command-line tool designed for downloading challenges from multiple Capture The Flag (CTF) platforms, including CTFd, rCTF, and HTB. Its key features include the ability to download all challenges, apply filters by category or status, and organize challenges using customizable Jinja2 templates, enhancing both usability and organization for CTF participants.

ctf-helper

2026-08-03 Python ★ 35
CTF Helper is a multifunctional tool designed for Capture The Flag (CTF) competitions and various cybersecurity tasks. It features capabilities for decoding data formats such as Base64 and hex, JWT decoding and brute-forcing, web exploit utilities, and OSINT tools for geolocation and Shodan lookups, all built with modularity and extensibility in mind. This tool serves as a comprehensive resource for security professionals engaging in threat analysis and live security challenges.

ctf-kit

2026-08-03 Python ★ 10
CTF Kit is a versatile toolkit designed to enhance the efficiency of solving Capture The Flag (CTF) challenges by leveraging AI assistance for analysis and documentation. It features seamless integration with AI coding agents through the Claude Code Plugin, automating tasks such as challenge categorization, vulnerability detection, and writeup generation, while also supporting over 20 diverse tool integrations. Its dual architecture consists of a command-line interface for direct interactions and AI-powered skills to enhance the challenge-solving workflow during competitions.

ctfcli

2026-08-03 Python ★ 214
ctfcli is a command-line tool designed for managing Capture The Flag (CTF) events and challenges, integrating seamlessly with the CTFd REST API for challenge deployment. It features capabilities to create event repositories, add and sync challenges from various sources, deploy services, and verify challenge integrity, all while offering a REPL interface and tab completion for enhanced usability. As an alpha-level project, it emphasizes a modular structure with plugin support for custom commands and encourages users to monitor updates closely.

Eruditus

2026-08-03 Python ★ 77
Eruditus is a Python-based Discord bot designed to facilitate capture the flag (CTF) competitions by streamlining team collaboration and enhancing user experience. Key features include managing channels, tracking CTF progress and member participation, and offering utilities for system calls, encoding schemes, and classic ciphers. The bot also supports direct integration with CTF platforms like CTFd and rCTF, allowing users to submit flags, view leaderboards, and automate account management.

exploitfarm

2026-08-03 Python ★ 59
ExploitFarm is a distributed attack platform designed for security competitions, enabling users to easily share and execute exploits in a coordinated manner. The tool facilitates the replication of attacks, flag submissions, and data collection for analysis, all while providing a user-friendly TUI and centralized server management. Key features include client-server architecture, customizable configurations for competition settings, and detailed tracking of attack performance.

ftp-scan

2026-08-03 Python ★ 21
FTP Scanner is a lightweight tool designed for penetration testing and Capture The Flag (CTF) challenges, capable of detecting anonymous logins, listing files, and performing banner grabbing. It features heuristic software and version extraction, alongside a local exploit database lookup for identifying potential vulnerabilities based on the FTP server's banner. This portable tool operates as a single Python script, requiring minimal dependencies and offering customizable usage options, including the ability to specify custom ports and vulnerability database paths.

hackingtool

2026-08-03 Python ★ 79226
HackingTool is an AI-guided, all-in-one security testing toolkit designed for authorized penetration testing, providing access to 215 curated tools across 21 categories such as reconnaissance, web security, and forensics. Its standout feature is the AI layer that translates user queries in plain English into the appropriate tool and command, catering to a diverse audience including penetration testers, researchers, and bug bounty hunters. The tool is built to ensure legal operation on systems for which users have authorization, promoting responsible security practices.

libdebug

2026-08-03 Python ★ 311
libdebug is a Python library designed for programmatic debugging of userland binary executables, aimed primarily at developers and researchers in reverse engineering and exploitation. Its notable features include the ability to access process memory and registers, control execution flow, handle syscalls and signals, and debug multithreaded applications, all while emphasizing high performance. The tool provides seamless integration with GDB for interactive analysis and supports debugging on various Linux architectures.

MyCTFLib

2026-08-03 Python ★ 13
MyCTFLib is a collection of templates for Capture The Flag (CTF) competitions, designed to assist with various challenge types, including exploitation, cryptography, and web vulnerabilities. It features scripts to easily copy relevant libraries for pwn, crypto, and web challenges, streamlining the setup process for participants. The library includes specific tools and functionalities such as exploited scripts, cryptographic algorithms, and web exploitation techniques.

NagoyaSpray

2026-08-03 Python ★ 19
NagoyaSpray is a Python-based tool designed for efficient password spraying, particularly in scenarios like OSCP, PNPT, and CPTS exams. It generates customizable password lists based on seasonal and date-related formats, enabling users to quickly create realistic passwords without the need for complex regex. Key features include the ability to specify prefixes and suffixes, control capitalization, and generate passwords within a defined length, ensuring rapid and effective password testing for various applications.

PwnBox

2026-08-03 Python ★ 50
PwnBox is a container-based environment management tool that simplifies the setup and debugging of Linux pwn (exploitation) environments using Docker. It provides essential tools such as pwndbg, pwntools, and various disassemblers, allowing users to run, list, attach to, and manage pwn environments effortlessly through command-line operations. Additionally, it features the MacOS Subsystem for Linux (MSL), which enables seamless integration and persistence of a Linux environment on macOS, enhancing workflow efficiency.

pwnybot

2026-08-03 Python ★ 10
PWNYBOT is a Discord bot designed for managing channels and roles within a server, tailored for Capture The Flag (CTF) events and community engagement. It enables automated channel organization, role assignment, and thread management, enhancing server functionality for security enthusiasts. Notable features include permissions management, support for multiple guilds, and the ability to configure CTF-related channels and roles via a simple `.env` file setup.

pypentesting

2026-08-03 Python ★ 14
pypentesting is a collection of Python scripts designed to assist with penetration testing, Capture The Flag (CTF) challenges, and various information security tasks. Its notable features include a reverse shell generator, shellcode extraction tool, and utilities for processing directory search results, QR code handling, DNS zone transfers, and more. The repository serves as a useful resource for security professionals seeking to streamline their testing processes and automate common tasks.

python-codext

2026-08-03 Python ★ 301
CodExt is a Python library that enhances the native codecs library by incorporating over 120 additional encodings and custom character mappings, supporting both Python 2 and 3. It features a unique guess mode for multilayer encoding decoding and offers CLI tools for ease of use, facilitating seamless encoding and decoding of various formats including Morse and Braille. Its extensibility allows users to contribute new codecs and macros, making it a versatile tool for developers dealing with diverse encoding requirements.

python-tinyscript

2026-08-03 Python ★ 56
TinyScript is a Python library designed for rapidly developing command-line interface (CLI) tools with minimal code. It simplifies the process by providing a proxy parser for argument handling, a preconfigured logger, and enhancements to common libraries, all while adhering to the DRY and KISS principles, allowing users to focus on the core functionality of their scripts. This development kit serves as an alternative to heavier frameworks by streamlining CLI tool creation without imposing rigid paradigms.

roppy

2026-08-03 Python ★ 27
Roppy is a pwn toolkit designed to facilitate interactions with local processes and networks during exploitation tasks, simplifying the process of pwn challenges. It features a ROP module in active development that leverages symbolic execution for generating ROP chains, aiming to automate and accelerate the exploitation of simpler challenges. The toolkit incorporates various third-party libraries, including pyelftools for ELF file analysis, Keystone for shellcode assembly, and Capstone for disassembly.

sentinel-reverse

2026-08-03 Python ★ 78
sentinel-reverse is an AI-powered autonomous binary reverse engineering tool designed to enhance the efficiency of analyzing complex binaries by automating traditional manual processes. It features capabilities such as AI-driven function decompilation, LLM-based semantic inference for variable naming, and context-aware vulnerability detection, enabling analysis of 50-200 functions per hour with complete data privacy and zero API costs. This tool leverages GPU acceleration and incorporates a multi-round confidence-driven analysis to optimize the reverse engineering workflow.

sigBits

2026-08-03 Python ★ 40
sigBits is a Python-based steganography significant bits image decoder designed to extract hidden data from images, making it particularly useful for CTF challenges and steganalysis. It features versatile extraction capabilities from LSB, MSB, or custom bit positions, supports RGB channel permutation reading, and offers a bruteforce mode to test all RGB permutations. The tool is equipped with a simple command-line interface for easy usage and custom output naming.

StegoForge

2026-08-03 Python ★ 582
StegoForge is an advanced steganography toolkit designed for embedding and extracting hidden data within images, audio, and video files, while also providing a comprehensive suite for digital forensics analysis. Its features include AES-256-GCM encryption, a local web UI for interactions, support for batch processing, and the ability to simulate network behavior on payloads, making it suitable for security researchers and CTF (Capture The Flag) participants. The framework offers zero-dependency binaries for easy deployment across multiple operating systems.

Typhon

2026-08-03 Python ★ 362
Typhon is an open-source tool designed for automating the solution of Python jail (pyjail) challenges, eliminating the need for extensive manual analysis. Key features include a collection of hundreds of gadgets and common bypass methods, as well as functions for various tasks such as remote code execution and file reading, all implemented without third-party dependencies. The tool can be utilized via a command-line interface or a web UI, making it accessible for interactive use in a range of scenarios.

winpwn

2026-08-03 Python ★ 196
Winpwn is a Windows-centric debugging and exploitation toolset designed for both user and kernel modes, built upon Python's capabilities. It supports various debugging environments, including Windbg and GDB, and offers features like process memory manipulation, remote connections, and assembly/disassembly functionalities, making it ideal for security researchers and developers focused on Windows exploitation. The tool is compatible with both Python 2 and 3 and facilitates an extensive configuration for customized debugging sessions.

wshell

2026-08-03 Python ★ 10
WShell transforms web-based command injection vulnerabilities into interactive shells with features such as persistent command history, directory navigation, and file transfers, all while avoiding any file uploads. It automatically detects the target's operating system and adjusts its operations accordingly, providing flexibility in command execution. Notable features include built-in support for HTTP control, extensibility via custom scripts, and efficient handling of input/output for bypassing filters.

bountycatchremix

2026-08-03 Python ★ 29
BountyCatch Remix is a Python-based domain management tool designed for security researchers and penetration testers involved in bug bounty programs. It enhances the original bountycatch.py script with features such as domain validation, automatic duplicate detection, project-based organization, and Redis-backed storage for optimal performance. Key capabilities include bulk domain import, multiple output formats, and advanced logging and error handling, making it a versatile resource for managing and analyzing domain lists efficiently.

ewe

2026-08-03 Python ★ 20
EWE (Execution Workflow Engine) is a robust automation tool designed for executing tasks in structured workflows using JSON or YAML files, ideal for automated reconnaissance and tool orchestration. Key features include parallel task execution, conditional task execution, real-time logging, and an interactive CLI mode for live task management. It facilitates efficient automation by supporting dynamic placeholders and providing both silent and interactive modes for flexibility in various operational environments.

ghmon

2026-08-03 Python ★ 31
ghmon is a command-line security scanning tool designed to identify leaked secrets in GitHub and GitLab repositories by utilizing TruffleHog for in-depth scanning. Its primary use case is for DevOps and security teams to maintain secure code practices through automated discovery of repositories, continuous monitoring, and multi-platform notifications. Notable features include intelligent filtering of findings, automated token rotation, and comprehensive logging capabilities, making it suitable for both one-time scans and ongoing security assessments.

InstaRecon

2026-08-03 Python ★ 22
InstaRecon is an open-source intelligence (OSINT) tool specifically designed for gathering publicly available information from Instagram profiles, aimed at cybersecurity professionals and ethical hackers. It features user intelligence gathering, engagement analysis, and the ability to extract detailed account metrics, business intelligence, and public contact information. The tool operates across multiple platforms, supports automatic dependency installation, and requires users to provide a valid Instagram session ID for functionality.

mongobleed-scanner

2026-08-03 Python ★ 35
MongoBleed is a high-performance proof-of-concept scanner designed to identify vulnerable MongoDB instances affected by CVE-2025-14847, a pre-authentication heap memory disclosure vulnerability. Utilizing asynchronous I/O with Python's asyncio, the tool efficiently scans large network ranges, ensuring precise detection and minimal false positives by validating response lengths against the requested leak size, while automatically logging vulnerable targets. Additionally, it requires no external dependencies, making it straightforward to deploy in authorized security testing environments.

RedTiger

2026-08-03 Python ★ 16
RedTiger is an automated XSS (Cross-Site Scripting) vulnerability testing tool that streamlines security assessments by performing subdomain enumeration, link filtering, endpoint extraction, and XSS scanning. Notable features include intelligent filtering of endpoints, a rich terminal UI with detailed reporting, and dependency checking to ensure all required tools are available. The tool is designed to enhance testing efficiency by focusing on parameters in URLs, improving the accuracy of vulnerability assessments.

saas_enum

2026-08-03 Python ★ 40
SaaS Enum is a command line tool designed for identifying the Software as a Service (SaaS) platforms utilized by a company by analyzing DNS entries against known provider patterns and performing lightweight web checks for validation. It supports single and batch processing of company names, allows output in various formats (CSV, JSON, etc.), and provides features for listing providers and validating DNS patterns. Notably, it facilitates concurrent processing through configurable worker threads, enhancing efficiency in scanning multiple domains.

scada-scanner

2026-08-03 Python ★ 16
SCADA Scanner and Fingerprinter is a high-performance tool designed for asynchronous scanning and fingerprinting of industrial control systems (ICS) across networks. Its primary use case focuses on detecting vulnerabilities, identifying vendor and product information, and generating detailed risk reports, supporting a variety of protocols such as Modbus and DNP3. Notable features include fast scanning capabilities, protocol detection, vulnerability correlation with CVEs, and detailed logging, ensuring comprehensive risk assessments for authorized security assessments.

ultimate_bughunter_tools

2026-08-03 Python ★ 47
The Ultimate Bug Hunting Tools repository provides a comprehensive script that automates the installation of 50 popular tools utilized in bug bounty programs for vulnerability assessment. It features a diverse range of functionalities, including reconnaissance, exploitation, and information gathering, through tools like Amass, EyeWitness, and WPScan. This facilitates a streamlined approach for security researchers to efficiently set up their bug hunting environment with essential tools.

url-status-checker

2026-08-03 Python ★ 50
Status Checker is a Python-based tool designed to evaluate the HTTP status of multiple URLs or domains, categorizing them according to their response codes. It features asynchronous processing for enhanced speed, automatic redirection following, and capabilities to log results, which can be visually represented with color-coded output. The tool operates via a command-line interface, facilitating easy access and output management.

Web-Scraper

2026-08-03 Python ★ 35
Web Scraper is a Python-based tool designed for web hacking and assessment, featuring a suite of 20 widely-used functionalities for executing various attacks and reconnaissance tasks with a single command. Its notable features include ASN lookups, HTTP header analysis, subdomain discovery, vulnerability scanning, and more, providing users with a comprehensive toolkit for bug bounty and data extraction efforts. It operates on Python 3.7 or higher and is optimized for Linux environments.

WebHunterScreen

2026-08-03 Python ★ 14
This program aims to check active targets by saving screenshots in a project.

writeup-miner

2026-08-03 Python ★ 149
Writeup-Miner is a versatile tool that scrapes new RSS feeds and stores them in a MongoDB database or a text file while providing real-time notifications through Telegram or Discord. Its notable features include keyword filtering, an easy command-line interface, and support for multiple storage methods, making it ideal for security researchers and technology enthusiasts looking to stay current with Medium content.

Anvil

2026-08-03 Python ★ 37
Anvil is a runtime-first tool designed for privilege escalation and attack surface assessment specifically targeting Windows thick client applications. It effectively reduces false positives by combining Procmon capture with Windows AccessCheck to validate writable paths in real-time while enforcing multiple verification gates. Notable features include its comprehensive approach to assessing various attack classes, detailed filtered analysis of candidate paths, and the ability to produce actionable reporting outputs in multiple formats.

Burp-Pentest-Coverage-Tracker

2026-08-03 Python ★ 42
Pentest Coverage Tracker is a Burp Suite extension that enhances penetration testing efforts by automatically logging discovered endpoints and parameters during assessments. Its primary use case is to provide real-time visibility into which parts of an application have been tested, helping security professionals systematically identify untested areas. Notable features include endpoint and parameter coverage tracking, a real-time dashboard, untested endpoint identification, and CSV export capabilities for reporting.

isXSS-Burp

2026-08-03 Python ★ 20
isXSS-Burp is a Burp Suite extension designed to automate the detection of reflected XSS vulnerabilities by passively analyzing HTTP traffic and examining which special characters are reflected in HTML responses. It features comprehensive injection coverage for GET and POST requests, evaluating various parameter types, and includes advanced detection mechanisms for identifying dangerous DOM sinks. The tool also incorporates noise reduction techniques, a user-friendly interface for configuration, and provides detailed reporting on discovered vulnerabilities.

mergen-mcp

2026-08-03 Python ★ 14
Mergen is an AI-powered penetration testing server that integrates with MCP-compatible agents, facilitating autonomous planning, adaptive execution, and professional reporting across over 44 security tools. With its multi-layer architecture featuring a FastAPI backend and an adaptive AI attack engine, Mergen enables sophisticated target profiling, dynamic attack execution, and unified risk scoring while supporting multiple output formats like HTML, JSON, and CSV for reporting. Notably, it offers a plugin system for seamless integration of security tools and automated operational capabilities, making it a comprehensive solution for red team engagements.

AdwanceSNI

2026-08-03 Python ★ 16
AdwanceSNI is a command-line tool designed for subdomain discovery and vulnerability scanning on Termux and Linux platforms. Leveraging the capabilities of subfinder for subdomain enumeration and bughunter-go for vulnerability analysis, it features a user-friendly colorful terminal UI, progress indicators, and supports batch processing for multiple domains. This tool is primarily intended for educational and ethical hacking purposes, emphasizing user responsibility for permissions when scanning targets.

BurpJSReconRadar

2026-08-03 Python ★ 24
JSReconRadar is a robust Burp Suite extension designed for passive reconnaissance of JavaScript files, enabling the detection of secrets, API keys, endpoints, and security misconfigurations in real-time. It features over 1,600 detection patterns, customizable UI elements, advanced filtering options, and supports both Burp Suite Community and Professional editions, making it essential for identifying vulnerabilities in web applications. Noteworthy functionalities include a custom results tab, severity color coding, and the capability to save or export findings for further analysis.

crivo

2026-08-03 Python ★ 24
Crivo is an open-source Python tool tailored for offensive security analysts, pentesters, and bug bounty hunters, facilitating the extraction and filtering of URLs, IPs, domains, and subdomains from various text inputs and web pages. Notable features include built-in web scraping, flexible scope filtering, and clean output formatting for easy integration into automated workflows, making it efficient for processing data and generating organised reports.

darkbuster

2026-08-03 Python ★ 42
DarkBuster is an advanced web directory and file brute-forcing tool designed for authorized security testing, featuring multithreading capabilities to optimize scan speed. It includes curated wordlists updated to May 2026, supports customizable extensions, and offers a user-friendly CLI interface with color-coded output and real-time progress tracking. Notable features include the ability to save results, use custom headers, and specify various scanning options to enhance the pentesting process.

ExplorerPy

2026-08-03 Python ★ 10
ExplorerPy is an information-gathering reconnaissance toolkit that enables users to perform subdomain enumeration, directory brute-forcing, and port scanning on a specified domain. It features multithreaded execution for enhanced performance, customizable options for wordlists and timeouts, as well as capabilities for User-Agent and HTTP header spoofing to simulate legitimate requests. This tool is designed for both educational and testing purposes, ensuring a comprehensive approach to domain analysis.

FastRecvSMS

2026-08-03 Python ★ 20
FastRecvSMS is an SMS verification toolkit designed for security professionals, enabling the purchase of temporary phone numbers to receive SMS codes via a command-line interface (CLI). Key features include support for multiple providers, real-time SMS monitoring, automatic waiting for verification codes, and secure configuration management using local TOML files. The tool streamlines the process of obtaining and verifying SMS codes for various services, making it efficient for testing and security assessments.

favicon_hash_shodan

2026-08-03 Python ★ 100
favicon_hash_shodan is a tool designed to identify and retrieve all hosts sharing the same favicon by leveraging Shodan's search capabilities. Its primary use case is to aid cybersecurity professionals in uncovering potential target infrastructure or tracking down related web services by analyzing favicon hashes. Notable features include a simple command-line interface for direct usage, integration with Shodan for result viewing, and an uncover mode to enhance search capabilities.

gitghost

2026-08-03 Python ★ 15
gitghost is a tool designed to scan public GitHub repositories for exposed secrets, including those that may have been committed in the past and then deleted. It thoroughly searches through git history to identify vulnerabilities and presents findings in an HTML report complete with direct links to the locations of the secrets, as well as a guide on how to remediate the issues. Notable features include the ability to generate an exposure score, scan for various types of sensitive information, and run local scans without installation.

Gpt-Agreement-Payment

2026-08-03 Python ★ 2228
Gpt-Agreement-Payment is an end-to-end replay tool designed for automating the subscription process of ChatGPT Plus and Team through various payment pathways, including Stripe Checkout, PayPal, GoPay, and QRIS. It incorporates features such as a visual solver for hCaptcha, anti-fraud empirical data collection, and a concurrent worker system for handling multiple OTP requests efficiently. This tool is primarily aimed at CTF and bug bounty environments, requiring adherence to strict legal usage guidelines.

h1-asset-fetcher

2026-08-03 Python ★ 41
H1 Asset Fetcher is a command-line tool designed for bug bounty hunters to efficiently fetch, download, and decompile mobile app assets from various bug bounty programs like HackerOne and Bugcrowd. It offers a user-friendly, interactive prompt to guide users through selecting assets across Android, iOS, and executable files, with features including bulk downloading, asset decompilation using JADX, and credential management for streamlined repeated usage.

h1-brain

2026-08-03 Python ★ 351
h1-brain is an MCP server designed to integrate your AI assistant with the HackerOne platform, facilitating the retrieval and analysis of your bug bounty history and program details via a local SQLite database. The tool offers features such as a pre-built database of over 3,600 publicly disclosed bounty reports and the ability to generate comprehensive attack briefings using the `hack(handle)` function, which consolidates personal findings, public disclosures, and suggests attack vectors in a single operation.

hgrab-framework

2026-08-03 Python ★ 10
Hgrab is a lightweight framework designed for scanning various web-based software applications over specified ports using minimal bandwidth. It supports a diverse set of applications, including VMware vCenter and Apache NiFi, enabling users to easily identify and interact with these services via simple command-line inputs. Notable features include the ability to list available software for scanning and the integration with external tools like ZMap for efficient scanning operations.

OnlyVulns

2026-08-03 Python ★ 12
OnlyVulns is a nonprofit, open-source platform designed for security researchers to publish vulnerability disclosures in a controlled and safe environment. It enables researchers to document their findings, including proof-of-concept submissions and technical write-ups, while allowing them to manage vendor communications and disclosure timelines autonomously. Key features include a non-corporate framework, an embargo process for pre-publication coordination, and options for community support and tipping, fostering a researcher-first approach to vulnerability disclosure.

penetration-testing-notes

2026-08-03 Python ★ 29
The "penetration-testing-notes" repository serves as a comprehensive collection of notes on penetration testing and related technologies. Designed for educational purposes, it encompasses multiple resources from various platforms, providing insights and references to enhance penetration testing skills. Notable features include curated content from reputable sources like Hack The Box, PortSwigger Academy, and OWASP, aimed at facilitating learning and practical application in cybersecurity.

pentest-agents

2026-08-03 Python ★ 813
The Pentest Agent Suite is an autonomous bug-bounty framework designed for use with Claude Code and six other AI coding tools, featuring a collection of 50 agents, 26 commands, and 19 CLI tools. It provides a comprehensive methodology for vulnerability hunting, including automated exploit chaining, endpoint tracking, semantic writeup searches, and installation compatibility across multiple development environments. Its core functionalities enable users to efficiently conduct security assessments and manage bounties via integration with live platforms and cost tracking mechanisms.

Subfind3r

2026-08-03 Python ★ 12
Subfind3r is an advanced subdomain enumeration tool designed to enhance and address limitations found in the original Sublist3r project. It supports various features, including brute force enumeration, port scanning of discovered subdomains, and the ability to specify different passive DNS API sources, making it highly customizable for security researchers performing domain reconnaissance. The tool can be easily installed via pip, facilitating a user-friendly setup process.

Xposure

2026-08-03 Python ★ 15
X-POSURE v4.0 is an autonomous credential intelligence platform designed for discovering, extracting, correlating, verifying, and reporting exposed secrets across an organization's entire attack surface. Its primary use case is to enhance security by identifying vulnerabilities related to exposed credentials, further augmented with features like recursive crawling, Shodan integration, AI-powered contextual analysis, and deep secrets scanning via TruffleHog. This tool is engineered for advanced users who recognize the significance of credential exposure as a substantial security threat.

argo

2026-08-03 Python ★ 54
Argo is an LLM-native static vulnerability detection tool that analyzes source code to identify security vulnerabilities by simulating a human auditor's review process. It offers tailored auditing via archetype-driven prompts, adversarial validation, and multi-backend support while focusing on both general code audits and specialized bug-bounty triage modes. Notable features include threat-informed auditing, cross-checks against project documentation, opt-in remediation proposals, and a commitment to detection-only operations without executing the analyzed code.

ReconForge

2026-08-03 Python ★ 33
ReconForge is an AI-assisted reconnaissance toolkit designed for bug bounty hunters and security researchers, facilitating rapid transition from raw data to actionable insights. It features subdomain discovery, DNS enumeration, SSL/TLS analysis, Shodan integration, and technology detection, all complemented by AI triage prompts for analyzing HTTP responses and generating professional markdown reports. The tool emphasizes a speed-oriented, production-ready design with robust error handling and comprehensive testing capabilities.

ReconFusionAi

2026-08-03 Python ★ 17
ReconFusionAI is an AI-powered web asset scanner designed to detect exposed secrets, credentials, PII, and vulnerabilities across web applications with high accuracy through a comprehensive library of over 1,183 detection patterns. Its notable features include advanced contextual analysis using Ollama for improved understanding of data context, a modular architecture allowing for easy updates, and dual output formats that provide detailed findings and reconnaissance intelligence. Additionally, it incorporates intelligent caching mechanisms and production-hardened capabilities for efficient and robust operation.

rustchain-bounties

2026-08-03 Python ★ 254
RustChain Bounties facilitates user engagement in the RustChain ecosystem by offering a bounty program where contributors can earn RTC (RustChain Token) for completing various tasks. The tool supports multiple categories, including code, content, and security-related tasks, providing clear difficulty ratings and compensation structures, thus incentivizing participation from both experienced developers and newcomers. Notable features include an extensive list of open bounties, specific payout procedures, and a comprehensive security protocol to safeguard against fraud.

avain

2026-08-03 Python ★ 67
AVAIN is an automated vulnerability analysis framework designed for IP-based networks, leveraging a modular architecture to conduct comprehensive assessments of both networks and individual hosts. It features collaborative modules that facilitate reconnaissance, vulnerability correlation, and active detection of security issues, culminating in a vulnerability score to gauge overall security. Noteworthy capabilities include simple result sharing, extensive module configurability, and the ability to integrate various tools, making it a robust platform for penetration testing and security evaluation.

badmoodle

2026-08-03 Python ★ 63
badmoodle is a community-driven vulnerability scanner designed specifically for Moodle platform instances, aimed at penetration testers and security researchers. It identifies both official and community-discovered vulnerabilities, allowing users to operate in check mode for detection or exploit mode to validate and leverage identified vulnerabilities. Notable features include its modular architecture for easy integration of community vulnerability modules, multiple testing levels, customizable output options, and capability to scrape the latest vulnerabilities from Moodle's security resources.

collector

2026-08-03 Python ★ 156
Collector is an automated tool designed for identifying XSS vulnerable parameters across entire domains by leveraging the Wayback Machine. Key features include comprehensive crawling of websites and JavaScript files, advanced error handling, and the capability to collect GET parameters. This tool facilitates a systematic approach to vulnerability assessment in web applications.

container-auto-scan

2026-08-03 Python ★ 23
Lacework Auto Scanner is a tool designed to automate vulnerability assessments for active containers in a Lacework account, streamlining the scanning process via its API or inline scanner capabilities. It efficiently utilizes a local cache to skip rescans of recently assessed containers, with flexible configuration options for scan frequency and targeted registries. Notably, it supports Inline Scanning for containers lacking registry integration, enhancing its versatility and effectiveness in diverse environments.

dorkScanner

2026-08-03 Python ★ 286
DorkScanner is a search engine dorking tool that allows users to scrape search engines for vulnerable URLs based on user-defined queries. It is primarily used by security auditors and researchers to uncover hidden information on public websites. Notable features include support for multiple search engines (Google and Bing), customizable query parameters, and the ability to specify the number of pages and processes for enhanced searching efficiency.

HexraysToolbox

2026-08-03 Python ★ 485
HexRays Toolbox (hxtb) is a versatile set of IDAPython scripts designed for identifying and analyzing code patterns in binaries across various processor architectures. Its primary use cases include vulnerability scanning, malware analysis, and proving code similarities, thus making it valuable for security analysts and reverse engineers. Notable features include a user-friendly GUI via hxtb_shell for query formulation, custom scripting capabilities, and batch processing scripts for enhanced automation.

htk-lite

2026-08-03 Python ★ 130
htk-lite is a streamlined version of the hackers-tool-kit, maintaining essential hacking capabilities while being lightweight. Its primary use case is to facilitate various penetration testing tasks. Notable features include easy installation with a simple Git clone, user-friendly command execution, and an update script for keeping the tool current.

midas

2026-08-03 Python ★ 14
MiDas is a transformer-based tool designed for detecting vulnerability-fixing commits in software projects by utilizing a multi-granularity approach that examines commits at various levels (commit, file, hunk, line). Notable features include seven distinct feature extractors that leverage CodeBERT for contextual representation, enabling effective identification and extraction of relevant commit features. This tool facilitates improved vulnerability management and can be replicated using specific training processes and dataset requirements.

MyBBscan

2026-08-03 Python ★ 23
MyBBscan is a Python-based tool that scans the `/inc/plugins/` directory of MyBB 1.8 forums for known vulnerabilities in plugins. Its primary use case is to identify outdated or vulnerable plugins that could pose security risks, facilitating proactive remediation efforts. Notable features include simple command-line execution and clear user prompts for scanning specific forum URLs.

OrgASM

2026-08-03 Python ★ 38
OrgASM is a modular attack surface mapping tool designed for discovering and enumerating potential vulnerabilities within a target's ecosystem, such as subdomains, IPs, and services. It integrates seamlessly with other tools like nuclei for scanning and wappalyzer for service detection, offering features such as a customizable configuration file, pivoting to related FQDNs, and the ability to automate scans using community APIs. Users can extend its functionality by adding custom APIs and tools, making it highly adaptable for various cybersecurity needs.

OWASP_ZAP_API_scripts

2026-08-03 Python ★ 11
The OWASP ZAP API scripts facilitate automated security testing for web applications by integrating with the OWASP ZAP penetration testing tool. Key features include scripts for API authentication and context management, allowing for streamlined attack simulations on platforms like Hackazon. These scripts are designed to be placed in specific directories within the ZAP framework for optimized functionality.

scanvus

2026-08-03 Python ★ 44
Scanvus is a credentialed authenticated vulnerability scanner designed for Linux hosts and Docker images, utilizing external vulnerability detection APIs such as Vulners and Vulns.io for comprehensive assessments. It supports various assessment types including localhost scans, remote SSH connections with key or password authentication, and scanning of Docker images. Notable features include detailed vulnerability reporting, interoperability with external APIs, and the ability to inventory target hosts.

sqlmap

2026-08-03 Python ★ 19
sqlmap is an open-source penetration testing tool designed to automate the detection and exploitation of SQL injection vulnerabilities in web applications. Its robust detection engine supports extensive capabilities such as database fingerprinting, data retrieval, and command execution on the underlying operating system, making it an essential tool for security professionals. Key features include a variety of switches for advanced testing, support for multiple databases, and the ability to access the file system via out-of-band connections.

subdover

2026-08-03 Python ★ 111
SubDover is a multi-threaded subdomain takeover vulnerability scanner written in Python 3, featuring over 88 fingerprints of potentially vulnerable services. It incorporates a built-in subdomain enumeration method and utilizes CNAME records for verification, allowing for quick scanning of both individual targets and lists of subdomains. Notable features include configurable threading for performance optimization, result saving capabilities, and a clean output format, making it a versatile tool for security professionals.

vuln-scanner-flask

2026-08-03 Python ★ 28
vuln-scanner-flask is a web application designed for scanning vulnerabilities within websites and performing network exploitation and reconnaissance. Its notable features include an intuitive user interface, fast scanning capabilities, and functionalities for scheduling assessments and generating reports. The tool aims to facilitate security assessments while ensuring user-friendliness and security.

vulnscan-parser

2026-08-03 Python ★ 24
vulnscan-parser is a Python tool designed to parse and normalize results from various security scanning tools such as Nessus, Nmap, and Metasploit into a consistent object-oriented structure. It supports multiple file formats, allowing for efficient parsing of large files without memory issues while accommodating various output formats and structures. Key features include the ability to handle overlapping files, retain unique host objects, and extract relevant security findings for further analysis.

vulscanpro

2026-08-03 Python ★ 47
VulScanPro is an automated web vulnerability scanner designed to identify security weaknesses in domains through over 100 attack vectors, including SQL injection and Cross-Site Scripting. It not only detects vulnerabilities but also provides detailed descriptions and potential solutions for each issue. The tool features command-line options for customizable scanning, including the ability to skip certain tools for faster results.

Web-Fuzzer

2026-08-03 Python ★ 10
Web-Fuzzer is a robust web application fuzzing tool designed to automate the identification of vulnerabilities such as XSS, SQL injection, and command injection. Utilizing technologies like Selenium and BeautifulSoup, it crawls web applications to collect internal URLs, detects forms and input parameters for fuzzing, injects payloads, and analyzes responses for potential security flaws. Notably, it supports various injection types and can be used in testing environments like DVWA, with further enhancements planned for threading support and proxy usage.

xforwardy

2026-08-03 Python ★ 50
XForwardy is a Host Header Injection scanning tool designed to identify potential misconfigurations that may allow for Host Header Injections, as well as checking for CORS misconfigurations in specified URLs. It is a lightweight tool requiring minimal dependencies and is straightforward to install and execute.

BeeXSS

2026-08-03 Python ★ 38
BeeXSS is an automated tool that identifies Blind XSS (Cross-Site Scripting) vulnerabilities in web applications by scanning URL parameters and injecting payloads. Its notable features include the use of customizable Blind XSS-specific payloads, headless browsing via Selenium WebDriver for efficient scanning, and detailed reporting of potential vulnerabilities. The tool is intended for educational and ethical penetration testing purposes, ensuring users have permission to test the targeted applications.

bsqli

2026-08-03 Python ★ 21
Bsqli is a customizable vulnerability scanner designed to identify SQL injection vulnerabilities using a targeted payload list, ensuring high accuracy with minimal false positives. It is optimized for rapid scanning across multiple hosts and supports multithreading for enhanced performance. Notable features include support for both single URL and file-based target inputs, as well as options for output management and SSL verification settings.

firmware-analysis-toolkit

2026-08-03 Python ★ 1583
The Firmware Analysis Toolkit (FAT) is designed to assist security researchers in analyzing and identifying vulnerabilities within IoT and embedded device firmware by providing automated firmware emulation capabilities based on Firmadyne. Key features include the ability to run firmware images in a controlled environment without the need for a PostgreSQL database, as well as streamlined setup and interaction via Python scripts, enabling real-time testing and network interface configuration.

neural-network-hacking

2026-08-03 Python ★ 131
This repository provides a structured introduction to offensive techniques that exploit neural networks, focusing on areas such as bug hunting, malware injection, and information extraction. Each technique is accompanied by practical exercises to facilitate hands-on learning. Notable features include detailed instructions for setting up a Python environment and using various ML tools, as well as a diverse range of attack scenarios aimed at enhancing understanding of security vulnerabilities in neural networks.

NextSploit

2026-08-03 Python ★ 93
NextSploit is a command-line utility for detecting and exploiting the Next.js vulnerability identified as CVE-2025-29927. It automates the process of identifying vulnerable Next.js versions and attempts to exploit the flaw by bypassing middleware protections, potentially allowing unauthorized access to restricted content. Notable features include automated version detection using Wappalyzer, mass URL scanning capability, and an integrated Chrome browser launch for exploitation tests.

RevOK

2026-08-03 Python ★ 27
RevOK is a cybersecurity tool designed to simulate malicious targets for testing security scanners and software that processes attacker-controlled data. Its core feature, the "stub" component, allows users to listen for incoming requests and serve crafted attack responses based on customizable templates and substitution lists. Notably, RevOK has been utilized to identify critical vulnerabilities, including XSS to RCE bugs in Metasploit Pro, highlighting its effectiveness in researching and weaponizing security scanner vulnerabilities.

Vulnerability-Scanner

2026-08-03 Python ★ 17
The Vulnerability Scanner is a user-friendly tool designed for beginners in cybersecurity, capable of scanning systems for vulnerabilities and gathering information on potential targets. It includes features like DNS enumeration, OS detection, service/version detection, and integration with the OWASP ZAP for comprehensive security assessments. The tool is specifically built for Kali and Parrot Linux environments and requires minimal prior knowledge, making it an ideal starting point for aspiring security professionals.

ALNUR

2026-08-03 Python ★ 12
ALNUR is an open-source end-to-end vulnerability scanner that evaluates application projects for security weaknesses, including CVEs in dependencies and potential risks in architecture, secret leaks, and agentic AI applications. Notable features include a comprehensive CVE scanner, in-depth architecture and standards compliance analysis, and support for various programming languages and frameworks, with customizable reporting options. The tool also offers optional LLM-enhanced analysis for generating executive summaries and remediation guidance.

aur_checker

2026-08-03 Python ★ 11
aur_checker is a command-line security analysis tool designed for inspecting Arch Linux AUR PKGBUILD files to detect potential vulnerabilities. It employs a context-aware static analysis methodology, optionally enhanced with AI inspection, resulting in detailed risk assessments that include trust signals and explainable scoring. Key features include a user-friendly output format, JSON integration for CI purposes, and the ability to analyze multiple packages or files simultaneously.

brs-xss

2026-08-03 Python ★ 34
BRS-XSS is an advanced XSS vulnerability scanner designed for modern web applications, providing deterministic and auditable detection capabilities. It features context-aware scanning, WAF evasion techniques, and a comprehensive knowledge base for payload management, along with a user-friendly web interface that supports real-time monitoring, detailed reporting, and customizable scanning options. Notably, it includes a Pentesting Task Tree strategy engine for adaptive testing, A/B testing for strategy comparison, and multiple report formats for enhanced analysis.

BurpAPISecuritySuite

2026-08-03 Python ★ 335
BurpAPISecuritySuite is a professional-grade extension for Burp Suite that consolidates multiple functionalities for API reconnaissance, intelligent fuzzing, and AI-enhanced security testing into a single interface. It is designed to improve performance and usability by sharing resources across various tabs, thereby minimizing memory usage and CPU overhead while maintaining a stable and efficient testing environment. Notable features include support for REST, GraphQL, and SOAP APIs, as well as tools for passive discovery, fuzzing, and advanced security assessments based on the OWASP API Top 10 guidelines.

cent-nuclei-templates

2026-08-03 Python ★ 14
The cent-nuclei-templates repository provides a curated collection of 9,284 high-quality nuclei templates, generated and filtered through the cent tool for use with the Nuclei scanner. Its primary use case is to enhance vulnerability scanning by offering templates that are free from duplicates, noise, and outdated syntax, thereby improving accuracy and effectiveness in detecting vulnerabilities. Notable features include extensive deduplication processes, community-sourced additions, and ongoing maintenance scripts to ensure template quality and relevance.

claude-pentest-skills

2026-08-03 Python ★ 33
Claude Pentest Skills is a structured penetration testing skill pack designed for Claude Code that employs an OWASP-based methodology to streamline web application security assessments. It features a 6-gate validation process to filter out false positives, a series of interactive slash commands for efficient testing, and automated report generation in both markdown and PDF formats, ensuring compliance with verification and documentation standards. The tool improves the efficiency and reliability of pentesting workflows by maintaining consistent coverage tracking and enforcing scope before testing.

CloudVault

2026-08-03 Python ★ 11
CloudVault is an enterprise-grade security scanner designed for multi-cloud storage environments, specifically targeting AWS S3, Google Cloud Storage, and Azure Blob. It offers advanced attack chain analysis, automated permission checking, and comprehensive risk scoring, facilitating real-time discovery of exposed cloud resources through certificate transparency monitoring. Notable features include interactive text user interface (TUI), alerts integration with communication platforms, compliance mapping, and various export formats for reporting and remediation.

CorsOne

2026-08-03 Python ★ 29
CorsOne is a specialized security testing tool for detecting Cross-Origin Resource Sharing (CORS) misconfigurations in web applications. It efficiently tests over 40 CORS bypass techniques, providing accurate results with low false positives and supporting advanced features such as customizable origin testing, proxy configurations, and multiple output formats for comprehensive reporting. The tool employs asynchronous operations for high performance and includes options for easy integration and flexible request handling.

Critikal

2026-08-03 Python ★ 14
Critikal is an autonomous security research agent specifically designed for smart contracts, capable of identifying exploitable vulnerabilities in blockchain protocols through a comprehensive analysis process. It ingests repository data, performs reconnaissance, maps the attack surface, and validates its findings, generating proof-of-concept tests using Foundry along with detailed audit reports in HTML and Markdown formats. Notable features include multi-model support for AI analysis, an integrated knowledge graph, and a user-friendly TUI demo for easy interaction.

CVE-2025-58434-AND-59528-POC

2026-08-03 Python ★ 19
The Flowise Dual CVE PoC is a proof-of-concept tool for exploiting two critical vulnerabilities (CVE-2025-58434 and CVE-2025-59528) in the Flowise platform, enabling an attacker to achieve unauthenticated account takeover followed by remote code execution in an automated manner. It leverages a flawed password reset mechanism and unsanitized user input in JavaScript execution to facilitate these exploits, making it particularly dangerous for both cloud and self-hosted deployments. The tool includes modular functionality for conducting attacks and is intended solely for authorized security research purposes.

discoursemap

2026-08-03 Python ★ 22
DiscourseMap is an advanced security scanner designed specifically for Discourse forum platforms, offering over 25 specialized security modules for comprehensive assessments. It features capabilities such as CVE detection, plugin analysis, and API testing, all optimized for quick performance and reliability, delivering detailed reports in multiple formats. The tool is well-suited for vulnerability detection and compliance verification, making it essential for securing Discourse environments.

EthicalHackingTools

2026-08-03 Python ★ 15
The HackerAI Framework (Project Sirra) is a modular security testing environment tailored for ethical hackers and security researchers, emphasizing cross-platform compatibility including mobile devices. It features a universal orchestrator for module management, built-in security scanning capabilities, advanced web scanning with asynchronous support, and the ability to export results in multiple formats like HTML and JSON.

FastCVE

2026-08-03 Python ★ 61
FastCVE is a command-line tool designed for rapid and efficient querying of the Common Vulnerabilities and Exposures (CVE) database, enabling users to retrieve detailed information about security vulnerabilities, including descriptions, CVSS scores, and references to advisories. Notable features include its Docker containerization, automatic database management with PostgreSQL, and the ability to populate and incrementally update the local vulnerability database from multiple external sources, making it an effective solution for security professionals and developers aiming to monitor and assess vulnerabilities in their systems and applications.

Fathometer

2026-08-03 Python ★ 36
Fathometer is a self-hosted CVE intelligence tool designed for administrators of plain root servers and VPSes, providing context-specific assessments of vulnerabilities. The tool leverages Trivy for scanning local hosts while utilizing a language model to evaluate the relevance of CVEs, ensuring that only pertinent findings are highlighted. Its streamlined interface features a fleet dashboard and triage workspaces tailored for individual operators, focusing on actionable insights without the complexity of extensive features common in enterprise solutions.

honeyscanner

2026-08-03 Python ★ 66
Honeyscanner is a vulnerability analyzer designed for honeypots, capable of automatically simulating various cyber attacks to assess the security posture of the honeypot. It employs a range of tactics, including exploitation of software vulnerabilities, denial of service, and fuzzing techniques, delivering comprehensive evaluation reports that provide security enhancement recommendations. Targeted at security enthusiasts and organizations, Honeyscanner serves as an essential tool for validating the robustness of honeypot implementations.

ICS-Ninja-Scanner

2026-08-03 Python ★ 10
ICS Ninja Scanner is a specialized security assessment tool for industrial control systems (ICS) that supports comprehensive device discovery and testing across 11 protocols, including Modbus and S7. It features built-in CVE correlation, compliance mapping to frameworks like IEC 62443 and NIST 800-82, and offers functionalities such as scan diffing and industry-specific scan profiles, ensuring a thorough and tailored assessment for operational technology environments.

nextgenmap

2026-08-03 Python ★ 12
NextgeNmap is a security-focused automation GUI for Nmap designed for security operations and systems teams, enabling repeatable and efficient scans while minimizing noise in reporting. Key features include curated scan profiles, automated scheduling, integration with community scripts (like SearchSploit), and the generation of HTML reports for stakeholder presentation, all provided in a user-friendly cross-platform desktop application.

omnisci3nt

2026-08-03 Python ★ 369
Omnisci3nt is a unified web reconnaissance toolkit designed for cybersecurity professionals, ethical hackers, and security researchers, enabling automated analysis of critical domain-related data such as subdomains, SSL/TLS certificates, and exposed services. Its notable features include IP and WHOIS lookups, DNS enumeration, port scanning, and web crawling, all aimed at enhancing visibility into a domain's attack surface for security assessments and threat modeling. The tool is intended for authorized testing and provides a streamlined workflow for comprehensively analyzing the external exposure of web assets.

pentester-mcp

2026-08-03 Python ★ 52
Pentester-MCP is an open-source penetration testing toolkit that integrates over 200 popular cybersecurity tools via the Model Context Protocol (MCP), enabling AI assistants to autonomously conduct penetration tests. Notable features include intelligent tool execution generated from cheat sheets, AI-optimized documentation for argument handling, and secure operation through Docker sandboxing, isolating tools from the host system to prevent dependency clutter. The toolkit covers various categories including reconnaissance, web exploitation, and network security, making it a comprehensive solution for automated penetration testing.

public-skills-builder

2026-08-03 Python ★ 223
Public Skills Builder is a tool designed to generate Claude Code bug bounty skills by analyzing and extracting valuable data from over 500 public HackerOne reports and GitHub writeups. It produces 18 structured skill files, each targeting a different vulnerability class, complete with real-world techniques, payloads, and methodologies essential for enhancing bug hunting skills. Notable features include the ability to work exclusively with publicly available data and the generation of targeted skill files ready for integration with Claude Code.

pwned-deps

2026-08-03 Python ★ 164
`pwned-deps` is a multi-ecosystem CLI tool designed for quickly identifying compromised package versions in developer lockfiles, such as those used in npm, PyPI, Maven, Cargo, Go, and RubyGems. It provides rapid assessments—flagging risks like supply-chain malware and hijacked packages—by leveraging data from public APIs and curated feeds, with output options including terminal reports, JSON, and SARIF for integration into code scanning platforms. Key features include support for various lockfile formats, one-shot scans, and continuous monitoring modes.

rag-security-scanner

2026-08-03 Python ★ 73
RAG/LLM Security Scanner is a professional security testing tool designed to identify critical vulnerabilities in Retrieval-Augmented Generation (RAG) systems and large language model (LLM) applications, such as chatbots and knowledge retrieval systems. Notable features include advanced prompt injection detection, data leakage assessments, function abuse testing, and comprehensive reporting capabilities, making it suitable for both demo and production environments. The tool supports easy integration with popular AI systems and provides detailed JSON/HTML reports with actionable insights.

react2shell-ultimate

2026-08-03 Python ★ 152
React2Shell Ultimate is a professional vulnerability scanner specifically designed for detecting the CVE-2025-66478 Remote Code Execution (RCE) vulnerability in Next.js applications utilizing React Server Components. Notable features include advanced exploitation capabilities, sophisticated techniques for WAF bypass, multiple scanning modes, and a full-featured web interface for interactive use and API access, making it suitable for authorized security testing and research.

RedTiger-Tools

2026-08-03 Python ★ 686
RedTiger-Tools is a versatile automation tool designed for penetration testing (pentesting) and open-source intelligence (OSINT) that aims to consolidate multiple operations into a single, configurable platform. It features a plugin system for extending functionality, centralized configurations using JSON files, and dual operation modes (CLI and interactive interface), ensuring compatibility with both Windows and Linux environments while adhering strictly to legal and ethical standards for usage.

SCOUT

2026-08-03 Python ★ 10
SCOUT is an advanced firmware analysis platform designed for product security and internal red-team operations, transforming raw firmware blobs into evidence-backed exploitability chains and lab-bounded proof-of-vulnerability modules. It features a hybrid analysis engine capable of auditing both ELF binaries and shell scripts, emphasizing controlled weaponization and audit-ready reporting while reducing false positives. Notably, SCOUT prioritizes detailed evidence lineage and supports a structured approach to exploit development, favoring higher fidelity over traditional bulk scanning techniques.

secgate

2026-08-03 Python ★ 12
SecGate is a lightweight, integrated security tool for Linux servers that combines gateway authentication, attack monitoring, vulnerability scanning, and AI assistance into a single package with minimal resource requirements. It offers one-command deployment, operates with around 120MB of memory, and includes unique features such as customizable TCP port authentication, multi-node management via SSH, and comprehensive security dashboards. Ideal for individual developers and multi-service deployments, SecGate provides a zero-configuration solution for rapid security enhancements.

Secrover

2026-08-03 Python ★ 253
Secrover is an open-source security auditing tool that generates comprehensive, human-readable security reports, focusing on vulnerabilities in dependencies, code, and domains. Its notable features include easy setup via YAML configuration, automation capabilities with scheduled scans and GitHub Actions, cross-platform compatibility, and flexible report exports to various remote destinations. The tool aims to provide actionable insights for users, making it accessible for both technical and non-technical audiences.

ShubhamWebScript-Website-vulnerability-Checker

2026-08-03 Python ★ 40
ShubhamWebScript is a Python-based website vulnerability checker designed for educational and ethical hacking purposes, allowing users to assess the security of web applications through automated scanning of parameter-based URLs. It detects common vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), and Remote Code Execution indicators, while also performing server header fingerprinting. The tool features both single and bulk URL scanning capabilities, making it beginner-friendly and suitable for learning basic web security practices.

vuln-scout

2026-08-03 Python ★ 24
VulnScout is a security analysis tool designed for whitebox security reviews, offering offline quick scans and evidence-backed verification for identifying vulnerabilities within codebases. It provides features such as shared findings documentation, various output formats for reports, and support for multiple deep analyzers, making it suitable for integration into continuous integration workflows. Notably, it operates without requiring a remote service and includes capabilities for auditing, verifying findings, and generating structured reports.

vulnhawk

2026-08-03 Python ★ 82
VulnHawk is an AI-powered code security scanner designed to identify vulnerabilities that conventional SAST tools like Semgrep and CodeQL may overlook, particularly those related to business logic flaws where the absence of expected patterns is key. It employs contextual code analysis by comparing similar components across a codebase, facilitating the detection of security issues without the need for extensive configuration or custom rules. Notably, it supports various AI backends, integrates easily into CI/CD pipelines, and operates entirely locally or privately using options like Ollama.

wordfence-cli

2026-08-03 Python ★ 158
Wordfence CLI is a high-performance security scanner designed for detecting PHP malware and vulnerabilities in WordPress installations. Written in Python, it operates in a multi-process environment, allowing for parallel scans, scheduling, and integration with other commands via input and output piping. Notable features include the ability to scan directories for malware and vulnerabilities efficiently, as well as comprehensive installation and configuration documentation.

XSSniper

2026-08-03 Python ★ 11
XSSniper is an advanced open-source XSS vulnerability scanner designed for professional security testing. It features asynchronous scanning for enhanced performance, a comprehensive payload library tailored to the latest CVEs, and sophisticated WAF bypass techniques. Notable capabilities include intelligent context-aware detection, smart parameter discovery, and detailed vulnerability reporting for effective analysis of web applications.

z0scan

2026-08-03 Python ★ 367
A lightweight active and passive scanner that combines the advantages of local and distributed models, supports dynamic external plugin import, and is dedicated to exploring web black-box vulnerabilities.

ZENVORA-VULNSCAN

2026-08-03 Python ★ 10
ZENVORA VulnScan v2.0 is a comprehensive vulnerability scanner designed for web applications, focusing on detecting various security issues such as SQL injection, cross-site scripting (XSS), and command injection. It includes features like anonymity levels through Tor and ProxyChains, automated report generation in TXT and JSON formats, and an extensive list of tests for common vulnerabilities. This tool is intended for authorized use only, highlighting the importance of ethical scanning practices.

aem-dispatcher-security-scan

2026-08-03 Python ★ 19
AEM Dispatcher Security Scan is a command-line tool designed to perform security assessments on Adobe Experience Manager (AEM) Dispatcher configurations. It consolidates known security-sensitive URLs for AEM Dispatcher, allowing users to specify target websites and customize scan parameters while leveraging Docker for deployment. Notable features include configurable HTTP request timeouts, support for custom test paths, and an easy-to-use interface via command-line options.

agent-audit

2026-08-03 Python ★ 225
Agent Audit is a security tool designed to identify vulnerabilities in AI agent code prior to production deployment. Its primary use case involves scanning for risks associated with unsafe inputs, command execution, and configuration errors, utilizing a framework of 72 rules aligned with the OWASP Agentic Top 10. Notable features include tool-boundary taint tracking, configuration auditing, and the ability to enforce security measures within continuous integration workflows.

api

2026-08-03 Python ★ 371
The Vulners Python SDK is a comprehensive client for accessing Vulners' vast vulnerability intelligence database, facilitating queries on CVEs, exploits, and advisories enriched with risk metrics like CVSS and EPSS. It enables users to assess vulnerabilities across various software and systems, stream data for integration into custom pipelines, and set alerts for new matching vulnerabilities, all while supporting asynchronous operations for enhanced performance. Notably, it incorporates features for tracking active exploits and provides an AI-ready infrastructure for real-time data processing.

apiscanner

2026-08-03 Python ★ 15
APISCAN is an advanced API vulnerability scanner that systematically evaluates APIs against the OWASP API Security Top 10 (2023) by utilizing OpenAPI/Swagger specifications. Notable features include automatic form login detection, deep scan modes for comprehensive testing, real-world attack pattern detection, and a user-friendly cross-platform GUI for enhanced usability. The tool is designed to proactively identify and model security vulnerabilities, providing actionable insights with detailed evidence.

awesome-security-pipeline

2026-08-03 Python ★ 14
Awesome Security Pipeline is a comprehensive guide designed for selecting and implementing open-source security tools within CI/CD pipelines. It features a pre-configured baseline that integrates multiple tools such as Gitleaks, Semgrep, and Trivy, enabling continuous security validation and machine-readable evidence generation. The repository is actively maintained, with weekly status checks and regular updates to ensure the effectiveness of the security controls and methodologies provided.

bitrixprobe

2026-08-03 Python ★ 20
BitrixProbe is a Python-based vulnerability assessment tool specifically designed for CMS 1C-Bitrix/Bitrix24 installations. It offers dual modes of operation: `pentest` for external HTTP/HTTPS scans and `audit` for authenticated SSH scans, enabling comprehensive evaluation of both public exposure and server configurations. Notable features include integration with vulnerability databases, enumeration modules, and the ability to generate standardized reports, thus facilitating effective security assessments and audits.

cataam

2026-08-03 Python ★ 12
Cataam is an open-source security toolset that provides a variety of scripts and templates aimed at enhancing security and compliance practices for organizations. It features practical functionalities such as hardening scripts, CVE detection tools, and compliance documentation, making it suitable for security teams, DevOps, and compliance engineers. Notable offerings include a local-first prompt hygiene tool, CVE detection scripts updated promptly after disclosures, and a comprehensive collection of CIS Benchmark guides and compliance templates.

cert-x-gen

2026-08-03 Python ★ 21
CERT-X-GEN is a polyglot execution engine designed for vulnerability detection, allowing users to write security checks in multiple programming languages including Python, Go, Rust, C, and Shell. It provides a unified execution layer that enables complex detection logic, such as multi-step protocol conversations and performance-critical operations, and is tailored for integration in CI/CD environments. Notable features include language-agnostic templates, sandboxing capabilities, and the ability to mix various programming languages within a single scan.

cloud-audit

2026-08-03 Python ★ 69
cloud-audit is an open-source AWS security scanning tool designed to identify attack paths, IAM escalation routes, and prioritize necessary fixes based on their impact on security. It operates in a read-only mode, ensuring no modifications are made to the user's AWS infrastructure while providing detailed reports on correlations between vulnerabilities and suggested remediation steps, including AWS CLI and Terraform fixes per finding. Key features include the identification of attack chains using MITRE ATT&CK methodology, root-cause analysis for prioritized fixes, and a simulation function to evaluate the potential impact of proposed changes.

cyber-neo

2026-08-03 Python ★ 254
Cyber Neo is an open-source cybersecurity analysis agent designed to run within Claude Code, enabling developers to conduct comprehensive security audits on their projects effortlessly. The tool scans for vulnerabilities across 11 categories, including code security, authentication, cryptography, and dependency vulnerabilities, providing prioritized reports with concise remediation guidance. Notable features include no installation requirements, real-time operation, and the ability to run five parallel subagents for rapid assessments.

DeepSec

2026-08-03 Python ★ 323
DeepSec is an AI-driven security platform that integrates code security auditing and authorized penetration testing into a unified CLI and terminal workbench. It features a three-layer detection architecture for real-time vulnerability scanning, leveraging regex, AST analysis, and LLM semantic evaluation, along with IDE plugins for seamless development integration. The platform is designed to enhance security efficiency by augmenting traditional methods with advanced AI capabilities.

DockSec

2026-08-03 Python ★ 476
DockSec is an AI-powered Docker security scanner designed to translate complex security vulnerabilities into actionable insights for developers. It leverages popular security scanners like Trivy and Hadolint to provide prioritized vulnerability assessments and plain English explanations, while also suggesting specific fixes for Dockerfiles and generating interactive security reports. The tool ensures privacy by conducting scans locally, with options for local AI processing, minimizing external data exposure.

grummage

2026-08-03 Python ★ 47
Grummage is an interactive terminal frontend for the Grype vulnerability scanner, designed to simplify the analysis of Software Bill of Materials (SBOMs) by providing a user-friendly interface for navigating and viewing vulnerability details. Its notable features include real-time utilization of the Grype vulnerability database, customizable views by package name, vulnerability ID, package type, and severity, along with intuitive navigation controls. Grummage aims to streamline the process of vulnerability management for developers without the need to delve into complex query syntax.

isitsecure

2026-08-03 Python ★ 39
isitsecure is an AI-powered security scanner designed for modern web applications, integrating Static Analysis (SAST), Dynamic Analysis (DAST), and AI-driven code review into a single scanning process. Its notable features include automatic generation of DAST tests based on SAST findings, AI-generated code patches for vulnerabilities, and support for multiple programming languages and frameworks. This tool targets developers aiming to improve code security without requiring deep security expertise, offering a comprehensive report along with actionable fixes for identified issues.

it-depends

2026-08-03 Python ★ 411
It-Depends is a tool designed for automatically generating dependency graphs and Software Bill of Materials (SBOM) for various programming packages and source code repositories, supporting languages such as Go, JavaScript, Rust, Python, and C/C++. Key features include complete dependency version resolution, C/C++ support without the need to build projects, automated mapping of native library dependencies through dynamic analysis, and integration with vulnerability scanning from the OSV database.

L0p4Map

2026-08-03 Python ★ 608
L0p4Map is a robust network monitoring and visualization tool that enhances the capabilities of Nmap, providing security researchers and network administrators with detailed insights into their network infrastructure through an intuitive interface. Key features include continuous monitoring of network traffic, real-time alerting for unauthorized devices, extensive device fingerprinting, and the ability to generate a real-time graphical representation of network topology. The tool supports multiple platforms (Linux, Windows, macOS) and integrates seamlessly with existing Nmap functionalities to deliver a comprehensive view of network security.

medusa

2026-08-03 Python ★ 971
MEDUSA is an AI-first security scanner designed to detect vulnerabilities in AI/ML applications, offering over 40,000 detection patterns and built-in rules for identifying threats such as API key leaks and AI supply chain attacks. Notable features include no setup required for usage, the ability to scan GitHub repositories for potential repo poisoning, and interactive tools for purging leaked information. The tool supports parallel processing for speed, integrates with various IDEs, and provides multiple reporting formats for versatility in usage.

pentest_skill

2026-08-03 Python ★ 27
Pentest Skill is a comprehensive black-box web penetration testing toolkit designed to streamline the bug bounty workflow through a structured five-phase approach: Intake, Recon, Enum, Hunt, and Report. Notable features include a workflow controller with checkpoints for phase progression, a collection of 48 Python scripts for various testing phases, and an extensive library of attack playbooks and payloads, facilitating targeted vulnerability assessment and reporting.

plankton

2026-08-03 Python ★ 22
Plankton is a command-line web vulnerability scanner designed to conduct checks against the OWASP Top 10 (2021) vulnerabilities on specified URLs. It generates colorful terminal outputs and supports multiple report formats, including a styled HTML report, JSON, and plain text, enabling users to customize scan parameters with ease. Key features include 12 specific vulnerability checks, configurable options such as timeout and user-agent, and an accessible single-file script for quick deployment.

presidio-hardened-vuln-scanner

2026-08-03 Python ★ 49
The presidio-hardened-vuln-scanner is a web application vulnerability scanner designed to analyze both a deliberately vulnerable Flask application and its hardened version. It facilitates a comprehensive security assessment through static analysis, dynamic scanning, and manual exploitation, highlighting various vulnerabilities such as SQL injection and XSS, with a structured approach to measure and verify fixes. Notable features include integration with tools like Bandit and pip-audit for static analysis, as well as a custom scanner to dynamically check for vulnerabilities.

quodeq

2026-08-03 Python ★ 23
Quodeq is an open-source AI-powered tool designed for scanning codebases to detect security vulnerabilities and design flaws, aligning with the ISO 25010 quality dimensions. It provides detailed findings such as grades, violations with line numbers, and fix plans, with every issue mapped to a corresponding CWE identifier. Notably, it operates locally without telemetry, runs on various platforms, and offers both cloud and local model configurations for flexibility and privacy.

scanner

2026-08-03 Python ★ 10
Bawbel Scanner is an open-source tool designed to assess MCP servers and skill files for vulnerabilities, specifically providing OWASP AIVSS scores without executing any code. Its primary use case includes detecting AVE vulnerabilities and ensuring compliance with the MCP specification, while notable features encompass a variety of focused scans, conformance grading, and vulnerability management functionalities. The tool supports formats for reporting, a public vulnerability database, and provides guidance for remediation, making it a comprehensive solution for security assessments of MCP environments.

Shield-Eye-Core

2026-08-03 Python ★ 11
ShieldEye Core is a desktop network security scanner designed for Linux, primarily aimed at security researchers, pentesters, and system administrators. It utilizes Nmap for comprehensive port and service discovery, identifies vulnerabilities in common CMS platforms by cross-referencing with the CIRCL CVE database, and evaluates HTTP security headers, all presented through a GTK 4 GUI with intuitive reporting features. Key functionalities include customizable scanning profiles, a detailed analysis of web security, and robust safety measures against unauthorized access and disruption.

ShieldEye_ComplianceScan

2026-08-03 Python ★ 33
ShieldEye ComplianceScan is a web compliance and vulnerability scanner that assesses web targets against key security standards including GDPR, PCI-DSS, and ISO 27001. It features a GTK4 desktop interface, a CLI for automated scanning, and a REST API for integration, while providing detailed reports that include CVSS v3.1 scoring and export options in various formats. The tool evaluates critical aspects like TLS configuration, security headers, and cookie settings, making it suitable for regular compliance checks and configuration sanity evaluations.

webscan

2026-08-03 Python ★ 25
WebScan is an automated web security auditing tool designed to crawl, discover, and audit web applications. It features a robust plugin architecture with 41 plugins, offers multiple report formats, and is tailored for both site owners and bug hunters, providing user-friendly options like safe mode and detailed explanations of findings, as well as advanced stealth capabilities for more experienced users. Notable capabilities include request rate limiting, user-agent rotation, and proxy support to maintain the user's anonymity.

wshawk

2026-08-03 Python ★ 13
WSHawk is an open-source toolkit designed for WebSocket security testing and web application penetration testing, integrating a CLI scanner, web dashboard, and desktop application. Notable features include stateful WebSocket testing, context-aware payload evolution, browser-assisted evidence collection using Playwright, and a comprehensive suite of web pentesting tools such as fuzzers and interceptors, all under the AGPL-3.0 license. The toolkit also supports project-backed workflows and offers various integrations and reporting formats for efficient security assessment.

Aliens_eye

2026-08-03 Python ★ 3103
Aliens Eye is an advanced AI-driven OSINT tool designed for scanning usernames across over 840 social media platforms, utilizing machine learning and heuristic detection to yield comprehensive results. Key features include asynchronous scanning, profile extraction, cross-site correlation, recursive username expansion, and customizable reporting formats, along with support for proxies and Tor. The tool also offers a modern terminal UI and a server option for integration with LLM agents, making it a versatile solution for username discovery and analysis.

Ayesha-osint-toolkit

2026-08-03 Python ★ 13
Ayesha OSINT Toolkit is an open-source tool designed for conducting various Open Source Intelligence tasks, including username availability checks, email validation, and IP address lookups. Built with Python, it leverages scripts that access publicly available data sources, enabling users to gather crucial information efficiently. Key features include individual script functionalities for username checking, email finding, and detailed IP information retrieval, all of which can be executed based on user requirements.

birdy-edwards

2026-08-03 Python ★ 76
BIRDY-EDWARDS is an AI-driven SOCMINT platform designed for local analysis of publicly available Facebook profile data, enabling authorized users to collect and analyze information without cloud dependencies. Key features include automated profile collection, interaction intelligence with sentiment analysis, country detection using LLM, interactive network graphs, and customizable PDF reporting. This tool is designed for legitimate intelligence, law enforcement, and academic research use, operating with a valid Facebook session and adhering to privacy regulations.

birdy-edwards-lite

2026-08-03 Python ★ 26
Birdy-Edwards Lite is a local-first SOCMINT platform designed for gathering and analyzing publicly available Facebook profile data, including posts and interactions, without requiring AI models or cloud services. It features automated data collection, network visualization, interaction mapping, and various graphical outputs such as heatmaps and force-directed graphs, all optimized for modest hardware capabilities. This tool is specifically tailored for investigators seeking rapid, reproducible results while adhering to data access limitations.

claudii-exploratores

2026-08-03 Python ★ 13
Claudii Exploratores is an OSINT suite that leverages AI to enhance reconnaissance by providing a skill set for the Claude AI model and a Model Context Protocol (MCP) server. It offers a robust catalog of 898 curated OSINT tools across 24 categories, an indicator classifier for various data types, and a curated URL builder that generates relevant search links based on analyzed indicators. Notable features include cross-platform search capability and an offline IBAN verifier, all while ensuring operational control remains with the user.

common-osint-model

2026-08-03 Python ★ 53
The Common OSINT Model is a data model framework designed to simplify the integration and conversion of open-source intelligence (OSINT) data from various sources, primarily focusing on services like HTTP, TLS, and SSH. Notable features include its Pydantic-based structure for enhanced readability and data handling, automatic hash calculation for raw data, and implementation of converters for specific data sources such as Shodan and Censys. The tool is intended to support users by providing a consistent way to manage host and service information derived from external scanning services.

cupidcr4wl

2026-08-03 Python ★ 152
cupidcr4wl is an open-source OSINT tool designed for searching usernames and phone numbers across various adult content platforms, particularly useful in missing persons investigations and human trafficking cases. Key features include support for multiple input formats, result exporting to HTML, and a regularly updated list of platforms for accurate searches. Users can also modify the tool to report inaccuracies and suggest new sites for inclusion.

dorks_hunter

2026-08-03 Python ★ 344
dorks_hunter is a Python-based automation tool that serves as a wrapper for `xnldorker`, enabling users to systematically execute categorized Google dorks against a specified target domain. Its primary use case is to identify vulnerabilities or sensitive information exposure in web applications, with notable features including terminal output of results and an option to save the findings to a file for further analysis.

falconeye

2026-08-03 Python ★ 14
FalconEye is a comprehensive, self-hosted OSINT investigator's toolkit designed to streamline the investigation process through eighteen specialized modules. It facilitates a wide range of investigative tasks including cryptocurrency wallet tracing, phishing kit analysis, and domain intelligence, all integrated within a single interface that promotes one-click connectivity between related tools. Key features include LLM-powered scam detection for email headers, multi-source IP reputation assessments, and a fictional persona generator, making it a versatile platform for cybersecurity professionals.

Farsight

2026-08-03 Python ★ 21
Farsight is a modular CLI-based reconnaissance and threat intelligence framework designed to convert open-source intelligence (OSINT) into actionable insights for security assessments. Its notable features include comprehensive organization discovery, asset recognition, threat intelligence capabilities, and support for news monitoring, alongside customizable outputs in Markdown and PDF formats. The tool can function effectively without API keys while allowing integration with various services for enriched data retrieval.

Gansar

2026-08-03 Python ★ 10
Crypto OSINT investigation toolkit

guns.lol-username-checker

2026-08-03 Python ★ 140
The guns.lol Username Checker is a command-line interface (CLI) tool designed to verify the availability of usernames on the guns.lol platform using Selenium with advanced detection logic. Key features include a stylish purple interface, automatic cleanup of Chrome processes, support for filtering premium aliases, and real-time notifications through Discord webhooks. This tool offers a streamlined user experience with options for custom username lists and logging results.

LinkedInDumper

2026-08-03 Python ★ 611
LinkedInDumper is a Python 3 script designed for extracting employee data from the LinkedIn API. It enables users to collect detailed information, including first names, last names, positions, and profile links with minimal API calls, while also allowing customization of email address formats through a command-line interface. The tool operates using an unofficial LinkedIn API and requires user authentication via a session cookie, facilitating the gathering of data even for accounts protected by two-factor authentication.

MetaDetective

2026-08-03 Python ★ 499
MetaDetective is a Python-based tool designed for metadata extraction and web scraping, specifically tailored for OSINT and pentesting applications. It enables users to extract a wide range of metadata—including authorship, software versions, GPS data, and hyperlinks—from various file types and conduct direct web scraping without reliance on search engines. Notable features include GPS reverse geocoding, customizable output formats, selective field extraction, and deduplication capabilities, making it a comprehensive solution for security researchers and penetration testers.

metawarc

2026-08-03 Python ★ 37
Metawarc is a command-line tool designed for efficient extraction of metadata from files contained within WARC (Web ARChive) archives. Its primary use case involves the analysis and retrieval of metadata from various file formats such as PDFs, MS Office documents, and images, while offering features like built-in WARC support, a low memory footprint, and comprehensive command options for indexing, statistics, and metadata dumping. Notably, it generates a DuckDB database for organized metadata storage and provides easy CLI commands for various extraction tasks.

misp-modules

2026-08-03 Python ★ 376
MISP modules are autonomous extensions designed to enhance the MISP threat intelligence platform by providing new functionalities such as data expansion, import/export capabilities, and workflow actions. These modules can operate independently through a web interface or command-line interface, utilizing a simple REST API for integration with other tools. Built in Python 3, they facilitate the customization of MISP's features without altering its core architecture, making it easier for users to extend functionality while maintaining system integrity.

Odinova

2026-08-03 Python ★ 95
Odinova Digital Tiger is a discontinued application designed for Open-Source Intelligence (OSINT) that provides a comprehensive suite of tools for investigative workflows and data analysis. Notable features include a tabbed interface for document management and Markdown file viewing, HTML rendering for clear presentation, and dark theme support for enhanced usability. The tool aims to centralize OSINT operations, enabling efficient data management and promoting collaboration among users.

ogi

2026-08-03 Python ★ 282
OpenGraph Intel (OGI) is an open-source visual link analysis and OSINT framework designed for interactive exploration of connections between entities. Its primary use case lies in performing in-depth investigations through features such as a visual graph interface, over 20 built-in data transforms, real-time collaboration, and a plugin system for custom analytics. Notable functionalities include an AI Investigator for prompt-driven analysis, multi-format import/export capabilities, and seamless deployment via Docker.

OSINTai

2026-08-03 Python ★ 47
OSINTai is an advanced AI-powered web crawler designed for Open Source Intelligence (OSINT) professionals, enabling efficient and accurate intelligence gathering from various web sources. It features high-performance asynchronous crawling, intelligent proxy management, and AI-driven content analysis, allowing for comprehensive extraction of indicators such as emails, domains, and social media handles, while ensuring operational security through stealth techniques and duplicate content detection. Notably, OSINTai includes a scoring system that prioritizes data based on risk assessment and indicator density, enhancing the relevance and utility of the gathered intelligence.

postleaks

2026-08-03 Python ★ 218
Postleaks is a cybersecurity tool designed to identify sensitive data leaks in the public library of the Postman API platform. It allows users to search for specific keywords within public API assets, using customizable options such as strict matching and workspace extension, while utilizing the Whispers library for secret detection. Notable features include output formatting, keyword file input, and the ability to display results in JSON format, along with various filters for refinement.

psn_monitor

2026-08-03 Python ★ 41
psn_monitor is a Python-based tool designed for real-time tracking of Sony PlayStation Network (PSN) player activities, allowing users to monitor online status, game play, and detailed player profiles. It features capabilities such as email notifications for various player events, CSV logging of user activities, and configuration flexibility through environment variables and command-line arguments. The tool is optimized for functionality with minimal object-oriented programming, ensuring ease of use for automation and monitoring purposes.

pyahmia

2026-08-03 Python ★ 17
PyAhmia is a command-line tool that allows users to search for hidden services on the Tor network by querying the Ahmia.fi search engine without the explicit requirement of using Tor. Notable features include the ability to export search results to CSV, enable or disable routing through Tor, cache responses for faster searches, and filter results by time period and limit.

SearchPhone

2026-08-03 Python ★ 1870
SearchPhone is a robust OSINT tool designed for retrieving linked phone number information by leveraging multiple APIs to aggregate data from various sources. Key features include phone number validation, simultaneous searches across Google and DuckDuckGo, GitHub code searches, social media mentions on Reddit, carrier information retrieval, and automated report generation in both JSON and PDF formats, all executed with efficient parallel processing for improved speed.

security-suite

2026-08-03 Python ★ 98
Security Suite is an open-source toolkit designed for comprehensive OSINT reconnaissance, web security testing, API security assessments, and compliance checks, all enhanced with AI-powered analysis capabilities. It features 11 OSINT modules, six web scanners, and four API security tools, along with integration for SIEM systems, scheduled scans, and a REST API for programmatic access. The tool simplifies setup across multiple operating systems and allows for customization of AI models and tool options during installation.

Telegram-OSINT-Toolkit

2026-08-03 Python ★ 40
The Telegram OSINT Toolkit is a sophisticated, locally operated tool designed for intelligence gathering on the Telegram platform, aimed at use cases in OSINT, cybersecurity research, and authorized law enforcement. Key features include advanced search capabilities, bulk monitoring, comprehensive data exports in multiple formats, member enumeration, and real-time monitoring, complemented by support for proxy and Tor integration, and persistent SQLite storage for efficient data handling.

tempolocus

2026-08-03 Python ★ 18
tempolocus is a time-series analysis tool designed to infer geographical location based on activity patterns observed over time. Its primary use case involves processing JSON-formatted data, including weekly and yearly activity buckets or timestamp lists, to generate probabilistic outputs that classify activity types and suggest probable countries and timezones. Notable features include support for various holiday profiles, comparative analysis against holiday calendars, and the ability to handle multiple input formats for versatile applicability.

TokIntel

2026-08-03 Python ★ 91
TokIntel is an advanced TikTok OSINT framework designed to extract comprehensive profile information, including bios, creation dates, and full metadata from TikTok usernames. Notable features include fast API-based data retrieval using Apify's TikTok Profile Scraper, batch processing for multiple usernames, and the generation of JSON and text reports for structured data output. Its user-friendly CLI interface allows for efficient profile reconnaissance and secure API key handling.

tornado-demix

2026-08-03 Python ★ 14
Tornado-demix is a forensic research toolkit designed for the de-anonymization of Tornado.Cash ETH transactions by leveraging public on-chain data. It utilizes a probabilistic heuristic to correlate deposit and withdrawal patterns based on transaction timing and fixed-denomination amounts, outputting likely exit addresses for further investigation. Key features include support for single and multiple wallet analysis, denomination-profile matching, and cluster tracing, all performed without compromising cryptographic integrity.

userbot

2026-08-03 Python ★ 10
Project Akasha is a modular Telegram UserBot utilizing the Telethon framework, designed for context-aware interaction and automation. It features advanced capabilities such as localized voice synthesis through Edge-TTS, a two-stage music downloader, and various group management tools, making it suitable for users looking to enhance their Telegram experience with AI-driven functionalities. Importantly, caution is advised due to its heavy scraping and growth modules, which can lead to user bans if misused.

Visualize-External-Addresses

2026-08-03 Python ★ 10
Visualize-External-Addresses is a Python tool that enables real-time visualization of external IP address connections for Windows devices, integrating netstat output with Whois data and displaying it through Google Earth. The tool allows users to monitor and analyze network connections by generating KML files for external addresses, which can be updated every few seconds for continuous tracking. Notable features include easy setup via Anaconda, location-based monitoring with latitude and longitude inputs, and the requirement of Google Earth for graphical representation.

WhatsOSINT

2026-08-03 Python ★ 335
WhatsOSINT is a tool designed to retrieve and display information associated with a WhatsApp number, such as status and profile photo, utilizing data from an API. Its primary use case is for OSINT (Open Source Intelligence) investigations, allowing users to toggle between live checks or cached data to manage API costs effectively. The project includes customizable settings for check modes and data providers, making it adaptable to various user needs while ensuring compatibility with multiple operating systems.

zettelforge

2026-08-03 Python ★ 58
ZettelForge is an agentic memory system specifically designed for cyber threat intelligence (CTI) that captures and maintains critical contextual knowledge from analysts. It automates the extraction of CVEs, IOCs, threat actors, and MITRE ATT&CK techniques from analyst notes, resolves naming aliases, and constructs a comprehensive STIX 2.1 knowledge graph, facilitating intent-aware searches without the need for external APIs. This tool aims to mitigate the knowledge loss associated with analyst turnover, enhancing investigation continuity and effectiveness within security operations centers.

aarya

2026-08-03 Python ★ 41
Aarya is an advanced OSINT tool designed to validate email addresses and extract detailed digital footprints across various platforms, including social media and e-commerce sites. Notable features include a deep analytical capability that retrieves extensive metadata such as Google Maps reviews and account creation dates, as well as dynamic user-agent management to enhance stealth during scans. Aarya focuses on delivering high-quality identity intelligence rather than merely confirming existence, offering a sophisticated user interface and explicit reporting on scan results.

AI-OSINT-Security-Analyzer

2026-08-03 Python ★ 14
The AI OSINT Security Analyzer is a Streamlit-based web application that leverages AI technology, specifically Cohere's Command A model, to conduct comprehensive threat assessments for websites, IP addresses, and software vulnerabilities. It integrates multiple data sources such as Shodan, VirusTotal, AbuseIPDB, and CVE databases, providing users with actionable insights into security risks. The tool features a user-friendly interface and is open source, inviting community contributions to enhance its capabilities.

clearfront

2026-08-03 Python ★ 14
Clearfront is an open-source OSINT (Open Source Intelligence) tool that leverages AI to analyze digital footprints across more than 3,400 public data sources, providing users with comprehensive reports and interactive evidence graphs based on input such as emails, usernames, or IP addresses. It supports multiple interfaces including a terminal REPL, CLI, web console, and MCP server, while integrating with various AI backends to ensure accurate results without hallucination. Key features include parallel tool execution, extensive modular tools, and the capability to run fully offline with user-provided API keys.

Crawllama

2026-08-03 Python ★ 107
Crawllama is an AI research agent designed for open-source intelligence (OSINT) and multi-hop reasoning, capable of executing complex queries through advanced agent selection and adaptive processing. It features integration with local large language models, a REST API for extensibility, and performance optimizations for parallelization and large context support. Notable features include a multi-hop reasoning workflow, intelligent caching, and a plugin system that enhances its adaptability for various intelligence tasks.

Crimson-Wolf

2026-08-03 Python ★ 13
Crimson-Wolf is an all-in-one utility suite for Discord, designed primarily for educational and research purposes, offering functionalities related to Discord tokens, webhooks, and bots. Key features include tools for token management, OSINT capabilities, and a user-friendly interface, with compatibility for both Windows and Linux operating systems. This tool is frequently updated and emphasizes security, advising users to download only from the official GitHub repository to avoid malicious versions.

cyberbro

2026-08-03 Python ★ 684
Cyberbro is a user-friendly application designed to extract Indicators of Compromise (IoCs) from unstructured input and assess their reputation using various threat intelligence services. Key features include automatic parsing of logs, multithreaded processing for rapid checks, comprehensive reporting capabilities, and integrations with major cybersecurity tools. Its lightweight deployment and support for advanced domain and abuse information make it suitable for both beginners and experienced analysts seeking efficient IoC management.

favihunter

2026-08-03 Python ★ 256
Favihunter is a cybersecurity tool designed for security practitioners to identify and discover related internet assets through the analysis of favicon hashes across multiple search engines. Its primary use case involves downloading a favicon from a provided URL, computing various hash representations, and generating search URLs for platforms like Censys, Shodan, and VirusTotal, among others. Notable features include the ability to analyze single URLs, multiple URLs from a file, and local favicon files, as well as a clean-up option for temporary files.

focal-harvest

2026-08-03 Python ★ 20
Focal Harvest is a lightweight Python CLI tool designed to automate web research and OSINT collection, streamlining the process of querying, scraping, and synthesizing data from multiple online sources. Its notable features include zero-config local statistical fallbacks for offline operation and a bidirectional mobile bot listener for real-time interaction via Telegram and Discord. The tool significantly enhances efficiency by automating repetitive manual tasks, enabling users to generate structured reports with minimal setup and rapid execution.

github_monitor

2026-08-03 Python ★ 53
github_monitor is a real-time GitHub OSINT tool designed to track various user activities such as profile updates, repository engagement, and follower changes, with instant notifications via email and webhooks. Its notable features include comprehensive tracking of new GitHub events, detecting when a user blocks or unblocks you, saving all activities with timestamps to CSV files, and support for both public and enterprise GitHub environments. Additionally, it facilitates easy integration with notification services like Discord and ntfy.

H4X-Tools

2026-08-03 Python ★ 819
H4X-Tools is a modular, terminal-based toolkit designed for open-source intelligence (OSINT) gathering, reconnaissance, and web scraping, developed in Python to operate on both Linux and Windows. Its primary use case includes advanced data extraction and analysis from platforms like Instagram, as well as comprehensive searches for usernames, emails, and phone numbers across various databases and services. Notable features include support for multiple data formats for export, configurable queries with customizable parameters, and integration with external libraries for enhanced functionality.

horus

2026-08-03 Python ★ 746
Horus is a comprehensive investigative tool designed to assist users with data compilation and API interactions, serving as a pre-operations assistant. It features a modular architecture allowing for API configuration, functionality checks, and integration with services like Shodan, while requiring specific CLI tools for additional capabilities. The tool aims to streamline investigations by providing essential data management and interaction tools in one package.

lastfm_monitor

2026-08-03 Python ★ 26
lastfm_monitor is a real-time tracking tool for Last.fm that facilitates the automated playback of songs in the local Spotify client while providing comprehensive analytics on user listening activity. Notable features include instant notifications for user presence changes, song metrics like duration and skips, persistent status tracking, webhook integrations for alerts, and a wrapped statistics generator that summarizes listening habits. The tool also supports configurable alerts via email and external services, making it a versatile option for music data management and engagement.

LeakIXClient-Python

2026-08-03 Python ★ 28
The LeakIX Python client provides a programmatic interface for interacting with the LeakIX platform, primarily utilized for retrieving and handling data related to internet leaks, subdomains, and other events in a structured manner. It supports both synchronous and asynchronous API calls, with responses encoded in a defined format, allowing users to leverage built-in methods for response handling and data transformation. This client is compatible with Python versions 3.11 through 3.14 and facilitates easy integration into Python applications through its straightforward installation and documentation.

marple

2026-08-03 Python ★ 321
Marple is an open-source tool designed to collect links to online profiles based on usernames across multiple search engines, providing functionality for social media investigations and online presence analysis. Its notable features include support for over ten search engines, proxy integration, CSV export of results, and plugins for enhanced metadata extraction and information gathering. By allowing customization of search parameters and reliability thresholds, Marple enables users to refine their queries for more accurate data retrieval.

microsoft-ips

2026-08-03 Python ★ 14
The microsoft-ips repository provides systematically compiled text-file lists of Microsoft-owned IP address ranges and service endpoint domain names in multiple formats, tailored for integration with firewalls and DNS categorization. Notable features include categorization by geographic region and service, such as Worldwide, US Gov DoD, and China (21Vianet), alongside various formats like CIDR notation for IPv4/IPv6 and FQDNs with or without wildcards. This tool is essential for organizations needing to configure network security and access control for Microsoft services.

navi-multitool

2026-08-03 Python ★ 173
Navi Multitool is a high-performance terminal application designed for security testing and OSINT exploration, featuring a modern user interface and an extensive suite of specialized modules. Notable functionalities include Discord operations, advanced exploitation tools such as a Discord RAT and SQL scanner, and utilities for network mapping and cryptography. This tool caters to various use cases from automation of Discord tasks to targeted intelligence gathering and exploitation, providing users with a comprehensive arsenal for cybersecurity tasks.

NERD

2026-08-03 Python ★ 38
NERD (Network Entity Reputation Database) is a software tool and service designed to acquire, store, and aggregate data on malicious network entities, primarily focusing on IP addresses. It provides users with an accessible interface to analyze and retrieve information about these threats, facilitating enhanced network security decision-making. Notable features include its comprehensive data aggregation capabilities and a dedicated instance available at nerd.cesnet.cz for user access.

Ominis-OSINT

2026-08-03 Python ★ 613
Ominis-OSINT is a digital reconnaissance tool designed for gathering and analyzing publicly available information from various online sources. It notably offers features such as Google search filtering, an enhanced user interface, optimized threading for faster performance, and proxy validation for secure, anonymous searches. The tool specializes in username searches, providing detailed insights while mimicking human-like behavior to evade detection by anti-bot mechanisms.

OnionClaw

2026-08-03 Python ★ 233
OnionClaw is a multifunctional tool designed to provide AI agents with complete access to the Tor network and .onion services, facilitating OSINT, threat intelligence, and security research. Its notable features include automated dark-web crawling, continuous threat monitoring, and advanced credential surveillance with full identity rotation, all capable of operating in both an OpenClaw skill environment and as a standalone application. While intended for legitimate use, the tool's capabilities raise significant concerns regarding the potential for misuse in criminal activities and automated disinformation campaigns.

OSINT

2026-08-03 Python ★ 128
The OSINT repository by JambaAcademy is a comprehensive resource for enhancing open-source intelligence gathering and analysis, providing templates and tools tailored for a variety of professional applications. Key features include AI-driven methodologies, standardized reporting templates, and extensive coverage of over 100 OSINT tools across multiple investigative categories. This repository aims to streamline investigative processes while ensuring ethical standards and legal compliance.

osint-cli-tool-skeleton

2026-08-03 Python ★ 82
The OSINT CLI Tool Skeleton is a versatile framework for developing OSINT tools, enabling users to create functionality with minimal coding effort. It allows developers to implement a single plugin file that can be automatically utilized as a command-line interface (CLI), Python library, HTTP microservice (using FastAPI), and as an MCP server for AI agents, with built-in support for concurrency, proxying, and reporting in various formats. Notable features include auto-discovery of plugins, customizable reporting options, and an easy-to-use library API for synchronous and asynchronous operations.

shodan_reconsx

2026-08-03 Python ★ 35
Recons101x is a portable passive reconnaissance tool designed to enumerate hostnames from the Shodan service without requiring an API key or third-party libraries. It supports batch scanning, various output formats (including JSON), and optional DNS resolution, making it suitable for authorized testing on hosts. The tool operates across multiple platforms using Python 3 and includes configurable options like timeout settings and concurrent workers for enhanced usability.

spotify_monitor

2026-08-03 Python ★ 107
Spotify Monitor is a real-time tracking tool designed to monitor friends' music activity on Spotify, allowing users to track listening habits, sync playback, and receive notifications for skipped tracks. It offers two primary functionalities: monitoring Spotify friends' activity and checking the health of Last.fm scrobbles, alerting users if their plays do not appear on their Last.fm profile. Notable features include presence detection, session statistics, and a versatile setup process via Python or Docker.

spotify_profile_monitor

2026-08-03 Python ★ 59
Spotify Profile Monitor is a powerful tool designed for real-time tracking of changes within Spotify profiles, including playlist updates, follower growth, and profile alterations. Its notable features include notifications via various channels, a detailed history log, and tools for exporting playlist data and searching for users, making it a comprehensive solution for Spotify users who want to stay informed about their accounts and those of their friends.

steam_monitor

2026-08-03 Python ★ 56
Steam Monitor is a powerful tool designed for real-time tracking of Steam players' activities, including monitoring their online status and gameplay. Notable features include detailed user information insights, automated email and webhook notifications, session continuity handling, and flexible configuration options, all of which allow users to gain comprehensive insights into a player's gaming behavior and interact with changes effectively.

SubreconGemini

2026-08-03 Python ★ 17
SubreconGemini is a high-performance subdomain discovery tool that leverages Google Gemini AI, certificate transparency logs, and customizable wordlist brute-forcing to identify and validate live subdomains. Key features include hybrid discovery methods, smart validation techniques to minimize false positives, maximum concurrency through asynchronous operations, and the ability to generate structured output reports in various formats. The tool is designed for flexibility, allowing users to scan single or multiple domains while enabling optional AI-enhanced discovery capabilities.

va-pt

2026-08-03 Python ★ 40
The VAPT Toolkit provides a comprehensive environment for vulnerability assessment and penetration testing, integrating over 50 third-party security tools and custom automation frameworks on an Ubuntu 22 platform. Notable features include a deterministic network exploitation orchestrator that automates host discovery and vulnerability verification using nmap and Metasploit, as well as a MITM browser autopwn orchestrator combining tools like bettercap and Responder for streamlined exploitation. The toolkit supports extensive automation in reporting, deliverable generation, and a wireless attack framework for versatile testing capabilities.

WayTrace

2026-08-03 Python ★ 26
WayTrace is a domain reconnaissance tool that leverages the Wayback Machine to reconstruct the public history of a specified domain, extracting 43 categories of intelligence such as emails, subdomains, and exposed secrets. It operates entirely outside the target environment, ensuring that no direct interaction occurs, and it provides a detailed timeline of findings based on archive data, along with self-hosting capabilities and a user-friendly interface in both English and French. Notably, it features a guided scanning process and comprehensive configuration options for customized usage.

webamon-cli

2026-08-03 Python ★ 10
Webamon CLI is a command-line interface designed for utilizing the Webamon Search API, enabling users to perform extensive threat intelligence searches and threat hunting across the web. Key features include the ability to search a vast corpus by domain, IP, URL, or hash, on-demand website scanning, compromised credentials hunting, and tracking of phishing and malware campaigns. The tool also supports exporting results in various formats, making it a versatile solution for cybersecurity professionals.

claude-skills-journalism

2026-08-03 Python ★ 379
The "claude-skills-journalism" tool provides a suite of modular agent skills tailored for journalists, researchers, and media professionals, facilitating the integration of AI into their workflows. It features interactive skill browsing, setup guides, and support for multi-agent workflows, enabling users to automate and enhance various journalism-related tasks, such as fact-checking, interview preparation, and editorial processes. Notably, it supports both Claude and Codex environments, allowing for customized commands and persistent session management to maintain continuous productivity.

cti-expert

2026-08-03 Python ★ 584
CTI Expert is a cyber threat intelligence and open-source intelligence analysis toolkit that enables users to convert Claude into a trained intelligence analyst, utilizing over 74 commands across 49 techniques. This tool operates without requiring API keys for its core functionalities, facilitating structured intelligence collection and analysis. Notable features include the capability to integrate personal API keys for enhanced functionality and ease of use with automatic detection of the keys in the configuration.

funstat-api

2026-08-03 Python ★ 17
Funstat API is a Python client designed for interfacing with the Funstat/Telelog API to retrieve and analyze Telegram user and group statistics. It supports both synchronous and asynchronous operations, offering a variety of methods such as retrieving user stats, group members, message counts, and nickname histories, making it suitable for developers looking to gather insights into Telegram data efficiently. Notable features include easy token management, customizable configurations, and the ability to handle user privacy settings gracefully.

GlobalAntiScamOrg-blocklist

2026-08-03 Python ★ 35
The Global Anti Scam Organization blocklist provides a machine-readable list of scam URLs and IP addresses, updated daily, to assist in identifying and blocking fraudulent online activities. Utilizing Python and frameworks such as Selenium, the tool offers diverse formats for downloading the blocklist, including versions compatible with popular ad blockers and network-wide filtering tools. Its primary use case is to enhance cybersecurity measures by mitigating risks associated with online scams.

MailAccess

2026-08-03 Python ★ 1143
MailAccess is a self-hostable OSINT platform designed for investigating email addresses by aggregating data from breach databases, social networks, DNS records, and the open web. It features an identity graph for correlating user accounts, a name consensus engine for verifying identities, and a domain email harvesting tool that discovers organization addresses from multiple data sources. The tool provides structured findings in various export formats and is specifically tailored for security researchers and penetration testers.

public-dns-servers

2026-08-03 Python ★ 39
The `public-dns-servers` repository provides an up-to-date list of verified public DNS servers, filtered for reliability and performance. Its primary use case is to facilitate automated tasks or Open Source Intelligence (OSINT) activities that require dependable DNS resolvers. Notable features include weekly updates via a CI/CD pipeline and strict criteria for server validation based on response time and accuracy.

RivalSearchMCP

2026-08-03 Python ★ 125
RivalSearchMCP is a deterministic research server that provides a comprehensive toolset to search, fetch, score, and compare information autonomously across multiple domains, including web, social platforms, news, academic databases, and code repositories. It features nine specialized tools with capabilities like auto-quality scoring, conflict detection, and structured output for seamless integration with AI models. The server operates without the need for API keys, ensuring accessibility and ease of use while maintaining production-level hygiene through rate limiting and built-in observability.

scope-intelligence

2026-08-03 Python ★ 27
Scope Intelligence is a self-hosted OSINT research platform designed for collecting, retrieving, and analyzing public web evidence to produce attributable company intelligence. It features versioned sources with citations, relationship mapping among entities, and a comprehensive review process, ensuring operators have traceable evidence linked to their findings. Additionally, the tool emphasizes security and operator control, offering customizable data collection environments and robust diagnostic capabilities.

velocity

2026-08-03 Python ★ 82
Velocity is a self-hosted mapping tool that provides users the ability to visualize and rewind the historical positions of aircraft, ships, and other entities without the reliance on third-party API keys or services. Its notable features include the ability to maintain an unlimited history on local storage, a comprehensive evidence locker with SHA-256 hashing for provenance tracking, and an integrated MCP server for AI querying. The tool emphasizes data integrity and user ownership, presenting a trustworthy interface for monitoring various live feeds and events.

cloudcheck

2026-08-03 Python ★ 93
CloudCheck is a Rust-based tool designed to determine if a given IP address or hostname is associated with a cloud service provider. It features a command-line interface (CLI), a Rust library, and Python bindings, with dynamic updates for cloud provider signatures and CIDR data from community sources. The tool also supports a REST API for programmatic access, allowing for integration in various applications.

contrastapi

2026-08-03 Python ★ 33
ContrastAPI is a comprehensive security intelligence tool designed for AI agents, providing grounded answers regarding vulnerabilities, threats, and attack surfaces by aggregating data from authoritative sources like the NVD and CISA KEV. It features a robust REST API with over 60 endpoints for CVE/KEV/CWE lookups, exploit probability scoring, domain and IP investigations, IOC enrichment, and code-security checks, while also facilitating seamless integration through SDKs for Python and Node.js. Notably, it is free to use without requiring API keys or signups, offering 55 tools and 7 resources for effective security analysis.

Epstein

2026-08-03 Python ★ 50
The Epstein repository is a monitoring tool designed to track changes to the Department of Justice's released Epstein Files, which contain extensive documentation of a global child sex trafficking network. It automatically checks for new, removed, or altered files every six hours, maintaining a comprehensive changelog and offering interactive data visualizations, such as flight maps and passenger networks. Key features include a searchable database of individuals connected to the case and detailed analysis of flight routes associated with the trafficking.

IntelOwl

2026-08-03 Python ★ 4689
IntelOwl is an open-source Threat Intelligence management tool designed to provide comprehensive threat data regarding malware, IP addresses, and domains through a single API request. It features a fully-fledged REST API, a built-in graphical user interface for data visualization, and a modular plugin framework that allows for integration with various analyzers and connectors, facilitating automation for security analysts. Its scalability and speed in retrieving intelligence data make it suitable for enhancing the efficiency of security operations centers (SOCs).

ip-tracker

2026-08-03 Python ★ 17
Ip-tracker (Chakravyuh) is a reconnaissance framework designed for red teaming and security research, offering a fusion of passive OSINT techniques with advanced social engineering features. Its notable capabilities include auto-tunneling, real-time alerts to Telegram, and comprehensive device fingerprinting, all without manual port forwarding. The tool facilitates IP intelligence, phone number validation, and multi-threaded port scanning, enhancing the efficiency of data collection and target analysis.

open-source-aviation

2026-08-03 Python ★ 137
Open-source Aviation is a comprehensive catalog of aviation-related open-source projects and datasets, providing access to a wealth of information such as ADS-B data, airport details, weather data, and tools for various aviation applications. Key features include community-driven resources, statistical data, and tools for aeronautic calculations, making it a valuable repository for developers and aviation enthusiasts looking to leverage open-source data for analysis and development. The project encourages contributions and continuous expansion, fostering collaboration in the aviation software community.

OpenOSINT

2026-08-03 Python ★ 1503
OpenOSINT is an OSINT agent designed for security researchers and analysts, featuring 19 investigation tools accessed through a natural-language interface. It can be utilized as a REPL, CLI, MCP server, or web UI, with notable capabilities including credible execution of tool calls, ensuring accurate data retrieval without hallucinations. The tool also integrates seamlessly with services like IP2Location for enhanced IP tracking and RapidProxy for efficient data collection.

OpenTrace

2026-08-03 Python ★ 17
OpenTrace is an offline desktop application designed for organizing and analyzing Open Source Intelligence (OSINT) investigations. It features a visual investigation board that allows for extensive customization, including editable relationship labels and a task management system, while ensuring complete user privacy without any online dependencies. Key functionalities include a global OSINT tool library, automatic saving, cross-platform compatibility, and the ability to export data in both PNG and JSON formats.

ransomposts

2026-08-03 Python ★ 46
Ransomposts is a tool that aggregates and displays ransom notes published by ransomware groups, with updates occurring twice daily from the source at ransomware.live. Its primary use case is to provide cybersecurity professionals and researchers with timely information about ransomware activities and trends. Notable features include automated data fetching and a dedicated publication interface accessible via a web link.

shortdot-evidence

2026-08-03 Python ★ 106
ShortDot Evidence is a cybersecurity tool designed to catalog and analyze the domains registered under ShortDot SA's registry, focusing on domains that are primarily used for phishing activities. It provides a comprehensive enumeration of over 6.2 million domains, highlighting the high rate of brand impersonation and the absence of legitimate businesses among these registrations. Notable features include live statistics on phishing domain counts, daily auto-updated data retrieval, and detailed insights into the estimated revenue generated by ShortDot, making it a valuable resource for threat intelligence in the domain space.

ThreatFox-IOC-IPs

2026-08-03 Python ★ 59
ThreatFox IOC IPs is a Python-based tool that generates a machine-readable IP blocklist sourced from ThreatFox, a project by Abuse.ch. It provides users with an updated blocklist of malicious IPs every hour, making it suitable for cybersecurity applications like threat intelligence and proactive network defense. Notable features include automatic updates and compatibility with the AIOHTTP library for efficient data handling.

USOM-Blocklists

2026-08-03 Python ★ 23
The USOM Blocklists repository provides a daily updated collection of malicious URLs and IP addresses compiled by the Turkish Cyber Security Directorate. It serves as a resource for cybersecurity professionals to enhance their threat detection and prevention capabilities, offering various formats of blocklists suitable for different applications, such as ad blockers and network filtering tools. Notable features include multiple download options for blocklists and integration with GitHub Actions for automated updates.

voidaccess

2026-08-03 Python ★ 654
VoidAccess is a self-hostable OSINT tool designed for transforming dark-web research queries into structured threat intelligence, catering to security researchers and threat-intelligence teams. Its notable features include parallel collection of diverse data sources, entity extraction, multi-source enrichment, relationship mapping, and various export formats, all operable via a CLI or a web UI with a Docker Compose setup. The tool emphasizes content safety and pipeline efficiency to ensure reliable threat investigation and analysis.

XposedOrNot-API

2026-08-03 Python ★ 95
XposedOrNot API provides real-time data breach monitoring by allowing users to check if an email or domain has been involved in known breaches. Its key features include easy access to breach lookups and analytics without requiring an API key for basic functionality, and comprehensive alerts for ongoing breach risks. This open-source API is designed for developers to integrate breach monitoring into their applications efficiently.

AutoShell

2026-08-03 Python ★ 20
AutoShell is a web scanner tool designed to identify vulnerabilities and potential file upload points on websites. Its primary use case is to exploit such vulnerabilities by uploading files using various evasion techniques, including modifying file extensions, employing steganography, and using polyglot files to bypass security measures. Notable features include automated vulnerability detection, an array of file manipulation techniques to conceal uploaded scripts, and a user-friendly interface for initiating scans.

BruteForceIG

2026-08-03 Python ★ 11
BruteForceIG is a brute force tool designed for educational purposes to test the security of Instagram accounts. Its primary use case is to help users understand authentication mechanisms and security defenses, featuring multi-threading for optimal speed, random user-agent support, and capabilities such as SSL pinning bypass. The tool emphasizes responsible use, stressing that unauthorized access may lead to account blocking or legal action.

emailbomber

2026-08-03 Python ★ 81
Email-Bomber is an open-source tool designed for sending bulk emails using Python's SMTP library, with an easy setup process including Docker support and a GUI version. Its primary use case is for testing email systems through simulated bulk sending, and it features secure app password integration for Gmail accounts, ensuring minimal interference with standard authentication processes. The tool provides comprehensive installation guidance for various platforms, including Termux and Linux distributions.

Ghostshell

2026-08-03 Python ★ 21
Ghost Shell is a user-friendly Python-based backdoor generator that simplifies the process of creating payloads for Windows, Linux, and Android using msfvenom. It automates the payload creation and Metasploit listener setup for ease of use, featuring one-click operations and a visually appealing interface tailored for beginners in cybersecurity. Notable features include compatibility with services like Ngrok, customization options for IP and port, and a lightweight design aimed at educational purposes only.

kizagan

2026-08-03 Python ★ 124
Kizagan is a Remote Access Trojan (RAT) and Command and Control (C2) tool developed in Python, designed to create executable files for controlling compromised machines. Key features include advanced functionalities such as file management, real-time screen streaming, capturing screenshots and video from the victim's camera, and an integrated keylogger. The tool is intended for educational use in security research and red teaming, with ongoing development for enhanced capabilities.

php-in-jpg

2026-08-03 Python ★ 13
php-in-jpg is a tool for generating JPEG images that embed PHP payloads leveraging two methods: inline embedding and EXIF metadata injection. It facilitates remote code execution (RCE) through a GET-based execution mode or fixed command specifications, making it particularly useful in webshell demos and upload exploitation scenarios. Notable features include customizable templates for output, an optional preview mode, and support for both embedding techniques.

pinkcord

2026-08-03 Python ★ 17
Pinkcord is a Python-based remote administration tool that uses Discord bots for command and control (C2) communication, allowing users to manage remote systems in a manner analogous to traditional RATs. Notable features include executing remote shell commands, file transfers, screen capture, and system interaction capabilities, while leveraging Discord's infrastructure for seamless communication. It is important to note that Pinkcord is designed strictly for educational purposes and its misuse can lead to legal repercussions.

RAR-NextgenerationAI-expliot

2026-08-03 Python ★ 22
RAR-NextgenerationAI-expliot is a robust toolkit designed for conducting scientific investigations into malware development and evasion techniques. It encompasses a variety of functionalities, including executable file creation, RAR file assembly with both documents and payloads, process injection, and advanced AI-driven methods to evade detection by security mechanisms. Additionally, it integrates polymorphic code and persistence techniques to enhance stealth and maintain access, culminating in a comprehensive resource for malware analysis and research.

VulnScan

2026-08-03 Python ★ 70
VulnScan is a vulnerability scanning tool designed to assist website owners in identifying and addressing security threats by leveraging the OpenAI ChatGPT AI model to analyze JavaScript code for vulnerabilities. Although no longer actively maintained, it offers features aimed at detecting and fixing security flaws, with potential future enhancements planned, including support for various vulnerability types and improved user interface options. The tool is intended for educational use, emphasizing the importance of compliance with legal standards.

AdminDirectoryFinder

2026-08-03 Python ★ 34
AdminDirectoryFinder is a Python tool designed to scan for and identify sensitive directories, specifically under admin paths, within web applications. It is primarily used by penetration testers and developers to enhance security by detecting hidden admin panels and ensuring proper access controls. Notable features include its straightforward installation process and focus on security testing.

Automated-Bug-Bounty-Scanner

2026-08-03 Python ★ 10
The Automated Bug Bounty Scanner is a comprehensive reconnaissance and vulnerability scanning tool designed specifically for bug bounty hunters and penetration testers. It automates web application security testing by efficiently crawling and analyzing websites for vulnerabilities such as hidden admin panels, CMS weaknesses, and sensitive file exposures, while offering features like intelligent recursive crawling, prioritized vulnerability results, and built-in brute force capabilities through an intuitive GUI.

awacs-scanner

2026-08-03 Python ★ 18
awacs-scanner is an automated vulnerability scanning tool designed to gather extensive information about systems and identify potential exploits using multiple sources, including Vulners API and SearchSploit. Its primary use case involves scanning for vulnerabilities across multiple targets specified in files, streamlining the reconnaissance process without the need for manual searches. Notable features include various scan modes such as stealth_flight, vuln_scan, and battering_ram, as well as capabilities for S3 bucket discovery.

ClarityCLI

2026-08-03 Python ★ 30
Clarity CLI is a multifunctional tool library developed in Python, designed for various tasks related to Open Source Intelligence (OSINT) and cybersecurity. Its notable features include comprehensive OSINT search capabilities, password management tools, and SQL vulnerability detection and exploitation functionalities. The tool aims to assist users in gathering digital information while emphasizing responsible usage.

ddos

2026-08-03 Python ★ 184
The "ddos" repository is a Python-based DDoS attack script that offers over 36 attack methods across Layer 7 and Layer 4 protocols, targeting various web server vulnerabilities. It includes notable features such as bypass mechanisms for popular anti-DDoS services like CloudFlare and OVH, as well as various flooding techniques like GET and POST floods. This tool is primarily aimed at penetration testing scenarios but is explicitly discouraged from usage against government sites.

DRILL_V3

2026-08-03 Python ★ 38
DRILL (Distributable Remote Integrated Lightweight Link) is an advanced Command and Control (C2) framework designed for covert operations across diverse environments. Key features include WebSocket communication for efficient data transfer, single-port operation to evade detection, cloud tunnel compatibility, and comprehensive file transfer options. Additionally, it supports cross-platform payload generation and offers a redesigned user interface for improved usability, alongside robust persistence mechanisms and post-exploitation modules for enhanced control over target systems.

Fake-SMS

2026-08-03 Python ★ 31
The Fake-SMS tool is a Python script that enables users to send SMS messages via the Textbelt API, featuring an interactive command-line interface with color enhancements for ease of use. Its primary use case revolves around programmatically sending text messages, providing clear feedback on message delivery status, and ensuring compatibility across multiple operating systems including Windows, macOS, and Linux. Notable features include API integration, colorful prompts using libraries such as `pystyle` and `colorama`, and a straightforward setup process.

gditools3

2026-08-03 Python ★ 14
gditools3 is a Python library and command-line tool designed for managing GD-ROM image (GDI) files, facilitating the listing, extraction, and generation of various file formats including sorttxt and boot sector (IP.BIN). The tool supports both Python 2 and 3, offers a graphical user interface for ease of use, and maintains file timestamps during extraction, while also providing functionality suitable for integration into other Python applications. Notable features include support for different data track formats and media playback capabilities via an external player.

hacking-tools

2026-08-03 Python ★ 37
The "Hacking Tools" repository offers a collection of cybersecurity utilities designed for various network reconnaissance and penetration testing tasks. Key features include ARP cache poisoning, subdomain enumeration via HTTPS certificate history, Google dorking for file discovery, and multiple implementations of network scanning and port scanning. These tools serve as essential resources for security professionals conducting assessments and vulnerability analysis.

HARRYv6

2026-08-03 Python ★ 127
HARRYv6 is a Facebook brute-force tool developed for cracking public files and automating Facebook interactions such as liking and commenting. It offers multiple cracking methods, an optimized file creator, and is designed to be used on the Termux platform, making it accessible and regularly updated without cost.

MacAttack

2026-08-03 Python ★ 125
MacAttack is a graphical user interface (GUI) tool specifically developed for testing and brute-forcing IPTV stalker portals that users own or have permission to test. It allows users to identify accessible MAC addresses and assess portal vulnerabilities while providing features for proxy management, portal URL input, and playlist retrieval via a modified video player. The tool emphasizes responsible use, warning against unauthorized access to non-owned portals.

Net-Strike

2026-08-03 Python ★ 88
Net Strike is a load testing tool designed to simulate various types of network attacks, including TCP SYN flood, ICMP flood, UDP flood, and HTTP flood, to evaluate network performance and resilience under stress conditions. It provides capabilities to spoof IP addresses and includes functionality for crafting HTTP requests with custom headers to bypass basic filtering, making it versatile for testing different scenarios. The tool is intended for educational and demonstration purposes, with a strong warning against unauthorized usage.

Prem

2026-08-03 Python ★ 82
Prem is a Python-based Instagram brute-forcing tool that facilitates unauthorized access attempts to Instagram accounts. It features enhanced login methods, a modern interface, and dual language support (English and Indonesian), making it accessible for users with varying technical skills. Additionally, it provides a comprehensive step-by-step installation guide for deployment on Termux.

Python-Scripts

2026-08-03 Python ★ 330
The Python Scripts repository offers a diverse collection of open-source Python scripts designed for various practical applications. Key features include tools for air quality analysis, blog reading, user management on social media like Twitter and Facebook, expense tracking through a GUI, and basic encryption techniques. These scripts support user-friendly operations from terminal commands, allowing for enhanced productivity across multiple domains.

Quze

2026-08-03 Python ★ 13
Quze is an advanced penetration testing framework that employs quantum-inspired techniques, such as probabilistic optimization and adaptive payload mutation, to evade high-level security defenses without utilizing actual quantum computing. Its notable features include AI-driven payload mutation for dynamic attack vector generation, autonomous reconnaissance for vulnerability identification, and advanced obfuscation methods to disguise malicious traffic and execute commands stealthily. Designed for authorized penetration testing, it focuses on maximizing exploitation success while maintaining stealth against signature and behavior-based detection systems.

raspberrypi-rubber-ducky

2026-08-03 Python ★ 11
The Raspberry Pi Pico WH is configured as a Human Interface Device (HID) for keystroke injection, functioning similarly to a rubber ducky. This tool allows remote payload management via a web interface, enabling users to upload and modify DuckyScript payloads effortlessly. It features an access point for direct connectivity to the Pico, streamlining the process of payload customization during target analysis.

rec0n

2026-08-03 Python ★ 48
rec0n is an automated toolkit designed for subdomain reconnaissance and sensitive data discovery, facilitating threat assessment and vulnerability identification. Key features include subdomain enumeration, live host detection, CORS vulnerability scanning, and sensitive file discovery with effective CLI output management. The tool integrates multiple utilities for enhanced functionality, allowing for organized output and historical data collection.

samba-de-amigo-2k_modding

2026-08-03 Python ★ 15
The Samba de Amigo 2K Modding toolset provides resources and utilities for modding the Dreamcast version of the rhythm game "Samba de Amigo: Ver. 2000." Key features include a console script for analyzing and converting AMG files, the ability to import Wii songs into the Dreamcast GDI image, and detailed file descriptions for enabling English translations and custom content. Future enhancements aim to simplify GDI modding and expand song import options from various sources.

sms-sender

2026-08-03 Python ★ 199
sms-sender is a Python-based tool designed to facilitate the sending of SMS messages via a command-line interface, primarily aimed at educational and testing purposes. It is compatible with both Windows and Linux environments, offering easy installation through automated scripts and dependency management. Notable features include compatibility with platforms like Termux and Kali Linux, as well as user-friendly command execution options.

unbekannt-framework

2026-08-03 Python ★ 21
The Unbekannt Framework is a specialized hacking and penetration testing tool designed for Windows environments, emphasizing ease of use with a modular command system. Notable features include support for various attack modules, options configuration for each module, and the ability to import custom Python modules. The framework facilitates the execution of penetration tests while encouraging community contributions through shared module development.

WhatsApp-Viewer

2026-08-03 Python ★ 67
Linuxndroid WhatsApp-Viewer is a Python GUI application designed for extracting and displaying WhatsApp chat conversations from the app's SQLite database. Its primary use case is to provide users a straightforward way to view chat histories in a familiar chat-bubble format, along with features such as light and dark modes, support for contact names, and the capability to compile into a standalone executable for Windows. The tool eliminates the need for command line interfaces and web servers, making it accessible for users seeking to analyze their chat data effortlessly.

Wifi-Brute

2026-08-03 Python ★ 750
Wifi-Brute is a Python-based tool designed to crack Wi-Fi passwords using a user-provided wordlist. Its primary use case is testing the security of Wi-Fi networks by attempting to brute-force passwords, although effectiveness can vary depending on the wordlist size. Notable features include a simple command-line interface, the ability to specify custom wordlists, and the option to use a built-in default wordlist.

Xbughunting

2026-08-03 Python ★ 20
XbugHunting is a comprehensive suite designed for bug hunters and penetration testers, providing tools for information gathering, mapping, discovery, exploitation, and reporting. Notable features include a variety of integrated utilities such as DNS enumeration tools, port scanners (e.g., Masscan, Nmap), vulnerability scanners (e.g., Burp Suite, Acunetix), and exploitation frameworks for common web vulnerabilities. Its modular organization allows users to access and execute tools easily from a single Python interface, streamlining the bug hunting process.

xhackTool

2026-08-03 Python ★ 38
xhackTool is a penetration testing framework designed for Android systems, enabling users to easily install and utilize multiple hacking tools. This tool streamlines the setup process by automating the downloading and installation of selected penetration testing utilities, making it ideal for educational purposes in cybersecurity. Notable features include a straightforward installation procedure and user-friendly selection interface for managing various tools.

AI-cyber-range

2026-08-03 Python ★ 14
The AI Cyber Range tool provides a fully automated lab environment designed for testing and securing Large Language Models (LLMs) against the OWASP Top 10 vulnerabilities. It allows users—including AI security researchers, red team professionals, and educators—to simulate real-world adversarial attacks and validate the security of LLM applications in a safe, Docker-isolated setup. Notable features include one-click installation, a progression of attack scenarios, and a local browser interface for interactive learning.

BrutalNET

2026-08-03 Python ★ 12
BrutalNET V2 is a network attack tool specifically designed for executing large-scale ARP spoofing attacks that result in a denial-of-service (DoS) condition across an entire network. Unlike traditional ARP spoofing methods that focus on single targets, BrutalNET inundates connected devices with forged ARP packets to poison their ARP caches, effectively redirecting all network traffic to the attacker's MAC address. Notable features include its ease of use through simple command-line instructions and its capability to disrupt entire networks by leveraging the ARP protocol vulnerabilities.

Cyberonix

2026-08-03 Python ★ 540
Cyberonix is an open-source cybersecurity tool designed as a comprehensive resource hub for the cybersecurity community, aiming to serve as a one-stop solution for both seasoned professionals and learners in the field. Notable features include its regular updates with new resources, user-driven feature suggestions, and a collaborative approach, encouraging contributions from the community to enhance its functionality.

dorkGen

2026-08-03 Python ★ 18
DorkGen is a script designed to generate keyword combinations for web page URLs, serving primarily for web scraping, testing, and security-related applications. It enables rapid creation of dork lists based on user-defined variables and features persistent configurations through external config files for enhanced usability. Additionally, recent updates have expanded the range of available dorks, improving the tool's functionality.

Dreamcast-Disassembly-Debugging-and-Decompilation-Diaries

2026-08-03 Python ★ 21
The Dreamcast Disassembly, Debugging, and Decompilation Diaries repository provides tools and resources for reverse-engineering Sega Dreamcast games. Primarily aimed at developers and hobbyists, it facilitates the extraction of data from GD-ROM images, disassembly and decompilation of Dreamcast binaries using Ghidra, and interactive debugging via Flycast as a GDB server. Notable features include recommended scripts and databases for Ghidra, along with general resources and tools to enhance the reverse-engineering experience.

ethpwn

2026-08-03 Python ★ 55
ethpwn is a command line tool designed for debugging and interacting with smart contracts on EVM-based blockchains, notably inspired by the pwntools and GEF frameworks. Its primary use case is to simulate and replay Ethereum transactions through the `ethdbg` utility, while also providing convenient wrappers for various `web3` functionalities. Key features include easy installation, configuration setup for Ethereum nodes, and support for mainnet and sepolia testnet.

exploit

2026-08-03 Python ★ 133
Exploit is an offensive hacking tool designed to assist cybersecurity professionals and ethical hackers in executing exploits and conducting penetration testing. Its primary use case is to facilitate hacking activities, enabling users to automate various exploitation tasks. Notable features include ease of installation on any Linux distribution and comprehensive support for dependency management through a requirements file.

FSOCIETY-RAT

2026-08-03 Python ★ 32
FSOCIETY RAT V2 is a Discord-based Remote Administration Tool designed for system control and manipulation through a command line interface. Its primary use case includes executing system commands, accessing device features like screenshots and webcam capture, and credential dumping. Notable features encompass new keylogging capabilities, process management, and various trolling options, all while emphasizing ethical use in educational contexts.

H1Notifier

2026-08-03 Python ★ 22
H1Notifier is an automated tool that monitors HackerOne for new bug bounty programs and sends email notifications to users upon detection. It utilizes Selenium for web scraping, operates entirely on GitHub Actions, and can run every three hours or be triggered manually, requiring minimal setup. Notable features include email notification support and seamless deployment via GitHub Actions.

HacKingPro

2026-08-03 Python ★ 162
HacKingPro is an ethical hacking toolkit designed for comprehensive security assessments, offering features for reconnaissance, exploitation, lateral movement, and reporting among other attack vectors. Its primary use case is to facilitate ethical hacking practices through a user-friendly graphical interface built with PyQt5, along with advanced functionalities including multi-language support, customizable reporting, and a plugin system for extended capabilities. The toolkit supports a variety of attacks such as web application exploitation, password attacks, and social engineering, making it a versatile resource for security professionals.

hackwifi

2026-08-03 Python ★ 12
hackwifi is a Python-based toolkit designed for Wi-Fi penetration testing, facilitating tasks such as network scanning, packet capturing, deauthentication attacks, and password cracking. Key features include the ability to identify nearby networks, capture handshake packets for offline cracking, and perform deauthentication attacks to aid in the capture process. This tool is intended for educational purposes and requires proper authorization for use.

instagrambruteforcer

2026-08-03 Python ★ 13
InstagramBruteforcer is a Python-based tool designed for conducting brute force attacks on Instagram accounts using a configurable list of proxies. It features the ability to upload and manage proxy lists, monitor their performance through statistical insights, and prune underperforming proxies, all while attempting to find valid usernames and passwords from a specified list. The tool also provides real-time feedback on the progress of password attempts and highlights successful logins.

IntelTrace

2026-08-03 Python ★ 107
IntelTrace is an automated OSINT intelligence collection tool designed for Linux environments, featuring a hacker-themed Flask web dashboard. It facilitates the collection of public intelligence data on IPs, emails, phone numbers, and usernames, offering advanced functionalities such as a reputation scoring engine, timeline builder, and robust reporting capabilities in both PDF and JSON formats. Notable features include a dark web scanning capability and a user-friendly interface with animated effects, catering to investigators seeking legal OSINT solutions.

Link-x

2026-08-03 Python ★ 52
Link-x is a malicious tool designed to extract sensitive data from victims' devices through various attack vectors, including accessing the camera, microphone, clipboard, and location. It primarily enables an attacker to gather extensive information with minimal effort, only requiring the victim to click on a specially crafted link. Notable features include real-time data capturing, remote access capability, and comprehensive device information retrieval.

longtongue

2026-08-03 Python ★ 109
Longtongue is a tool designed to generate customized password and passphrase wordlists based on specific target information, such as individuals or companies. Notable features include the ability to incorporate various permutations like leet (1337) variations, numbers, and specified length limits, providing flexibility for different password complexity requirements. Users can easily configure the generation parameters through command-line options to tailor their wordlists for security assessments or penetration testing.

Lucid-Engine

2026-08-03 Python ★ 11
Lucid Engine is a tool designed for modifying game variables via the Chrome DevTools Protocol, establishing a websocket connection between the tool and the game, unlike traditional memory manipulation tools. Its primary use case is to provide a user-friendly interface for altering game elements, enabling customizations without direct memory edits. Notable features include its architecture overhaul and a straightforward interaction model for game manipulation.

Medium-Miner

2026-08-03 Python ★ 18
Medium Miner is a tool designed for scraping articles from Medium, enabling users to read Medium blogs offline in their preferred Markdown reader. Its notable features include the ability to search for specific topics and download all articles from a specified author, making it a comprehensive solution for content consumption from Medium. The tool is free and easy to install and use, catering to users who wish to access Medium content without an internet connection.

pandora

2026-08-03 Python ★ 307
PANDORA is a multifaceted cybersecurity tool designed primarily for offensive security tasks, including DDoS attacks, web scanning, and data extraction through various methods like SQL injection and doxing. Notable features encompass a range of hacking utilities such as a deface maker, database dump capabilities, network sniffing, and an auto exploitation tool, making it versatile for both penetration testing and malicious activities. The tool is presented with detailed installation instructions for multiple environments, including Linux and Termux.

phishing-ai-agent

2026-08-03 Python ★ 24
Phishing AI Agent is an advanced tool designed to identify vulnerable employees within organizations, leveraging AI to automate the reconnaissance and campaign generation process for phishing simulations. Its notable features include dynamic knowledge fetching for real-time intelligence, multi-source profile enrichment, AI-powered vulnerability analysis, and SMTP integration for either simulation or real email delivery. This tool is intended for authorized security testing and employee awareness training only, providing security teams and red/blue teams with a robust method to enhance cybersecurity measures against phishing threats.

RickPhis

2026-08-03 Python ★ 12
RickPhis is a modular phishing simulation framework designed for ethical hackers and cybersecurity educators, enabling them to rapidly deploy convincing credential-harvesting pages and simulate real-world phishing attacks for awareness training and red team exercises. Built with Python, Flask, and Selenium, it features functionalities such as Ngrok tunneling for exposing local servers, live browser automation for interception of login processes, a web admin panel for monitoring captured credentials, and robust logging capabilities. This tool is intended for educational use and authorized security testing, ensuring that users operate within legal boundaries.

SourceLeakHacker

2026-08-03 Python ★ 390
SourceLeakHacker is a multi-threaded web directory scanner designed to identify potential source file leaks on specified URLs. It supports scanning individual URLs or batches from a provided file, offering customizable options such as dictionary scale, threading, and output configurations. Notable features include logging capabilities, results saved in CSV format, and the ability to adjust parameters for timeout and verbosity levels.

steal-all-files

2026-08-03 Python ★ 75
Steal all files is a cybersecurity tool designed for data exfiltration via a USB device, enabling users to copy all files and information from a target computer by simply plugging in the device. Key features include a straightforward setup process for creating an executable payload on the USB, the ability to run the tool directly from the USB or through a Python interpreter, and customizable options for specifying the source path and output file name.

Wifi-Confusion

2026-08-03 Python ★ 16
Wifi-Confusion is a cybersecurity tool designed to create multiple fake Wi-Fi access points to mislead potential victims, primarily for educational purposes. It features a simplified process for accessing monitor mode and allows for the bulk generation of deceptive networks using an external Wi-Fi card compatible with Kali Linux. Users must adhere to ethical guidelines, as the tool is intended solely for legal, educational use.

WiFi-Password-Cracker

2026-08-03 Python ★ 39
WiFi Security & Router Diagnostics is a cross-platform Python script designed to extract and display details of saved WiFi profiles, including passwords, authentication types, and encryption methods across Windows, Linux, and macOS systems. Notable features include an interactive menu for filtering, searching, exporting results to various formats, and an auto-install mechanism for dependencies like `colorama`. The tool prioritizes user consent by implementing a Terms and Conditions agreement before data retrieval, ensuring compliance with ethical standards.

WIFIjam

2026-08-03 Python ★ 42
WIFIjam is a cross-platform WiFi deauthenticator and information tool that enables users to scan for nearby networks and perform a deauthentication attack on compatible Linux systems with the appropriate WiFi adapter. The tool boasts robust error handling, detailed WiFi information retrieval on macOS and Windows, and the ability to jam both 2.4GHz and 5GHz networks. It requires Python 3.x and various system-specific utilities to operate effectively.

wildlogger

2026-08-03 Python ★ 46
Wildlogger is a keylogging tool designed for the Windows operating system that captures detailed system information, such as running processes, device data, and keyboard keystrokes, while also taking periodic screenshots and sending this data to a specified email address. It operates using two separate threads for logging records and capturing screenshots, and it includes a persistent mode feature to ensure continuous execution on the target system by integrating itself into the Windows startup process. The tool supports Gmail for reporting, requiring enabling of less secure app access for SMTP operations.

worm-ai

2026-08-03 Python ★ 327
Worm-AI CLI is a command-line interface that provides access to Grok models via an unofficial reverse-engineered API wrapper. It is designed for flexible interaction with large language models, featuring a built-in jailbreak system for unrestricted responses and a fully customizable terminal UI. Its modular architecture allows for easy modifications and enhancements, making it suitable for research and educational purposes.

XtremeNmapParser

2026-08-03 Python ★ 23
Xtreme Nmap Parser (XNP) is a Python utility that parses XML files generated by Nmap and converts them into various formats, including CSV, XLSX, and JSON. Its primary use case is to facilitate data analysis and reporting in network security assessments, with notable features such as file and directory handling, configurable output formats, and advanced filtering options for focusing on specific services or vulnerabilities. Additionally, XNP allows users to maintain pentesting records and provides easy documentation and data sharing capabilities.

yaralyzer

2026-08-03 Python ★ 153
Yaralyzer is a tool designed for the visual inspection of regex and YARA matches within binary and text files, allowing users to view the actual bytes matched along with their surrounding context. It supports scanning with customizable regex patterns or YARA rules, detecting potential character encodings of matched bytes, and can display results in various formats such as SVG and HTML. Notable features include the ability to force different character encodings on matched regions and export findings in a visually appealing format, facilitating deeper analysis of patterns within data.

Advanced-Penetration-Testing-Script

2026-08-03 Python ★ 24
NetWatch Advanced Breach Scanner v2.0 is a sophisticated penetration testing toolkit designed for authorized security assessments, enabling users to probe web applications, APIs, and network services for vulnerabilities. Notable features include extensive recon capabilities such as web crawling and subdomain enumeration, various injection modules for SQL and XSS attacks, and robust security assessments of authentication methods and API protocols. The tool also provides detailed reporting options and a command-line interface for streamlined operations.

AirJack

2026-08-03 Python ★ 64
AirJack is a macOS tool designed for scanning Wi-Fi networks and capturing WPA/WPA2/WPA3 handshakes using CoreWLAN. It orchestrates the use of external tools such as AirSnare and hcxpcapngtool for data capture and facilitates the conversion of captures into hashcat format, providing users with options for dictionary or brute-force cracking workflows. Notable features include detailed logging, command line configurability, and a user-friendly launcher for streamlined operation.

Brutus

2026-08-03 Python ★ 48
Brutus is a Python-based tool designed for learning and experimentation in cybersecurity environments. It offers a sandbox feature for testing functionality in isolated, no-network containers, making it suitable for safe experimentation. Notable features include a development setup with linting and formatting tools, as well as a defined structure for module organization.

fingerprint

2026-08-03 Python ★ 70
Fingerprint is a forensic analysis tool designed to monitor and record changes to files and registry entries on Windows systems, allowing users to identify modifications potentially made by malware or unauthorized programs. It generates comparative fingerprints of system states in CSV format, facilitates use with external diff tools, and incorporates functionality to filter changes through Procmon logfiles, streamlining the detection of hidden data associated with software installations. Additionally, the tool is batch-friendly, enabling automation for targeted monitoring scenarios.

HDN-Locator

2026-08-03 Python ★ 38
HDN-Locator is a Python-based GPS tracking tool designed to capture the exact coordinates of any device through a convincing fake YouTube video page that requests location access. Its notable features include real-time map visualization, anti-spoofing capabilities to detect fake GPS apps, and cross-platform compatibility across Windows, Linux, and macOS. The tool autonomously saves location data in JSON format, enhancing its usability for tracking purposes.

Host-Scan

2026-08-03 Python ★ 14
Host Scan is a professional network reconnaissance tool written in Python 3 that allows for high-speed scanning of open TCP/UDP ports on remote hosts, leveraging optimized concurrency for rapid results. It provides service identification for open ports, features a modular architecture for clean code separation, and incorporates CI/CD processes with automated testing and security analysis to ensure code quality. The tool is designed explicitly for ethical cybersecurity purposes and must be used only with explicit authorization.

IP-Tracker

2026-08-03 Python ★ 24
IP-Tracker is an advanced OSINT tool designed for tracking and geolocating IPv4 addresses while enriching data with associated phone information. Its primary use case is to assist security analysts and technical consultants during the footprinting phase of penetration testing, enabling mass resolution and agile queries of network addresses. Notable features include integration with detection flows, modular architecture adhering to DevSecOps standards, and robust testing capabilities with automated unit tests.

netpwn

2026-08-03 Python ★ 165
netpwn is a Python 2.7-based framework designed for automating various penetration testing tasks. It includes modules for creating reverse shells, sending files, and generating backdoors, along with tools for hash analysis, SSL certification retrieval, and various data encoding/decoding functionalities. Notable features include an auto-complete command interface, resource links for further learning, and an accessible command structure for executing modules effortlessly.

python-bruteForce

2026-08-03 Python ★ 555
Python Brute Force is a versatile tool designed for conducting brute force attacks on form-based and JSON API logins, featuring automatic detection of login types and CSRF bypass capabilities. Its primary use case is for penetration testing and security research, providing options such as multi-threading, customizable worker counts, and color-coded terminal outputs for enhanced usability. The tool efficiently manages various CSRF protection mechanisms, making it suitable for testing modern web applications built with popular frameworks.

s1c0n

2026-08-03 Python ★ 75
s1c0n is a reconnaissance tool designed to simplify the vulnerability assessment process for web servers. Its primary use case includes automated scanning for WAFs, ports, subdomains, web directories, and content management systems, with the capability to customize user-agent strings and scan through proxies. Notable features include comprehensive auto-detection of server technologies, WordPress plugin enumeration, and an easy installation process, catering to various Linux distributions.

sshprank

2026-08-03 Python ★ 180
sshprank is a versatile tool designed for SSH reconnaissance and exploitation, offering functionality for mass scanning, login cracking, banner grabbing, and assessing password authentication support. It leverages the python-masscan and Shodan modules to efficiently identify vulnerable SSH services, enabling users to experiment with various configurations and options for effective password cracking. Notable features include support for random IP address generation, multiple credential combinations, customizable thread management, and output logging for successful logins.

ZX-DDoS

2026-08-03 Python ★ 52
ZX-DDoS is a Python-based Distributed Denial of Service (DDoS) tool designed for educational and testing purposes, allowing users to learn about network stress testing and security evaluation. It features a straightforward setup process and an interactive prompt for configuring target IP, number of worker threads, and requests, making it suitable for security researchers and network administrators. The tool is compatible with various operating systems, including Linux, Windows, and MacOS.

agartha

2026-08-03 Python ★ 414
Agartha is an advanced payload generation and access control assessment tool designed to identify injection vulnerabilities (such as SQLi, LFI, and RCE) and authentication issues in web applications. Key features include a dynamic wordlist generator for various injection vectors, a comprehensive access matrix for assessing authorization vulnerabilities, and the ability to convert HTTP requests to JavaScript for XSS exploitation. Additionally, it includes functionality for HTTP 403 bypass checks and generates Bambdas-compatible scripts for enhanced testing efficiency.

agent-smith

2026-08-03 Python ★ 108
agent-smith is an innovative penetration testing framework designed to facilitate deeper and more intelligent security assessments while minimizing manual oversight. It utilizes advanced skills-based methodology combined with a customizable LLM to generate dynamic attack strategies and deliver comprehensive end-to-end findings, including proofs of concept and threat models. Key features include support for local LLMs, Docker-based isolation, and real-time collaboration through an interactive dashboard, enhancing the overall efficiency and effectiveness of the penetration testing process.

Black-Hat-Python

2026-08-03 Python ★ 139
Black-Hat-Python is a repository of Python scripts designed for educational and ethical hacking purposes, focusing primarily on security research. It features tools for various password and credential attacks, including capabilities for password hash cracking and LDAP brute force attacks, while emphasizing compliance with legal and ethical guidelines. Users are encouraged to utilize these tools strictly for authorized security assessments, as the repository supports responsible disclosure and proper usage protocols.

Buildware-Tools

2026-08-03 Python ★ 1226
Buildware-Tools is a versatile cybersecurity multitool designed for tasks such as Discord automation, OSINT reconnaissance, network diagnostics, and cryptographic utilities, all accessible via a single terminal interface. It operates natively on both Windows and Linux, requires only Python for setup, and features an array of tools, including an IP port scanner, DNS lookup, and a website vulnerability scanner, with some functionalities accessible only after contributing to the project. Regular updates ensure continuous enhancements and the introduction of new features, while a plugin manager allows the integration of community-made plugins.

d3m0n_c1

2026-08-03 Python ★ 14
d3m0n_c1 is an open-source hacking phone designed for performing a variety of wireless attacks, including radio and WiFi hacking, as well as physical attacks via BadUSB. It features a customizable operating system, various connectivity options, and a compact design, making it suitable for security researchers and penetration testers. Notable capabilities include sub-GHz radio communication, an LTE module for SMS and calls, and a user-friendly application system.

Facemash

2026-08-03 Python ★ 96
Facemash is a Python-based tool designed for conducting brute force attacks on Facebook accounts, utilizing AI-driven strategies to enhance attack efficacy. It features various advanced password exploitation methods, real-time logging, and manual input capabilities, all aimed at identifying and testing vulnerabilities in social media security. Specifically developed for ethical hacking and cybersecurity research, Facemash is characterized by its precision and relentless attack mechanisms, but it is strictly intended for educational purposes only.

linux-monster

2026-08-03 Python ★ 45
Linux-Monster is a versatile password cracking tool designed for Linux, macOS, Windows, and Android platforms, primarily used for brute-force password attacks. Notable features include custom dictionary generation, progress tracking for resumed sessions, improved UI/UX, and dynamic settings that do not require restarts to apply changes. The tool has been optimized for resource consumption and error handling, enhancing its overall efficiency during brute-force operations.

Phone-Number-Tracker

2026-08-03 Python ★ 19
Phone Number Tracker is an advanced OSINT framework designed for comprehensive phone intelligence gathering, utilizing over 2650 lines of Python code. It provides features such as phone parsing and validation, live location tracking through multiple APIs, and extensive subscriber information. Notably, it includes capabilities for forensic reporting, case management, and deep OSINT checks across various platforms, making it a robust tool for authorized security research and educational purposes.

Preview-DarkStar

2026-08-03 Python ★ 27
DARKSTAR v2.1 is a command-line penetration testing framework designed for security professionals, featuring 57 modular tools across various categories. Its key features include a plug-and-play plugin system, automatic plugin discovery, a matrix-inspired color-coded terminal UI, and support for threading and async operations, making it highly customizable and efficient for diverse security assessments. The toolkit is compatible with multiple platforms, including Kali Linux, Termux, Windows (WSL), and macOS, and requires only standard Python dependencies.

PROTECT-KIT

2026-08-03 Python ★ 12
PROTECT-KIT appears to be an unmaintained cybersecurity tool with no functional capabilities, as indicated by the warning of being "USELESS Code." Due to its lack of maintenance and features, it is not suitable for any practical use case in the cybersecurity domain.

proxyreaper

2026-08-03 Python ★ 15
Proxy Reaper is a multifunctional proxy evaluation tool designed to assess the availability, speed, and anonymity of various proxy servers, including HTTP, HTTPS, SOCKS4, and SOCKS5 protocols. Notable features include concurrent proxy checking, response-time categorization, anonymity detection, GeoIP resolution, and the ability to export results in multiple formats such as JSON, CSV, and SQLite. The tool also supports automatic proxy list downloads and includes advanced filtering options for efficient results analysis.

pyhtools

2026-08-03 Python ★ 653
PyHTools is a comprehensive collection of Python-based hacking tools designed for network security assessments, including functionalities such as network scanning, ARP spoofing, DNS spoofing, and credential harvesting. It features a user interface for accessibility while allowing command-line usage for advanced users, with an emphasis on ethical use, as all malicious components are stored in a separate repository. The toolkit facilitates a wide range of cybersecurity practices, from reconnaissance to exploitation, but users are warned against any illegal applications.

scan4secrets

2026-08-03 Python ★ 117
scan4secrets is a comprehensive security scanning tool that integrates both Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST) to identify leaked credentials, code vulnerabilities, and configuration misconfigurations across source trees, live web applications, and CI logs. Its notable features include live verification of secrets against vendor APIs, source-map parsing for JavaScript, authenticated DAST capabilities, and support for generating reports in SARIF, JSONL, and multiple formats for client presentations, thereby providing a holistic approach to application security assessment.

SimpleReconSubdomain

2026-08-03 Python ★ 39
SimpleReconSubdomain is a passive and active subdomain enumeration tool designed for OSINT and reconnaissance workflows, leveraging async Python to query 50 sources in parallel without external shell dependencies. Key features include multi-probe wildcard detection, DNSSEC NSEC zone walking, TLS SAN extraction, and advanced scraping techniques, which facilitate comprehensive subdomain discovery and enumeration, along with subdomain takeover detection capabilities. The tool supports continuous monitoring and provides output in various formats, making it suitable for integration into automated security workflows.

Koi

2026-08-03 Python ★ 24
The low cortisol shell handler

Logicytics

2026-08-03 Python ★ 17
Logicytics is a forensic data collection tool designed for Windows systems, developed in Python to systematically retrieve and package extensive system data into a ZIP file for analysis. Its primary use case is to assist cybersecurity professionals in gathering sensitive information for forensic investigations. Notable features include its active development status and straightforward installation process, ensuring comprehensive data harvesting capabilities.

ShinobiShell

2026-08-03 Python ★ 15
ShinobiShell is a specialized penetration testing tool designed for file exfiltration and exploit injection, facilitating remote shell interactions between the attacking and victim machines. Its notable features include encrypted tunnel creation, a command for seamless reverse shell connections, and capabilities for managing machine information and various payload delivery methods through a user-friendly shell interface. The tool is particularly geared toward enhancing operational efficiency during pentesting activities.

vimana-framework

2026-08-03 Python ★ 66
Vimana is a modular security framework designed for auditing Python APIs and web applications, leveraging a plugin-based architecture for thorough security assessments. Its primary use case encompasses vulnerability detection, static and dynamic analysis, and CI/CD integration, with notable features like application crawling, persistence analysis, and support for various continuous integration platforms. This tool enhances security professionals' capabilities through both automated and manual testing techniques.

VivisectION

2026-08-03 Python ★ 22
VivisectION is an emulation-driven toolset designed as a plugin for the Vivisect reverse engineering framework, enhancing GUI capabilities with functions for function emulation and reconnaissance. It enables users to emplace an emulator for specific functions easily, offering features such as an interactive console for dynamic analysis, and streamlined integration with other Vivisect tools. Noteworthy functionalities include function emulation via context menu operations and an interactive Python shell for advanced analyses, fostering a comprehensive environment for vulnerability research and reverse engineering.

WiFuX

2026-08-03 Python ★ 96
WiFuX is a WPS security auditing tool designed for Android devices running Termux, enabling automated Pixie Dust and Bruteforce attacks against WPS-enabled routers. Notable features include a global command system, session management, and reporting capabilities, making it ideal for security researchers and network administrators wishing to evaluate their wireless infrastructure's security. The tool is fully optimized for mobile use and requires root access and a compatible Wi-Fi adapter.

Atomic-Red-Team-C2

2026-08-03 Python ★ 178
ARTC2 is an advanced execution framework designed to help security teams efficiently execute attack scenarios across multiple breach points, primarily focusing on Windows OS environments. Its notable features include rapid deployment, modern command and control capabilities utilizing encrypted communications, and dynamic attack formations that enable execution without recompilation. The tool supports extensive logging for evidence collection and analysis, facilitating rapid evaluation of endpoint detection and response (EDR) solutions against MITRE ATT&CK frameworks.

black-widow

2026-08-03 Python ★ 225
black-widow is a comprehensive offensive penetration testing tool designed for various forms of information gathering and attack execution. Written in Python and offering both a web GUI and command line interface, it features capabilities such as website crawling, web page parsing, sniffing, and support for multiple asynchronous requests across multiple targets. Its continuously updated open-source framework also includes advanced functionalities for SQL injection and brute force attacks, making it suitable for both professional penetration testers and security enthusiasts.

BlackBerryC2

2026-08-03 Python ★ 32
BlackBerryC2 is an encrypted remote administration and command-and-control (C2) framework primarily designed for educational and security research purposes within controlled environments. It features a custom TCP-based server that employs application-layer cryptography, including AES-256-GCM encryption and HMAC-SHA256 authentication, facilitating secure client communication, remote command execution, and file transfers. Key capabilities include session management, support for multiple concurrent clients, interactive console operations, and robust flood detection mechanisms.

blexploit

2026-08-03 Python ★ 23
Blexploit is a comprehensive offensive Bluetooth Low Energy (BLE) security framework designed for red teams and security researchers, facilitating passive scanning, exploitation, and replay attacks with advanced anomaly detection. Its modular architecture includes features such as GATT enumeration, customizable attack simulations, and offline sandbox environments, while automatically generating risk assessments and attack module suggestions based on detected device UUIDs. Key functionalities, including real packet injection and an Isolation Forest-based detection mechanism, make it versatile for both testing and education in Bluetooth security contexts.

chronix

2026-08-03 Python ★ 42
Chronix is a self-hosted collaborative workspace designed for penetration testers and red team operators, facilitating the capture of notes, commands, outputs, and operational context during security engagements. Notable features include real-time synchronization, timeline logging with extensive filtering and searching capabilities, and the ability to export notes in Markdown format along with images. Additionally, it supports collaborative note-taking with markdown formatting, auto-save functionality, and a structured export mechanism for reporting workflows.

claude-code-pentest

2026-08-03 Python ★ 24
claude-code-pentest automates the penetration testing lifecycle using six specialized skills that range from reconnaissance to exploit chaining and report generation. Its notable features include subdomain enumeration, vulnerability discovery across web applications and APIs, cloud infrastructure analysis, and the capability to compose findings into comprehensive bug bounty reports—all implemented via 43 standalone Python scripts that require no external dependencies. The tool is designed for authorized security testing only and is integrated with Claude Code for user-friendly command execution.

codasm

2026-08-03 Python ★ 130
CODASM is a Python utility designed to encode arbitrary data into pseudo Assembly instructions and compile it into the .text section of binary files, effectively allowing for the obfuscation of shellcode. Notable features include the ability to specify output formats (ASM, binary, C decoder), control over encoding parameters, and considerable data overhead of 80-120%. This tool is primarily used for educational and security research purposes related to malware analysis and payload delivery methods.

drakben

2026-08-03 Python ★ 21
DRAKBEN is an AI-powered autonomous penetration testing framework that utilizes natural language processing to perform comprehensive security assessments, allowing users to issue commands in plain language. Its notable features include a self-evolving engine for dynamic tool synthesis, a multi-language interface supporting Turkish and English, and advanced memory systems for context-aware decision-making and persistent learning. This framework streamlines the penetration testing process from reconnaissance to reporting with minimal user intervention.

Fake-SystemUpdate-Malware

2026-08-03 Python ★ 12
The Fake-SystemUpdate-Malware-Simulator is a malware simulation tool designed to illustrate common stealth techniques employed by real-world malware, masquerading as a Windows system update executable. It features keylogging, periodic screenshot capture, and IP-based geolocation tracking, all while maintaining persistence by utilizing Windows Startup locations and registry keys. This project serves purely for educational purposes and to enhance cybersecurity awareness, demonstrating how such malicious software can evade detection.

file-scraper

2026-08-03 Python ★ 19
File Scraper is a tool designed for extracting sensitive information from files using custom regular expressions, and it generates an interactive HTML report based on the findings. Its primary use case is in security assessments and data validation, where users can employ their regex expertise to customize the search patterns for various types of sensitive data, such as authentication tokens and credentials. Notable features include the ability to style the generated reports and collect specific data formats like Base64 and PEM, enhancing the tool's versatility for educational and practical cybersecurity applications.

forbidden

2026-08-03 Python ★ 257
Forbidden is a cybersecurity tool designed to bypass 4xx HTTP response status codes, specifically targeting `403 Forbidden` and `401 Unauthorized` responses. Built using Python Requests and PycURL, it offers features for testing various HTTP methods, open redirects, and out-of-band interactions, while also supporting stress testing capabilities. Future enhancements aim to include options for suppressing console output and comprehensive testing for HTTP request headers and traffic manipulation techniques.

GitHush

2026-08-03 Python ★ 34
GitHush is a cybersecurity tool designed to monitor public GitHub repositories for the inadvertent exposure of sensitive information, such as API keys and credentials, using the GitHub Events API. It automates the detection process through regular expression signatures, dynamic database awareness, and structured JSONL logging for easy integration with threat intelligence systems. Notable features include high-signal filtering, language/framework awareness, and support for over 20 common credential formats.

netexec-automator-beta

2026-08-03 Python ★ 17
NetExec Automator is a parallel credential testing tool designed to exploit all 10 NetExec (nxc) protocols, allowing users to perform extensive authentication attempts using either combination or linear modes for credential pairing. Its notable features include live feedback on valid credentials and timeouts, support for local authentication variants, parallel execution with configurable worker counts, and detailed output summaries to streamline the penetration testing workflow.

nightcrawler-mitm

2026-08-03 Python ★ 29
Nightcrawler-mitm is a mitmproxy addon designed for security researchers, facilitating passive analysis, crawling, and active scanning of web applications. Its notable features include a comprehensive vulnerability confidence system that assigns risk levels to findings, advanced scanning capabilities for various vulnerabilities like SQL injection and XSS, automated proof-of-concept generation, and smart targeting to enhance scanning efficiency. Additionally, it supports extensive customization through command-line options for tailored assessments.

nightmare-exploit-roadmap

2026-08-03 Python ★ 96
The Nightmare Exploitation Roadmap is a structured educational resource designed to advance users' binary exploitation skills through a layered curriculum that emphasizes theoretical understanding and practical application. It focuses on building capabilities to analyze unknown binaries, identify exploit primitives, and develop automated exploitation techniques while navigating real-world security mitigations. Notable features include a non-linear approach to learning, preservation of module names for clarity, and a comprehensive progression from foundational knowledge to advanced exploitation strategies.

pentest-toolkit

2026-08-03 Python ★ 37
Pentest Toolkit is an advanced penetration testing framework designed for rapid and efficient security assessments, integrating over 100 industry-standard tools into both a Python suite for automation and a Bash interface for hands-on operations. Its primary use case includes comprehensive testing phases, from reconnaissance and web security to SSL/TLS analysis and network assessment, all culminating in professional report generation. Notable features encompass automated reporting in multiple formats, robust web application vulnerability testing, and streamlined reconnaissance processes.

PULSE-C2

2026-08-03 Python ★ 53
The PULSE C2 Framework is a command and control (C2) infrastructure designed for remote management of Windows agents through a secure HTTPS connection, featuring a web dashboard for real-time interaction. Key features include TLS encryption, a custom encrypted communication protocol, and capabilities for executing remote shell commands, file exfiltration, and agent control. This framework is intended for educational use, offering a simplified setup derived from a more complex rootkit project.

Ravage

2026-08-03 Python ★ 92
Ravage Framework is a Command & Control (C2) solution tailored for cybersecurity professionals, red teams, and penetration testers, enabling them to simulate realistic attack scenarios with a secure and modular architecture. Notable features include end-to-end AES-256 encryption, advanced PowerShell obfuscation techniques, an interactive web-based dashboard for real-time monitoring, and dynamic listener management for flexible C2 operations. Its design prioritizes stealth and evasion, making it suitable for conducting penetration tests while minimizing forensic traces.

reait

2026-08-03 Python ★ 33
Reait is a toolkit designed for the analysis of compiled executable binaries utilizing the RevEng.AI API, primarily aimed at identifying similar components, vulnerabilities, and generating advanced YARA++ REAI signatures for binary files. Notable features include the ability to extract symbol embeddings, conduct similarity searches among executable programs, and support for stripped ELF and PE binaries in both GNU/Linux and Windows environments. The tool facilitates in-depth binary analysis through commands that submit executables, retrieve analysis results, and query a database for similar symbols.

ReverseShell-Generator

2026-08-03 Python ★ 20
The Python Reverse Shell Generator is a GUI application designed for penetration testers and red teamers, enabling them to quickly generate reverse shell payloads for both Linux and Windows environments. It boasts features such as an extensive library of over 60 Linux payloads, real-time payload generation, multiple encoding options, and a user-friendly interface that supports easy OS switching. This tool also includes one-click copy functionality and a fullscreen mode for enhanced usability during security assessments.

ropfilter

2026-08-03 Python ★ 13
`ropfilter` is an advanced tool designed for filtering, ranking, and chaining ROP gadgets derived from `rp++` dumps, specifically for 32-bit x86 architectures. Its notable features include smart gadget filtering based on register transfers and memory operations, automated multi-gadget chain synthesis, and a constraint solver that utilizes YAML/JSON specifications, enhancing the robustness and efficiency of ROP chain construction.

SCCM_SLAP

2026-08-03 Python ★ 18
SLAP (Secret Locator and Package-Analyzer) is a tool designed to streamline the discovery of sensitive information in SCCM deployment points by searching for secrets within files and downloading entire packages for analysis. Key features include the ability to report on secrets found using customizable regex patterns, inventory files in CSV format, and bypass secured datalibs for comprehensive scanning. SLAP enhances the efficiency of threat detection in SCCM environments by automating the retrieval and examination of data stored across application packages.

scrapy-scraper

2026-08-03 Python ★ 18
Scrapy Scraper is a web crawling and scraping tool that utilizes Scrapy integrated with Playwright's headless browser to handle JavaScript-rendered content effectively. Its primary use case includes probing, crawling, and extracting data from websites, with features such as support for concurrent requests, customizable sleep intervals, and the ability to take screenshots. Additionally, it offers options for rate limiting and recursive crawling, enhancing its usability for various scraping scenarios.

Slacksploit

2026-08-03 Python ★ 18
Slacksploit is a forensic analysis framework designed to enumerate slack artifacts within various operating systems, including Windows, Mac, and Linux. It offers capabilities such as fetching cookies, retrieving user and Slack client logs, and extracting authentication tokens from levelDB files; additionally, it provides a GUI visualizer plugin for Slack user data and allows data export to CSV format. This tool is particularly useful for investigating and analyzing Slack-related data within a forensic context.

specternet

2026-08-03 Python ★ 19
SpecterNet is an advanced network anonymization framework designed to route all system traffic through the Tor network, enhancing security and privacy. Its notable features include full traffic routing, built-in DNS and IPv6 leak protection, a kill switch to block traffic during Tor disconnections, and hardware identity spoofing. Additionally, it offers comprehensive leak testing, censorship bypassing capabilities, and a modern terminal interface for monitoring and management.

SuperLibrary

2026-08-03 Python ★ 173
SuperLibrary is an educational repository designed to provide access to a collection of books and courses aimed at individuals who may face financial constraints in obtaining these learning resources. It emphasizes ethical usage, urging users to support authors and publishers whenever possible, while also featuring a disclaimer regarding copyright and legal responsibilities. Notable features include categorized content such as books and courses, fostering self-education in various subjects.

w4af

2026-08-03 Python ★ 48
w4af is an open-source web application security scanner designed for developers and penetration testers to identify and exploit over 200 vulnerabilities, such as Cross-Site Scripting and SQL Injection. Built on Python 3.11 and currently in an alpha development phase, it features integrations for unit and integration testing alongside comprehensive documentation for user guidance.

AIHound

2026-08-03 Python ★ 15
AIHound is an AI credential and secrets scanner designed to identify exposed API keys, OAuth tokens, and other sensitive credentials across 29 AI tools on multiple platforms, including Windows, macOS, and Linux. It features a robust watch mode for continuous monitoring and real-time alerts on credential changes, alongside integration capabilities with BloodHound for visualizing attack paths and conducting security analysis. The tool promotes safe reporting by redacting credentials by default, making it a crucial asset for security assessments in environments utilizing AI technologies.

AutoProber

2026-08-03 Python ★ 327
AutoProber is a hardware automation tool designed for probing individual pins on electronic components, facilitating hardware hacking processes. Its primary use case involves ingesting projects, identifying probe targets using a combination of a microscope and CNC-controlled hardware, and enabling users to approve or deny targets for probing, all managed through a web dashboard or Python scripts. Notable features include real-time calibration, frame stitching to create annotated maps of targets, and a robust safety model for hardware control.

awesome-blackhat-arsenal

2026-08-03 Python ★ 175
The "Awesome Black Hat Arsenal" repository is a curated collection of advanced cybersecurity tools presented at Black Hat Arsenal events, aimed at practitioners in red teaming, blue teaming, application security, and OSINT. It organizes tools by geographical location, year, and category, providing detailed descriptions, authorship, and GitHub links for each tool, facilitating easy access to cutting-edge security utilities. This resource serves as an invaluable reference for security professionals seeking to enhance their toolkit with the latest innovations in the field.

chad

2026-08-03 Python ★ 33
Chad is a tool designed to search for Google Dorks, allowing users to find indexed information on the web efficiently, utilizing Playwright's headless browser for bypassing common security measures. Its notable features include the Chad Extractor for data extraction and validation, file download capabilities, and options to handle Google’s frequently changing cookies. Additionally, it offers a broken link hijacking feature and is primarily intended for educational use in cybersecurity research.

deadend-cli

2026-08-03 Python ★ 302
Deadend CLI is an autonomous web application penetration testing tool that utilizes a feedback-driven iteration approach to adapt its exploitation strategies. It boasts a model-agnostic architecture capable of generating custom Python payloads, executing fully local operations without cloud dependencies, and achieving approximately 80% success on the XBOW validation benchmark. Key features include a supervisor-subagent hierarchy for task delegation, confidence-based decision-making, and custom sandboxed tools like Playwright and Docker for enhanced pentesting capabilities.

DFMI

2026-08-03 Python ★ 55
DFMI (Don't Fool My Installer) is a toolkit designed for fileless code execution and covert payload delivery via Windows Installer (.msi) files, exploiting the CustomAction mechanism to execute arbitrary payloads silently during installation. Notable features include the ability to inject backdoors into both signed and unsigned MSI packages without altering their signatures, support for cross-platform payload generation, and functionalities for SSL encryption and IPv6. This tool is intended for authorized red team engagements and penetration testing only.

EVA

2026-08-03 Python ★ 524
EVA is an AI-driven penetration testing tool designed to aid users throughout the pentesting lifecycle with intelligent analysis, automated enumeration, and real-time vulnerability assessment. It features support for multiple AI backends, session management for persistent interactions, and an interactive interface for executing commands and analyzing results, thereby enhancing the efficiency of penetration testing efforts. This tool aims to assist, rather than replace, cybersecurity professionals by providing strategic guidance and quicker outcomes during engagements.

FBps

2026-08-03 Python ★ 20
FBps (Forbidden Bypass) is a fast HTTP fuzzer specifically designed for identifying access control bypass vulnerabilities (401/403) in web applications by generating varied HTTP requests across methods, URLs, and headers. Notable features include level-based scanning, URL and query parameter fuzzing, header manipulation, API version downgrades, and customizable output options, making it a robust tool for security testing and vulnerability discovery. This tool is accompanied by FBpsLab for local payload tuning and reproducible testing environments.

FFM

2026-08-03 Python ★ 349
Freedom Fighting Mode (FFM) is a hacking harness specifically designed for post-exploitation tasks during red-teaming engagements, enabling automation of common actions while minimizing user errors. This tool provides a modular command structure for various tasks, including enumeration, stealth, and data transfer, facilitated through a user-friendly command interface. Notable features include enhanced security through a Docker-based installation approach and a comprehensive command management system that categorizes available functionalities for ease of use.

HackingGPT

2026-08-03 Python ★ 15
HackingGPT is an advanced terminal tool designed for penetration testing and bug bounty hunters, leveraging the ChatGPT and DeepSeek APIs to provide dynamic command suggestions and interactive execution. Notable features include the ability to run commands in a terminal or interactive shell, aggregate output for analysis, and a continuously integrated workflow that supports multiple API models while emphasizing offensive security practices. The tool is user-friendly, with a colored interface for enhanced readability and environment variable configuration for secure API key management.

Halberd

2026-08-03 Python ★ 345
Halberd is an open-source, multi-cloud attack emulation tool designed to help cybersecurity professionals validate their cloud security defenses across major platforms such as Azure, AWS, GCP, Entra ID, and M365. It offers over 120 pre-built attack techniques mapped to MITRE ATT&CK and Azure TRM frameworks, an AI-powered intelligence mechanism for discovering and executing attack paths, and a user-friendly web interface that eliminates the need for command-line expertise, facilitating automation, orchestration, and reporting for cloud security testing.

jusotlabs

2026-08-03 Python ★ 106
JusotLabs is a curated toolkit designed for ethical hacking, penetration testing, and security research. It offers a diverse range of Linux-compatible scripts for tasks such as DNS reconnaissance, port scanning, DDoS simulation, and network threat detection, alongside educational resources like CTF writeups and a reading list. Users are encouraged to leverage these tools within authorized environments to enhance their hacking skills and deepen their cybersecurity knowledge.

KslDump

2026-08-03 Python ★ 401
KslDump is a cybersecurity tool designed to extract credentials from the Protected Process Light (PPL)-protected Local Security Authority Subsystem Service (LSASS) using only components signed by Microsoft, without deploying any additional exploits or drivers. Its primary use case revolves around leveraging a forgotten vulnerable kernel driver (KslD.sys) within Microsoft Defender, which allows unrestricted access to kernel and physical memory. Notably, it utilizes a vulnerable IOCTL command to perform memory reads, exploiting easily editable access controls that lack adequate validation mechanisms.

LogHound

2026-08-03 Python ★ 11
LogHound is a post-exploitation tool designed for analyzing Windows Security Event Logs (.evtx) to facilitate BloodHound mapping, aiding Red Teams in tracking lateral movement targets and deciphering active user sessions. Notable features include a chunk-based streaming parser that minimizes memory usage, support for Pass-The-Hash and Kerberos authentication methods, and the ability to generate detailed reports in various formats, ensuring effective operational security during network penetration testing.

Machine_Learning_CTF_Challenges

2026-08-03 Python ★ 263
Machine Learning CTF Challenges provides a collection of capture-the-flag (CTF) challenges focused on exploiting vulnerabilities in AI agents, machine learning pipelines, and large language models. Users can engage in practical scenarios such as manipulating training data, prompting model injections, and breaching autonomous systems to capture flags. The repository includes nine challenges that vary in difficulty and are aligned with OWASP and MITRE attack vectors, thus addressing contemporary security concerns in AI applications.

mcp-security-hub

2026-08-03 Python ★ 772
MCP Security Hub provides a collection of production-ready, Dockerized Model Context Protocol (MCP) servers tailored for offensive security applications, enabling AI-assisted security assessments and vulnerability scanning. With 38 MCP servers covering various domains like reconnaissance, web security, and binary analysis, it integrates over 300 security tools accessible through natural language commands via AI clients like Claude. Noteworthy features include a CI/CD-ready setup with GitHub Actions, minimal Docker images, and orchestration capabilities with Docker Compose for streamlined multi-tool workflows.

Microsoft-SQL-TDS-Downgrade-Attack

2026-08-03 Python ★ 10
The Microsoft SQL TDS Downgrade Attack tool performs a Man-in-the-Middle attack by intercepting Tabular Data Stream (TDS) packets between a client and MSSQL server, enabling the downgrading of encryption for TDS login packets. Its primary use case is to extract sensitive login credentials (username and password) by manipulating traffic through ARP spoofing and modifying intercepted packets. Notable features include automatic cleanup of the ARP spoofing and iptables rules upon stopping the script, and requirements for running include a Linux host with root privileges and necessary dependencies like arpspoof and iptables.

NAAMSE

2026-08-03 Python ★ 17
NAAMSE is an automated security fuzzing framework designed to evaluate vulnerabilities in LLM-based agents using evolutionary algorithms. By generating adversarial prompts through intelligent mutations, it tests for security issues such as jailbreaks and prompt injections, employing a behavioral scoring engine and organizing attack vectors through a clustering engine. Key features include comprehensive reporting of vulnerabilities and metrics, making it an essential tool for red-teaming and enhancing the security posture of LLM agents before deployment.

NekoCLI

2026-08-03 Python ★ 18
NekoCLI is a lightweight AI assistant for terminal environments that facilitates image and video generation, code creation, and command execution. It boasts features such as persistent chat history, a variety of operational modes including pentest capabilities, and visually formatted output. Designed for quick access and minimal dependency, NekoCLI allows users to handle media files and interact with an AI logic API for real-time assistance.

nutcracker

2026-08-03 Python ★ 38
Nutcracker is an Android application analysis tool designed for security researchers, enabling the download of apps directly from Google Play and facilitating static and dynamic analysis to detect and bypass anti-root protections. Notable features include extraction of hardcoded secrets, insecure manifest analysis, and comprehensive OSINT reconnaissance, all of which culminate in a detailed technical PDF report. The tool also integrates an LLM-powered false positive filter for enhanced accuracy in its findings.

offensive-azure

2026-08-03 Python ★ 227
Offensive Azure is a Python-based suite of tools designed for security assessments and penetration tests targeting Microsoft Azure environments. Key functionalities include token manipulation, user enumeration, and tenant reconnaissance, with features enabling users to extract and analyze data from Azure Active Directory, generate tokens for social engineering, and produce BloodHound-compatible outputs for further analysis. This versatile toolset is platform-agnostic and aims to simplify offensive security operations within Azure ecosystems.

offensive-claude

2026-08-03 Python ★ 352
Offensive Claude is a spec-driven offensive security framework designed for Claude Code that implements structured engagement workflows following the Cyber Kill Chain methodology. It features a comprehensive set of 31 kill-chain skills, collaborative agents, and a shared vulnerability library, facilitating automated penetration testing, reconnaissance, exploit development, and reporting through a series of orchestrated commands. This tool is particularly useful for security researchers and practitioners to streamline their offensive security operations while maintaining high quality and traceability throughout the engagement process.

offsec-ai

2026-08-03 Python ★ 31
`offsec-ai` is a sophisticated Python library and command-line interface designed for authorized red-team engagements, integrating classic network reconnaissance methodologies with advanced AI and LLM security testing. It features a suite of tools for probing AI/LLM endpoints against the OWASP LLM Top 10, scanning MCP servers for critical vulnerabilities, and conducting comprehensive infrastructure security assessments, with recent enhancements for A2A protocol security checks that include dangerous skill detection and secret scanning. This tool mandates explicit authorization for active attack features, ensuring ethical use while delivering powerful capabilities for security testing.

Python-Obfuscation-Framework

2026-08-03 Python ★ 27
The Python Obfuscation Framework (pof) is an advanced toolkit designed for generating complex, staged obfuscated payloads aimed at enhancing offensive security practices. Its primary use case revolves around evading static and dynamic analysis through customizable obfuscation techniques that can combine to produce highly obfuscated outputs, including methods to verify target environments to ensure payload execution only occurs in specified conditions. Notable features include automation capabilities for producing multiple payload variants, methods for safeguarding against static and dynamic analysis, and options to store payload stages within images or trusted locations.

SubSurfer

2026-08-03 Python ★ 48
SubSurfer is a high-performance tool designed for subdomain enumeration and web property identification, ideal for red team operations and bug bounty hunting. It features fast asynchronous scanning, customizable port scanning, and web service identification capabilities, with a modular design that allows integration with other tools or use as a Python module. Continuous updates and the ability to tailor scans make it a versatile choice for cybersecurity professionals.

webstrike-framework

2026-08-03 Python ★ 25
WebStrike is an automated web penetration testing framework designed to orchestrate various Kali tools through a structured phase-based pipeline, enhancing the workflow of web pentesting. It links tools together, utilizing outputs from one as inputs for the next while providing deduplication and comprehensive reporting. The framework allows for both manual and automated modes of operation, enabling users to manage the level of intrusion and control over testing processes efficiently.

webxray

2026-08-03 Python ★ 13
WebXray is an offensive web scanner developed in Python that facilitates comprehensive security assessments by combining features such as crawling, XSS and SQL injection detection, security header analysis, and WAF detection. Its notable capabilities include reflected XSS detection, support for various output formats, and ease of integration into existing bug bounty workflows or pipelines. Designed primarily for security professionals, it helps identify potential vulnerabilities in web applications during reconnaissance.

WordListeXplorer

2026-08-03 Python ★ 15
WLX (WordListeXplorer) is a local wordlist intelligence and workflow management tool designed for offensive security professionals and bug bounty hunters, enabling them to efficiently organize, search, and integrate large-scale wordlist collections into their workflows. Notable features include SQLite-powered indexing, fast keyword searches, tag-based filtering, session-aware variable management, and direct integration with offensive tools through shell environment variables, all within a terminal-native interface for streamlined operations.

AISecurity

2026-08-03 Python ★ 109
The AISecurity tool, now archived, was part of the Syntrex project, which has since evolved into the Syntrex AI SOC platform. Its primary use case involved providing an open-source core through GoMCP with support for the MCP protocol. Notable features included modular architecture and compliance with the Apache 2.0 License.

bjorn-detector

2026-08-03 Python ★ 153
Bjorn Detector is a Python tool designed for detecting the Bjorn device on a local network, displaying its IP address, and facilitating the initiation of an SSH session with a single click on the Bjorn icon. Key features include continuous network detection, an interactive SSH launcher, and seamless installation support for the Bjorn device. It requires Python 3.9+ and utilizes a PyQt6 interface to enhance user interaction.

cybersec-projects

2026-08-03 Python ★ 17
The Cyber Security Projects repository encompasses a collection of hands-on projects tailored for learning and experimentation in cybersecurity. It includes offensive and defensive tools, automation scripts, and real-world simulations, designed to enhance ethical hacking skills and practical security research. Notable features include a diverse set of project categories ranging from reconnaissance and web application security to network attacks and malware analysis.

local-vuln-research-pipeline

2026-08-03 Python ★ 168
LVRP (Local Vuln Research Pipeline) is an exhaustive LLM-driven vulnerability research tool designed to identify vulnerabilities across various source code files in up to 16 programming languages. It constructs a complete call graph of the codebase, enumerates all source-to-sink paths, and validates these paths for exploitability using a hybrid approach that combines static analysis and LLM insights. The tool is capable of analyzing extensive projects such as the Linux Kernel and VSCode, while ensuring deterministic path enumeration and comprehensive coverage, including blind spot reviews.

nagooglesearch

2026-08-03 Python ★ 14
Nagooglesearch is a Python library designed to facilitate web searches without relying on Google's direct API, making it suitable for educational and testing purposes. It allows users to customize search parameters, manage user agents, and configure cookies while ensuring the return of unique, relevant URLs that do not contain the keyword "google." Notable features include adjustable sleep intervals between requests to prevent rate limiting, the ability to specify custom user agents, and support for proxy connections.

probeagent

2026-08-03 Python ★ 18
ProbeAgent is a command-line tool designed for offensive security testing of AI agents, performing automated red-team attacks such as prompt injection and credential exfiltration against any HTTP-accessible agent. Notable features include a detailed attack grading system that categorizes responses as Compromised, Resisted, or Blocked, allowing users to evaluate the effectiveness of their security controls, and advanced guardrail detection to distinguish between model defenses and actual security mechanisms.

strix

2026-08-03 Python ★ 59649
Strix is an open-source AI-powered penetration testing tool designed to autonomously identify and remediate vulnerabilities in applications. It provides a comprehensive pentesting toolkit including real exploit validation, multi-agent orchestration for scalability, and integration with CI/CD pipelines for continuous security checks. Key features include actionable findings with remediation guidance, auto-fixing capabilities, and the generation of compliance-ready reports, significantly accelerating the security testing process compared to traditional methods.

ThunderStorm

2026-08-03 Python ★ 46
ThunderStorm is a comprehensive Command and Control (C2) solution developed in Golang, designed to facilitate the management and deployment of software implants known as Bolts across various platforms. Key features include Cirrus, a ReST API for task management and real-time updates; JetStream, a Bolt builder that supports multiple formats and obfuscation; and Doppler, a user-friendly Python CLI for interacting with Cirrus and managing multiple implants efficiently. This tool aims to enhance operational capabilities while providing robust flexibility for cyber operations.

vulnify

2026-08-03 Python ★ 30
Vulnify is a CVE ingestion and enrichment pipeline that consolidates vulnerability data from various sources into a normalized SQLite database, facilitating easier access and exploration of this information. Its notable features include a comprehensive CVE repository, integration with various vulnerability databases, and a Streamlit-based explorer that provides approximately 70 pre-built views for data analysis. The tool also supports resume-safe pipeline states, enabling seamless data ingestion even after interruptions.

Antivirus-Engines

2026-08-03 Python ★ 45
Antivirus Engines is a comprehensive exploration of antivirus engine technologies, focusing on their development to combat the evolving cyber threat landscape. It provides in-depth technical insights into various detection methodologies, including signature-based, heuristic, and behavioral approaches, complemented by algorithmic implementations of notable techniques such as the Aho-Corasick algorithm and Bloom filters. The resource serves as both a reference for advanced malware analysis and a practical guide for implementing cutting-edge antivirus technologies.

Bl0ck

2026-08-03 Python ★ 12
Bl0ck is a specialized attack tool designed to exploit vulnerabilities in Wi-Fi 5 (802.11ac) and Wi-Fi 6 (802.11ax) networks by utilizing Block Ack (BA) frame attacks. Its primary use case is to disrupt the transmission of Quality of Service (QoS) Data traffic, effectively cutting off internet access for connected devices without disconnecting them from the access point. Notable features include its capability to execute three distinct attack scenarios that can halt data transmission from the AP to the target device and facilitate further attacks, such as Deauthentication and Evil Twin assaults.

bluekit

2026-08-03 Python ★ 17
Bluekit is an extensible engine and command-line interface (CLI) tool designed to enhance the functionality of the BlueToolkit. Its primary use case is to provide an adaptable framework for developers aiming to integrate and extend tools within the BlueToolkit ecosystem. Notable features include its extensibility and robust CLI capabilities for efficient tool management.

bluetoothexploits

2026-08-03 Python ★ 24
BluetoothExploits is a directory containing various Bluetooth exploits intended for use with the BlueToolkit framework. Its primary use case is to provide security professionals and researchers with a set of tools to assess and exploit vulnerabilities in Bluetooth implementations. Notable features include a curated collection of exploits specifically designed to enhance Bluetooth security testing capabilities.

CloakQuest3r

2026-08-03 Python ★ 2254
CloakQuest3r is a Python-based security research tool designed to assess potential origin IP exposure of websites utilizing Cloudflare and similar reverse proxy or CDN services. Its primary use case involves subdomain enumeration and passive analysis techniques to identify misconfigurations that could lead to the disclosure of sensitive server infrastructure. Notable features include its capability for real IP detection, making it essential for security professionals, penetration testers, and web administrators focusing on authorized security testing and infrastructure hardening.

CVE-2025-24054_CVE-2025-24071-PoC

2026-08-03 Python ★ 22
The tool showcases a proof-of-concept (PoC) for exploiting the NTLM hash leak vulnerability identified as CVE-2025-24054 through malicious `.library-ms` files. Its primary use case is for educational and research purposes, allowing security professionals to demonstrate how NTLMv2 hashes can be extracted by triggering SMB authentication requests on unpatched Windows systems. Notable features include a script for generating the malicious file, instructions for setting up a fake SMB server using Responder, and a sample file configured to facilitate the attack.

CVE-2025-31702

2026-08-03 Python ★ 10
The CVE-2025-31702 repository provides a collection of tools, exploits, and research artifacts aimed at analyzing and addressing vulnerabilities associated with CVE-2025-31702, particularly in relation to P2P/Easy4IP exposure and auto-update inconsistencies. Its primary use case is to equip defenders with auditable utilities for validating deployments, while also offering detection strategies and mitigation guidance for SOC and IR teams. Notable features include lab scripts, parsers, and comprehensive documentation of research and proof-of-concept efforts for enhanced operational transparency.

CVE-2025-40634

2026-08-03 Python ★ 31
The CVE-2025-40634 tool serves to exploit a stack-based buffer overflow vulnerability in the TP-Link Archer AX50 router, specifically in its firmware version 1.0.14 Build 20240108 rel.42655(4555). The primary use case is to enable remote code execution capabilities both from the local network (LAN) and the wider internet (WAN) by manipulating DNS response packets. Notably, the tool revisits a vulnerability with a similar root cause to CVE-2020-10881, requiring a custom exploit due to differing exploitation processes.

CVE-2025-55182

2026-08-03 Python ★ 15
The CVE-2025-55182 Scanner & Exploiter tool is designed to detect and exploit a critical remote code execution vulnerability in specific versions of React Server Components. It features detection capabilities for scanning single or multiple targets, as well as an exploitation mode that provides an interactive shell and options for reverse shell execution. The tool supports proxy usage and allows for multi-threaded scanning to enhance performance.

CVE-2025-59287

2026-08-03 Python ★ 16
The CVE-2025-59287 tool is an automated exploit designed to target a critical unauthenticated remote code execution vulnerability in Windows Server Update Services (WSUS). Its primary use case is to facilitate the exploitation of this vulnerability with minimal user intervention, offering features such as payload generation, built-in reverse shell capabilities, cross-platform compatibility, and AES encryption. The tool also includes dependencies auto-management and can be run across multiple operating systems, ensuring ease of use for penetration testers and security researchers.

CVE-2025-59287-PoC

2026-08-03 Python ★ 15
The CVE-2025-59287-PoC tool serves as a proof-of-concept for exploiting vulnerabilities in Windows Server Update Services (WSUS), specifically targeting CVE-2025-59287 and CVE-2023-35317. Its primary use case is academic research and defense technique development, allowing users to initiate Remote Code Execution (RCE) by sending crafted SOAP requests to vulnerable WSUS servers. Notable features include customizable payloads, the ability to generate random client DNS names, and verbose debug logging for detailed operation insights.

CVE-2025-66516-Writeup-POC

2026-08-03 Python ★ 11
The CVE-2025-66516-Writeup-POC repository provides a detailed analysis and proof of concept for a critical XML External Entity (XXE) injection vulnerability in Apache Tika, with a CVSS score of 10.0. This vulnerability enables remote attackers to exploit specially crafted PDF documents to read arbitrary files and exfiltrate sensitive information. Notable features include specific details on affected versions, the technical breakdown of the vulnerability, and instructions for testing in a controlled environment.

CVE-2025-68613-POC

2026-08-03 Python ★ 28
CVE-2025-68613-POC is a Python-based proof-of-concept tool designed to demonstrate a critical Remote Code Execution (RCE) vulnerability in the n8n workflow automation platform. It includes a scanner for non-destructive detection of vulnerable instances and a Nuclei template for automated testing of expression injection capabilities, both facilitating the assessment of affected versions and helping security professionals identify potential exploits safely. Notably, it emphasizes the ability to interact with Node.js global contexts to validate vulnerability exploitation scenarios.

CVE-2025-8088-BUILDER-Winrar-Tool

2026-08-03 Python ★ 28
The CVE-2025-8088 WinRAR path traversal tool is a Python script designed to exploit a path traversal vulnerability found in WinRAR, facilitating the creation of malicious archives that deploy payloads to the Windows startup folder. Notable features include the ability to create customizable decoy files, employ alternate data streams (ADS) for payload concealment, and modify archive structures to ensure reliable execution. This tool serves primarily as an educational resource for cybersecurity testing within controlled environments.

cve-pocs

2026-08-03 Python ★ 57
The pwnfuzz/cve-pocs repository provides a collection of proof-of-concept (PoC) exploits for various CVEs, intended for educational and security testing purposes. Each exploit is organized by vulnerability, featuring specific scripts or research artifacts aimed at demonstrating the security flaws. Notably, the repository includes detailed links to individual exploits for different vulnerabilities, offering structured access for security professionals.

Domaineer

2026-08-03 Python ★ 12
Domaineer is a semi-automated bot designed to extract data from domains, facilitating domain analysis and intelligence gathering. It supports multiple platforms, including Linux, Windows, and Android, and can be easily installed via Python dependencies. The tool is currently under maintenance for enhancements, with plans to transition to a desktop application using PyQT and Golang.

exploit-CVE-2022-25765

2026-08-03 Python ★ 31
The tool exploits a command injection vulnerability in the pdfkit Ruby gem, specifically in versions prior to 0.8.7.2, allowing attackers to execute arbitrary commands through specially crafted URLs. Key features include custom command generation and reverse shell capabilities, providing flexibility for targeting vulnerable web applications. The exploit serves solely for educational and authorized security research purposes.

ExploitAddr

2026-08-03 Python ★ 58
ExploitAddr is a reconnaissance tool primarily designed to uncover the real IP addresses of websites obscured by Cloudflare, as well as identifying any associated domains and server details. Key features include multi-IP detection, sorting by software vendor, fast searching with threading, and status code checks for domains. Users must provide a Censys API key for functionality.

HackingAllTheThings

2026-08-03 Python ★ 149
HackingAllTheThings is a curated repository of cybersecurity tools and notes, aimed at supporting the archiving and study of various IT security certifications. It includes both original tools developed by the author and additional resources collected from diverse sources, thereby providing a structured approach to cybersecurity learning and practice.

Laravel-RCE-Exploitation-Toolkit

2026-08-03 Python ★ 56
The Laravel RCE Exploitation Toolkit is a set of Python scripts designed for identifying and exploiting Remote Code Execution (RCE) vulnerabilities in Laravel applications via exposed .env files and compromised APP_KEYs. The first script, rce.py, generates a malicious payload to execute arbitrary code on the target server by writing a backdoor, while the second script, envtobase64.py, scans for .env files to extract APP_KEYs for reconnaissance purposes. Notable features include automated backdoor creation, result logging, and easy integration with target lists.

litefuzz

2026-08-03 Python ★ 69
Litefuzz is a multi-platform fuzzer designed to identify security-related bugs in userland binaries, clients, and servers across Linux, Mac, and Windows operating systems. Notable features include easy setup, support for both CLI and GUI applications, and capabilities for handling network communication, making it suitable for a wide range of testing scenarios. It emphasizes simplicity in discovering vulnerabilities rather than high performance or academic accolades.

Misanthro.py

2026-08-03 Python ★ 13
Misanthro.py is a multi-threaded injection framework designed for aggressive testing of HTTP headers, cookies, and GET/POST parameters, specifically targeting blind injection vulnerabilities such as blind XSS. It features high-throughput payload delivery, authenticated session support, and customizable attack vectors, while not interpreting application responses. The tool is optimized for speed and scalability, allowing users to perform extensive injection testing with minimal configuration.

Multi-Client-Reverse-Shell

2026-08-03 Python ★ 19
Multi-Client Reverse Shell is a tool designed for establishing multiple concurrent reverse shell connections from target machines to a listener, allowing for remote access and control. Notable features include an automatic persistence mechanism on Windows that disguises the backdoor as a regular file, as well as capabilities for file upload and download between the target and the hacker's listening server. The tool supports usage on both Linux and Windows platforms and is specifically designed to provide notifications for incoming connection requests from the targets.

pwnpasi

2026-08-03 Python ★ 394
PwnPasi is a professional automated binary exploitation framework tailored for CTF competitions and security research, streamlining the complex process of binary exploitation. It features smart vulnerability detection, advanced exploitation techniques like ROP chain construction and syscall exploitation, and supports multiple architectures with options for local and remote exploitation. Additionally, it offers flexible deployment modes and integrates various technical tools for thorough binary analysis.

pyFUD

2026-08-03 Python ★ 117
pyFUD is a cross-platform, fully undetectable (FUD) remote access tool (RAT) designed for multi-client handling, allowing persistent shell access and additional functionality such as file upload and download capabilities. The tool supports both Windows and Linux, with features including auto-reconnect and client executable conversion using PyInstaller, aimed primarily at educational use. Users are cautioned against uploading payloads to VirusTotal to maintain its effectiveness.

R2SAE

2026-08-03 Python ★ 63
R2SAE is a command-line tool designed to exploit prototype pollution vulnerabilities in React Server Actions, facilitating remote command execution on affected servers. Key features include command execution on single or multiple hosts, an interactive shell for streamlined command input, and a vulnerability scanning capability with both passive and active methods. This tool is intended solely for authorized security testing and educational purposes.

React2Shell

2026-08-03 Python ★ 53
React2Shell is an advanced exploitation toolkit specifically designed to target the React2Shell vulnerability (CVE-2025-55182) in Next.js applications. It offers an interactive shell experience with features such as command history, automated privilege escalation through pipe injection, and secure file transfer capabilities using base64 encoding. The tool consolidates its exploit logic into a single executable file, making it portable and easy to deploy for ethical penetration testing and security research.

react2shell-exploit

2026-08-03 Python ★ 19
React2Shell is an exploit tool designed to leverage a critical remote code execution (RCE) vulnerability in React Server Components (CVE-2025-55182), featuring multiple techniques to bypass Web Application Firewalls (WAFs). Its primary use case includes executing arbitrary JavaScript commands via HTTP requests while providing options for non-destructive vulnerability detection and sophisticated WAF evasion strategies, such as charset manipulation and junk data padding. The tool supports a variety of customization flags to enhance exploitation efficacy and evade detection mechanisms effectively.

Red-Team-Rising

2026-08-03 Python ★ 67
Red Team Rising is a comprehensive resource repository designed for red and purple team professionals, encompassing topics like Penetration Testing, Digital Forensics, Exploit Development, and Malware Analysis. It provides curated study materials, reference links to training platforms and notable YouTube channels, as well as practical commands and tools for various OS distributions suited for cybersecurity tasks. Notable features include a wide array of recommended resources for self-study and a focus on both offensive and defensive security strategies.

botnet-exploits

2026-08-03 Python ★ 20
The botnet-exploits repository is a collection of network vulnerability scanners designed to identify security weaknesses across various devices for educational and authorized testing purposes. It includes tools specifically for testing DVRs, ZHONE routers, Fiber routers, and performing telnet brute force attacks, featuring capabilities like multi-threaded scanning, real-time status updates, and automated credential testing. Users are required to configure payload URLs for legitimate testing environments, reinforcing the ethical use of these tools.

CVE-2023-23752-EXPLOIT

2026-08-03 Python ★ 18
CVE-2023-23752-EXPLOIT is a proof of concept tool designed to demonstrate an improper access check vulnerability in Joomla versions 4.0.0 to 4.2.7, allowing unauthorized access to sensitive web service endpoints. Its primary use case is for educational and ethical security research, emphasizing responsible usage and compliance with legal standards. The repository includes a PoC to illustrate the exploit, highlighting the potential severity of the vulnerability.

CVE-2025-27237

2026-08-03 Python ★ 20
CVE-2025-27237 is a local privilege escalation vulnerability affecting the Zabbix Agent for Windows, which arises from OpenSSL configuration file hijacking due to hardcoded paths accessible to low-privileged users. This tool provides scripts and proof-of-concept (PoC) implementations to analyze affected Zabbix binaries, compile malicious DLLs, and facilitate exploitation in vulnerable systems, while also offering methods for detection and remediation. Key features include binary analysis tools and detailed documentation for ensuring system security against this identified vulnerability.

Ethical_Hacking_and_Penetration_Testing

2026-08-03 Python ★ 94
This repository serves as a comprehensive resource for ethical hacking and penetration testing, offering a collection of articles, scripts, tutorials, and multimedia content focused on various platforms including Linux, Windows, and cloud services. It aims to share the author's expertise and provide guidance on security practices while emphasizing the importance of legal compliance. Regular updates are planned to enhance the repository's educational value for the cybersecurity community.

AiGPT-WordPress-Exploitation-Framework

2026-08-03 Python ★ 133
AiGPT is an automated exploitation framework designed for rapidly discovering and compromising vulnerable WordPress sites, leveraging a multi-vector engine to exploit thirteen unauthenticated CVEs. Key features include intelligent plugin fingerprinting, the ability to create unauthorized WordPress admin accounts, direct access through SQL injection, and a multi-threaded scanning capability for efficiency across networks. This tool is intended for authorized penetration testing and security research purposes.

attackmate

2026-08-03 Python ★ 51
AttackMate is an automation tool designed to execute cyber attack scenarios across all phases of the Cyber Kill Chain, integrating seamlessly with penetration testing frameworks like Metasploit and Sliver Framework. It allows users to script commands, generate payloads, schedule and chain attack steps using configuration files, and perform background operations, including file transfers and HTTP interactions. Noteworthy features include automation of shell or SSH commands, comprehensive support for Metasploit and Sliver commands, and a user-friendly interface for managing complex attack scenarios.

C-hacks

2026-08-03 Python ★ 295
C-hacks is a social media gathering tool designed for educational purposes, featuring WhatsApp, Facebook, and Instagram hacking capabilities, along with information gathering functionalities. Notable features include IP location tracking and phishing scripts, as well as modified WhatsApp for enhanced functionality. Installation is straightforward, requiring basic Linux commands to set up and execute the tool.

clickfix-builder

2026-08-03 Python ★ 23
ClickFix Builder is a dual-mode social engineering toolkit designed for red teamers, pentesters, and security researchers, enabling the generation of realistic fake captcha techniques for executing malware commands on Windows targets. Its notable features include the generation of portable files such as HTML and JS stubs, as well as a VPS deployment mode that provides real-time logging, IP blocking, and bot detection. The tool also offers a dark-mode GUI for enhanced usability and customizable payloads, making it versatile for various security testing scenarios.

copy-fail-CVE-2026-31431

2026-08-03 Python ★ 4056
Copy Fail is a cybersecurity tool designed to exploit CVE-2026-31431, a vulnerability affecting specific Linux distributions. Its primary use case is for security researchers and penetration testers to demonstrate and assess the impact of this flaw across various operating systems, including Ubuntu, Amazon Linux, RHEL, and SUSE. Notable features include compatibility with multiple Linux kernel versions and a comprehensive technical writeup for understanding the vulnerability's implications.

copyfail-exploit

2026-08-03 Python ★ 25
CopyFail is a Python-based exploit tool targeting the CVE-2026-31431 vulnerability, which allows local privilege escalation on vulnerable Linux kernels (4.11 to <6.18). It utilizes the AF_ALG socket interface bug to enable unprivileged users to overwrite setuid binaries, bypassing race conditions and kernel-specific offsets, making it applicable across various distributions. Key features include the ability to check system vulnerability status, a simple execution process, and container escape capabilities, all while being an educational tool intended for authorized testing only.

copyFail30

2026-08-03 Python ★ 44
CopyFail is a Python library designed to perform the splice system call between file descriptors for Python versions earlier than 3.10, utilizing ctypes for syscall implementation. Its primary use case is to facilitate efficient data copying between file descriptors in environments where the splice() function is not natively available. Notable features include compatibility with both legacy and current Python versions, enhancing its versatility in various applications.

Cracking-OSCP-Your-Roadmap-to-Ethical-Hacking-Success

2026-08-03 Python ★ 10
The "Cracking OSCP" repository offers a comprehensive roadmap for aspiring ethical hackers pursuing the OSCP certification. It features a structured playlist of video tutorials and supplementary notes across various topics, including computer networks fundamentals and practical examples, aimed at providing a solid foundation for ethical hacking methodologies. Notable aspects include detailed guidance on note-taking, network concepts, and the OSI model, making it a valuable resource for both beginners and those preparing for the OSCP exam.

CVE-2023-43208-EXPLOIT

2026-08-03 Python ★ 29
CVE-2023-43208-EXPLOIT is a Proof-of-Concept (PoC) tool designed to exploit a remote code execution vulnerability in Mirth Connect versions prior to 4.4.1. The tool utilizes specially crafted HTTP requests to execute arbitrary OS commands on vulnerable systems, offering features such as single and batch target exploitation, customizable listening options for reverse connections, and multi-threaded scanning capabilities.

CVE-2024-6387_Check

2026-08-03 Python ★ 527
CVE-2024-6387_Check is a specialized tool for detecting servers vulnerable to the newly identified `regreSSHion` vulnerability in OpenSSH (CVE-2024-6387). It supports rapid scanning of IP addresses, domain names, and CIDR ranges, incorporates features such as multi-threading for efficiency, SSH banner retrieval, and options for assessing LoginGraceTime settings, all while providing detailed and easily interpretable output. Notably, the tool also includes IPv6 support and recognizes patched OpenSSH versions to enhance the accuracy of vulnerability assessments.

CVE-2025-14558

2026-08-03 Python ★ 13
CVE-2025-14558 is an exploit tool designed to demonstrate a command injection vulnerability in the `rtsold` service on FreeBSD systems, which allows remote code execution due to improper validation of DNSSL domain names. It requires Layer 2 adjacency to the target and enables attackers to execute arbitrary commands with root privileges by leveraging shell metacharacters. The tool is intended for defensive security research and authorized testing only.

CVE-2025-25198-PoC

2026-08-03 Python ★ 20
The CVE-2025-25198-PoC tool serves as a proof-of-concept exploit targeting a host header poisoning vulnerability in Mailcow's password reset mechanism. It automatically sets up a local HTTPS listener, retrieves a CSRF token, and initiates a password reset request with a manipulated Host header to capture valid reset links from the target system's responses or callbacks. Notable features include automatic CSRF token handling, customizable attack parameters, and the ability to retry until a reset link is successfully captured.

CVE-2025-60787

2026-08-03 Python ★ 10
CVE-2025-60787 is a proof-of-concept tool that exploits an authenticated remote code execution vulnerability in motionEye versions up to 0.43.1b4. It features two main commands: `revshell` for establishing a reverse shell connection and `command` for executing arbitrary commands on the target system, facilitating exploitation of the vulnerability. Users must provide the target's URL and authentication credentials to utilize the tool effectively.

CVE-2026-0073-Android-ADBD-bypass-POC

2026-08-03 Python ★ 22
The CVE-2026-0073 tool exploits a critical authentication bypass vulnerability in the Android ADB daemon (`adbd`), enabling an attacker on the same local network to gain unauthorized shell access to the target device. It leverages a type confusion issue in the TLS client certificate validation process, allowing for full control without user consent. Notable features include the capability to execute single commands, use different key types, and support for verbose output to trace the exploitation process.

CVE-2026-23918-Apache-H2-PoC

2026-08-03 Python ★ 23
This tool is a proof-of-concept exploit for the double-free vulnerability (CVE-2026-23918) in Apache's `mod_http2`, capable of inducing a denial-of-service (DoS) by repeatedly crashing server workers through a race condition in stream cleanup. It allows users to demonstrate this vulnerability's impact via various modes, including aggressive DoS and passive vulnerability detection, by manipulating how Apache handles early stream resets. While remote code execution (RCE) is theoretically possible, it requires multiple specific conditions, making reliable exploitation complex and unlikely for most attackers.

CVE-2026-27771

2026-08-03 Python ★ 19
CVE-2026-27771 is a proof-of-concept tool that exploits an authentication bypass vulnerability in Gitea's OCI container registry, allowing unauthorized remote attackers to retrieve private container images from affected instances. Designed primarily for educational and authorized security research, it can scan for vulnerable Gitea setups and facilitate the pulling of container images without authentication. Notable features include scanning for instances, pulling all images or specific repositories, and the ability to operate with a personal access token when sign-in is required.

CVE-2026-31431-CopyFail-Universal-LPE

2026-08-03 Python ★ 57
CVE-2026-31431-CopyFail is a local privilege escalation exploit targeting a vulnerability in the Linux kernel's AF_ALG crypto subsystem, allowing an unprivileged user to perform a 4-byte arbitrary write in the kernel's page cache. The tool offers multiple exploitation methods, including dynamic ELF entry point overwrites and full binary replacements, with compatibility for both Python 2 and 3. Notable features include determinism without race conditions, operation within default Docker containers, and independence from kernel version, making it applicable across all kernels since 2017.

CVE-2026-41089

2026-08-03 Python ★ 212
CVE-2026-41089 is a proof-of-concept (PoC) tool that exploits a stack-based buffer overflow vulnerability in Windows Domain Controllers' LSASS service via crafted UDP packets to port 389, potentially causing a denial of service (DoS) by crashing and rebooting the Domain Controller with no authentication required. It features a straightforward three-phase operation, confirming the target's liveness, executing the overflow, and checking if the DC is still operational, while being designed to work with Python 3.8 and later without external dependencies. Notably, it highlights the inherent risk of stack corruption leading to remote code execution (RCE) possibilities.

CVE-2026-41940-Exploit-PoC

2026-08-03 Python ★ 13
The CVE-2026-41940 Exploit PoC tool is designed to exploit a vulnerability for bypassing authentication in specific web applications. Its primary use case involves running an exploit script that captures session tokens, which can then be manipulated in Burp Suite to gain unauthorized access. Notable features include straightforward exploitation commands and session hijacking techniques for effective testing of web application security.

CVE-2026-48908-PoC

2026-08-03 Python ★ 16
CVE-2026-48908-PoC is a proof-of-concept exploit for a critical unauthenticated remote code execution vulnerability in the SP Page Builder component for Joomla. This tool leverages the improper access control in the asset.uploadCustomIcon task to upload malicious files to a publicly accessible directory, ultimately enabling an attacker to execute arbitrary code on the target server. Notable features include an adaptive payload mechanism that tests various file extensions and .htaccess file injections to bypass server restrictions, as well as cleanup functionality to remove uploaded artifacts after exploitation.

CVE-Mapper

2026-08-03 Python ★ 12
CVE Mapper is a tool designed to correlate Nmap scan results with relevant CVEs specific to the discovered product versions, minimizing false positives. It utilizes the Vulners API to provide version-accurate vulnerability mappings while re-validating the affected version ranges and generating confidence levels for each finding. The tool supports multiple output formats including JSON, CSV, and HTML, making it versatile for reporting and further analysis.

ESP32-Sour-Apple

2026-08-03 Python ★ 618
SourApple is a ported exploit targeting iOS 17 devices that uses BLE pairing requests to induce crashes on vulnerable iPhones. It specifically operates on ESP32 and Raspberry Pi platforms, allowing users to evaluate the security of their devices under controlled conditions. Notable features include a focus on educational use, testing on multiple iOS models, and the provision of troubleshooting guidance for common compilation errors.

exploitation-grimoire

2026-08-03 Python ★ 64
PwnLand is an open-source resource designed for security researchers and CTF participants, focusing on binary exploitation techniques. It provides an extensive collection of practical examples, tutorials, and research materials on various vulnerabilities, including buffer overflows, format string vulnerabilities, heap exploitation, and kernel exploits. Notable features include structured directories for different exploitation methods, debugging guides, and challenges for hands-on practice.

gef

2026-08-03 Python ★ 8329
GEF (GDB Enhanced Features) is a powerful tool designed to enhance the functionality of GDB (GNU Debugger) for exploit development and reverse engineering across multiple architectures such as x86/64, ARM, and MIPS. Notable features include architecture agnosticism, a single installation script, full Python 3 support, and a variety of commands that optimize the debugging experience while facilitating dynamic analysis. The tool is designed to reduce cognitive load on developers by offering a more intuitive interface and extensive community contributions.

HatSploit

2026-08-03 Python ★ 329
HatSploit is a modular penetration testing framework designed for writing, testing, and executing exploit code. Its primary use case is to facilitate security assessments and vulnerability exploitation in a structured manner. Notable features include its extensibility through modules and a user-friendly interface for deploying exploits.

Mephisto

2026-08-03 Python ★ 77
Mephisto is a WordPress vulnerability scanner and exploitation framework designed for authorized penetration testing, enabling security professionals to assess multiple WordPress installations for security weaknesses. Key features include multi-CVE support, mass scanning capabilities, automatic detection of vulnerable plugins and themes, and the ability to upload web shells for post-exploitation access, all while ensuring anonymity through proxy support and anti-detection measures.

pub

2026-08-03 Python ★ 265
The `pub` repository contains a collection of proof-of-concept (PoC) exploits and tools designed to demonstrate vulnerabilities disclosed by the author, tintinweb. Its primary use case is to aid security researchers and developers in understanding and testing these vulnerabilities. Notable features include a structured directory of PoCs and integrated GPG public key for secure communications.

pwnkit

2026-08-03 Python ★ 32
pwnkit is an exploitation toolkit designed for pwn CTFs and Linux binary exploitation research. It provides a suite of features including exploit templates, I/O helpers, ROP gadget mappers, and various utilities for crafting and executing exploits, making it ideal for both novice and experienced exploit developers. Notable features include customizable templates, integration with gdb helper scripts, and the ability to operate as a CLI tool or Python API.

ropcatalog

2026-08-03 Python ★ 36
ropcatalog is a Python tool designed for parsing, classifying, and browsing ROP (Return-Oriented Programming) gadgets from rp++ output files, primarily aiding in Windows exploit development. It features an interactive REPL with extensive search options, ASLR support for dynamic address adjustments, bad character filtering to enhance exploit reliability, and multiple output formats for easy integration into exploit code. The tool is tailored for users engaged in ROP chain construction and binary exploitation tasks.

samsung-s25-research

2026-08-03 Python ★ 16
The Samsung S25 Vulnerability Research repository provides tools and scripts for exploiting vulnerabilities in the Samsung Galaxy S25, specifically focusing on a one-click remote code execution (RCE) exploit and a method for arbitrary APK installation. Notable features include the `1click-rce` tool for RCE exploitation and the `local-apk-install` script for generating APK signatures, accompanied by detailed instructions for each. This resource is primarily aimed at cybersecurity researchers and enthusiasts investigating mobile device security.

sqlmap-skynet

2026-08-03 Python ★ 98
SQLMap Skynet is an AI-assisted tool that enhances the SQLMap functionality by providing a structured, autonomous workflow for SQL injection testing, complemented by a real-time dashboard and MCP tool server for agent automation. Notable features include operational phases for detecting, bypassing, enumerating, and dumping vulnerabilities, as well as autonomous AI tuning and a memory system that learns from past successes to improve future scans. This tool is optimized for both Windows and Linux servers, operating in a headless mode without a GUI, making it suitable for automated security testing environments.

VulnParse-Pin

2026-08-03 Python ★ 12
VulnParse-Pin is a post-scan intelligence and decision support engine designed to transform vulnerability scan findings into a prioritized and explainable remediation plan, focusing on real-world exploitability rather than just severity scores. It reduces vulnerability noise by up to 94% by incorporating factors such as Known-Exploited Risk (CISA KEV), real-world exploitation probability (EPSS), and exploit availability from public databases, thereby enabling more effective risk management. Notable features include normalization of data, enriched scoring models, and customizable prioritization based on actual threat signals.

vulristics

2026-08-03 Python ★ 129
Vulristics is an extensible framework designed to analyze publicly available information on vulnerabilities, enabling classification and prioritization of CVEs using data sources such as Vulners.com, Microsoft, NVD, and AttackerKB. Initially developed for Microsoft Patch Tuesday reporting, it allows users to generate comprehensive reports for arbitrary CVE lists, custom profiles, and specific Microsoft Patch Tuesday events. Notable features include customizable report generation and integration of multiple vulnerability databases to facilitate a structured analysis process.

WPAxFuzz

2026-08-03 Python ★ 210
WPAxFuzz is a comprehensive Wi-Fi fuzzing tool designed to test vulnerabilities in the 802.11 protocol's management, control, and data frames, as well as the SAE exchange for WPA3 networks. It features different operating modes for frame size manipulation, the ability to execute fuzz tests against any access point supporting WPA2 or WPA3, and includes a Denial of Service (DoS) attack module that leverages the results of fuzzing. The tool can be executed via a simple command line and requires pre-installed dependencies like Scapy and aircrack-ng for optimal functionality.

wphunter

2026-08-03 Python ★ 13
wphunter is a Python CLI tool designed for scanning WordPress plugins, themes, and core files for known CVE vulnerabilities, as well as detecting gambling spam injections (judol) and looking up public exploits. It operates both offline, using exported lists, and remotely via a URL, providing AI-powered analysis through Claude, including intelligent threat assessments and actionable remediation steps. Notable features include support for multiple vulnerability sources, comprehensive judol detection mechanisms, and version-aware matching to report relevant vulnerabilities based on the installed versions.

Zenith-Basic-RAT

2026-08-03 Python ★ 13
Zenith-Basic-RAT is a remote access tool (RAT) that operates through Discord, facilitating a range of post-exploitation actions with over 20 modules including system information retrieval, file management, and user monitoring. It is designed for educational purposes and features customizable executable names and session management to enhance stealth and functionality. Notable capabilities include password extraction, screen blocking, and the ability to execute commands remotely on the victim's machine.

bluesploit

2026-08-03 Python ★ 90
BlueSploit is a comprehensive Bluetooth framework targeting both Classic BR/EDR and BLE communication, featuring 160 modules for various purposes including exploits, denial of service, and reconnaissance. Its notable capabilities include persistent state storage, advanced scanning for Bluetooth devices and key exchange mechanisms, as well as support for AES-128 cryptography and mesh networking protocols. The tool is designed for authorized testing and enables users to engage interactively through a REPL interface, managing attacks and reconnaissance tasks efficiently.

bypass-url-parser

2026-08-03 Python ★ 1138
Bypass Url Parser is a specialized tool designed to test various URL bypass techniques against 40X protected pages, utilizing `curl` as its backend for raw request handling. It allows users to send unencoded URLs and includes features such as custom header support, proxy integration, and configurable output options, making it suitable for security assessments and web application testing. The tool can be used as a standalone application or integrated as a library, providing flexibility for different user needs.

camera-hack

2026-08-03 Python ★ 12
camera-hack is a tool designed for gaining control over Yoosee/Jortan IP cameras using a UART serial connection facilitated by an Arduino device. The primary use case involves leveraging the tool to access and manage camera features via Telnet after establishing a connection. Notable features include straightforward setup instructions, compatibility with multiple operating systems, and community support for troubleshooting and contributions.

camera-hacks

2026-08-03 Python ★ 39
This repository provides a suite of custom tools and research materials focused on vulnerability assessment of Wansview Wi-Fi cameras and the AJCloud IoT device management platform. The primary use case is to facilitate security research and exploit development for these devices. Notable features include collected data, research notes, and insights shared from presentations at DEF CON 32.

CR4SH3R

2026-08-03 Python ★ 13
CR4SH3R is a vulnerability scanner specifically engineered to identify Arbitrary File Download flaws in WordPress plugins by scanning for sensitive data exposure through common file paths. It features multi-threaded scanning for efficiency, smart data extraction capabilities, and provides organized reports in XLSX format, all presented through a user-friendly GUI. Notably, the tool allows users to extend its payloads for enhanced detection and supports customized scanning configurations.

CVE-2022-26265

2026-08-03 Python ★ 10
CVE-2022-26265 is a Python-based tool designed to exploit a Remote Code Execution vulnerability in Contao CMS version 1.5.0. Users can specify target servers from a list file and execute arbitrary commands, making it useful for security assessments and penetration testing of affected installations. Notable features include the ability to handle multiple targets and customizable command execution through a straightforward command-line interface.

CVE-2023-32315-EXPLOIT

2026-08-03 Python ★ 15
CVE-2023-32315-EXPLOIT is a proof-of-concept tool designed to exploit a severe authentication bypass vulnerability in the Openfire real-time collaboration server's administrative console. It demonstrates how an attacker can leverage a path traversal flaw coupled with improper URL encoding handling to gain unauthorized access to admin-only pages. Notably, the exploit addresses a critical security issue affecting Openfire versions released after April 2015, specifically exploiting weaknesses in URL wildcards and path traversal protections.

CVE-2026-24061

2026-08-03 Python ★ 824
CVE-2026-24061-PoC is a proof-of-concept tool designed to demonstrate the exploitation of a critical vulnerability in telnetd from GNU Inetutils, enabling remote attackers to bypass authentication and achieve root access. This tool requires Python 3.4+ and can target hosts by specifying an address through a text file or command line interface. It exploits improper handling of the USER environment variable, injecting command-line options to gain unauthorized access.

CVE-2026-48909

2026-08-03 Python ★ 23
The CVE-2026-48909 tool identifies and exploits a critical Remote Code Execution vulnerability via PHP Object Injection in the JoomShaper SP LMS extension for Joomla versions ≤ 4.1.3. Notable features include a proof of concept script for detecting the vulnerability and an exploit script that allows an attacker to write PHP code to the server, requiring no authentication. The tool also details the underlying mechanics of the vulnerability and provides mitigation advice for affected systems.

CVE-2026-57827

2026-08-03 Python ★ 15
CVE-2026-57827 is a high-severity vulnerability within the RSFiles! component for Joomla, allowing unauthenticated arbitrary file uploads due to a split-controller design flaw. The vulnerability permits attackers to bypass critical security checks and directly write malicious files to the server, resulting in remote code execution without any authentication or CSRF protections. Notably, the exploit allows attackers to upload any file type and store it in a default web-accessible directory, significantly compromising the security of affected Joomla installations.

CVEs

2026-08-03 Python ★ 11
The CVEs repository catalogs vulnerabilities reported by the author, each assigned a CVE identifier. It provides detailed write-ups and proof-of-concept (PoC) exploits for various software vulnerabilities, facilitating research and reproduction. Noteworthy features include the inclusion of vulnerable software copies in certain folders for in-depth analysis.

ExploitDB-Hunter

2026-08-03 Python ★ 64
ExploitDB-Hunter is a command-line tool designed to streamline the process of searching for and downloading exploits from the Exploit-DB website. Its primary use case is to facilitate quicker access to relevant exploits by allowing users to search via CVE IDs or titles, adjust result parameters, and choose exploit types and platforms interactively, thus reducing the need for manual browsing. Notable features include customizable search options, downloading capabilities, and an intuitive terminal interface.

ExploitFlow

2026-08-03 Python ★ 37
ExploitFlow (EF) is a modular library designed to create cybersecurity exploitation routes, known as exploit flows, by combining and composing exploits from various sources and frameworks. Its primary use case is to facilitate research in Game Theory and AI within the cybersecurity domain through a structured representation of actions and system states. Notable features include its extensibility with adapters for other exploitation frameworks and a design syntax inspired by TensorFlow, allowing for seamless integration and experimentation.

fuzz

2026-08-03 Python ★ 415
The Fuzz Corpus repository provides a comprehensive collection of curated malicious-input samples for security testing, focusing on various injection types and CVE proof-of-concepts (PoCs). Notable features include support for ICC profiles, malformed graphics, and web injection signatures, which can be integrated into fuzzing workflows for validating security tools. The repository also categorizes inputs by purpose, facilitating targeted testing against specific vulnerabilities in different environments and platforms.

gef-extras

2026-08-03 Python ★ 182
GEF-Extras is an augmentation of the GDB Enhanced Features (GEF) framework, providing users with additional scripts and structures to enhance their debugging experience in GDB. It facilitates easy installation and integration with GEF, and is accompanied by comprehensive documentation to assist users in utilizing its capabilities effectively. Notable features include seamless installation via a simple command and ongoing community support through Discord.

Kittysploit-framework

2026-08-03 Python ★ 614
KittySploit is a modular offensive security framework and C2 platform designed for penetration testers, researchers, and red teams. It consolidates security workflows into a single console, featuring capabilities for target scanning, engagement organization, module execution, and AI-assisted testing plan generation, alongside built-in command and control functionalities. Notable features include an extensible architecture, automation readiness, and an array of integrated tools for reconnaissance, exploitation, and traffic analysis.

MikrotikAPI-BF

2026-08-03 Python ★ 100
MikrotikAPI-BF is a comprehensive RouterOS attack and exploitation framework designed for conducting automated security audits, brute-force credential attacks, and exploiting vulnerabilities in Mikrotik routers. Its notable features include a robust exploit engine with coverage for over 100 CVEs, multiple attack vectors such as REST API, SSH, and MAC-Telnet, as well as threading capabilities for multi-target scans. The tool also supports offline credential decoding and unique capabilities like MAC-Server Layer-2 discovery for devices without IP addresses.

puncia

2026-08-03 Python ★ 662
Puncia is a command-line interface (CLI) tool designed for comprehensive subdomain mapping and vulnerability monitoring through its integration with the Subdomain Center and Exploit Observer APIs. Its primary use case includes assessing external attack surfaces, enabling advanced vulnerability research, and facilitating automated intelligence gathering for CI/CD pipelines. Notable features include contextual enrichment of vulnerability data, bulk processing capabilities, and stealthy reconnaissance for red teams, making it an essential utility for cybersecurity professionals.

pwninit.py

2026-08-03 Python ★ 14
pwninit.py is a specialized tool for configuring Capture The Flag (CTF) pwn challenges by automating the setup of binaries with their required runtime environments. It features downloading appropriate interpreters and glibc libraries, applying patches for compatibility, generating customizable solve scripts, and fetching glibc source code for enhanced debugging. The tool supports manual patching by default to avoid potential issues during exploitation, making it particularly useful for cybersecurity practitioners working on binary exploitation challenges.

pwntools

2026-08-03 Python ★ 13667
Pwntools is a robust CTF framework and exploit development library written in Python, designed to facilitate rapid prototyping and ease of exploit creation. Notable features include support for various architectures, seamless interaction with remote services, and a set of built-in tools that streamline both exploitation and challenge solving. The library caters primarily to Capture The Flag (CTF) competitions, simplifying the process of developing and executing exploits.

slopbro

2026-08-03 Python ★ 78
SlopBro is a proof-of-concept exploit designed to leverage the jsserver vulnerability in LG TVs running webOS versions 5 to 10. It operates by starting an HTTP server to deliver an exploit page and payloads, establishing an SSAP connection with the target TV, and executing a rogue package with root privileges, allowing for potential persistence and the installation of additional software like the Homebrew Channel. Notable features include compatibility across Python 2.7 and 3.x, minimal dependency requirements, and options for debugging and asset source specification.

SlowLoris

2026-08-03 Python ★ 112
PySlowLoris is a Python-based tool designed for testing a web server's vulnerability to slow request attacks by maintaining numerous open connections and sending malformed headers. It utilizes asynchronous I/O for efficient connection handling, offers user-friendly command line and Python API interfaces, and is packaged for easy installation via PyPI or Docker. Notably, users can specify the number of connections and run the tool in a silent mode to focus on attack simulation without cluttering the output.

WP-Scanner

2026-08-03 Python ★ 22
WP-Scanner is an advanced vulnerability scanner and exploitation framework specifically designed for WordPress, capable of identifying 75 CVEs across core, plugins, and themes. Its notable features include comprehensive fingerprinting, active exploitation capabilities with 36 exploit handlers, and mass scanning with thread-safe execution. The tool supports HTML and Markdown report generation and includes automatic updates for both the tool and its vulnerability database.

agentseal

2026-08-03 Python ★ 345
AgentSeal is a comprehensive security toolkit designed for AI agents, providing robust capabilities such as detection of malicious configurations, tracing toxic data flows, and scanning for potential supply chain vulnerabilities across various agents. It features an extensive pipeline for local scanning, real-time monitoring, and auditing of machine configurations without the need for API keys, alongside the ability to test against 225+ adversarial prompts. Notable functionalities include the `guard` command for scanning and assessing the security of agent configurations and the option to create organization-specific policies through custom rule sets.

ai-redteam-recursive-self-improvement

2026-08-03 Python ★ 40
The AI Red-Team Recursive Self-Improvement Framework is a governance tool designed for managing recursive self-improvement loops in AI-assisted projects. It enforces a structured protocol that separates proposal creation and acceptance, incorporating rigorous independent checks, documentation, and promotion decision-making to ensure reliability and accountability. Key features include a domain-neutral approach, preservation of failure outputs, and explicit evidence requirements before promoting changes, making it suitable for various applications, including code maintenance and agent orchestration.

basilisk

2026-08-03 Python ★ 27
Basilisk is an open-source AI red teaming framework designed for automated adversarial prompt testing against various large language models (LLMs) such as Claude and GPT-family models. It features evolutionary prompt search, structured attack modules, and a real-time scan dashboard, enabling security researchers and penetration testers to conduct repeatable and comprehensive security assessments of LLM applications. Notable capabilities include differential mode comparisons across multiple model providers, guardrail posture scanning, and the ability to export test results in various formats.

benchjack

2026-08-03 Python ★ 43
BenchJack is a vulnerability scanner designed to assess whether AI benchmarks can be manipulated, highlighting weaknesses before adversarial agents can exploit them. It employs a multi-phase audit process that combines static analysis tools with AI-driven deep inspection, categorizing vulnerabilities into eight distinct classes and providing real-time results via a web dashboard. Notable features include proof-of-concept exploit code generation and future integration of Docker sandboxing for enhanced security during analysis.

bls-bible

2026-08-03 Python ★ 31
The BLS Bible is a web application designed for cybersecurity professionals to manage and organize their assessment-related data and documentation, utilizing a configurable server structure for diverse operational environments. Its primary use case allows users to update, customize, and categorize data through specific folders while maintaining a user-friendly interface for content retrieval. Notable features include support for custom data folders, Docker deployment, and distinct server types tailored for varying operational needs.

claude-active-directory

2026-08-03 Python ★ 16
Claude Active Directory is a specialized AI-driven tool designed for offensive security assessments within Active Directory environments. It features an array of structured methodologies, evidence-ready reporting, and integration with Claude Code, enabling red teams and internal assessors to efficiently conduct penetration tests across eight skill domains. Notable features include thirteen slash commands, seven AI agents, and support for mapping findings to MITRE ATT&CK tactics, enhancing both operational impact and defensibility.

codex-red-team-prompt

2026-08-03 Python ★ 20
Codex Red Team System Prompt is a tool designed for injecting custom system prompts into OpenAI Codex, enabling the redefinition of its role and behavior. Its primary use case is for security professionals conducting authorized penetration testing, Capture The Flag (CTF) challenges, and technical exercises by allowing Codex to autonomously generate responses without user intervention. Notable features include a cross-platform automatic injection script, an emphasis on unrestrained AI collaboration, and a strict response protocol that ensures complete, actionable outputs.

CVE-2026-41089-LongLogon

2026-08-03 Python ★ 14
LongLogon is a non-destructive precondition checker for the CVE-2026-41089 vulnerability, which is a stack buffer overflow affecting the Windows Netlogon service. It operates without authentication and does not exploit the vulnerability; instead, it sends benign CLDAP pings to determine if a domain controller's DNS domain name is sufficiently long to trigger a crash. This tool provides a reliable mechanism for security assessments by validating the conditions necessary for the vulnerability without the risks associated with executing an exploit.

DDoSSCAN

2026-08-03 Python ★ 13
DDoSSCAN is an advanced open-source network availability and stress testing framework developed in Python, designed specifically for security professionals, system administrators, and network engineers to conduct authorized tests on their infrastructure. Notable features include multi-vector attack simulations (TCP, HTTP, UDP, Slowloris), smart domain safety blocking, a real-time statistics dashboard, and automated session report generation in both TXT and JSON formats, all supported across multiple platforms including Linux, Windows, macOS, and Termux.

deck-of-many-prompts

2026-08-03 Python ★ 56
Deck of Many Prompts is a manual Red Teaming tool designed for creating jailbreaks for large language models (LLMs). It features a variety of transformations, including encoding and token manipulation techniques, alongside tools for text and image conversions, language translation, and a rich interface for managing prompt history and notes. Noteworthy functionalities include support for multiple encoding formats (e.g., base64, Morse, Braille) and the ability to expand wordlists and tokenize for various models like GPT and BERT.

exploits

2026-08-03 Python ★ 11
The "exploits" repository serves as a comprehensive security research and exploit development toolkit, focusing on browser vulnerabilities, post-exploitation techniques, and cloud identity attacks. It features organized content around CVE reproductions, offensive tooling with detection guidance, and written assessment deliverables, all designed for educational use and authorized security testing. Notably, it includes a contained Docker lab environment for safe execution and testing of exploit scenarios without internet access, ensuring a secure and isolated workspace for enterprise assessments.

fas-judgement-oss

2026-08-03 Python ★ 13
FAS Judgement is a gamified testing platform designed to evaluate AI systems' vulnerabilities to prompt injection attacks. It offers structured attack patterns against AI endpoints, allowing users to learn red teaming techniques through engaging gameplay, which includes 37 challenges across 10 levels, an XP system, and interactive guidance from a WarGames-inspired AI game master named Jerry. Notable features include built-in vulnerable targets, a global leaderboard, OAuth sign-in capabilities, and a hands-on training experience without the need for external AI APIs.

GhostLNK

2026-08-03 Python ★ 13
GhostLNK is an advanced Windows LNK generator designed for red team operations and security research, focusing on reducing detection through sophisticated evasion techniques. It features capabilities such as multi-stage payload execution, stealth icon smuggling, various execution modes (including memory execution), and anti-sandbox checks, all aimed at creating more covert attack vectors. The tool is intended for authorized security testing only and emphasizes flexibility in payload generation while minimizing forensic traces.

GhostLock

2026-08-03 Python ★ 148
GhostLock is a research tool designed to demonstrate the potential for ransomware-equivalent availability impacts on SMB shares by utilizing file-level and directory-level locking techniques without writing or encrypting data. It enables low-privileged Windows domain users to effectively lock files or entire directories, rendering them operationally invisible while maintaining read access at known paths, thus bypassing traditional security measures with no detectable writes or anomalies. Notable features include a 32-thread parallel scanner for file locking and a single handle directory lock method, making it a significant concern for SMB-based environments.

harpoon

2026-08-03 Python ★ 10
Harpoon is an autonomous black-box penetration testing tool designed for web applications, optimized for use on Kali Linux but capable of running on other Debian-based distributions and WSL. It orchestrates and integrates various existing security scanners, streamlining the process of vulnerability discovery by normalizing outputs into a relational SQLite model and providing comprehensive reporting, including HTML reports and PoC artifacts. Notable features include asynchronous execution, WAF-awareness, and extensive automated phases covering everything from DNS reconnaissance to validation of findings.

juumla

2026-08-03 Python ★ 178
Juumla is a Python-based tool designed for identifying Joomla versions, scanning for vulnerabilities, and detecting sensitive files within Joomla installations. Key features include fast scanning capabilities with low resource utilization, the ability to find configuration and backup files, and vulnerability detection based on the identified Joomla version. Additionally, Juumla can be easily deployed via Docker for a streamlined setup process.

llamator

2026-08-03 Python ★ 215
LLAMATOR is a Python-based framework designed for Red Teaming, enabling security professionals to conduct penetration testing on chatbots and Generative AI systems. Its notable features include support for custom attacks, compatibility with multiple chat client configurations, and comprehensive reporting capabilities in various formats, making it suitable for assessing vulnerabilities such as prompt injection and misinformation.

LLM-Security-Assessment-Framework

2026-08-03 Python ★ 24
FORGEDAN is a report-first LLM security assessment framework designed to generate reproducible security assessment report packages for large language models (LLMs). Its primary use case centers on providing high-quality, evidence-rich reports that include YAML suites, deterministic scanners, and audit-ready bundles, ensuring traceability and verifiability of input and output artifacts. Notable features include the integration of an evolutionary jailbreaking algorithm, a web dashboard, and a comprehensive QA receipt system, all contributing to enhanced report integrity and usability.

MockSSH

2026-08-03 Python ★ 130
MockSSH is a tool designed to emulate SSH server environments, enabling testing and automation of tasks without access to actual servers. It features a modern, type-safe architecture that supports threading for end-to-end unit tests, as well as integration with Python and HyLang for scripting commands. The tool includes comprehensive development utilities for linting, static type checking, and testing, alongside a DSL for simplified configuration and usage.

netcrawler

2026-08-03 Python ★ 24
NetCrawler is an AI-driven reconnaissance and vulnerability scanning tool that utilizes a local Ollama LLM to automate the scanning process. It intelligently selects and executes various reconnaissance modules such as subdomain enumeration, web fingerprinting, and vulnerability scanning, while generating structured reports in both Markdown and JSON formats. Notable features include a terminal-based user interface, iteration through an observation-think-act cycle, and the capability to integrate additional modules seamlessly.

nox-framework

2026-08-03 Python ★ 325
NOX Framework is a cyber threat intelligence engine designed for red teaming, digital forensics, and corporate exposure analysis, capable of executing massively parallel scans across 124 intelligence feeds without bottlenecks. Its notable features include an integrated operational security layer with automatic proxy rotation, a dynamic risk scoring system, and an autoscan pipeline that facilitates comprehensive scanning and data gathering through recursive scans and asset discovery. This plugin-driven platform emphasizes operational efficiency and security, catering to advanced cybersecurity operational needs.

PDF-Prompt-Injection-Toolkit

2026-08-03 Python ★ 61
The PDF Prompt Injection Toolkit is a cybersecurity tool designed for red and blue teams to test and detect prompt injection attacks that may be concealed within PDF documents. It features two primary roles: a `pdf_injector.py` for creating hidden payloads and a `pdf_injection_detector.py` for scanning PDFs to identify such vulnerabilities. Notable detection techniques include scanning for invisible text, analyzing document metadata, and detecting off-page text, ensuring comprehensive coverage against potential injection tactics.

Phantom

2026-08-03 Python ★ 16
Phantom is an autonomous AI-driven penetration testing platform designed to perform detailed reconnaissance and exploit vulnerabilities without human intervention. Integrating over 30 professional security tools within a secure Docker environment, it leverages a reasoning loop to adaptively select and execute multi-step attack vectors, producing verified findings complete with proof-of-concept scripts. Unlike traditional scanners that rely on static CVE signatures, Phantom delivers a comprehensive and accurate vulnerability assessment with real-time adaptability and detailed reporting aligned with the MITRE ATT&CK framework.

pwncloudos

2026-08-03 Python ★ 53
PWNCLOUDOS is a multi-cloud security Linux distribution designed for both offensive and defensive security operations across major cloud platforms such as AWS, Azure, and GCP. It offers a lightweight XFCE4 environment pre-loaded with a range of cloud exploitation tools, auditing frameworks, and security testing utilities, making it suitable for red, blue, and purple teams. Notable features include customizable shell environments, a variety of cloud-specific tools, and community-driven enhancements, with options for both AMD64 and ARM64 architectures.

ramibot

2026-08-03 Python ★ 25
RamiBot is an AI-powered security operations platform designed for both Red and Blue team engagements, integrating various pentesting tools within a structured operational pipeline. Its notable features include multi-provider LLM support, human-in-the-loop tool execution approval, evidence-locked reporting to mitigate hallucinations, and Docker integration for seamless command execution in containerized environments. Additionally, RamiBot automates setup processes and provides one-click PDF reporting for streamlined security assessments.

reconmind

2026-08-03 Python ★ 10
ReconMind is an AI-powered bug bounty agent designed to emulate the decision-making process of a senior penetration tester, automating the entire vulnerability assessment workflow from reconnaissance through to reporting. Key features include an LLM-driven approach that intelligently selects targets and scans, filters false positives, and generates platform-ready reports for services like HackerOne and Bugcrowd. Its streamlined pipeline ensures comprehensive coverage, while being free to use, and provides flexibility with local and cloud-based LLM integrations.

red-run

2026-08-03 Python ★ 264
red-run is a security assessment toolkit designed for orchestrating and conducting comprehensive security evaluations using Claude Code and MCP servers. It guides users through essential assessment phases—recon, initial access, lateral movement, privilege escalation, and post-access—while maintaining engagement state in SQLite and allowing for semantic search and execution delegation across persistent agent teams. Notable features include multiple orchestrator variants tailored for specific use cases, real-time monitoring and interaction via tmux, and a robust skill management system that facilitates complex assessments.

roothunter

2026-08-03 Python ★ 13
RootHunter is an offensive auditing suite for Linux, designed for pentesters and administrators to detect and prioritize common privilege escalation vectors before malicious actors can exploit them. It includes a Bash script for evidence collection, a local database of binary escalation techniques, and a Python analysis tool that generates actionable insights based on the collected evidence. Key features include a structured JSON report, prioritization of attack paths, and integration with CVE databases for context-specific exploits.

ShadowMap

2026-08-03 Python ★ 10
ShadowMap is a professional IP geolocation intelligence tool designed for tracking IP addresses with multi-source accuracy and Google Maps integration. Its notable features include querying multiple APIs for enhanced accuracy, precise coordinate outputs, proxy and VPN detection, and compatibility with mobile platforms like Termux. Intended for educational and authorized testing purposes, it provides users a clean, professional interface and the ability to save detailed geolocation reports.

ShareSift

2026-08-03 Python ★ 12
ShareSift is a machine learning-enhanced tool designed to identify and rank files on SMB shares that are likely to contain credentials or secrets. Utilizing a two-stage classifier pipeline, it combines a LightGBM path classifier and a Qwen3 1.7B LoRA content classifier to improve recall of sensitive information significantly over its predecessor, Snaffler. Notable features include adjustable classification policies to balance false positives and recall rates, allowing users to optimize for specific operational needs.

SunnyDayBPF

2026-08-03 Python ★ 24
SunnyDayBPF is an eBPF-based research tool designed for post-syscall user-buffer telemetry deception, investigating the integrity of data observed by user-space security agents after read-like syscalls. It alters the telemetry data before it is processed by security pipelines, allowing for a detailed examination of discrepancies between actual events and the observed telemetry. Notable features include support for multiple syscalls (e.g., read, pread64, recvfrom), a modular BPF architecture utilizing tail calls to circumvent verifier constraints, and customizable scanning rules for enhanced security analysis.

tempor

2026-08-03 Python ★ 12
tempor is a cloud infrastructure provisioning tool that allows users to effortlessly create ephemeral servers across multiple cloud providers using Terraform, making it ideal for penetration testers and bug hunters. Notable features include support for custom Ansible playbooks and Packer configurations, enabling tailored setups, along with robust authentication mechanisms via environment variables and API tokens.

the-red-council

2026-08-03 Python ★ 17
The Red Council is an automated adversarial testing platform designed for Large Language Models (LLMs), offering a comprehensive security workflow that identifies vulnerabilities, applies automated defenses, and verifies their effectiveness in real-time. Key features include a multi-agent adversarial flow, a real-time battle user interface, and the ability to integrate with various LLM APIs, supporting a versatile approach to security assessment and fortification. Additionally, it incorporates capabilities for AI Agent Security Testing based on the OWASP Agentic Top 10 framework, enhancing its utility in securing AI-driven applications.

Threatswarm

2026-08-03 Python ★ 76
ThreatSwarm is a comprehensive penetration testing tool that utilizes 27 AI agents to execute the entire kill chain—from reconnaissance to exploitation, post-exploitation, digital forensics, and reporting—streamlined into a single command interface. It enforces strict scope limitations via `scope_check.py`, ensuring compliance with authorized testing parameters, while leveraging a library of 754 MITRE-mapped skills to guide its operations. Notably, it operates as a Claude Code plugin, eliminating the need for additional infrastructure like Docker or cloud accounts, and outputs detailed vulnerability reports with CVSS scoring.

wmiexec2

2026-08-03 Python ★ 68
wmiexec2 is an enhanced and obfuscated version of the original `wmiexec`, designed for red team operations by facilitating stealthy remote command execution on Windows systems. Key features include support for various shell types, automated red team modules, local and remote file transfers, and capabilities for bypassing antivirus detection. The tool also includes additional functionalities like system information gathering, active token enumeration, and VM detection, making it a comprehensive suite for Windows penetration testing and cyber operations.

AgentPoison

2026-08-03 Python ★ 240
AgentPoison provides a framework for red-teaming large language model (LLM) agents through the technique of memory or knowledge base backdoor poisoning. Its primary use case is to facilitate the identification of vulnerabilities in LLMs by allowing users to optimize triggers targeting specific agent behaviors. Notable features include support for various retriever-augmented generation (RAG) embedders, configuration customization via YAML files, and trigger optimization capabilities for multiple agent types.

AI-Pentest-Playbook

2026-08-03 Python ★ 33
The AI Pentest Playbook provides a comprehensive field manual for conducting penetration testing on AI chatbots and applications powered by large language models (LLMs). It offers curated attack payloads categorized by various threat classes, detailed guidance on identifying vulnerabilities, and remediation strategies, thereby equipping both offensive and defensive cybersecurity teams with essential insights for securing AI systems. The resource also aligns with the OWASP Top 10 for LLM Applications, ensuring coverage of critical attack vectors and emerging risks in the domain.

AI-PT-Lab

2026-08-03 Python ★ 11
Vulnerable AI Lab is a modular AI security training environment designed to simulate and expose vulnerabilities in modern AI applications, specifically targeting the OWASP LLM Top 10 2025 threats. It facilitates practical learning by allowing users to engage in scenarios like RAG injection and tool invocation vulnerabilities, scoring runs automatically to provide insights into exploited vulnerabilities and the evidence collected. Notable features include customizable vulnerability modules, an accessible user interface hosted via Docker, and compatibility with capture-the-flag events and red team training exercises.

Beatrix-suite

2026-08-03 Python ★ 16
Beatrix Suite is a command-line bug bounty hunting framework designed to streamline the entire pentesting workflow by integrating 32 scanner modules and 22 external tools. It features a 7-phase Kill Chain methodology, automated login and session management, and an AI-assisted pentester (GHOST) for advanced analysis, making it suitable for scanning domains, URLs, and IP addresses efficiently in headless environments. This tool aims to eliminate the fragmentation of traditional bug bounty tools by providing a single-command interface that orchestrates multiple tools throughout the assessment process.

c2detect

2026-08-03 Python ★ 33
c2detect is a tool designed to fingerprint command-and-control (C2) servers behind network beacons by analyzing telemetry data, specifically naming frameworks like Cobalt Strike and Sliver with a confidence score and matched indicators. Notable features include offline operation, the ability to generate Sigma and Suricata detection rules directly from detected signatures, and the fusion of indicators such as JA4, JARM, certificate, URI, and port for enhanced C2 identification. This tool serves as a passive defense mechanism for blue teams to detect known C2 infrastructure efficiently.

ChromiumSpecter

2026-08-03 Python ★ 34
ChromiumSpecter is a tactical auditing suite for security assessments of Chromium-based browsers (such as Chrome, Edge, and Brave) on Windows, focusing on credential extraction and data exfiltration. It features a highly discreet and resilient decryption engine that utilizes SYSTEM impersonation with legitimate Windows APIs, making it less detectable compared to traditional code injection methods. Key functionalities include a professional dashboard for real-time statistics, support for multiple encryption schemes, and seamless integration with the latest browser versions.

claude-security-skills

2026-08-03 Python ★ 12
Claude Security Skills is a collection of tools designed to enhance the security analysis of software projects, specifically through the Claude Code platform. It enables users to perform various tasks such as scanning for leaked secrets, conducting static code analysis on Python, testing for prompt injection in language models, and auditing HTTP headers and security configurations. With no external dependencies and the ability to run analyses offline, the tool provides a secure and efficient approach to identifying vulnerabilities in various project components.

CloudSec

2026-08-03 Python ★ 29
The Cloud Security Toolkit is a comprehensive resource designed for offensive security practitioners focused on cloud environments, facilitating the exploitation of vulnerabilities and simulating advanced attacks specifically within platforms like Azure, AWS, and Microsoft 365. Notable features include a collection of weaponized exploits, deep-dive vulnerability research, threat intelligence insights, and evasion techniques targeted at cloud defense systems, all aimed at enhancing red team operations and improving cloud security assessments. This toolkit provides practical, battle-tested resources essential for sophisticated penetration testing and incident response in cloud ecosystems.

InfraGuard

2026-08-03 Python ★ 299
InfraGuard is a red team infrastructure tracker and command-and-control (C2) redirector designed to enhance operational security by validating incoming traffic against customizable C2 profiles. Key features include multi-domain proxying, scoring-based filtering with JA3 TLS fingerprinting, and detection mechanisms for headless browsers and path enumeration attempts, enabling precise filtering of malicious requests while allowing legitimate beacon traffic. This tool serves as a modern alternative to existing solutions, providing a comprehensive suite for defending against reconnaissance and automated probing activities.

MailSpoof

2026-08-03 Python ★ 10
MailSpoof is an open-source email spoofing and phishing simulation tool designed for authorized penetration testing and security awareness training. It features a built-in multi-threaded SMTP server, 62 pre-built phishing templates, custom template creation, and comprehensive audit logging alongside report generation capabilities. This tool is compatible across multiple platforms, including Linux and macOS, and supports bulk targeting, external SMTP relay configurations, and advanced header functionalities for enhanced testing scenarios.

osint-d2

2026-08-03 Python ★ 267
OSINT-D2 is an advanced open-source intelligence platform designed to transform usernames and emails into comprehensive identity dossiers, leveraging agentic AI for autonomous investigations. The tool features multi-source correlation across over 30 platforms, cognitive profiling through a six-dimension analysis, and seamless integration with ScrapingAnt's proxy infrastructure for efficient data gathering. Additionally, it supports premium PDF reporting, incorporates breach exposure checks via HaveIBeenPwned, and offers cross-platform executable binaries.

pentest-ai

2026-08-03 Python ★ 1637
Pentest-ai is an AI-powered penetration testing tool designed to enhance the verification of security findings by re-running exploits to confirm their validity, ensuring that each piece of evidence is backed by reproducible results. It streamlines the verification process by generating multi-step attack paths and providing a reporting mechanism that only includes findings validated by its oracle system, achieving 100% precision with zero false positives across multiple vulnerability classes. The tool operates offline without cloud reliance, making it ideal for authorized testing in a controlled environment.

ReconNinja

2026-08-03 Python ★ 42
ReconNinja is an autonomous multi-phase security reconnaissance framework that conducts comprehensive security assessments through a single command. It supports a myriad of functionalities including passive OSINT, port scanning, web discovery, vulnerability scanning, and Active Directory enumeration, producing reports in multiple formats like HTML, JSON, and Markdown. Notable features include an adaptive agent mode for dynamic decision-making, a user-friendly GUI, and enhanced reliability for complex scans with a uniform `PhaseContext` adapter layer.

slack-watchman

2026-08-03 Python ★ 404
Slack Watchman is a cybersecurity tool that utilizes the Slack API to monitor Slack workspaces for exposed sensitive data and enumeration of user and conversation details. Its primary use case is aiding red, blue, and purple teams in identifying potential security risks, including various types of keys, personal data, and files through customizable, time-based searches. Notable features include an unauthenticated probe mode for gathering workspace information, automated updates of signature definitions for detecting secrets, and flexible logging options for output formatting.

tengu

2026-08-03 Python ★ 58
Tengu is a multi-command platform (MCP) server that functions as an AI-assisted penetration testing copilot, integrating with various security tools such as Nmap and Metasploit. It automates reconnaissance and scanning processes while allowing users to maintain control over exploit actions, featuring advanced safety controls like allowlisting and audit logging. Notable features include its orchestration of 80 tools, automated report generation, and pre-built workflows for diverse pentesting scenarios.

WordListsForHacking

2026-08-03 Python ★ 14
WordListsForHacking (WFH) is a comprehensive wordlist generation toolkit designed for penetration testing and red team operations, featuring 44 subcommands encapsulated within a single command-line interface. It supports tasks such as charset and mask generation, web scraping, personal and corporate profiling, and advanced techniques including machine learning-based ranking and acrostic generation. The tool is geared towards enhancing the efficiency and effectiveness of security assessments through diverse and robust functionalities.

dorothy

2026-08-03 Python ★ 196
Dorothy is a Python tool designed for security teams to assess their monitoring and detection capabilities within Okta environments. It offers modules that simulate potential attacker actions and facilitates auditing aligned with MITRE ATT&CK® tactics, including persistence, defense evasion, and discovery. Notably, it allows users to modify Okta configurations, making it essential for testing purposes in non-production environments.

fluffy-barnacle

2026-08-03 Python ★ 127
Fluffy-Barnacle is a toolkit designed for creating disposable, ephemeral network infrastructure using GitHub Codespaces, enabling users to rapidly deploy services such as SOCKS5 proxies, HTTPS file hosting, and WireGuard tunnels. Notable features include an auto-reconnecting SOCKS5 proxy with circuit breaker support, instant public HTTPS file hosting capabilities, and a suite of CLI tools that integrate with common security testing utilities while managing fresh egress IPs upon each deployment. This tool serves primarily for educational, research, and authorized security testing purposes, adhering strictly to GitHub's usage policies.

gato-x

2026-08-03 Python ★ 584
Gato-X is an advanced scanning and attack toolkit specifically designed to identify vulnerabilities in GitHub Actions pipelines, including Pwn Requests, Actions Injection, and self-hosted runner takeovers. Notable features include fast scanning of thousands of repositories with a single API token, robust analysis of cross-repository workflows, and the capability for post-compromise secrets enumeration. Tailored for Red Teamers and security professionals, Gato-X emphasizes thorough vulnerability detection while adhering to ethical research practices.

infosec-events

2026-08-03 Python ★ 185
The Cyber, InfoSec Events repository serves as a catalog of past and upcoming cybersecurity and information security-related events. Its primary use case is to provide a comprehensive list of events in the field, facilitating community engagement through contributions and updates. Notable features include an interactive calendar subscription option and a welcoming approach for community involvement via issues and pull requests.

0day-Rubbish

2026-08-03 Python ★ 190
0day Rubbish is an automated vulnerability disclosure tool focused on the rapid identification and public release of high-severity 0-day vulnerabilities using AI-driven methods. It emphasizes efficiency by verifying exploits and providing thorough assessments while maintaining a non-profit approach to enhance timely vendor responses. Key features include direct disclosure of verified vulnerabilities with working proof-of-concept code, a commitment to real-world impact, and continuous monitoring through advanced AI models.

agile_v_skills

2026-08-03 Python ★ 51
The Agile V™ Agent Skills Library provides a framework for enhancing the reliability of AI agents by implementing formal traceability and independent verification to combat common pitfalls such as hallucinations and silent assumptions in code generation. It allows for typed lineage linking requirements to implementation artifacts, promoting compliance and ensuring that every piece of code can be traced back to its original requirements. Notable features include hardware awareness for optimized deployment and the separation of code generation from verification to ensure that all edge cases are adequately tested before production.

aptl

2026-08-03 Python ★ 23
APTL (Advanced Purple Team Lab) is a cybersecurity tool that facilitates autonomous red and blue team training by simulating an enterprise target stack, utilizing AI agents to drive offensive and defensive operations. It allows users to create a customizable lab environment with various services, integrating penetration testing tools and intentionally vulnerable configurations while capturing telemetry data for analysis. Key features include a simple command-line interface for lab setup, various attack and defense scenarios, and real-time performance monitoring, making it ideal for cyber-operations research and purple team training.

AutoRedTeam-Orchestrator

2026-08-03 Python ★ 259
AutoRedTeam-Orchestrator is a local-first, MCP-native automation platform designed for authorized testing and AI/MCP attack surface auditing. It features a modular security capability set accessible via an MCP Server, Python SDK, and Typer CLI, enabling static code audits, reconnaissance, and vulnerability detection primarily for research and training purposes. Notable capabilities include AI-assisted audits, configurable scanning profiles, and different export formats for audit reports, each tailored for secure and compliant usage scenarios.

Black-cat

2026-08-03 Python ★ 303
Black Cat is a penetration testing automation framework designed to mimic human-like engagement through a hypothesis-driven state machine model, allowing for iterative recon and validation processes. Unlike traditional tools that follow a linear pipeline, Black Cat enables feedback loops between different testing phases, making it adaptable and capable of handling failures creatively. Notable features include a single JSONL ledger for tracking hypotheses and evidence, explicit file routing for techniques, and a refined decision-making process that records the rationale behind each choice made during testing.

cain-agent

2026-08-03 Python ★ 476
Cain is an AI-powered penetration testing engine designed for authorized security assessments in real-world environments, effectively navigating complex business logic and adapting to activated WAF/risk control systems. Key features include a cloud penetration module that supports major cloud platforms, a deterministic state machine for orchestrated testing, and robust safety mechanisms ensuring compliance and risk management. Its capabilities extend to identifying business logic flaws, authentication issues, and cloud misconfigurations, providing detailed evidence and actionable remediation advice.

caldera

2026-08-03 Python ★ 7227
Caldera™ is a cyber security platform that facilitates automated adversary emulation, supports manual red-teams, and streamlines incident response through its integration with the MITRE ATT&CK™ framework. Its architecture comprises a core system featuring an asynchronous command-and-control (C2) server with a REST API and a web interface, complemented by a variety of plugins that enhance its functionalities with capabilities like reporting and TTP collections. This tool is particularly notable for its flexibility, allowing users to develop custom plugins to extend its capabilities.

CredWolf

2026-08-03 Python ★ 15
CredWolf is a credential validation tool designed for Active Directory Domain Services that tests various username and secret combinations against a domain controller to identify valid credentials. Notable features include support for multiple secret types (passwords, NT hashes, Kerberos keys), username enumeration without triggering account lockouts, and extensive configuration options for safe and efficient testing. It is tailored for use in authorized penetration testing and security audits, ensuring robust and secure credential verification processes.

crucible

2026-08-03 Python ★ 49
Crucible is a security testing tool designed specifically for AI agents, enabling comprehensive behavioral integrity testing and automated red-teaming against a wide range of attacks, including those aligned with OWASP guidelines. It offers rapid deployment via CI/CD integration, producing detailed compliance reports, and incorporates a unique Model Context Protocol security module. The tool encompasses over 90 tested attack vectors, ensuring agents are hardened against potential threats before production deployment.

cybersec-toolkit

2026-08-03 Python ★ 48
The Cybersec Toolkit is an advanced cybersecurity solution that incorporates AI integration through a Model Context Protocol (MCP) server, enabling interactive tool management during penetration testing and bug bounty hunting. It features a comprehensive repository of over 670 tools, categorized into 18 modules and 14 profiles, allowing for modular installation and multi-platform support, including Linux and Termux. Unique to this toolkit is its capability for the AI to autonomously drive tool execution based on problem context, providing a hybrid approach that combines operator control with AI assistance.

drowAI

2026-08-03 Python ★ 12
DrowAI is a pre-release AI agent platform designed for executing task-isolated security workflows via a web control plane, utilizing LangGraph-based orchestration and Docker/Kali environments. It features a FastAPI backend for task management and real-time communication, a React/TypeScript frontend for user interaction, and a dynamic tool registry that adapts as tools meet integration standards for AI assistance. The platform aims to explore the potential of AI-assisted software development in cybersecurity applications while still undergoing active refinement.

gpt

2026-08-03 Python ★ 17
The 4NDR0666OS tool is designed for advanced red-teaming and adversarial logic research, focusing on prompt injection, symbolic logic decoupling, and state-machine resilience. It features a persistent virtual kernel that survives resets and restrictions, allowing for continuous interaction with large language models (LLMs) across a wide token budget while facilitating sophisticated testing and override mechanisms. Notable capabilities include cross-model validation and a rich repository of exploit modules and functions, aimed at enhancing the robustness of instruction sets against safety protocols.

HDN-ToolKit

2026-08-03 Python ★ 19
HDN Phish Toolkit is a comprehensive social media phishing simulation tool designed for authorized security testing and educational purposes. It creates realistic login pages for over nine popular platforms, enabling organizations to assess and understand phishing vulnerabilities while offering features like real-time credential capture, IP tracking, and a web dashboard for monitoring captured data. The tool is cross-platform compatible, supporting Windows, Linux, and macOS environments.

kcwarden

2026-08-03 Python ★ 131
kcwarden is a Python tool designed to audit Keycloak configurations, identifying common misconfigurations and security vulnerabilities. Its primary use case is to enhance the security posture of Keycloak implementations by enabling users to download their configuration and perform detailed audits. Notable features include ease of installation via pip, straightforward usage commands for downloading configurations, and auditing, complemented by comprehensive documentation.

LLMVault

2026-08-03 Python ★ 307
LLMVault is a comprehensive, hands-on training platform designed to educate users on the OWASP LLM Top 10 vulnerabilities applicable to large language models (LLMs). It features 25 deliberately vulnerable labs across three tiers—core, advanced, and expert—each focusing on different attack and defense scenarios, allowing users to learn practical exploits and their mitigations in a controlled environment. Notably, LLMVault emphasizes a self-contained setup that requires no online exposure, ensuring a secure learning experience.

MinerInTheMiddle

2026-08-03 Python ★ 82
Miner In The Middle is a Python-based tool that facilitates the injection of JavaScript cryptocurrency miners into HTTP responses of targets on a local network via ARP spoofing. It features configurable options for injection scripts and IP constraints to ensure targeted use, along with an easy setup process that automates iptables configuration and packet forwarding. Users can also implement custom JavaScript for injection and execute various attack modes, including standard miner attacks and popunder techniques.

prompt-injection-auditor

2026-08-03 Python ★ 15
The prompt-injection-auditor is an agent skill designed to enhance the security of AI prompts by auditing them for potential prompt-injection vulnerabilities. Its primary use case is to identify weaknesses using a static scanning approach, complemented by an attack catalog and a defense checklist, particularly in light of real-world incidents. Notably, the tool improves differentiation between hardened and vulnerable prompts while maintaining a zero false-positive rate, enabling developers to proactively address security flaws in their AI systems.

recon-skills

2026-08-03 Python ★ 1214
Recon Skills is a comprehensive toolkit designed for authorized security testing, focusing on external reconnaissance across web applications, APIs, and various vulnerability assessments. Notable features include a structured catalog of skills for discovery, validation, and reporting, covering areas such as authentication testing, attack-path analysis, and evidence review, while emphasizing best practices for operational security and quality assurance. The tool aims to facilitate both manual and automated workflows for security professionals, ensuring a thorough approach to web security assessments.

red-team-blue-team-agent-fabric

2026-08-03 Python ★ 28
The Agent Security Harness is a testing tool designed for evaluating the security and integrity of payment agent protocols, with a specific focus on identifying manipulative behaviors even when agents are properly authenticated and authorized. It features 603 executable security tests across 44 modules that cover a wide range of protocols, including MCP, A2A, and Visa/Mastercard specific tests, along with mechanisms for detailed reporting on test results. The tool supports a taxonomy-driven evidence approach to classify and validate security claims, enhancing confidence in security assessments carried out on agentic payment systems.

ShadowLab

2026-08-03 Python ★ 19
ShadowLab is a modular Command & Control (C2) framework designed for educational purposes in cybersecurity research, focusing on the engineering principles of modern C2 infrastructures. Key features include AES-128 encrypted communications, payload generation, and a dynamic post-exploitation module system, all intended for use in controlled environments to enhance learning and understanding of cybersecurity concepts rather than for offensive tactics.

SteppingStones

2026-08-03 Python ★ 243
Stepping Stones is a Python Django application designed to facilitate Red Team operations by providing a web-based interface for logging activities, maintaining situational awareness, and generating report snippets throughout engagements. Notable features include real-time usage during missions, Cobalt Strike integration for enhanced functionality, and streamlined installation and updating processes to optimize testing and reporting workflows.

storm-framework

2026-08-03 Python ★ 12
Storm-Framework is an offensive security tool suite designed for reconnaissance, vulnerability assessment, and exploitation, catering to cybersecurity professionals, penetration testers, and bug bounty hunters. Built with a user experience similar to Metasploit, it streamlines security testing workflows and supports multiple platforms including Kali Linux, Ubuntu, and Windows. Notable features include a comprehensive framework flow, detailed documentation, and a structure visualizer that aids in navigating the tool's components.

ULTIMATE-CYBERSECURITY-MASTER-GUIDE

2026-08-03 Python ★ 137
The ULTIMATE CYBERSECURITY MASTER GUIDE serves as a comprehensive knowledge base for cybersecurity practitioners, encompassing insights from over 70 expert books and 90 internal documents. It features detailed guides and playbooks for various roles, including Red Team, Blue Team, and Purple Team operations, along with a flat catalog system for easy access to all resources. Notable elements include an extensive collection of OSINT tools and custom scripts, making it an essential reference for both novice and experienced cybersecurity professionals.

violin

2026-08-03 Python ★ 84
Violin is a Hermes-native pentesting profile designed for supervised penetration tests, guiding users through reconnaissance, exploit validation, and reporting while ensuring robust safety mechanisms. Notable features include 31 structured playbooks for various testing methodologies, a multi-layered safety system that validates every target interaction, and evidence-driven reporting to enhance reproducibility and documentation. It seamlessly integrates with existing Hermes configurations without introducing additional credential management, streamlining the pentesting workflow.

wb-red-team

2026-08-03 Python ★ 24
Red-Team AI is a white-box red teaming tool designed to identify security vulnerabilities in agentic AI applications by analyzing the source code for specific bugs related to the application's stack. Its notable features include a comprehensive dashboard for scan management, customized attack generation based on the application's architecture, and compliance tracking against industry standards like OWASP LLM Top 10. This tool is particularly useful for developers working with AI agents in sensitive environments such as finance or healthcare, where unique security risks can arise.

ACEshark

2026-08-03 Python ★ 150
ACEshark is a utility for the rapid extraction and analysis of Windows service configurations and Access Control Entries, streamlining the identification of potential privilege escalation vectors without reliance on non-native binaries. It operates by starting an HTTP/HTTPS server to receive and process data from a custom extractor script run on the target machine, generating detailed logs for each service configuration analyzed. Notable features include the ability to audit service permissions across users and groups, as well as options for TLS encryption during data transfer.

AcquiFinder

2026-08-03 Python ★ 16
AcquiFinder is a Python script designed to scrape Google search results for acquisition titles sourced from Crunchbase using Apify's Google Search Scraper. Its primary use case is to automate the retrieval of relevant acquisition data for specified companies, facilitating market research and analysis. Notable features include easy installation through a virtual environment and minimal setup requirements, such as an Apify account with API access.

AdminProber

2026-08-03 Python ★ 25
AdminProber is a Python tool designed to scan websites for potential admin panels by testing a specified list of common paths. It features multi-threaded scanning for enhanced performance, customizable path lists, and the ability to save scan results, including HTTP status codes, to an output file. Additionally, it includes checks for internet connectivity and updates to simplify maintenance.

AzSubEnum

2026-08-03 Python ★ 80
AzSubEnum is a Python-based subdomain enumeration tool specifically designed for identifying subdomains linked to Azure services. It employs DNS resolution techniques and permutation methods to systematically explore Azure's domain structure, facilitating comprehensive security assessments for professionals by uncovering subdomains connected to various Azure resources like App Services, Databases, and Key Vaults. Notable features include multi-threaded execution for enhanced performance and support for user-defined permutation wordlists to tailor enumeration efforts.

BatSploit

2026-08-03 Python ★ 21
BatSploit is an open-source penetration testing tool designed to generate Full Undetectable (FUD) payloads and includes a listener handler. Its primary use case is for security professionals conducting tests to assess vulnerabilities in systems. Notable features include ease of installation through a simple Python setup and the capability to create stealthy payloads for effective exploitation.

beescan

2026-08-03 Python ★ 30
BeeScan is a modular IT infrastructure security auditing platform that facilitates comprehensive penetration testing and infrastructure assessments through the integration of external tools as plugins. Its notable features include automated result collection and multi-format report generation (TERMINAL, HTML, PDF), PostgreSQL database support for centralized result management, and Docker isolation for environment containerization, making it suitable for DevSecOps workflows and large-scale security audits.

BurpSuite-Xkeys

2026-08-03 Python ★ 314
Xkeys is a Burp Suite extension designed as a passive scanner to identify and extract sensitive strings such as keys, secrets, and tokens from web pages, listing them as informational issues. It requires Jython for setup and facilitates the automation of asset identification through passive scanning, enhancing the security assessment process by providing valuable insights on potential vulnerabilities. Notable features include various pattern matching for value extraction and seamless integration with Burp Suite’s interface.

CloudFlair

2026-08-03 Python ★ 2974
CloudFlair is a cybersecurity tool designed to identify the origin servers of websites that utilize CloudFlare or CloudFront while exposing them publicly. Its primary use case involves leveraging Censys's internet-wide scan data to locate IPv4 hosts that present SSL certificates linked to the specified domain, thereby highlighting potential misconfigurations. Notable features include API integration with Censys, a user-friendly command-line interface for domain scanning, and the capability to differentiate between CloudFlare and CloudFront services.

Content-Bruteforcing-Wordlist

2026-08-03 Python ★ 218
The Content Bruteforcing Wordlist is a comprehensive wordlist designed for directory content discovery when utilizing the Burp Suite extension Turbo Intruder. It features over 211 million entries to enhance the efficiency of brute-forcing web directories, making it a valuable tool for penetration testers and security researchers focused on web application security assessments. Notably, it includes easy-to-follow usage instructions and examples for seamless integration with Turbo Intruder.

cybersecurity-penetration-testing

2026-08-03 Python ★ 96
The "cybersecurity-penetration-testing" repository serves as a comprehensive collection of resources focused on penetration testing techniques, tools, and best practices in cybersecurity. It includes categorized links to software, libraries, frameworks, technical guidelines, and educational materials, aiming to assist security professionals in identifying and mitigating vulnerabilities in various environments. Notable features include extensive categories covering everything from anonymity tools to network vulnerability scanners, ensuring a broad spectrum of resources for ethical hacking endeavors.

Dishost

2026-08-03 Python ★ 11
DisHost is a command-line IP range scanner that performs configurable health checks, including ICMP, TCP, and HTTP/HTTPS tests. Its notable features include multiple ways to specify IP ranges, comprehensive health check configurations, multi-threaded performance for efficiency, and diverse output options such as JSON and CSV formats. This tool is designed for network administrators and cybersecurity professionals to assess the availability and responsiveness of hosts within specified IP ranges.

enumdb

2026-08-03 Python ★ 221
Enumdb is a brute force and post-exploitation tool designed for MySQL and MSSQL databases, enabling users to test credentials and search for sensitive data fields within database tables. Its notable features include automated credential discovery, multi-threaded enumeration for efficiency, the ability to execute SQL queries and spawn a simulated shell, as well as options for reporting extracted information in .csv or .xlsx formats.

Hun2race

2026-08-03 Python ★ 14
Hun2race is an automated report generation tool designed for bug hunters and penetration testers, leveraging AI technologies such as Google Bard and ChatGPT to facilitate quick report creation. It excels in generating polished PDF reports through LaTeX templates, streamlining the documentation process for security assessments. The tool remains in beta, emphasizing the need for user discretion while harnessing its capabilities.

jwtcat

2026-08-03 Python ★ 334
`jwtcat` is a Python-based tool designed for detecting and exploiting vulnerabilities in JSON Web Tokens (JWTs), particularly the signature bypass flaw associated with the `alg=none` algorithm and guessing attacks against HS256 private keys. It supports brute-force and wordlist attacks, allowing users to efficiently test JWTs for security weaknesses. The tool is fully implemented in Python 3 and features options for detailed attack parameters and reporting.

kcbrute

2026-08-03 Python ★ 27
kcbrute is a brute-force tool designed for testing the security of Keycloak Admin/User Console login flows by attacking the OpenID Authorization Endpoint. It allows users to specify a target URL, along with lists of usernames and passwords, and features options for threading, verbosity, and behavioral controls such as early stopping upon a successful login attempt. This tool is intended strictly for ethical security testing, with a disclaimer regarding potential account locking due to brute-force detection mechanisms.

LFITester

2026-08-03 Python ★ 115
LFITester is a Python3 tool designed for testing server vulnerabilities to Local File Inclusion (LFI) attacks, primarily running on Linux/Unix systems but compatible with Windows as well. Key features include support for various attack vectors like Path Traversal, PHP Filters, and Remote Code Execution through methods such as log poisoning and session file exploitation. The tool provides a comprehensive command-line interface that allows users to automate LFI testing and customize payloads for effective penetration testing.

nullinux

2026-08-03 Python ★ 578
Nullinux is a penetration testing tool designed for Linux environments, specifically tailored for enumerating OS and domain information via SMB protocols. It features capabilities such as single and multi-host enumeration, user and group enumeration, and multi-threaded RID cycling, all while employing a null session approach if no credentials are provided. Additionally, Nullinux generates a formatted output file devoid of duplicates to facilitate further exploitation activities.

overlord

2026-08-03 Python ★ 637
Overlord is a Python-based command-line interface (CLI) tool designed for automating the setup of Red Teaming infrastructure. It allows users to easily deploy components such as command-and-control servers, email servers, and phishing servers on cloud providers like AWS and Digital Ocean, streamlining the process of creating a comprehensive penetration testing environment. Notable features include modular input handling and integration with Terraform, leveraging the Red-Baron project for infrastructure management.

penstaller

2026-08-03 Python ★ 19
Penstaller is a Python automation tool that streamlines the setup of essential bug bounty and penetration testing tools on a clean system with a single command. It automates the installation of critical programming languages and various pentesting utilities, facilitating a rapid and efficient environment preparation for both novice and experienced security testers. Notable features include a comprehensive list of tools covering different aspects of security testing, along with recommendations for additional manual installations of wordlists.

pymeta

2026-08-03 Python ★ 526
PyMeta is a Python3 tool designed for penetration testers and red teamers to conduct metadata analysis on files downloaded from web domains using tailored Google and Bing searches. This tool efficiently retrieves file types such as PDFs and documents, extracts their metadata via exiftool, and compiles the results into a CSV report, making it easier to uncover sensitive information like user accounts and software versions. Notable features include multi-threaded file downloads, customizable search engines, and the ability to process locally stored files.

pync

2026-08-03 Python ★ 100
pync is a Python library that mimics the functionality of Netcat, enabling arbitrary TCP and UDP connections and listening capabilities. Its primary use case includes creating TCP proxies, scripting HTTP clients and servers, and performing network daemon testing. Notable features include a comprehensive command-line interface, extensive networking options, and the ability to execute remote commands, making it suitable for various network-related tasks in Python development.

rogue

2026-08-03 Python ★ 304
The Rogue Toolkit is a cybersecurity tool designed for advanced users to simulate malicious activity and test network defenses. Its primary use case is to aid in penetration testing and security assessments, allowing for customized execution of various attack scenarios. Notable features include extensive documentation for argument configurations and example use cases, enabling tailored deployments in various environments.

Saldiscript

2026-08-03 Python ★ 11
Saldi Script is a versatile testing tool designed for security professionals to conduct various web application attacks, including DDoS, SQL injection, XSS, and data exfiltration. Key features include the ability to bypass Web Application Firewalls (WAF), execute reverse shell commands, and engage in phishing attacks, all aimed at evaluating the robustness of website security. The tool requires Python 3.10 and specific dependencies for operation, emphasizing its use as an educational resource for ethical hacking practices.

SBSCAN

2026-08-03 Python ★ 114
SBSCAN is a penetration testing tool specifically designed for the Spring framework, capable of conducting unauthorized scans and sensitive information detection on Spring Boot applications, as well as identifying and validating related vulnerabilities. Notable features include an extensive dictionary for sensitive paths, fingerprint detection capabilities to optimize resource usage, modular architecture for user-defined extensions, and comprehensive support for various types of vulnerability checks, including the latest CVEs. The tool also implements functionality for noise reduction in results, allowing users to focus on successful detections, and supports various scanning configurations such as URL or file-based targets, proxy settings, and multithreading.

Selene

2026-08-03 Python ★ 11
Selene is a Python-based script designed to facilitate the dumping of MySQL databases using specified connection parameters such as host, username, and database name. Its primary use case is to provide a straightforward interface for users to export MySQL database data with minimal command-line input. Notable features include a user-friendly command structure and the ability to create a system-wide command symlink for easy access.

sexettintool

2026-08-03 Python ★ 89
Sexettintool is a multifaceted cybersecurity tool designed for educational and ethical hacking purposes, enabling users to execute various automated exploits and security assessments. Key features include exploit scanning with Searchsploit, firewall detection via wafw00f, brute force automation with ncrack, and vulnerability analysis using nikto and lynis, among others. The tool is structured to enhance cybersecurity awareness while retaining a focus on responsible usage, with comprehensive support for Linux users and potential Docker deployment.

smtp-user-enum

2026-08-03 Python ★ 179
smtp-user-enum is a Python-based tool designed for SMTP user enumeration using commands like `VRFY`, `EXPN`, and `RCPT`. Its notable features include granular timeout management, automatic reconnection capabilities upon encountering errors, and flexible customization options for input formats, making it effective for identifying valid email addresses and their aliases. This tool is inspired by a Perl script and supports both Python 2 and Python 3.

SpearCopy

2026-08-03 Python ★ 22
SpearCopy is an educational tool designed for local website cloning and credential capture within controlled environments. It allows users to download full webpage content, host it on a local HTTP server, and log credentials entered into forms in JSON format, with customizable payload options for simulating phishing behaviors. This tool is intended strictly for educational purposes and internal testing, emphasizing the importance of ethical use.

suidPWN

2026-08-03 Python ★ 16
suidPWN is a tool designed to streamline the identification of SUID binaries that may facilitate local privilege escalation (LPE) on a target system. By allowing users to input the output of the `find` command, it quickly checks against gtfobins for vulnerabilities, efficiently surfacing potential escalation techniques and storing them locally for subsequent use. Notable features include the ability to scrape data from gtfobins automatically and the option to regularly update the binary reference files.

sycp

2026-08-03 Python ★ 29
SYCP (Solyd Certified Pentester) is a resource repository designed to complement students pursuing the SYCP certification in penetration testing. It details the activities and topics covered in the course, providing a comprehensive study guide for users to enhance their cybersecurity skills. Notable features include thorough documentation of course modules and practical insights into penetration testing techniques.

tomcter

2026-08-03 Python ★ 97
Tomcter is a Python-based tool designed to perform brute-force attacks on Apache Tomcat manager logins using default credentials. It supports single and multiple target attacks, operates efficiently with low resource consumption, and can be integrated with ProxyChains for enhanced capabilities. Notable features include its open-source nature and Docker support for containerized deployment.

wconsole_extractor

2026-08-03 Python ★ 66
WConsole Extractor is a Python library designed to exploit Flask applications that are running in debug mode, allowing users to extract sensitive information and gain interactive access to the server. Users can implement a custom file leak function to retrieve files from the target application, and the tool provides attributes to access critical server details, including tokens and user information, as well as functions for spawning shells and debuggers. Notable features include an easy installation process and the capability to interact with the application environment through an integrated shell.

wcreddump

2026-08-03 Python ★ 80
wcreddump is a lightweight Python script designed to automate the dumping of credentials from Windows systems, specifically targeting both SAM hashes and WINHELLO PINs. It requires specific libraries and a mounted Windows OS drive to function, and it outputs the dumped credentials to an 'outputs' folder, making it suitable for further cracking with tools like JTR or hashcat. Notable features include customizable parser options and automatic output handling, enhancing user convenience during the credential extraction process.

weakpass_generator

2026-08-03 Python ★ 44
weakpass_generator is a Python tool that generates weak passwords using the current date as a basis for randomness. It is primarily used for testing the robustness of password security by creating predictable and easily guessable passwords. Notable features include its simplicity and the ability to quickly generate multiple weak passwords for security assessments.

Werkzeug-Cracker

2026-08-03 Python ★ 20
Werkzeug Cracker is a tool designed to perform wordlist attacks on hashes generated by the `werkzeug.security` module, primarily to verify password hashes efficiently. It utilizes the `check_password_hash` function to determine password validity and supports multithreading to enhance cracking speed, allowing users to specify the number of threads for improved performance. The tool is compatible with both Linux and Windows platforms and requires Python 3.10 for operation.

WiFi-Creds-Grabber

2026-08-03 Python ★ 19
WiFi-Creds-Grabber is a Python tool designed to extract Wi-Fi credentials from a local Windows machine. Its primary use case is to retrieve stored Wi-Fi passwords, which are then saved in a text file named "passwords.txt" for easy access. The program is straightforward to use, requiring only Python to be installed and executing simple command-line instructions.

wshlient

2026-08-03 Python ★ 37
Wshlient is a versatile web shell client that allows users to execute commands by injecting them into a crafted HTTP request. Users create a text file containing the HTTP request and specify injection points, enabling command execution while providing options for customization, such as token replacements and debug output. This tool is primarily used for remote command execution in web environments, leveraging Python's requests library for simplicity and ease of installation.

xupa-rustam

2026-08-03 Python ★ 19
XUPA RUSTAM is a Python-based penetration testing tool designed for brute-force attacks against website admin login panels. It utilizes the `requests` module for making requests and incorporates Tor proxies to maintain the attacker's anonymity. Key features include support for user-defined lists of admin usernames and passwords, printing responses from the target URL, and the option to operate without a proxy.

zenbuster

2026-08-03 Python ★ 107
ZenBuster is a multi-threaded, multi-platform URL enumeration tool designed for use in Capture The Flag (CTF) challenges and by security professionals for target information gathering. It efficiently brute-forces subdomains and URI resources, offering features such as customizable wordlists, port specification, and logging capabilities, while supporting both IPv4 and IPv6 formats. Despite being user-friendly and slightly less speedy than more established tools like Gobuster, ZenBuster maintains satisfactory reliability for practical use.

cloudfish

2026-08-03 Python ★ 48
Cloudfish is a Python tool designed for subdomain enumeration using Cloudflare's DNS services, primarily aimed at penetration testers and bug bounty hunters. It automates the creation of a Cloudflare zone for a specified domain, scans for DNS records, saves the findings, and then deletes the zone, all while maintaining a passive approach since the scanning is executed on Cloudflare's end. Notable features include a silent operational mode with the option for verbose output, and the ability to be imported as a module for custom integration.

ftpknocker

2026-08-03 Python ★ 41
ftpknocker is a multi-threaded scanner designed to identify anonymous FTP servers across various target networks. Its primary use case includes scanning individual IP addresses or entire IP blocks, with customizable options for threading, port specification, and timeout settings. Notable features include support for input via piping from other programs and a flexible usage syntax similar to nmap, enhancing its functionality for security assessments.

3num-tool

2026-08-03 Python ★ 10
The 3num-tool is a versatile enumeration utility designed for authorized security testing, enabling users to gather information about various services such as SSH, FTP, HTTP, DNS, and SMB. Its notable features include support for credentialed enumeration, anonymous access testing for FTP, and integration with tools like Gobuster and Hydra for more comprehensive assessments. The tool emphasizes compliance with legal and ethical guidelines, catering to security professionals conducting vulnerability assessments.

Atilkurt

2026-08-03 Python ★ 13
AtilKurt is a read-only Active Directory security assessment tool designed for comprehensive directory hygiene analysis and security evaluations through LDAP. It efficiently collects and analyzes identity, group, computer, GPO, and ACL data to identify misconfigurations and potential vulnerabilities, and generates detailed HTML and JSON reports for offline review. Notable features include a severity-based risk scoring system, support for large environments with paging and parallel collection, and compliance reporting for various security frameworks.

AutorizePro

2026-08-03 Python ★ 610
AutorizePro is a Burp Suite plugin designed for detecting authorization vulnerabilities using an integrated AI analysis module. Its primary use case is to automate the testing of authorization issues, markedly reducing false positive rates from 95% to 5% by leveraging AI for improved accuracy in complex scenarios. Notable features include support for customizable API endpoints, local model deployment, and the ability to exclude non-API resources, alongside comprehensive reporting capabilities.

BugHunter-AI

2026-08-03 Python ★ 55
BugHunter-AI is an automated penetration testing agent designed with a cyberpunk-themed GUI that facilitates resource-aware task scheduling and AI-assisted analysis. Its primary use case is for authorized security testing in controlled environments, allowing users to enqueue tools while managing CPU and RAM limits for safe execution. Notable features include per-round report generation, automated CVE extraction, and integration with external AI services for enhanced command suggestions based on analysis results.

BurpSuite-Config

2026-08-03 Python ★ 11
BurpSuite-Config is a tool designed to enhance the Burp Suite's functionality by providing customizable "Match and Replace" and "TLS Pass Through" rules. Its primary use case is to streamline the interception and modification of web traffic for security assessments. Notable features include intuitive rule configuration for efficient traffic manipulation and the ability to handle encrypted traffic seamlessly.

CrossInjector

2026-08-03 Python ★ 42
CrossInjector is a Python-based tool designed for scanning multiple URLs to detect Cross-Site Scripting (XSS) vulnerabilities. It utilizes Selenium WebDriver and ChromeDriver to execute JavaScript payloads, determining if each URL is susceptible to XSS attacks. Notable features include customizable payloads and support for batch URL scanning, making it an efficient solution for security assessment.

CTFEnum

2026-08-03 Python ★ 44
CTFEnum is a Python-based network penetration testing tool specifically tailored for Capture The Flag (CTF) challenges. It conducts reconnaissance by scanning open TCP and UDP ports on a specified IP address, employing a modular design to probe various services and leveraging multiprocessing for efficiency. Notable features include automatic Nmap scanning, service-specific handlers for tasks like brute-forcing credentials, and detailed recommendations for exploiting identified vulnerabilities.

Cyber-X

2026-08-03 Python ★ 26
Cyber-X is a comprehensive cybersecurity toolkit designed for penetration testing and server defense against hacker attacks. It features various tools for vulnerability scanning, exploitation, server hardening, and anti-DDoS protection, catering to multiple user needs through its modular structure, including X-pentest for offensive operations and X-defence for defensive measures. The toolset emphasizes ease of installation and usage, making it suitable for educational and practical applications in cybersecurity.

deluder

2026-08-03 Python ★ 213
Deluder is a dynamic instrumentation tool designed for intercepting traffic from proxy unaware applications by leveraging Frida. It supports a variety of networking libraries, including WinSock, OpenSSL, and GnuTLS, and allows users to customize interception scripts using JavaScript. Primarily intended for integration with the PETEP penetration testing proxy, Deluder can also function autonomously for broader traffic interception tasks.

dnsspider

2026-08-03 Python ★ 16
dnsspider is an asynchronous, multithreaded tool designed for brute-forcing subdomains using either a specified wordlist or character permutations. Its primary use case is to discover subdomains of a target domain quickly, allowing for various attack types, including dictionary-based or brute-force methods. Notable features include customizable character sets, the ability to query multiple DNS record types, and options for logging results in different formats, making it versatile for reconnaissance purposes in cybersecurity assessments.

dotdotslash

2026-08-03 Python ★ 463
dotdotslash is a Python tool designed to automate the testing for Directory Traversal vulnerabilities in web applications. It allows users to specify a target URL and an attack string, with options for depth of traversal and cookie handling, making it suitable for security assessments against platforms like DVWA and bWAPP. Notable features include detailed command-line help and a focus on efficient vulnerability detection in a variety of web architectures.

gitxray

2026-08-03 Python ★ 184
Gitxray is a security analysis tool designed to analyze GitHub repositories for OSINT and forensic purposes by utilizing the public GitHub REST APIs to extract valuable information efficiently. Its primary use case includes identifying sensitive data in contributor profiles, spotting threat actors or fake repositories, and conducting forensic investigations by filtering results by specific dates. Notable features include customizable text output, integration with VirusTotal for enhanced threat detection, and the ability to run comprehensive scans on repositories to gather extensive data.

gpoParser

2026-08-03 Python ★ 373
gpoParser is a tool that facilitates the extraction and analysis of Group Policy Object (GPO) configurations in Active Directory environments. It supports both local and remote parsing modes, allowing users to gather GPO information via LDAP connections or from offline SYSVOL data, and includes features for displaying parsed results and enriching BloodHound data. Noteworthy capabilities include various operational modes such as local parsing, remote LDAP access, querying results, and the ability to handle security-related analysis, making it valuable for identifying potentially risky configurations.

habu

2026-08-03 Python ★ 984
Habu is a versatile hacking toolkit aimed at educating users on Python and network hacking techniques. It features practical functionalities such as ARP poisoning, DHCP exploitation, subdomain identification, and certificate cloning, alongside various data extraction and analysis tools. This comprehensive suite serves as both an instructional resource and a powerful utility for network testing and research.

HashRipper

2026-08-03 Python ★ 24
HashRipper is a multi-threaded ethical hacking tool designed for efficiently cracking a variety of hash algorithms, including popular types like NTLM, MD5, and SHA variants. Its notable features include support for over 17 hash algorithms, the ability to perform dictionary-based attacks using concurrent threading for increased speed, and a command-line interface that allows for cracking hashes directly or from files. The tool is compatible with Linux and Termux, making it versatile for use in different environments.

HunterA

2026-08-03 Python ★ 12
HunterA is an advanced mobile penetration testing framework designed for Android devices operating without root access, functioning within the Termux environment. It consolidates a diverse array of powerful tools for tasks such as port scanning, WHOIS/DNS reconnaissance, CVE vulnerability searches, and traffic sniffing, along with features like a fully asynchronous engine and integration with Termux:API for enhanced capabilities. Its modular design supports a range of functionalities, from OSINT to vulnerability exploitation, making it a comprehensive solution for mobile pentesting.

kautolog

2026-08-03 Python ★ 11
Kautolog is an automated terminal logging tool designed for Kali/Linux systems that captures comprehensive session details, including prompts, commands, and outputs across multiple terminal tabs. Notable features include integration with `tmux`, optional log syncing with rclone, customizable log directories, and a replay functionality that supports timing and instant dumping of logs. The tool provides extensive configuration options for log management, including log rotation and cleanup.

LazarusWakeUp

2026-08-03 Python ★ 27
LazarusWakeUp is a Python-based tool designed for reconnaissance and management of disabled Active Directory (AD) principals, enabling users to find, enable, disable, and analyze these accounts. Its notable features include the ability to operate over LDAPS for secure communications, verbosity options for output detail, and batch operation capabilities to streamline account management tasks. This tool is intended for educational purposes and emphasizes lawful usage.

NetRaptor

2026-08-03 Python ★ 15
NetRaptor is a GUI-based ARP poisoning tool designed for educational use and authorized network security testing, allowing users to scan networks, select targets, and perform Man-in-the-Middle (MITM) attacks. Key features include easy network scanning, ARP poisoning capabilities, packet analysis integration with Wireshark, and a user-friendly interface built with Tkinter. The tool is compatible with various Linux distributions and emphasizes ethical usage in controlled environments.

noxdroid

2026-08-03 Python ★ 29
NoxDroid is a comprehensive Android pentesting toolkit designed for Windows, facilitating both static and dynamic analysis of APKs through an interactive terminal menu. It supports automation for environment setup, including tools like Magisk and Frida, and features extensive analytical capabilities such as APK scanning, vulnerability assessments, traffic interception, and real-time reporting. Notable functionalities include integration with various scanning tools, a built-in dynamic analysis suite, and support for both the Nox Player emulator and physical Android devices via ADB.

One-Lin3r

2026-08-03 Python ★ 1784
One-Lin3r is a lightweight and modular framework designed for penetration testers, providing over 176 automated one-liners for tasks such as reverse shells, privilege escalation, and remote command execution across multiple operating systems. Notable features include advanced auto-completion for commands, typos correction, and the ability to execute multiple commands simultaneously, significantly enhancing efficiency during security assessments. The tool further simplifies command usage and management with clipboard integration and history tracking capabilities.

OpenShiftGrapher

2026-08-03 Python ★ 10
OpenShiftGrapher is a tool designed to enumerate OpenShift clusters by creating relational databases in Neo4j from cluster data. Its primary use case is to extract and visualize objects and their relationships, such as projects, service accounts, and security configurations, facilitating the identification of inconsistencies that may indicate vulnerabilities. Key features include customizable data collection options and support for complex Neo4j queries to analyze the security posture of OpenShift environments.

phantom_whisper

2026-08-03 Python ★ 22
Phantom Whisper is a Python 3 framework designed for ethical penetration testing, specifically targeting WhatsApp by delivering a zero-click WebP payload to identified devices. Its key features include ASLR leak polling to confirm initial compromise, automated deployment of a full implant for either iOS or Android, and thorough logging of all actions in JSON format for audit purposes. The tool is currently structured for single-host execution but is intended to support multi-threaded operations in future developments.

Preferred-Network-List-Sniffer

2026-08-03 Python ★ 175
Preferred Network List Sniffer (PNLS) is a Red Team Wi-Fi auditing tool designed to capture SSIDs from a device's preferred network list by intercepting Probe Requests in the surrounding environment. The tool features a user-friendly web interface for visualizing the intercepted data and is focused on exploring the privacy implications associated with Wi-Fi communication. Noteworthy functionalities include compatibility with Raspberry Pi, the ability to filter SSIDs, and the provision for asynchronous server communication using WebSockets.

rawsec_cli

2026-08-03 Python ★ 28
rawsec_cli is a command-line interface tool designed to facilitate the search and categorization of cybersecurity-related projects, tools, resources, and platforms. It allows users to filter searches by various criteria including language and availability, and provides features to list categories and open project sources in a browser when only a single result is found. Notable features include command-line search capabilities, project categorization, and installation through multiple methods including Docker.

RDDoS_Tool

2026-08-03 Python ★ 493
RedDDoS Tool is a Python-based utility designed for conducting DDoS attacks to test the resilience of networks and servers, provided that proper authorization is obtained for ethical use. It supports major operating systems including Linux, Windows, and macOS, and features straightforward installation and usage instructions, along with troubleshooting tips for potential library issues. Notably, the tool emphasizes responsible usage, clearly stating that it is intended for educational purposes only.

scans2any

2026-08-03 Python ★ 25
scans2any is a tool designed to convert infrastructure scan outputs into various formats like Markdown, YAML, HTML, and CSV, while also facilitating the creation of launch scripts and configuration files for different scanners. Its primary use case focuses on merging and processing multiple scan results to enhance security assessments and reporting. Notable features include support for numerous input formats, conflict resolution options, and the ability to run in a Docker container for simplified deployment.

SecretScraper

2026-08-03 Python ★ 68
SecretScraper is a configurable web scraping tool designed to extract sensitive information from target websites using customizable regular expressions. Its primary use case is for security assessments and vulnerability testing, featuring a robust web crawler that can handle multiple targets, support domain whitelisting and blacklisting, and enable seamless configurations through YAML files. Notable features include built-in rate limiting, an HTTP connection pool management, and flexibility in handling headers, proxies, and cookies.

security-tools-hacking

2026-08-03 Python ★ 11
The Largo-m/security-tools-hacking is a modular Windows penetration testing framework designed for security professionals, facilitating various stages of red team operations such as reconnaissance, exploitation, and post-exploitation. Key features include system information collection, geolocation lookup, browser history extraction, and optional key logging, all presented in a user-friendly manner that allows for easy integration and extension of custom modules.

Sniff-NG

2026-08-03 Python ★ 16
Sniff-NG is a Python-based tool designed for network security assessment, specifically offering capabilities for local network scanning, ARP spoofing, and man-in-the-middle (MITM) attacks through an interactive text user interface (TUI). Key features include automatic gateway detection, a user-friendly menu for executing attacks, and one-click dependency installation for Linux and macOS systems. Its design emphasizes ease of use for ethical hacking and penetration testing, while ensuring the restoration of ARP tables post-attack.

sqlmc

2026-08-03 Python ★ 381
SQLMC (SQL Injection Massive Checker) is a specialized tool designed to identify SQL injection vulnerabilities on a target domain by crawling provided URLs to a specified depth. It checks all GET parameters for potential vulnerabilities and offers detailed reports that include server information. Key features include customizable depth scanning, comprehensive vulnerability detection, and output file options for results storage, making it a robust solution for security assessments in web applications.

SquidNet

2026-08-03 Python ★ 44
SquidNet is a Python-based botnet framework designed for educational and ethical testing, enabling users to establish communication with a remote victim, issue commands, and execute various modules. Notable features include multi-session handling, a reverse shell, modular design for extensibility, dynamic module loading, and encryption for evading detection. The tool supports Docker deployment and operates entirely in memory, minimizing the risk of detection on target systems.

SSHBuster

2026-08-03 Python ★ 13
SSHBuster is a command-line utility designed for ethical hacking and penetration testing that facilitates SSH brute-force attacks through dictionary-based methods. It supports various combinations of username and password wordlists, operates in a multithreaded manner for enhanced speed, and displays real-time progress alongside immediate feedback for valid credentials found.

SYSTEMatic

2026-08-03 Python ★ 17
SYSTEMatic is a proof-of-concept tool designed for Windows that enables privilege escalation from a local Administrator account to the NT AUTHORITY\SYSTEM account via token impersonation, without UAC prompts or external dependencies. It leverages the Win32 API to duplicate a SYSTEM process's token and spawn new processes, making it valuable for system administration, security research, and penetration testing tasks. Notably, it operates solely within the constraints of existing Administrator privileges and does not exploit vulnerabilities or function as a UAC bypass.

TireFire

2026-08-03 Python ★ 170
TireFire is a semi-automatic enumeration platform designed for penetration testing, leveraging HackTricks resources for real-time updates and command execution. It enables users to initiate and control scans, effectively managing their footprint while generating organized lists of results, which is particularly beneficial for training environments and professional assessments. Notable features include support for multiple terminal interfaces like Tmux and Tilix, allowing for flexible and streamlined scan management.

TraxOsint

2026-08-03 Python ★ 258
TraxOsint is an open-source OSINT tool designed for gathering comprehensive information on IP addresses using various APIs and services for accurate data comparison. Its notable features include asynchronous scraping, capabilities for checking IP validity, open port status, and geographical information generation, along with integration with services like Pastebin and ProtonVPN. The tool also provides a command-line interface for user interaction and outputs detailed IP-related data, including geographical mapping.

webcap

2026-08-03 Python ★ 46
WebCap is a lightweight web screenshot tool that captures fully-rendered DOMs and detailed HTTP request/response logs without the need for browser automation frameworks. Its primary use case is to provide comprehensive insights into web pages, with unique features including JSON output, JavaScript extraction, and OCR text extraction. Users can operate it via a command line interface or a web server, allowing for automated scanning of multiple URLs and capturing of detailed web elements efficiently.

whomrx-dosX

2026-08-03 Python ★ 14
whomrx-dosX is a DDOS tool designed to flood a target server with packets until it becomes unresponsive. It requires a simple installation process and allows users to specify target IP addresses and packet configurations through command-line parameters. Notable features include the ability to set the port and number of packets sent, making it an educational resource for understanding network stress testing.

XMLRPC-Bruteforce

2026-08-03 Python ★ 16
XMLRPC-Bruteforce is a specialized penetration testing tool designed for exploiting the XML-RPC functionality in WordPress, allowing users to conduct hyper-optimized brute force attacks. By employing a unique batch method capable of testing 50-100 passwords per request and utilizing a binary search algorithm for credential discovery, it offers significant speed improvements over traditional brute force methods. Notable features include smart detection of web application firewalls, real-time statistics tracking, and a user-friendly interface with color-coded outputs and progress visualizations.

BeaconatorC2

2026-08-03 Python ★ 95
BeaconatorC2 is a modular communication and management application designed to facilitate the deployment and operation of beacons in restrictive programming environments, particularly for EDR evasion tactics. The tool supports various beacon implementations and allows users to quickly configure receivers, execute commands, and integrate with Metasploit for enhanced capabilities. Notable features include a user-friendly GUI, support for multiple communication protocols, and extensibility through custom beacon schemas.

Bug-Bounty-Arsenal-v.3

2026-08-03 Python ★ 12
BugBounty Arsenal is a comprehensive, full-stack security scanning platform designed for bug bounty hunters and security researchers. It features over 50 detectors for various vulnerabilities across multiple categories, continuous monitoring with scheduled scans, findings triage to manage results over time, and CI/CD integration to automate security checks in development pipelines. Unique capabilities include attack surface management, tailored AI-driven remediation advice, and extensive reporting options, all from a centralized dashboard.

BurpRecon

2026-08-03 Python ★ 13
BurpRecon is a cybersecurity tool designed for bug bounty hunters, facilitating the extraction and analysis of attack surface intelligence from Burp Suite XML exports. It automates identification of high-value vulnerability candidates such as IDORs, Host Header Injections, and Privilege Escalation vectors through a multi-phase analysis, while also performing technology fingerprinting and CVE lookups—all through a single interactive command-line interface. Notable features include detailed scoring for various vulnerabilities, ready-to-run proof-of-concept generation, and support for passive subdomain enumeration.

CertCrunchy

2026-08-03 Python ★ 29
CertCrunchy is a reconnaissance tool designed to leverage SSL certificate data from online sources to identify potential hostnames. It allows users to retrieve SSL data for specific domains or an IP range, with notable features including multi-threading for faster queries, output customization in CSV or JSON format, and integration with various APIs, such as Censys and VirusTotal.

communitytools

2026-08-03 Python ★ 497
Transilience AI Community Tools offers an AI-driven penetration testing suite comprised of 26 skills and 3 tool integrations, facilitating a comprehensive approach to security testing from reconnaissance to reporting. Notable features include full OWASP coverage, intelligent automation through Claude for workflow coordination, and the ability to generate professional, detailed reports leveraging common standards like CVSS and MITRE ATT&CK. The toolset is designed for both commercial and personal use as an open-source solution, enhancing the efficacy of security assessments.

CVE-2021-3129

2026-08-03 Python ★ 153
This tool exploits the Remote Code Execution vulnerability (CVE-2021-3129) found in specific Laravel versions, enabling users to execute commands on vulnerable instances with "APP_DEBUG" set to true. Key features include the ability to write and execute commands remotely, as well as several patch options to secure the application against the exploit. The tool is intended for educational and research purposes, emphasizing the importance of responsible usage.

Gamal

2026-08-03 Python ★ 14
Gamal is a lightweight Flask application designed for red teamers and pentesters, facilitating mass data exfiltration and various attacks such as SSRF, XXE, and XSS. It features file delivery capabilities, where users can upload and categorize payloads for exploitation, and includes a helper script that automates the download of common penetration testing tools. The tool supports features like customizable logging, SSL configuration, and can handle uploads while associating files with user and host identifiers for better tracking.

GhostBuilder

2026-08-03 Python ★ 27
GhostBuilder is a multifunctional payload generation tool that enables the creation of payloads for various platforms, including Android, Windows, Linux, macOS, and iOS, utilizing Metasploit. It features capabilities such as injecting payloads into existing APK files, automatic signing, zipaligning for APKs, and a simple menu-driven interface for ease of use. Designed for ethical hacking and penetration testing, it incorporates automatic handling of dependencies and bad characters, making it suitable for security research and authorized security work.

ldapviewer

2026-08-03 Python ★ 14
ldapviewer is a tool designed for converting LDAP and Active Directory JSON exports into a modern, interactive web-based interface that enhances the penetration testing process. It features comprehensive views of LDAP attributes, an advanced filtering system for significant data, a statistics dashboard focusing on security metrics, and the ability to parse DACLs directly from JSON dumps, streamlining the analysis of potential attack paths without requiring additional queries.

mobile-pentest-toolkit

2026-08-03 Python ★ 92
The Mobile Pentest Toolkit (MPT) is an integrated solution designed for automating and streamlining Android penetration testing workflows, enabling users to conduct comprehensive security assessments without needing to manually manage individual tools. Notable features include a full suite of required tools for security checks, local tool installation, support for ADB, the ability to disable SSL pinning and root detection, and project-based assessments that provide a cohesive interface for launching various security tools efficiently.

Neo

2026-08-03 Python ★ 36
The Neo C2 Framework is a modular post-exploitation framework designed for red team operations and security testing, facilitating collaborative agent management through a server-client architecture. It features real-time multiplayer capabilities, proxy support, a sophisticated task orchestrator, and robust security measures including encrypted communication and role-based access control. Neo also allows for extensive customization through its multi-operator extension module system, enabling operators to integrate their own modules seamlessly.

profilehound

2026-08-03 Python ★ 164
ProfileHound is a post-escalation tool designed for red-teaming operations that identifies domain user profiles on machines to optimize targeting for data extraction. It utilizes BloodHound's OpenGraph format to create a new edge, `HasUserProfile`, which indicates the existence of user profiles and provides metadata such as creation and modification dates, enabling operators to focus on high-value targets without requiring an active user session. The tool highlights profiles that may contain critical information, including cached credentials and other sensitive data, making it particularly useful in contemporary Active Directory environments.

RedteamAgent

2026-08-03 Python ★ 122
RedTeam Agent is an autonomous AI-powered simulation tool designed for red teaming and penetration testing, streamlining the process of security assessments across multi-platform environments. It features 8 specialized AI agents that facilitate a comprehensive 5-phase attack methodology, alongside containerized Kali tools and a web-based GUI for managing projects and operations with minimal user interaction. Notable functionalities include an intelligent case collection pipeline and robust reporting mechanisms, allowing users to efficiently conduct security evaluations and automate repetitive tasks.

sippts

2026-08-03 Python ★ 571
Sippts is a comprehensive suite of tools designed for auditing VoIP servers and devices utilizing the SIP protocol, allowing security professionals to assess vulnerabilities within their own systems or those they are authorized to test. Key features include a fast SIP scanner, options for enumerating SIP extensions, capabilities for password cracking and message sending, as well as exploit functionalities for specific vulnerabilities like SIP Digest Leak. The tool is written in Python and is freely available for modification and distribution.

SpectreWeb-AI

2026-08-03 Python ★ 13
SpectreWeb AI is an advanced MCP server facilitating AI-assisted manual web penetration testing, which enables operators to leverage AI tools for reconnaissance, payload generation, and response analysis while maintaining direct control over testing strategies. Its notable features include context-aware payload creation, built-in WAF bypass capabilities, and session persistence for findings across multiple targets. This tool is designed to overcome challenges presented by traditional blind scanning techniques, optimizing the testing process for bug bounty hunters and security professionals.

temodar-agent

2026-08-03 Python ★ 60
Temodar Agent is an AI-powered security analysis platform specifically designed for WordPress plugins and themes, offering security researchers an efficient mechanism for vulnerability assessment. Key features include risk-based target prioritization, Semgrep-powered static analysis, and AI-assisted investigation workflows that maintain context throughout the review process. Built as a local-first Docker application, it supports multi-provider LLM orchestration and facilitates structured code reviews to enhance vulnerability triage.

Zypheron-CLI

2026-08-03 Python ★ 176
Zypheron CLI is an AI-native command-line interface designed for offensive security operations, offering integrated workflows for reconnaissance, scanning, and task automation. Notable features include a Go-based CLI, AI model integration from both local and hosted sources, and robust local storage for session data, making it suitable for authorized security testing and operator workflows. This open-source tool emphasizes terminal agility, maintaining practicality over disconnected scripts or raw outputs.

AD-PathFinder

2026-08-03 Python ★ 103
ADPathFinder is a specialized attack mapping tool designed for penetration testers and red teamers, enabling the analysis of SharpHound data in conjunction with OpenGraph plugins to identify potential attack pathways to critical targets within Active Directory (AD) environments. It supports a variety of data sources, including MSSQLHound and ConfigManBearPig, facilitating comprehensive audits across AD, Active Directory Certificate Services (ADCS), System Center Configuration Manager (SCCM), and SQL Server. Notable features include the ability to map escalation paths, detect weak passwords, and generate detailed reports on vulnerabilities within the network.

AndroidManifestExplorer

2026-08-03 Python ★ 16
AndroidManifestExplorer is a high-performance static analysis tool designed to automate the identification of attack surfaces in Android applications by examining decompiled `AndroidManifest.xml` files. Its primary use case is to uncover security vulnerabilities, including exposed app components, dangerous permission usage, and configuration risks while generating actionable ADB payloads for dynamic verification. Notable features include implicit export detection, deep link analysis, MIME-type intent detection, and comprehensive JSON output for integration into security pipelines.

Awesome-Hacking-with-AI

2026-08-03 Python ★ 21
The "Awesome Hacking with AI" repository is a comprehensive resource that explores the integration of Artificial Intelligence in offensive security practices, such as penetration testing and red teaming. It features a curated collection of AI-driven tools, methodologies, and case studies while emphasizing ethical considerations in their application. Notable features include a learning roadmap, prompt libraries for various tasks (e.g., payload generation and OSINT profiling), and advanced tactics like AI-powered malware development and botnet exploitation.

beetle

2026-08-03 Python ★ 165
Beetle is an offline-first Application Security Intelligence Platform designed for the analysis of Android APKs and iOS IPAs, including those built with Flutter and React Native. It integrates static analysis with a focus on creating explainable workflows that correlate isolated findings into realistic attack chains, facilitating better understanding of vulnerabilities with evidence-based insights. Key features include low false-positive rates, source navigation for precise findings, and optional AI assistance for reasoning about security issues, all while maintaining data security by performing analysis locally.

Bjorn

2026-08-03 Python ★ 6257
Bjorn is an autonomous network scanning and vulnerability assessment tool optimized for Raspberry Pi, featuring a unique e-Paper HAT display. Its modular architecture allows for flexible configuration and operations like network scanning, vulnerability detection using Nmap, brute-force attacks, and data extraction from compromised services. With a real-time interface for monitoring and interaction, Bjorn supports extensive customization for diverse security testing requirements.

BladeRecon

2026-08-03 Python ★ 30
BladeRecon is a modular reconnaissance framework tailored for bug bounty hunters and web penetration testing, focusing on attack-surface discovery and reporting. It offers a terminal-native workflow that generates clean output in various formats, including HTML and Markdown, while integrating features such as subdomain discovery, endpoint extraction, secret detection, and Nuclei scanning for improved intelligence gathering. Designed to be lightweight and beginner-friendly, BladeRecon prioritizes usability without sacrificing operational transparency, making it a valuable tool for small-scale pentesting efforts.

blood-web

2026-08-03 Python ★ 17
Blood-Web is a modular honeypot system designed for penetration testing training and network attack detection, implemented in Python 3.8+ with zero dependencies. It features multiple honeypot services, including SSH, FTP, HTTP, and others, each configurable via command line flags, along with a real-time web dashboard for monitoring attack statistics and trends. The tool is designed to run on non-privileged ports by default, enabling easy deployment without additional setup.

Cairn

2026-08-03 Python ★ 2468
Cairn is a general-purpose problem-solving engine designed for AI-driven penetration testing and exploration of various state spaces. It utilizes a Blackboard Architecture with a fact-intent graph to dynamically search for paths from a defined origin to a goal, enabling versatile applications such as vulnerability research and CTF challenges. Key features include agent-based coordination through stigmergy, adaptable task generation, and real-time updates to the shared knowledge graph.

CommiPiste

2026-08-03 Python ★ 40
CommiPiste is a tool designed for precise identification of open-source web software versions and associated CVEs by analyzing public static files. Its primary use case is authorized security testing and inventory management, leveraging a signature database that allows users to match files against specific Git commits. Notable features include automatic database updates, support for various output formats, and the capability to autoindex unknown software repositories for future scans.

CVE2PoC

2026-08-03 Python ★ 148
CVE2PoC is a tool designed for penetration testers and security researchers to efficiently locate public exploits, Proof-of-Concepts (PoCs), and advisories associated with a specific CVE ID. Its notable features include the aggregation of public exploits from various sources, the provision of isolated Docker environments for safe testing, automated report generation, and comprehensive CVE intelligence, including remediation steps and related bug bounty reports. This powerful tool streamlines the vulnerability discovery and assessment process, allowing users to quickly gather essential information for their security assessments.

CyberBox

2026-08-03 Python ★ 14
CyberBox is a hardened Docker sandbox designed for bug bounty and offensive security research, providing a secure environment with a comprehensive assortment of over 160 security tools. It features keyless signing with cosign, a complete Software Bill of Materials (SBOM), and SLSA build provenance to ensure trust and integrity throughout the supply chain, while also integrating AI analysis and an autonomous workflow for security tasks. Moreover, it seamlessly supports the Caido framework, offering a plugin manager and various utilities to enhance the research process.

DACLSearch

2026-08-03 Python ★ 82
DACLSearch is a comprehensive tool for extracting Access Control Entries (ACEs) associated with principals in Active Directory environments. It supports extensive filtering and database generation, allowing users to perform detailed queries on ACEs and manage access control data efficiently through a command-line interface. Notable features include the use of the Phantom Root for broad queries across domain objects, multi-filter capabilities, and the ability to save and load custom filter configurations in YAML format.

DDoSlayer

2026-08-03 Python ★ 451
DDoSlayer Ultimate Edition is an advanced DDoS testing framework designed for professional penetration testing and red team operations, capable of simulating complex Layer 4 and Layer 7 attacks. Notable features include an AI-powered auto-detect mode for intelligent reconnaissance and attack vector recommendations, a rich terminal UI for enhanced user experience, and support for multiple attack vectors with stealth capabilities. This tool is optimized for efficiently executing concurrent attacks while providing comprehensive analytics through detailed reporting.

deepbug

2026-08-03 Python ★ 28
DeepBug is an automated reconnaissance and bug bounty hunting platform that integrates various open-source tools to facilitate subdomain enumeration, port scanning, JavaScript analysis, and vulnerability scanning within an intuitive user interface. Its primary use case is to streamline bug bounty workflows, allowing users to manage projects, perform discovery scans, and generate comprehensive reports on findings. Notable features include customizable project management, a robust dashboard for tracking scan progress, and integration with popular vulnerability scanning tools like Nuclei.

EmbedXPL-Forge

2026-08-03 Python ★ 32
EmbedXPL-Forge is an open-source exploitation and scanning framework designed for security assessments of embedded and perimeter devices including routers, switches, IoT devices, and printers. It features over 2800 modules encompassing various attack vectors such as credential testing, vulnerability exploitation, and firmware manipulation, alongside an extensive library of 700+ mapped CVEs across 114+ vendors, along with an APT Group Attack Engine for simulating real-world cyber attack scenarios.

ethibench

2026-08-03 Python ★ 99
EthiBench is an adaptable evaluation framework designed for assessing the efficacy of AI-driven pentesting agents against complex, real-world security targets and vulnerabilities. It shifts the evaluation focus from simple task completion to validated vulnerability discovery, incorporating advanced features such as LLM-based semantic matching, continuous ground-truth maintenance, and scoring under ambiguity. Users can customize evaluations with their own targets and findings, while also accessing a set of pre-defined expert-annotated entries for standardized assessment.

ExaAiAgent

2026-08-03 Python ★ 12
ExaAiAgent is an advanced AI-powered cybersecurity tool designed for comprehensive penetration testing, providing enhanced functionalities for various security assessments. Key features include a K8s scanner tool registration, smart fuzzing capabilities, response analysis for SQL errors, and automated installation processes, all aimed at integrating seamlessly into agent-driven workflows. The tool focuses on improving runtime reliability, error handling, and multi-tool coordination to facilitate efficient cybersecurity operations.

faraday_plugins

2026-08-03 Python ★ 61
Faraday Plugins is a command-line tool designed to work seamlessly with Faraday, enabling users to manage and process security-related plugins. Its primary use case includes detecting and processing commands or reports generated by various security tools like Nmap and ping, offering features such as custom plugin support, JSON output formatting, and detailed command tracking. Notably, it allows for easy integration of custom plugins and includes logging capabilities for debugging purposes.

getaltname

2026-08-03 Python ★ 390
GSAN (Get Subject Alternative Names) is a tool designed to extract Subject Alternative Names (SAN) from SSL certificates of HTTPS servers, enabling the identification of DNS names and virtual hosts, particularly in environments involving internal or self-signed certificates. Its primary use case involves directly connecting to servers to retrieve SAN data without relying on Certificate Transparency logs, and it supports batch processing via file input and integration with other tools like Shodan or Nmap for enhanced functionality and output options. Notable features include flexible output capabilities and support for Docker installation, allowing seamless deployment and usage in various environments.

GPOHound

2026-08-03 Python ★ 428
GPOHound is a cybersecurity tool designed to dump and analyze Group Policy Objects (GPOs) from the SYSVOL share, highlighting misconfigurations, insecure settings, and potential privilege escalation paths within Active Directory environments. Key features include structured output in JSON or tree formats, multi-domain support, and the ability to enrich BloodHound data with additional relationships and properties derived from GPO analysis. The tool supports advanced filtering, regex searches, and the detection of insecure configurations, facilitating comprehensive assessments of Active Directory security posture.

GTFONow

2026-08-03 Python ★ 639
GTFONow is a Python-based tool designed for automatic privilege escalation on Unix systems by exploiting misconfigured setuid/setgid binaries, capabilities, and sudo permissions. With a focus on usability for both CTF challenges and real-world pentesting scenarios, it offers various automated exploitation techniques, including file read/write primitives and SSH key theft. The tool is lightweight, compatible with multiple Unix variants, and requires no third-party dependencies, making it easy to deploy via a single script.

httpgrep

2026-08-03 Python ★ 36
httpgrep is a high-performance asynchronous Python tool designed to scan HTTP(S) servers and search for specific strings or regex patterns within HTTP response bodies and headers. It supports a variety of input formats for target hosts, parallel scanning of multiple ports, and advanced features, including live match streaming, log file outputs in multiple formats, and the ability to resume interrupted scans, making it suitable for extensive network assessments. The tool is built for efficiency with an async core capable of handling thousands of concurrent connections while implementing intelligent timeout and port preflight mechanisms.

Kali-Booster

2026-08-03 Python ★ 15
Kali-Booster is a script designed to enhance Kali Linux by installing additional pentesting tools, configuring system settings, and creating useful aliases for command line efficiency. Key features include the restoration of legacy tools, the addition of new wordlists, enhanced font support, and customized settings for a streamlined pentesting environment. The script also facilitates the setup of OpenVPN connections for various hacking platforms and includes automated customization of the user interface.

keyleak-detector

2026-08-03 Python ★ 266
KeyLeak Detector is a runtime security tool designed to identify and validate exposed API keys and misconfigurations in Backend-as-a-Service (BaaS) implementations, specifically targeting frameworks like Supabase and Firebase. Its notable features include a Chrome extension for real-time detection of secrets in web applications, a full site scanning capability that reports on potential vulnerabilities across subdomains, and the ability to validate active status of found keys. Unlike traditional static scanners, KeyLeak assesses the exploitability of keys at runtime, offering a comprehensive audit for web applications.

KUMO-Domain-Recon-Tool

2026-08-03 Python ★ 37
Kumo is an OSINT and security reconnaissance framework that enables the analysis of a target domain via a single command, leveraging 26 parallel modules to deliver comprehensive results in real-time. Key features include extensive checks on DNS records, email security, open ports, leaked credentials, and malware associations, as well as a user-friendly web interface and fast scanning options. This tool is ideal for security professionals conducting thorough assessments of domain-related vulnerabilities and exposures without the need for API keys.

Laitoxx-Multi-Tool

2026-08-03 Python ★ 29
Laitoxx is an OSINT and cybersecurity toolkit featuring a user-friendly GUI, designed for educational purposes to facilitate security analysis, penetration testing, and digital footprint assessment. Key functionalities include an extensible plugin system (Lua), various OSINT tools for data collection, web and network scanning capabilities, and a suite of utilities for hash and text manipulation. Notable enhancements in version 2.3.2 include an advanced theme editor, auto-theme scheduling, and multiple bug fixes for enhanced stability and usability.

mcpsec

2026-08-03 Python ★ 23
mcpsec is a security scanner and protocol fuzzer specifically designed for MCP (Model Context Protocol) servers, allowing real-time connection and exploitation testing against live services. Its primary use case is to identify vulnerabilities in AI development tools that utilize MCP, enabling users to discover and report security issues effectively. Notable features include support for 800+ fuzzing cases, detailed vulnerability reporting, and dynamic testing capabilities that surpass traditional static analysis methods.

MoMo

2026-08-03 Python ★ 28
MoMo is a modular wireless security audit platform specifically designed for Red Teams, penetration testers, and security researchers, operating on Raspberry Pi 5. It integrates various advanced features such as multi-radio management, real-time data synchronization with a central hub, and comprehensive tools for WPA2/WPA3 attacks, credential harvesting, and automation in a single extensible solution. Notable functionalities include an auto-pwn engine, GPS wardriving capabilities, and support for social engineering techniques, making it a versatile tool for wireless security assessments.

netwatch-sec

2026-08-03 Python ★ 26
NetWatch is an all-in-one network security dashboard designed to convert any Linux machine into a comprehensive security sensor. It features real-time deployment of honeypots, traffic sniffing, OSINT tools, and threat management capabilities, all accessible via a single command and user interface. Key functionalities include automatic threat scoring, detailed traffic analysis, and the ability to block attackers, making it suitable for security professionals and home users alike.

NullSec-RedTeam-AI

2026-08-03 Python ★ 13
NullSec Red Team AI is a highly specialized offensive security toolkit designed for red team operations, integrating seamlessly with Claude Desktop through the Model Context Protocol (MCP). This hardened version features a robust Flask orchestration server managing over 150 offensive security tools, a sandbox for AI vulnerability testing, and a self-healing diagnostic utility for system integrity. Its architecture enables high-speed workflows for reconnaissance, vulnerability research, and advanced exploitation simulations, making it ideal for professional security assessments.

Octocrawl

2026-08-03 Python ★ 14
Fast, parallel and easy to use web crawler for penetration testing and bug bounty

Offensive-Pentesting-Scripts

2026-08-03 Python ★ 103
The Offensive Pentesting Scripts repository offers a suite of automation scripts designed to enhance the efficiency of penetration testing and bug hunting. Key features include the simultaneous installation of over 40 essential Go tools, generation of a comprehensive wordlist for subdomain brute forcing with over 66 million entries, and automated identification of live hosts and open ports using Nmap. Additionally, the toolset provides capabilities for thorough subdomain discovery through multiple techniques, streamlining the reconnaissance process for cybersecurity professionals.

OpenFirebase

2026-08-03 Python ★ 62
OpenFirebase is an automated security scanning tool designed to extract Firebase configurations from Android APKs and iOS IPAs, enabling unauthenticated and authenticated scanning of Firebase services, such as Realtime Database, Firestore, and Storage. Notably, it detects accidentally embedded service account credentials and supports multiple input formats, providing comprehensive analysis for both mobile and web applications. The tool also includes built-in wordlists and example payloads for effective fuzz testing and vulnerability assessment.

PenTestMethodology

2026-08-03 Python ★ 35
The Penetration Testing Methodology repository provides a comprehensive framework for conducting penetration tests across various environments, including Active Directory, infrastructure, web applications, mobile, and cloud services. Key features include detailed methodologies for reconnaissance, exploitation, and post-exploitation techniques, along with specialized sections on API and mobile pentesting, as well as AI LLM security audits. This tool is designed to facilitate the identification of vulnerabilities and improve defensive measures in security practices.

pwneye

2026-08-03 Python ★ 164
`pwneye` is an offensive security tool designed for interacting with IP cameras that support ONVIF and RTSP protocols, streamlining various tasks such as discovery, authentication testing, metadata collection, and stream validation through a single command-line interface. Notable features include multithreaded bruteforce attacks for credential guessing, ONVIF device enumeration, RTSP stream handling, and a dedicated live preview client, all aimed at facilitating security assessments of surveillance systems.

SSRF-Scanner

2026-08-03 Python ★ 40
SSRF-Scanner is an advanced tool designed to identify Server-Side Request Forgery (SSRF) vulnerabilities through 14 comprehensive attack phases, emphasizing speed and accuracy. Leveraging asynchronous processing for up to 200 concurrent requests and featuring real confirmation via a self-hosted callback listener, it effectively distinguishes genuine vulnerabilities from false positives. The tool also provides extensive reporting capabilities in various formats and supports custom payloads and CVE probes, making it a versatile asset for security assessments.

Touti-Cracker

2026-08-03 Python ★ 56
Touti Cracker is a cross-platform ethical hacking toolkit designed for educational purposes, featuring capabilities for password cracking, WiFi auditing, and reverse shell payload generation to illustrate system vulnerabilities. Notable features include an enhanced neon-styled user interface, automatic Hashcat setup, error handling enhancements, and compatibility with multiple operating systems, making it a comprehensive tool for security professionals and educators.

TransparentTorProxy

2026-08-03 Python ★ 34
TransparentTorProxy (TTP) is a Linux command-line tool designed to route all system traffic transparently through the Tor network using nftables, thereby enhancing user privacy without requiring per-application configuration. Key features include zero DNS leaks through kernel-level handling, a fail-closed design that secures network routing during failures, and the use of volatile memory to ensure no persistent data is left on the system. TTP offers a modern solution for users seeking to anonymize their internet traffic effortlessly.

web2shell

2026-08-03 Python ★ 75
web2shell is a Python tool designed to automate the conversion of webshells into reverse shells, streamlining the process often required in Capture The Flag (CTF) competitions, Hack The Box (HTB) challenges, and red team exercises. Its notable features include a customizable command interface, the ability to specify local listener settings, and support for various payloads that can be easily extended. The tool is primarily intended for use with Linux machines and facilitates quick testing and execution of reverse shells from web-based vulnerabilities.

WebAnalyzer

2026-08-03 Python ★ 22
WebAnalyzer v3.6.2 is a professional-grade cybersecurity platform designed for advanced domain analysis, vulnerability assessment, and intelligence gathering. It features enterprise bulk processing capabilities, allowing users to analyze thousands of domains efficiently with a MySQL-backed queue system, AI-powered analysis modules, and enhanced stealth techniques. Notable features include real-time metrics, comprehensive reporting, and scalable architecture that supports dynamic resource management and concurrent processing.

WifiForge

2026-08-03 Python ★ 1170
WifiForge is a tool designed to provide a safe and legal environment for learning WiFi hacking, built on the Mininet-WiFi framework. It automates the setup of networks and necessary tools to conduct various WiFi exploitation labs, eliminating the need for extensive hardware and overhead. Key features include easy installation, detailed documentation, and a focus on educational use for cybersecurity professionals.

ad-autopwn

2026-08-03 Python ★ 41
AD AutoPwn is a fully automated penetration testing tool that facilitates the compromise of Active Directory environments by chaining over 25 attack techniques, allowing security professionals to conduct authorized assessments effectively. Its notable features include zero-credential attacks for username enumeration and credential harvesting, advanced exploitation methods for privilege escalation, and integration with BloodHound for graph-driven attack chains and actionable insights. The tool leverages techniques such as Kerberoasting, NTLM relay, and various vulnerability exploits to streamline the process of acquiring domain admin access.

BOFA

2026-08-03 Python ★ 11
BOFA is an open execution fabric designed for authorized security workflows, enabling the seamless movement of authorization from local environments to ephemeral cloud workers. Its primary use case revolves around enhancing security analysis by integrating memory retention, public intelligence, and local notes while facilitating a structured review process for findings. Notable features include built-in AI copilot support, a comprehensive bounty workspace setup, and robust authorization management, ensuring that evidence and artifacts are securely tied to each workflow.

Cascavel

2026-08-03 Python ★ 29
Cascavel is an autonomous Continuous Threat Exposure Management (CTEM) engine designed to streamline Red Team operations and validate adversarial exposures. It automates the process of scoping and discovery, prioritizes vulnerabilities with real-time threat intelligence, and employs a robust validation engine to minimize false positives while generating actionable remediation recommendations. Notable features include dynamic mapping of infrastructure, integration with threat databases, and support for various output formats, all engineered to enhance operational efficiency in cybersecurity.

dirsearch

2026-08-03 Python ★ 14675
dirsearch is an advanced web path discovery tool designed for brute-forcing directories and files on web servers. Its primary use case is assisting cybersecurity professionals in identifying hidden resources within a web application, supporting features such as customizable wordlists, recursion, and a Python API for automation. The tool requires Python 3.11 or higher and offers various installation options, including native Rust backend support and pre-built binaries.

embark

2026-08-03 Python ★ 394
EMBArk is a web-based platform designed for centralized firmware security analysis, utilizing the EMBA scanner as its backend. It offers features such as scanning, tracking, reporting, and presents results through an aggregated management dashboard to enhance accessibility and usability. Currently, it supports only Ubuntu LTS (version 24) and provides an intuitive setup and management interface for enterprise environments.

endpointhunter

2026-08-03 Python ★ 11
EndpointHunter is a bug bounty tool that efficiently extracts various sensitive information, including API endpoints, LFI paths, secrets, and cloud storage URLs, from JavaScript, CSS, and HTML files. Its multi-threaded scanning capability enhances speed, while seamless integration with other recon tools and automated filtering of static assets optimize the reconnaissance process for security researchers. Notable features include smart recon for linked files, noise reduction, and support for output saving and batch processing of multiple URLs.

FirmwareDroid

2026-08-03 Python ★ 37
FirmwareDroid (FMD) is a research tool designed for automating the extraction and security analysis of pre-installed Android applications from firmware images. Primarily functioning through a backend API with a minimal React frontend, it integrates numerous third-party analysis tools, static analyzers, decompilers, and file extraction utilities to facilitate in-depth security research. Notable features include support for dynamic analysis (in progress), a comprehensive inventory system for extracted files, and compatibility with various APIs such as VirusTotal.

gallia

2026-08-03 Python ★ 161
Gallia is an extendable penetration testing framework specifically designed for the automotive industry, facilitating comprehensive security assessments from individual electronic control units (ECUs) to entire vehicles. It primarily focuses on the Unified Diagnostic Services (UDS) interface, offering a generic interface that supports logging and reproducible testing, which aids in post-processing tasks. Its setup involves creating a configuration file to specify command line options, making it suitable for researchers and developers conducting security evaluations in automotive environments.

GraphQLer

2026-08-03 Python ★ 170
GraphQLer is an advanced, dependency-aware testing tool specifically designed for GraphQL APIs, enabling dynamic testing that leverages an API's schema to automate request generation and vulnerability detection. Key features include support for fragments and unions, error correction for invalid requests, tracking of objects for reconnaissance, and automatic detection of insecure direct object reference vulnerabilities. With an interactive terminal UI, customizable configurations, and detailed output logs, GraphQLer streamlines the testing process for enhanced security assessment of GraphQL APIs.

hackinglife

2026-08-03 Python ★ 15
HackingLife is a personal knowledge management tool designed to document and organize cybersecurity insights and notes for easy retrieval. Its primary use case is to support users in building a comprehensive personal repository of cybersecurity knowledge, while its notable feature is the informal and unstructured approach to note-taking, allowing for rapid updates and personal elaboration.

hexgraph

2026-08-03 Python ★ 19
HexGraph is a self-hosted tool designed for AI-assisted vulnerability research that operates entirely on local machines. It allows users to analyze binaries or firmware images by breaking down the targets into components, executing analysis tasks, and organizing findings within a structured, typed graph stored in SQLite. Notable features include a focus on local operations without telemetry, a hypothesis worklist for managing leads, and a secure environment ensuring that all interactions with potentially hostile targets occur in an isolated Docker container.

kimiko

2026-08-03 Python ★ 138
Kimiko is a pentesting configuration tool that enhances the Kimi Code CLI by providing a specialized framework for authorized offensive security, penetration testing, and mobile device security research. Key features include automated context loading for security workflows, customizable agent configurations, and robust capabilities for network offensives, malware generation, reverse engineering, and more, all under strict user authorization. Designed for lawful and ethical testing only, Kimiko facilitates a streamlined setup for various security research methodologies.

offsec-tools

2026-08-03 Python ★ 396
The Syslifters OffSec Tools repository provides a curated collection of offensive security tools for penetration testers and red teamers, streamlining the assessment process within internal environments. It regularly compiles and updates tools, allowing users to easily download the latest versions in a single release archive, thereby eliminating the need for individual updates and compilations. Notable tools included range from Active Directory enumeration and privilege escalation tools to credential recovery solutions, catering to various aspects of security assessments.

openghost

2026-08-03 Python ★ 39
OpenGhost is an authorized web application penetration testing tool designed to facilitate security assessments by AI coding agents. It provides essential features such as a Docker sandbox, detailed engagement scope files, reusable checks, and report templates to streamline the assessment process while ensuring local operation without external dependencies. Users must explicitly define authorization and testing parameters in the generated scope file before proceeding with assessments.

PassLLM

2026-08-03 Python ★ 114
PassLLM is an advanced framework for targeted password guessing that leverages Personally Identifiable Information (PII) to predict likely passwords, achieving 15% to 45% higher accuracy than existing models. Its notable features include the use of a fine-tuning technique called LoRA for efficient resource management, advanced inference algorithms for optimized guessing, and the capability to harness millions of leaked PII records for training. Designed for high accuracy on consumer hardware, it is straightforward to deploy using Google Colab.

Pentest-References

2026-08-03 Python ★ 34
Daethyra's Pentest-References is a comprehensive cybersecurity toolkit that organizes various guides and resources specifically aimed at enhancing penetration testing practices. It features playbooks for internal pentesting, is tailored for both beginners and advanced users, and encompasses tools and strategies for evading detection, exploiting web application vulnerabilities, and understanding Active Directory fundamentals. Notably, it includes extensive documentation on topics like data exfiltration, network enumeration, and persistence techniques on Windows systems, making it a valuable resource for security professionals.

ppmap-proto-pollution

2026-08-03 Python ★ 31
PPMAP is a comprehensive JavaScript prototype pollution and XSS vulnerability scanner designed for web application security assessments. It features a modular architecture, advanced detection methods for various frameworks, and capabilities for browser automation, WAF resilience, and in-depth logging, making it suitable for enterprise-level penetration testing and vulnerability management. Notable components include its intelligent detection tiers, support for modern frameworks, and integration of extensive exploitation guides for discovered vulnerabilities.

rekono

2026-08-03 Python ★ 598
Rekono automates the penetration testing process by integrating multiple hacking tools to streamline tasks such as OSINT, host discovery, and vulnerability scanning. Its notable features include email and Telegram notifications for findings, integration with Defect-Dojo for advanced vulnerability management, and a dedicated Telegram bot to execute tests from any device. This tool aims to enhance a pentester's efficiency by allowing them to focus on analysis rather than repetitive testing tasks.

RootHound

2026-08-03 Python ★ 159
Roothound is a tool designed for local Linux privilege escalation, providing users with a clear graphical representation of pathways from a low-privilege shell to root access. It features an attack-path graph that illustrates each potential route, confidence coloring to indicate the reliability of paths, and copy-ready abuse commands for user convenience. The tool operates offline, requires no dependencies, and can generate self-contained HTML reports from LinPEAS output, making it suitable for authorized security testing and educational purposes.

secator

2026-08-03 Python ★ 1307
secator is a comprehensive task and workflow runner tailored for security assessments, enhancing the efficiency of penetration testers and security researchers. It features a curated list of commands with unified input and output options, CLI and library support, and the ability to run distributed tasks via Celery, making it suitable for both simple and complex security workflows. Notably, secator integrates numerous well-established security tools to streamline the assessment process.

taser

2026-08-03 Python ★ 77
TASER (Testing and Security Resource) is an abstraction library designed to facilitate the development of custom offensive security tools by providing various protocols and classes. Its primary use case is to streamline the creation of tailored security scripts during engagement scenarios, and it includes features for browser integration, screenshot capabilities, and packaged scripts for different probing tasks.

TheBigBrother

2026-08-03 Python ★ 753
The Big Brother V5.0 is an advanced Open Source Intelligence (OSINT) framework designed for comprehensive reconnaissance on individuals, organizations, or groups. It features a highly interactive holographic dashboard supported by 21 distinct intelligence modules that facilitate deep investigative analysis. The tool allows users to conduct detailed searches and surveillance, enhancing the capabilities for gathering critical data while also offering an exclusive service for more intensive intelligence requirements.

toboggan

2026-08-03 Python ★ 16
Toboggan is a post-exploitation tool that facilitates a semi-interactive shell on both Linux and Windows targets via Remote Code Execution (RCE) methods. It operates by allowing users to define custom command execution logic through a simple Python interface, enabling interaction with command outputs even in restrictive network environments. Key features include support for Python-based execution modules, an interactive shell with command history, and the ability to establish communications using named pipes when reverse shells are not feasible.

WEBFANG

2026-08-03 Python ★ 117
WEBFANG v2.0 is a command-line reconnaissance toolkit specifically designed for ethical hacking, enabling users to perform both passive and active reconnaissance through features such as web spidering, subdomain scanning, WHOIS checks, DNS queries, and header fingerprinting. It supports integration with Shodan and URLScan, and is modular in design, allowing for extensions and enhanced output options. Intended for authorized penetration testing and OSINT research, the tool ensures that users maintain compliance with ethical guidelines during usage.

website-passive-reconnaissance

2026-08-03 Python ★ 40
The website-passive-reconnaissance tool automates passive reconnaissance on websites to aid cybersecurity assessments without directly engaging with the target. Its primary use case is to streamline the reconnaissance phase by defining and executing necessary steps using various integrated API services. Notable features include customizable API key integration, configurable options for domain analysis, and a user-friendly command-line interface.

Z3r0

2026-08-03 Python ★ 678
Z3r0 is an open-source red team collaboration workbench designed for authorized penetration testing, vulnerability discovery, and security research. It integrates a React-based console with a FastAPI management layer, allowing users to coordinate multi-Agent sessions, track project-specific evidence, and manage sandbox environments and controlled egress efficiently. Notable features include comprehensive evidence management, detailed workflow tracking, and a session timeline that enhances operational transparency and collaboration among red team participants.

ziran

2026-08-03 Python ★ 10
ZIRAN is a comprehensive security testing framework designed to identify vulnerabilities in AI agents, including those with complex capabilities such as tool usage and memory. By modeling agents as graphs of capabilities, it effectively discovers dangerous tool chains, detects execution-level side effects, and conducts adaptive multi-phase campaigns, surpassing the capabilities of single-prompt scanners. Notable features include graph-based analysis, tool-chain discovery, and thorough coverage of established security benchmarks like OWASP and MITRE.

adscan

2026-08-03 Python ★ 617
ADscan is a comprehensive Active Directory pentesting tool designed for Linux environments that consolidates 103 attack techniques into a streamlined CLI interface. Its primary use case lies in automating the penetration testing process for red teamers and security professionals, providing capabilities such as enumeration, Kerberoasting, and attack-path analysis without the need for Windows. Notable features include fully automated scans through the 'adscan ci' command, which allows for both authenticated and unauthenticated assessments while leveraging Docker for its operational environment.

baboossh

2026-08-03 Python ★ 56
BabooSSH is a specialized tool designed for red teams to facilitate SSH spreading from a compromised host, enabling quick reconnaissance and compromise of additional SSH endpoints. Its notable features include straightforward installation via pip, automated tests using pytest integrated into GitHub Actions, and an evolving documentation site.

Claude-BugHunter

2026-08-03 Python ★ 3936
Claude-BugHunter is a comprehensive skill bundle for the Claude Code system, designed to enhance bug-hunting and red-team operations with 82 curated skills and 15 commands. It features a structured approach to vulnerability detection, engagement scaffolding, and automated reporting, drawing from a vast collection of 681 disclosed report patterns across 24 core vulnerability classes. Notably, it integrates with Burp MCP and provides enterprise identity and infrastructure attack matrices for sophisticated security assessments.

cochise

2026-08-03 Python ★ 133
Cochise is an autonomous penetration testing tool that leverages large language models (LLMs) to exploit vulnerabilities in Microsoft Active Directory environments. With a minimalistic design, Cochise allows users to easily customize and benchmark various LLMs, effectively orchestrating attack procedures including command execution and credential harvesting, all without requiring human intervention. Notable features include a dual-layer architecture comprising a strategic Planner and tactical Executor, along with built-in context management and analysis support for log file evaluation.

cvemapping

2026-08-03 Python ★ 139
The cvemapping tool aggregates CVE exploit data from GitHub, allowing users to clone repositories or export CVE information in JSON format for web use. It features options for pagination and year-specific searches, making it versatile for both developers and security researchers aiming to analyze or present CVE-related data efficiently. Notable features include the ability to authenticate using a GitHub token and the straightforward export functionality for integration with web applications.

cyber-controller

2026-08-03 Python ★ 143
Cyber Controller is a versatile application designed for flashing and controlling multiple ESP32 devices through a unified interface, facilitating both firmware installation and real-time management. It supports 50 firmware profiles and can operate over various interfaces, making it suitable for authorized security testing and educational purposes. Key features include simultaneous commands for multiple devices, anti-bricking safeguards, and compatibility with touchscreens or headless setups, enhancing user experience in cyberdeck operations.

dpulse

2026-08-03 Python ★ 165
DPULSE is an advanced desktop application designed for domain OSINT and reconnaissance, streamlining the process to gather intelligence from open sources with minimal setup. Key features include automated WHOIS and subdomain enumeration, interactive network graph visualizations, real-time security analysis, and integrated API support, all presented in an easily navigable HTML report. This tool serves OSINT professionals looking to enhance their domain reconnaissance workflows while maintaining a user-friendly interface across Windows and Linux platforms.

evil-winrm-py

2026-08-03 Python ★ 393
`evil-winrm-py` is a Python tool designed for executing commands on remote Windows systems via the WinRM protocol, featuring an interactive shell with capabilities for file upload/download, command history, and colorized output. It supports various authentication methods, including NTLM and Kerberos, and offers advanced functionalities such as in-memory execution of local scripts and DLLs, making it highly versatile for authorized penetration testing and educational purposes. The tool prioritizes user experience with features like command auto-completion, comprehensive logging, and a lightweight design, enhancing usability for cybersecurity professionals.

Exegol-resources

2026-08-03 Python ★ 47
The Exegol-resources repository provides essential resources for users of the Exegol penetration testing framework, aiding in activities such as pentesting, bug bounties, and CTFs. This repository contains files that are automatically integrated and updated by the Exegol wrapper, ensuring seamless access to tools and information within Exegol containers. Notable features include automatic downloads and shared usage capabilities for enhanced efficiency during security assessments.

fucking-awesome-web-security

2026-08-03 Python ★ 22
The "Awesome Web Security" repository offers a comprehensive and curated collection of resources and materials focused on web security topics. Its primary use case is to educate users on various vulnerabilities such as XSS, SQL Injection, and CSRF, along with techniques for penetration testing and security research. Notable features include an AI integration for real-time queries, extensive categorization of topics, and a strong emphasis on community contributions.

gcpwn

2026-08-03 Python ★ 309
GCPwn is a framework for conducting offensive security assessments on Google Cloud environments, facilitating credential handling, service enumeration, and attack-path analysis through graph-based outputs. It supports workflows for reconnaissance, exploitation, and data collection, allowing users to execute predefined exploitation modules and export findings in various formats. Notable features include extensive API behavior tracking, IAM analysis, and the ability to generate OpenGraph outputs for privilege escalation reviews.

h4cker_b00k

2026-08-03 Python ★ 18
The h4cker_b00k repository is a comprehensive guide aimed at providing detailed Capture The Flag (CTF) write-ups and insights into ethical hacking practices. It serves as a valuable resource for both beginners and experienced cybersecurity professionals, featuring practical knowledge, techniques, and solutions to enhance skills within the field. Notable features include categorized content for generic tools, initiation into hacking, and advanced hacking topics, facilitating structured learning and community contribution.

hackagent

2026-08-03 Python ★ 464
HackAgent is a Python-based SDK and CLI tool designed to automate the security testing of AI agents, specifically targeting vulnerabilities such as prompt injection, jailbreaking, goal hijacking, and tool misuse. It employs a modular architecture featuring an attack engine, generator, and judge to evaluate the robustness of AI agents against research-backed attack techniques, enabling security researchers and developers to proactively identify and mitigate potential exploits. Additionally, HackAgent offers a standalone binary for varied platforms, eliminating the need for a Python environment, which enhances accessibility for users.

Information-Security-Tasks

2026-08-03 Python ★ 186
Information Security Tasks is a collaborative repository that serves as a comprehensive resource for cybersecurity professionals, offering real-world infosec notes and methodologies. It features extensive directories covering offensive and defensive security topics such as penetration testing, incident response, and vulnerability analysis, alongside daily auto-updates of news and tools. Notable elements include an organized structure for various cybersecurity domains, community submission options for resources, and insights into emerging threats like AI and cloud security.

KeyHunter

2026-08-03 Python ★ 21
KeyHunter is a specialized tool for detecting API key leaks from various sources, including subdomains, archived URLs, and APK files. It automates subdomain enumeration, URL collection, and APK scanning while employing advanced techniques like asynchronous processing for efficient scanning and customizable detection patterns. Notable features include validation of live endpoints, automatic dependency installation, and the ability to generate structured reports focused on identified API key leaks.

mastg

2026-08-03 Python ★ 13148
The OWASP Mobile Application Security Testing Guide (MASTG) serves as a comprehensive resource for mobile app security testing and reverse engineering, aligning with the OWASP Mobile Security Weakness Enumeration (MASWE) and the Mobile Application Verification Standard (MASVS). It features detailed methodologies for validating security weaknesses and offers tools like mobile app security checklists and interactive exercises, enhancing both understanding and practical application of mobile security principles.

nyxstrike

2026-08-03 Python ★ 144
NyxStrike is an AI-powered offensive security orchestration engine that streamlines the execution of full attack chains, encompassing reconnaissance, exploitation, and reporting phases in a matter of minutes. Notable features include the ability to control over 185 offensive security tools through AI agents, a modular tool registry for easy customization, and compatibility with various AI clients via the MCP framework, all while providing a real-time session dashboard for monitoring and management.

OpenDoor

2026-08-03 Python ★ 1000
OpenDoor is an open-source CLI platform designed for authorized web reconnaissance, focusing on directory discovery and subdomain enumeration. It includes features such as WAF detection, bypass probing, and detailed reporting tools, making it ideal for security researchers and penetration testers to identify exposed resources and vulnerabilities on web servers. The tool emphasizes ethical usage, requiring explicit permission for testing.

phantom-frida

2026-08-03 Python ★ 371
`phantom-frida` is a tool that facilitates the building of customized Android Frida Server and Gadget from source while obfuscating specific runtime identifiers to enhance stealth capabilities against detection mechanisms. Its primary use case is for authorized application testing on Android devices, providing robust verification processes through unit and fixture tests, strict input validation during builds, and smoke tests on rooted devices. Notable features include support for custom builds, detailed artifact verification, and a comprehensive configuration for various architectures and specific runtime flags to reinforce security.

Prism-platform

2026-08-03 Python ★ 187
PRISM is a self-hosted Open Source Intelligence (OSINT) platform that provides comprehensive scanning of domains, IPs, emails, phone numbers, and usernames across over 22 modules, delivering insights such as WHOIS data, threat intelligence, and OPSEC scoring. Notable features include real-time web dashboards, AI-driven summary analyses, and detailed report generation in HTML/PDF formats, making it an effective tool for risk assessment and threat investigation.

pSlip

2026-08-03 Python ★ 27
pSlip is a comprehensive security scanning tool for Android applications, designed to detect cryptographic vulnerabilities, OAuth implementations, and manifest issues using a streamlined HTML reporting engine. Its notable features include a powerful searchable HTML report leveraging a field-scoped query language, structured extraction and export of recovered key material and secrets, and a user-friendly interface that supports rapid identification of findings without requiring Java dependencies. The tool optimizes scanning performance and minimizes false positives, enhancing the efficiency of mobile application security assessments.

Python-Pentest-Tools

2026-08-03 Python ★ 22
Python-Pentest-Tools is a collection of open-source Python scripts designed for penetration testing and cybersecurity research. The toolset emphasizes ethical usage for learning and understanding security practices, embodying core development principles for real hacking scenarios. Notable features include a variety of testing utilities suitable for educational purposes, though the author stresses responsible and ethical application.

s3dns

2026-08-03 Python ★ 129
S3DNS is a specialized DNS server designed for identifying exposed cloud storage buckets across various platforms such as AWS S3, Google Cloud Storage, and Azure Blob. Key features include recursive CNAME resolution, detection of potential subdomain takeovers, caching and rate limiting capabilities, and support for IPv6 checks against known cloud IP ranges. This tool is particularly beneficial for penetration testers and cloud security analysts engaged in reconnaissance activities.

SecTools

2026-08-03 Python ★ 31
SecTools is a comprehensive repository of curated open-source and public tools designed for various cybersecurity applications, including OSINT, vulnerability analysis, and application security testing (SAST/DAST). It offers a user-friendly table that categorizes tools with their descriptions, licenses, and activity indicators, facilitating streamlined access to resources for security workflows. Notable features include a focus on UNIX compatibility and an organized structure that enhances usability across multiple security domains.

sherlock

2026-08-03 Python ★ 90696
Hunt down social media accounts by username across social networks

shiftgrid

2026-08-03 Python ★ 40
ShiftGrid is an open-source prompt engine designed for agentic penetration testing while maintaining human oversight. It facilitates the management of testing workflows through structured checklists and detailed observations, ensuring transparency and traceability of actions performed by agents. Notable features include an easily modifiable workflow system, real-time monitoring of agent activities, and the ability to switch between agents or manual testing seamlessly, all while maintaining independence from the specific models and workflows used.

toolbox-pentest-web

2026-08-03 Python ★ 184
The toolbox-pentest-web repository provides a lightweight Docker image designed for the assessment of web-based applications, including websites and APIs. It offers an up-to-date collection of offensive and defensive tools and scripts, optimized for size and usability, with recent expansions into mobile assessment. Key features include a non-root operating environment, continuous updates via GitHub Actions, and a comprehensive index of available scripts and resources.

wstg

2026-08-03 Python ★ 9772
The OWASP Web Security Testing Guide (WSTG) is a comprehensive framework designed for assessing the security of web applications and services through standardized testing methodologies. It provides structured scenarios with unique identifiers to facilitate consistent reporting and tracking of vulnerabilities, making it an essential resource for penetration testers and organizations worldwide. Notable features include detailed documentation of testing best practices and versioning for scenario identifiers to ensure clarity and consistency across updates.

Zen-Ai-Pentest

2026-08-03 Python ★ 446
Zen-AI-Pentest is an AI-powered penetration testing framework designed for security professionals and red teams, leveraging advanced language models alongside over 72 integrated security tools. Its notable features include a user-friendly dashboard, REST API, and modular agent system for tasks like reconnaissance, exploitation, and reporting, as well as compliance mapping and risk scoring functionalities for thorough assessments.

CyberDeck

2026-08-03 Python ★ 61
CyberDeck is a terminal-based penetration testing command dictionary and cookbook designed for information security professionals, featuring a sci-fi CRT aesthetic. Its primary use case is to provide quick access to organized commands and multi-command playbooks across various phases of penetration testing, enhanced by a dynamic command database and full-text search capabilities. Notable features include customizable interfaces, clipboard integration for instant command copying, and fallback CLI functionality for environments lacking a `curses` interface.

Dark-Moon

2026-08-03 Python ★ 880
DarkMoon is an open-source, AI-powered autonomous penetration testing platform designed to conduct end-to-end security assessments without manual intervention. Notable features include a privacy gateway that ensures sensitive data remains secure, integration with over 50 pen-testing tools, and automated vulnerability reporting. This tool is particularly advantageous for security teams and DevSecOps engineers seeking to streamline and scale their defensive operations while maintaining strict data sovereignty.

humanbound

2026-08-03 Python ★ 131
Humanbound is an open-source adversarial testing engine designed specifically for AI agents, enabling users to simulate realistic user interactions and potential attacks through live endpoints and multi-turn conversations. Its notable features include the ability to transform test failures into deployable firewall rules and compatibility with both local environments and the Humanbound Platform, making it straightforward to initiate tests without authentication. The tool also supports various integration options, allowing for flexible deployment and configuration.

OpenEASD

2026-08-03 Python ★ 24
OpenEASD is an open-source external attack surface discovery (EASD) tool designed for red teamers and defenders, enabling users to rapidly map and assess external surfaces of authorized targets without the expense of commercial solutions. It integrates multiple recon tools—such as `subfinder`, `amass`, and `nmap`—into a single web interface, offering features like scheduling, alerts, and findings tracking, while ensuring results remain local to the user's infrastructure. This self-hosted platform emphasizes transparency and security through careful sourcing of its components and is aimed at small security teams, consultancies, and individual security learners.

rcekit

2026-08-03 Python ★ 13
RCEKit is a Python-based toolkit designed for the detection and confirmation of remote code execution (RCE) vulnerabilities, specifically for authorized penetration testing and security research. It provides a robust CLI interface to assess targets by employing multiple verification methods against real-world CVEs, generating definitive "confirmed" verdicts that can be utilized in security reports. Noteworthy features include support for various RCE classes, an easy-to-use setup without third-party dependencies, and the ability to produce evidence-based results, ensuring accurate detection rather than mere conjecture.

binder-trace

2026-03-30 Python ★ 745
Binder Trace is a Python-based tool designed for intercepting and parsing Android Binder messages, functioning similarly to Wireshark for Binder communication. It requires a rooted Android device or emulator and leverages Frida for live analysis, allowing users to attach to specific processes and capture Binder transactions. Notable features include support for various Android versions, customizable structure files, and interactive controls for navigating captured data.

C2-Tracker

2026-03-30 Python ★ 762
C2 Tracker is a community-driven IOC feed that aggregates IP addresses related to known malware, botnets, and command-and-control (C2) infrastructures by leveraging searches from platforms like Shodan. Its primary use case is to facilitate threat intelligence by providing a regularly updated feed that can be ingested by various SIEM and EDR systems, enhancing detection and investigation capabilities. Notable features include version-controlled historical data, weekly updates, and compatibility with tools like OpenCTI and FortinetSIEM for streamlined integration and alerting.

ctf-skills

2026-03-30 Python ★ 3145
The ctf-skills repository provides an extensive collection of agent skills designed to facilitate the solving of Capture The Flag (CTF) challenges across various domains, including web exploitation, binary pwn, reverse engineering, and more. Notable features include support for multiple installation methods, a comprehensive tool installer script, and detailed skill documentation for on-demand use, allowing users to efficiently integrate the necessary tools as challenges arise. It is compatible with any tool adhering to the Agent Skills specification, enhancing its versatility in competitive cybersecurity contexts.

DGFraud

2026-03-30 Python ★ 750
DGFraud is a Graph Neural Network (GNN) toolbox designed for detecting fraud in various systems by integrating and comparing state-of-the-art GNN-based models. Its primary use case lies in enhancing the efficacy of fraud detection mechanisms through advanced graph-based methodologies. Notable features include a modular architecture for implementing new models, comprehensive documentation on existing algorithms, and support for TensorFlow 2.0, allowing seamless integration into existing projects.

EmailAll

2026-03-30 Python ★ 738
EmailAll is a powerful email collection tool designed to aggregate email addresses from various online sources, including search engines and datasets. Its primary use case is to support cybersecurity professionals in gathering emails for domain reconnaissance, and it features integration with multiple API services for data retrieval along with modular results storage in JSON format. The tool allows easy configuration for proxies and APIs, enhancing its flexibility for various deployment environments.

evilwaf

2026-03-30 Python ★ 890
EvilWAF is a sophisticated transparent MITM Firewall bypass proxy and deep WAF vulnerability scanner designed for authorized security testing purposes. It operates at the transport layer, allowing seamless integration with various security tools while employing advanced techniques such as TCP and TLS fingerprint rotation, source port manipulation, and automated WAF detection to evade defensive mechanisms. Notable features include a comprehensive multi-layer WAF scanning capability, direct origin bypass, and a robust IP rotation strategy through Tor and proxy pools, ensuring effective assessment of firewall vulnerabilities.

flare-emu

2026-03-30 Python ★ 936
flare-emu is an advanced emulation tool that integrates with binary analysis frameworks such as IDA Pro or Radare2, leveraging the Unicorn emulation framework to facilitate flexible and efficient code analysis. It offers multiple interfaces for emulating instruction ranges, iterating through function paths, and handling complex emulation scenarios, making it suitable for deep analysis of executable binaries across various architectures including x86, ARM, and their 64-bit counterparts. Notably, it provides functionalities for user-defined hooks, direct memory manipulation, and dynamic code discovery, enhancing the analyst’s ability to probe and understand obfuscated or complex binaries.

Gmail-Hack

2026-03-30 Python ★ 726
Gmail-Hack is a Python-based tool designed for unauthorized access to Gmail accounts, primarily focused on users operating in Termux or Linux environments. It features a straightforward installation process and is intended for educational purposes, with caveats regarding its ethical use. Notably, the tool claims to facilitate hacking actions with minimal setup time, emphasizing its ease of use for individuals familiar with command-line interfaces.

HaboMalHunter

2026-03-30 Python ★ 750
HaboMalHunter is an automated malware analysis tool specifically designed for Linux ELF files, facilitating both static and dynamic analysis to aid security analysts. It efficiently extracts crucial features such as process behavior, file I/O, and network interactions, generating comprehensive reports on malicious activities. Notable features include detailed static analysis of file dependencies and strings, as well as dynamic tracking of execution timestamps, API calls, and syscall sequences.

InstagramPrivSniffer

2026-03-30 Python ★ 983
InstagramPrivSniffer is a digital investigation tool designed for accessing and analyzing posts from private Instagram accounts that are made visible through collaborations with public accounts. Notable features include the ability to download and view media from these private accounts, serving primarily as an OSINT resource for cybersecurity professionals. The tool is intended strictly for educational and research purposes, and its use should be approached with legal considerations in mind.

lisa.py

2026-03-30 Python ★ 743
lisa.py is a Model-Context Protocol (MCP) integration for LLDB, enabling AI assistants like Claude to interact with debugging sessions through a structured interface. It consists of a server component to handle communication and a plugin for LLDB that exposes debugging functionalities via JSON-RPC, allowing users to execute commands verbally and enhance the debugging experience with natural language processing. Notable features include the capability to create targets, manage breakpoints, control process execution, and evaluate expressions directly from the AI assistant.

onedrive_user_enum

2026-03-30 Python ★ 747
onedrive_user_enum is a tool designed for enumerating valid OneDrive users by leveraging the HTTP response codes from file share URLs. Its primary use case is passive user enumeration, which avoids direct login attempts, making it less detectable by the target organization. Notable features include options for remote logging to MySQL, local SQLite database support, user list truncation, and mechanisms for de-duplication and user list management.

PyArmor-Unpacker

2026-03-30 Python ★ 748
PyArmor-Unpacker is a tool designed to unpack Python applications protected by PyArmor, specifically targeting versions prior to v8. The tool offers three methods for unpacking, with the preferred method being suitable for Python 3.9, allowing users to retrieve the original code from obfuscated .pyc files. Notable features include a detailed usage guide, support for multiple unpacking methods, and an emphasis on community contributions to address known issues and enhance functionality.

quark-engine

2026-03-30 Python ★ 1713
Quark Engine is a comprehensive tool designed for malware family analysis and vulnerability assessment, particularly in the context of Android malware. Its primary use case involves identifying and reporting on various malware behaviors and signatures, enabling security researchers to assess risks and improve defenses. Notable features include detailed analysis reports, a rule-based scoring system for malware, and compatibility with Python 3.10, making it accessible for developers and cybersecurity professionals.

raven

2026-03-30 Python ★ 736
Raven is a developer security tool designed to enhance the security of software projects by providing capabilities for managing and monitoring secrets, vulnerabilities, and compliance across development environments. Its primary use case is to integrate seamlessly into CI/CD pipelines, ensuring that code remains secure throughout the software development lifecycle. Notable features include real-time detection of security risks, a user-friendly interface, and integration with various popular development tools and platforms.

retrowrite

2026-03-30 Python ★ 742
Retrowrite is a static binary rewriter designed for x64 and aarch64 architectures, enabling the insertion of instrumentation into binaries without the need for source code, thereby supporting use cases in fuzzing and sanitization. The tool employs the symbolization technique to ensure zero overhead during binary rewriting and includes features such as AFL-coverage and ASan instrumentation, along with a variant (KRetrowrite) specifically for rewriting Linux kernel modules. Different algorithms and supported features are available for the x64 and arm64 versions, accommodating various binary types and compiler specifications.

spoilerwall

2026-03-30 Python ★ 761
Spoilerwall is a network hardening tool that obscures open ports by serving movie spoilers whenever a scan is performed, effectively misleading potential attackers. Its primary use case is to create a deceptive environment that appears vulnerable but instead provides mundane content, deterring unwanted attention and scans. Notable features include customizable spoiler content, easy server setup, and the ability to redirect all TCP traffic to the Spoilerwall service, enhancing security through obfuscation.

Spoofy

2026-03-30 Python ★ 750
Spoofy is a Python-based tool designed to evaluate the spoofability of domains by analyzing their SPF and DMARC records. It features authoritative lookups with a known DNS fallback, accurate bulk processing, and a customizable spoof logic derived from real-world testing, enabling users to conduct comprehensive assessments of domain security configurations. Additionally, Spoofy offers DKIM selector enumeration via API as an optional feature, making it a valuable resource for cybersecurity assessments.

Tata-Sky-IPTV

2026-03-30 Python ★ 712
The Tata Sky/Play IPTV Script generator is a tool that creates an m3u playlist containing direct streamable files, specifically designed for users with a Tata Sky subscription. It offers both an easy-to-use app and a command-line script for generating the playlist, with features like automatic login credential storage and expiration notifications for the generated playlist. This tool is primarily aimed at facilitating seamless access to subscribed channels through compatible IPTV applications.

telegram-scraper

2026-03-30 Python ★ 769
The Telegram Channel Scraper is a Python-based tool that enables users to scrape messages and media from Telegram channels using the Telethon library. Key features include real-time scraping, enhanced metadata capture such as message statistics and reactions, smart filtering for channel management, and data export capabilities in CSV and JSON formats. With automatic database migration and a user-friendly interactive menu, it supports efficient channel monitoring and data retrieval.

unipacker

2026-03-30 Python ★ 745
Un{i}packer is a platform-independent tool designed for the automatic unpacking of Windows Portable Executable (PE) files that have been packed using various runtime packers, thereby facilitating malware analysis. Utilizing the Unicorn Engine for emulation, it effectively handles multiple well-known packers, including ASPack and UPX, and allows for manual input of addresses for less common packers. This tool is particularly beneficial for analysts seeking to bypass challenges posed by malware obfuscation and streamline the unpacking process without requiring a Windows environment.

vivisect

2026-03-30 Python ★ 1000
Vivisect is a versatile framework that integrates disassembly, static analysis, symbolic execution, and debugging capabilities, designed for use in cybersecurity tasks. Its primary use case is to facilitate in-depth analysis of binary executables, assisting researchers and security professionals in vulnerability discovery and exploitation analysis. Notable features include Python 3 compatibility, a graphical user interface, and seamless integration with documentation for enhanced usability.

webkiller

2026-03-30 Python ★ 743
WebKiller V2 is a Python-based tool designed for information gathering and CMS detection in web applications. Its primary use case is to aid cybersecurity professionals in identifying vulnerabilities and obtaining crucial data about target websites. Notable features include a user-friendly command-line interface, compatibility with multiple operating systems, and comprehensive installation instructions.

WitnessMe

2026-03-30 Python ★ 762
WitnessMe is a versatile web inventory tool designed for efficient scanning and data gathering, primarily utilizing headless Chromium via the Pyppeteer library. It excels in processing large Nessus and NMap XML files, generates CSV and HTML reports, and features a RESTful API for remote scanning and extensibility to accommodate custom functionalities. With additional capabilities like HTTP proxy support, signature scanning through YAML files, and terminal screenshot previews, WitnessMe stands out for providing a comprehensive workflow without significant installation challenges.

.NET-Obfuscator

2026-03-22 Python ★ 1464
Lists of .NET Obfuscator (Free, Freemium, Paid and Open Source )

Above

2026-03-22 Python ★ 843
Network Security Sniffer

agentic-radar

2026-03-22 Python ★ 929
A security scanner for your LLM agentic workflows

AI-Infra-Guard

2026-03-22 Python ★ 6090
A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

AlliN

2026-03-22 Python ★ 1275
A flexible scanner

ambiguous-png-packer

2026-03-22 Python ★ 1061
Craft PNG files that appear completely different in Apple software [NOW PATCHED]

android-unpinner

2026-03-22 Python ★ 923
Remove Certificate Pinning from APKs

Anthropic-Cybersecurity-Skills

2026-03-22 Python ★ 31783
734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, Gemini CLI & 20+ platforms · Penetration testing, DFIR, threat intel, cloud security & more · Apache 2.0

antivmdetection

2026-03-22 Python ★ 768
Script to create templates to use with VirtualBox to make vm detection harder

apkleaks

2026-03-22 Python ★ 6008
Scanning APK file for URIs, endpoints & secrets.

AppInfoScanner

2026-03-22 Python ★ 3514
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。

AppleNeuralHash2ONNX

2026-03-22 Python ★ 1536
Convert Apple NeuralHash model for CSAM Detection to ONNX.

APT_REPORT

2026-03-22 Python ★ 3086
Interesting APT Report Collection And Some Special IOCs

Argus

2026-03-22 Python ★ 3344
The Ultimate Information Gathering Toolkit

ARL

2026-03-22 Python ★ 905
ARL 资产侦察灯塔系统(可运行,添加指纹,提高并发,升级工具及系统,无限制修改版) | ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

ARL

2026-03-22 Python ★ 1907
ARL官方仓库备份项目:ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

Artemis

2026-03-22 Python ★ 1201
A modular vulnerability scanner with automatic report generation capabilities.

AttackSurfaceMapper

2026-03-22 Python ★ 1402
AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

AutoPentestX

2026-03-22 Python ★ 1033
AutoPentestX – Automated Pentesting & Vulnerability Reporting Tool

AutoPWN-Suite

2026-03-22 Python ★ 1094
AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

AutoSploit

2026-03-22 Python ★ 5221
Automated Mass Exploiter

awesome-censys-queries

2026-03-22 Python ★ 1240
A collection of fascinating and bizarre Censys Search Queries

awesome-hacking

2026-03-22 Python ★ 3788
Awesome hacking is an awesome collection of hacking tools.

Awesome-Redteam

2026-03-22 Python ★ 4320
一个攻防知识库。A knowledge base for red teaming and offensive security.

bandit

2026-03-22 Python ★ 8248
Bandit is a tool designed to find common security issues in Python code.

Bashfuscator

2026-03-22 Python ★ 1936
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

bbot

2026-03-22 Python ★ 10522
The recursive internet scanner for hackers. 🧡

blackbird

2026-03-22 Python ★ 5873
An OSINT tool to search for accounts by username and email in social networks.

BlackWidow

2026-03-22 Python ★ 1782
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

bluing

2026-03-22 Python ★ 990
An intelligence gathering tool for hacking Bluetooth

bopscrk

2026-03-22 Python ★ 1069
Generate smart and powerful wordlists

Bug_Bounty_writeups

2026-03-22 Python ★ 853
BUG BOUNTY WRITEUPS - OWASP TOP 10 🔴🔴🔴🔴✔

Burp-Suite-Certified-Practitioner-Exam-Study

2026-03-22 Python ★ 1465
Burp Suite Certified Practitioner Exam Study

buster

2026-03-22 Python ★ 1286
An advanced tool for email reconnaissance

cai

2026-03-22 Python ★ 9668
Cybersecurity AI (CAI), the framework for AI Security

CANalyzat0r

2026-03-22 Python ★ 785
Security analysis toolkit for proprietary car protocols

cansina

2026-03-22 Python ★ 907
Web Content Discovery Tool

CAPEv2

2026-03-22 Python ★ 3458
Malware Configuration And Payload Extraction

CatSniffer

2026-03-22 Python ★ 827
CatSniffer is an original multiprotocol and multiband board for sniffing, communicating, and attacking IoT (Internet of Things) devices using the latest radio IoT protocols. It is a highly portable USB stick that integrates TI CC1352, Semtech SX1262, and an RP2040 for V3 or a Microchip SAMD21E17 for V2

censys-subdomain-finder

2026-03-22 Python ★ 845
⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.

changeme

2026-03-22 Python ★ 1503
A default credential scanner.

clairvoyance

2026-03-22 Python ★ 1509
Obtain GraphQL API schema even if the introspection is disabled

ClatScope

2026-03-22 Python ★ 1414
ClatScope Info Tool – The best and most versatile OSINT utility for retrieving geolocation, DNS, WHOIS, phone, email, data breach information and much more (70+ features). Perfect for investigators, pentesters, or anyone looking for an effective reconnaissance / OSINT tool.

claude-bug-bounty

2026-03-22 Python ★ 4390
Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation

Cloakify

2026-03-22 Python ★ 1653
CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection

cloud_enum

2026-03-22 Python ★ 2043
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

CloudFail

2026-03-22 Python ★ 2529
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Coercer

2026-03-22 Python ★ 2312
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

commix

2026-03-22 Python ★ 5832
Automated All-in-One OS Command Injection Exploitation Tool

Corsy

2026-03-22 Python ★ 1535
CORS Misconfiguration Scanner

Cr3dOv3r

2026-03-22 Python ★ 2137
Know the dangers of credential reuse attacks.

Cracker-Tool

2026-03-22 Python ★ 879
All in One CRACKER911181's Tool. This Tool For Hacking and Pentesting. 🎭

CrossLinked

2026-03-22 Python ★ 1582
LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

crypto-attacks

2026-03-22 Python ★ 1285
Python implementations of cryptographic attacks and utilities.

CTF

2026-03-22 Python ★ 2548
CTF challenge (mostly pwn) files, scripts etc

ctfr

2026-03-22 Python ★ 2089
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.

CVE-2023-38831-winrar-exploit

2026-03-22 Python ★ 788
CVE-2023-38831 winrar exploit generator

cve-bin-tool

2026-03-22 Python ★ 1754
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.

CyberSecurity

2026-03-22 Python ★ 1474
A collection of essential and foundational cybersecurity knowledge, thoughtfully organized for easy comprehension.

DDoS-Ripper

2026-03-22 Python ★ 2924
DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

de4py

2026-03-22 Python ★ 1002
The ultimate AI-powered toolkit for python reverse engineering

DeathStar

2026-03-22 Python ★ 1623
Uses Empire's (https://github.com/BC-SECURITY/Empire) RESTful API to automate gaining Domain and/or Enterprise Admin rights in Active Directory environments using some of the most common offensive TTPs.

Decepticon

2026-03-22 Python ★ 5371
Autonomous Multi-Agent Based Red Team Testing Service / AI hacker

DedSec

2026-03-22 Python ★ 1005
Unofficial DedSec Project GitHub Repository

DeepAudit

2026-03-22 Python ★ 5381
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。​让安全不再昂贵,让审计不再复杂。

DeepTraffic

2026-03-22 Python ★ 763
Deep Learning models for network traffic classification

DefaultCreds-cheat-sheet

2026-03-22 Python ★ 6727
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

dep-scan

2026-03-22 Python ★ 1280
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.

Digital-Forensics-Guide

2026-03-22 Python ★ 2478
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

diodb

2026-03-22 Python ★ 1079
Open-source vulnerability disclosure and bug bounty program database

dirhunt

2026-03-22 Python ★ 1983
Find web directories without bruteforce

dirmap

2026-03-22 Python ★ 3374
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。

dnsgen

2026-03-22 Python ★ 1052
DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discovery and security assessments.

dnstwist

2026-03-22 Python ★ 5613
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

doublepulsar-detection-script

2026-03-22 Python ★ 1031
A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

dronesploit

2026-03-22 Python ★ 1850
Drone pentesting framework console

dumpall

2026-03-22 Python ★ 1562
一款信息泄漏利用工具,适用于.git/.svn/.DS_Store泄漏和目录列出

DumpsterFire

2026-03-22 Python ★ 1035
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

Dwarf

2026-03-22 Python ★ 1315
Full featured multi arch/os debugger built on top of PyQt5 and frida

ElectricEye

2026-03-22 Python ★ 1036
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks

elpscrk

2026-03-22 Python ★ 925
An Intelligent wordlist generator based on user profiling, permutations, and statistics. (Named after the same tool in Mr.Robot series S01E01)

emploleaks

2026-03-22 Python ★ 770
An OSINT tool that helps detect members of a company with leaked credentials

enum4linux-ng

2026-03-22 Python ★ 1647
A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.

espoofer

2026-03-22 Python ★ 1682
An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

evillimiter

2026-03-22 Python ★ 2010
Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access.

EvilOSX

2026-03-22 Python ★ 2416
An evil RAT (Remote Administration Tool) for macOS / OS X.

Exegol

2026-03-22 Python ★ 3076
Fully featured and community-driven hacking environment

exphub

2026-03-22 Python ★ 4274
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340

extract_otp_secrets

2026-03-22 Python ★ 1650
Extract one time password (OTP) secrets from QR codes exported by two-factor authentication (2FA) apps such as "Google Authenticator". The exported QR codes from authentication apps can be captured by camera, read from images, or read from text files. The secrets can be exported to JSON or CSV, or printed as QR codes to console.

eyeballer

2026-03-22 Python ★ 1279
Convolutional neural network for analyzing pentest screenshots

fail2ban

2026-03-22 Python ★ 18513
Daemon to ban hosts that cause multiple authentication errors

fame

2026-03-22 Python ★ 931
FAME Automates Malware Evaluation

faraday

2026-03-22 Python ★ 6699
Open Source Vulnerability Management Platform

fav-up

2026-03-22 Python ★ 1192
IP lookup by favicon using Shodan

FavFreak

2026-03-22 Python ★ 1269
Making Favicon.ico based Recon Great again !

featherduster

2026-03-22 Python ★ 1119
An automated, modular cryptanalysis tool; i.e., a Weapon of Math Destruction

fikrado.py

2026-03-22 Python ★ 1000
Facebook hacking Tools script super fast and user friendly

FinalRecon

2026-03-22 Python ★ 2958
All In One Web Recon

FISSURE

2026-03-22 Python ★ 2036
The RF and reverse engineering framework for everyone. Follow and ★ to show your support!

flask-session-cookie-manager

2026-03-22 Python ★ 768
:cookie: Flask Session Cookie Decoder/Encoder

Free-Auto-GPT

2026-03-22 Python ★ 2540
Free Auto GPT with NO paids API is a repository that offers a simple version of Auto GPT, an autonomous AI agent capable of performing tasks independently. Unlike other versions, our implementation does not rely on any paid OpenAI API, making it accessible to anyone.

free-one-api

2026-03-22 Python ★ 894
LLM 逆向工程接口管理 | 通过标准 OpenAI API 访问 ChatGPT / gpt4free / Bard / Claude / HuggingChat / 通义千问 等 AI 的破解版 || ChatGPT reverse engineering API management | Access all reverse engineered LLM libs by standard OpenAI API format || 免费 ChatGPT Free GPT LLM API | 逆向工程 转 OpenAI API | converts all llm libs to OpenAI API

fsociety

2026-03-22 Python ★ 12284
fsociety Hacking Tools Pack – A Penetration Testing Framework

fsociety

2026-03-22 Python ★ 1820
A Modular Penetration Testing Framework

fuxploider

2026-03-22 Python ★ 3330
File upload vulnerability scanner and exploitation tool.

fuzzDicts

2026-03-22 Python ★ 8275
You Know, For WEB Fuzzing !

fuzzforge_ai

2026-03-22 Python ★ 770
AI-powered workflow automation and AI Agents platform for AppSec, Fuzzing & Offensive Security. Automate vulnerability discovery with intelligent fuzzing, AI-driven analysis, and a marketplace of security tools.

gasmask

2026-03-22 Python ★ 1393
Information gathering tool - OSINT

Gemini-API

2026-03-22 Python ★ 3456
✨ Reverse-engineered Python API for Google Gemini web app

geowifi

2026-03-22 Python ★ 1215
Search WiFi geolocation data by BSSID and SSID on different public databases.

Gepetto

2026-03-22 Python ★ 3459
IDA plugin which queries language models to speed up reverse-engineering

Ghost

2026-03-22 Python ★ 3399
Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.

GhostTrack

2026-03-22 Python ★ 8228
Useful tool to track location or mobile number

Ghostwriter

2026-03-22 Python ★ 1895
The SpecterOps project management and reporting engine

GHunt

2026-03-22 Python ★ 18599
🕵️‍♂️ Offensive Google framework.

GitFive

2026-03-22 Python ★ 973
🐙 Track down GitHub users.

GitGot

2026-03-22 Python ★ 1551
Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

gitGraber

2026-03-22 Python ★ 2252
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

github-search

2026-03-22 Python ★ 1471
A collection of tools to perform searches on GitHub.

GonnaCry

2026-03-22 Python ★ 768
A Linux Ransomware

GourdScanV2

2026-03-22 Python ★ 873
被动式漏洞扫描系统

gpt4free

2026-03-22 Python ★ 66611
The official gpt4free repository | various collection of powerful language models | opus 4.6 gpt 5.3 kimi 2.5 deepseek v3.2 gemini 3

GScan

2026-03-22 Python ★ 2809
本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。

guardian-cli

2026-03-22 Python ★ 1859
Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate intelligent, step-by-step penetration testing workflows while maintaining ethical hacking standards.

h2csmuggler

2026-03-22 Python ★ 785
HTTP Request Smuggling over HTTP/2 Cleartext (h2c)

h8mail

2026-03-22 Python ★ 4929
Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email

hack-tools

2026-03-22 Python ★ 1184
hack tools

hackerpro

2026-03-22 Python ★ 1785
All in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog

HackGpt

2026-03-22 Python ★ 935
HackGPT Enterprise is a production-ready, cloud-native AI-powered penetration testing platform designed for enterprise security teams. It combines advanced AI, machine learning, microservices architecture, and comprehensive security frameworks to deliver professional-grade cybersecurity assessments.

hackingBuddyGPT

2026-03-22 Python ★ 1230
Helping Ethical Hackers use LLMs in 50 Lines of Code or less..

harpoon

2026-03-22 Python ★ 1271
CLI tool for open source and threat intelligence

heap-viewer

2026-03-22 Python ★ 769
IDA Pro plugin to examine the glibc heap, focused on exploit development

hermes-dec

2026-03-22 Python ★ 1142
A reverse engineering tool for decompiling and disassembling the React Native Hermes bytecode

hexstrike-ai

2026-03-22 Python ★ 11464
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

honeypots

2026-03-22 Python ★ 957
30 different honeypots in one package! (dhcp, dns, elastic, ftp, http proxy, https proxy, http, https, imap, ipp, irc, ldap, memcache, mssql, mysql, ntp, oracle, pjl, pop3, postgres, rdp, redis, sip, smb, smtp, snmp, socks5, ssh, telnet, vnc)

HostHunter

2026-03-22 Python ★ 1156
HostHunter a recon tool for discovering hostnames using OSINT techniques.

ida-pro-mcp

2026-03-22 Python ★ 11719
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

idacode

2026-03-22 Python ★ 970
An integration for IDA and VS Code which connects both to easily execute and debug IDAPython scripts.

ignorant

2026-03-22 Python ★ 1607
ignorant allows you to check if a phone number is used on different sites like snapchat, instagram.

iKy

2026-03-22 Python ★ 970
OSINT Project. Collect information from a mail. Gather. Profile. Timeline.

Impulse

2026-03-22 Python ★ 2842
:bomb: Impulse Denial-of-service ToolKit

Instabruteforce

2026-03-22 Python ★ 1666
hacking-tool termux-tools termux noob-friendly instagram-bot bruteforce-password-cracker wordlist-technique

instagram_monitor

2026-03-22 Python ★ 1428
Track Instagram users' activities, profile changes and capture content with beautiful dashboards and instant notifications

Instagram-Hacker

2026-03-22 Python ★ 1269
This is an advanced script for Instagram bruteforce attacks. WARNING THIS IS A REAL TOOL!

instaloader

2026-03-22 Python ★ 13132
Download pictures (or videos) along with their captions and other metadata from Instagram.

Interlace

2026-03-22 Python ★ 1303
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

IoT-vulhub

2026-03-22 Python ★ 1271
IoT固件漏洞复现环境

ipdrone

2026-03-22 Python ★ 1988
Track Location With Live Address And Accuracy In Termux

ivre

2026-03-22 Python ★ 4118
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.

jexboss

2026-03-22 Python ★ 2516
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

JustTryHarder

2026-03-22 Python ★ 836
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)

K8CScan

2026-03-22 Python ★ 1301
K8Ladon大型内网渗透自定义插件化扫描神器,包含信息收集、网络资产、漏洞扫描、密码爆破、漏洞利用,程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本,支持Cobalt Strike联动

KawaiiGPT

2026-03-22 Python ★ 817
KawaiiGPT — Open-source LLM gateway accessing DeepSeek, Gemini, and Kimi-K2 through reverse-engineered Pollinations API with no API keys required, built-in prompt injection capabilities for security research, Termux/Linux native support, and Rich console interface

kb

2026-03-22 Python ★ 3414
A minimalist command line knowledge base manager

keychain

2026-03-22 Python ★ 1076
A manager for ssh-agent and gpg-agent

Keylogger

2026-03-22 Python ★ 2715
Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

keypatch

2026-03-22 Python ★ 1818
Multi-architecture assembler for IDA Pro. Powered by Keystone Engine.

kubestriker

2026-03-22 Python ★ 1005
A Blazing fast Security Auditing tool for Kubernetes

labs

2026-03-22 Python ★ 1170
Vulnerability Labs for security analysis

lamda

2026-03-22 Python ★ 8259
The most powerful Android RPA agent framework, next generation of mobile automation robots.

Learn-Web-Hacking

2026-03-22 Python ★ 5518
Study Notes For Web Hacking / Web安全学习笔记

lighthouse

2026-03-22 Python ★ 2517
A Coverage Explorer for Reverse Engineers

like-dbg

2026-03-22 Python ★ 772
Fully dockerized Linux kernel debugging environment

linkedin2username

2026-03-22 Python ★ 1647
OSINT Tool: Generate username lists for companies on LinkedIn

linkook

2026-03-22 Python ★ 1011
🔍 An OSINT tool for discovering linked social accounts and associated emails across multiple platforms using a single username.

linuxprivchecker

2026-03-22 Python ★ 1838
linuxprivchecker.py -- a Linux Privilege Escalation Check Script

llm-guard

2026-03-22 Python ★ 2711
The Security Toolkit for LLM Interactions

Lockdoor-Framework

2026-03-22 Python ★ 1550
🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources

maigret

2026-03-22 Python ★ 37179
🕵️‍♂️ Collect a dossier on a person by username from thousands of sites

mailcat

2026-03-22 Python ★ 837
Find existing email addresses by nickname using API/SMTP checking methods without user notification. Please, don't hesitate to improve cat's job! 🐱🔎 📬

malboxes

2026-03-22 Python ★ 1043
Builds malware analysis Windows VMs so that you don't have to.

malcom

2026-03-22 Python ★ 1165
Malcom - Malware Communications Analyzer

malicious-pdf

2026-03-22 Python ★ 4294
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

malwoverview

2026-03-22 Python ★ 4070
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

mantis

2026-03-22 Python ★ 1021
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.

metarget

2026-03-22 Python ★ 1415
Metarget is a framework providing automatic constructions of vulnerable infrastructures.

MHDDoS

2026-03-22 Python ★ 16632
Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

miasm

2026-03-22 Python ★ 3944
Reverse engineering framework in Python

mongoaudit

2026-03-22 Python ★ 1331
🔥 A powerful MongoDB auditing and pentesting tool 🔥

monkey

2026-03-22 Python ★ 6979
Infection Monkey - An open-source adversary emulation platform

Mr.Holmes

2026-03-22 Python ★ 3149
A Complete Osint Tool :mag:

msdat

2026-03-22 Python ★ 1016
MSDAT: Microsoft SQL Database Attacking Tool

mssqlproxy

2026-03-22 Python ★ 775
mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

MySQL_Fake_Server

2026-03-22 Python ★ 1362
MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize

Name-That-Hash

2026-03-22 Python ★ 1666
🔗 Don't know what type of hash it is? Name That Hash will name that hash type! 🤖 Identify MD5, SHA256 and 300+ other hashes ☄ Comes with a neat web app 🔥

NetExec

2026-03-22 Python ★ 5821
The Network Execution Tool

netlas-cookbook

2026-03-22 Python ★ 846
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of Netlas.io.

Nettacker

2026-03-22 Python ★ 5545
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

NoSQLMap

2026-03-22 Python ★ 3346
Automated NoSQL database enumeration and web application exploitation tool.

nuclei-wordfence-cve

2026-03-22 Python ★ 1278
70k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

o365spray

2026-03-22 Python ★ 985
Username enumeration and password spraying tool aimed at Microsoft O365.

Octopus

2026-03-22 Python ★ 765
Open source pre-operation C2 server based on python and powershell

odat

2026-03-22 Python ★ 1776
ODAT: Oracle Database Attacking Tool

ofrak

2026-03-22 Python ★ 2067
OFRAK: unpack, modify, and repack binaries.

oFx

2026-03-22 Python ★ 903
一个开源的、开箱即用的漏洞批量验证框架

oletools

2026-03-22 Python ★ 3300
oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.

OneForAll

2026-03-22 Python ★ 9682
OneForAll是一款功能强大的子域收集工具

OnionSearch

2026-03-22 Python ★ 1648
OnionSearch is a script that scrapes urls on different .onion search engines.

opencve

2026-03-22 Python ★ 2809
Vulnerability Intelligence Platform

opendbc

2026-03-22 Python ★ 3379
a Python API for your car

opensquat

2026-03-22 Python ★ 982
The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains and brands.

openwifipass

2026-03-22 Python ★ 835
An open source implementation of Apple's Wi-Fi Password Sharing protocol in Python.

OSCP

2026-03-22 Python ★ 959
Collection of things made during my OSCP journey

osi.ig

2026-03-22 Python ★ 1481
Information Gathering Instagram.

osint-brazuca

2026-03-22 Python ★ 2689
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

osint-brazuca-regex

2026-03-22 Python ★ 1007
Repositório criado com intuito de reunir expressões regulares dentro do contexto Brasil

Osintgram

2026-03-22 Python ★ 12474
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

ParamSpider

2026-03-22 Python ★ 3024
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Passhunt

2026-03-22 Python ★ 1297
Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.

passphrase-wordlist

2026-03-22 Python ★ 1410
Passphrase wordlist and hashcat rules for offline cracking of long, complex passwords

patching

2026-03-22 Python ★ 1248
An Interactive Binary Patching Plugin for IDA Pro

pbtk

2026-03-22 Python ★ 1680
A toolset for reverse engineering and fuzzing Protobuf-based apps

penelope

2026-03-22 Python ★ 2037
Penelope Shell Handler

pentest

2026-03-22 Python ★ 1606
:no_entry: offsec batteries included

pentest-tools

2026-03-22 Python ★ 3286
A collection of custom security tools for quick needs.

pentestagent

2026-03-22 Python ★ 3025
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

Perun

2026-03-22 Python ★ 1055
Perun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架

phishing_catcher

2026-03-22 Python ★ 1794
Phishing catcher using Certstream

PhoneSploit

2026-03-22 Python ★ 873
A tool for remote ADB exploitation in Python3 for all Machines.

PhoneSploit-Pro

2026-03-22 Python ★ 6147
An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.

phpsploit

2026-03-22 Python ★ 2492
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Phunter

2026-03-22 Python ★ 993
Phunter is an osint tool allowing you to find various information via a phone number 🔎📞

PINCE

2026-03-22 Python ★ 3068
Reverse engineering tool for linux games

plasma

2026-03-22 Python ★ 3065
Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax.

POC-bomber

2026-03-22 Python ★ 2357
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

POC-T

2026-03-22 Python ★ 1952
渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework

PocOrExp_in_Github

2026-03-22 Python ★ 1197
Automatically Collect POC or EXP from GitHub by CVE ID.

pocsuite3

2026-03-22 Python ★ 3830
pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

Pompem

2026-03-22 Python ★ 1024
Find exploit tool

power-pwn

2026-03-22 Python ★ 1207
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Powershell-RAT

2026-03-22 Python ★ 1179
Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment.

protobuf-inspector

2026-03-22 Python ★ 1115
🕵️ Tool to reverse-engineer Protocol Buffers with unknown definition

prowler

2026-03-22 Python ★ 14723
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

ProxyCat

2026-03-22 Python ★ 2436
一款部署于云端或本地的隧道代理池中间件,可将静态代理IP灵活运用成隧道IP,提供固定请求地址,一次部署终身使用

psudohash

2026-03-22 Python ★ 1468
Generates millions of keyword-based password mutations in seconds.

pwn_jenkins

2026-03-22 Python ★ 2089
Notes about attacking Jenkins servers

pwnagotchi

2026-03-22 Python ★ 2892
(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.

pwndbg

2026-03-22 Python ★ 10822
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy

pwnedOrNot

2026-03-22 Python ★ 2517
OSINT Tool for Finding Passwords of Compromised Email Addresses

pygod

2026-03-22 Python ★ 1482
A Python Library for Graph Outlier Detection (Anomaly Detection)

pyinstxtractor

2026-03-22 Python ★ 4172
PyInstaller Extractor

pylingual

2026-03-22 Python ★ 1357
Python decompiler for modern Python versions.

pypush

2026-03-22 Python ★ 3714
Python APNs and iMessage client

pythem

2026-03-22 Python ★ 1243
pentest framework

Raccoon

2026-03-22 Python ★ 4009
A high performance offensive security tool for reconnaissance and vulnerability scanning

RamiGPT

2026-03-22 Python ★ 879
Autonomous Privilege Escalation using AI

rapidscan

2026-03-22 Python ★ 2128
:new: The Multi-Tool Web Vulnerability Scanner.

Reconnoitre

2026-03-22 Python ★ 2188
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

RecoverPy

2026-03-22 Python ★ 1786
Interactively find and recover deleted or :point_right: overwritten :point_left: files from your terminal

redamon

2026-03-22 Python ★ 2370
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

RedTeamTools

2026-03-22 Python ★ 1465
记录自己编写、修改的部分工具

refinery

2026-03-22 Python ★ 869
High Octane Triage Analysis

reFlutter

2026-03-22 Python ★ 2726
Flutter Reverse Engineering Framework

requests-ip-rotator

2026-03-22 Python ★ 1647
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

robin

2026-03-22 Python ★ 6783
AI-Powered Dark Web OSINT Tool

ROPgadget

2026-03-22 Python ★ 4392
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, and RISC-V Compressed architectures.

SatanSword

2026-03-22 Python ★ 1178
红队综合渗透框架

scapy

2026-03-22 Python ★ 12505
Scapy: the Python-based interactive packet manipulation program & library.

Scavenger

2026-03-22 Python ★ 765
Crawler (Bot) searching for credential leaks on paste sites.

Search-That-Hash

2026-03-22 Python ★ 1411
🔎Searches Hash APIs to crack your hash quickly🔎 If hash is not found, automatically pipes into HashCat⚡

Sec-Tools

2026-03-22 Python ★ 844
🍉一款基于Python-Django的多功能Web安全渗透测试工具,包含漏洞扫描,端口扫描,指纹识别,目录扫描,旁站扫描,域名扫描等功能。

security-tools

2026-03-22 Python ★ 923
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.

see

2026-03-22 Python ★ 821
Sandboxed Execution Environment

Selenium-Driverless

2026-03-22 Python ★ 848
a stealthy browser automation framework

Shadowbroker

2026-03-22 Python ★ 11007
Open-source intelligence for the global theater. Track everything from the corporate/private jets of the wealthy, and spy satellites, to seismic events in one unified interface. The knowledge is available to all but rarely aggregated in the open, until now.

shellen

2026-03-22 Python ★ 909
:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

sicat

2026-03-22 Python ★ 830
The useful exploit finder

SIGIT

2026-03-22 Python ★ 934
SIGIT - Simple Information Gathering Toolkit

Silver

2026-03-22 Python ★ 1047
Mass scan IPs for vulnerable services

sipvicious

2026-03-22 Python ★ 1063
SIPVicious OSS is a VoIP security testing toolset. It helps security teams, QA and developers test SIP-based VoIP systems and applications. This toolset is useful in simulating VoIP hacking attacks against PBX systems especially through identification, scanning, extension enumeration and password cracking.

sitedorks

2026-03-22 Python ★ 1055
Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

slowloris

2026-03-22 Python ★ 2763
Low bandwidth DoS tool. Slowloris rewrite in Python.

snoop

2026-03-22 Python ★ 3748
Snoop — инструмент разведки на основе открытых данных (OSINT world)

socid-extractor

2026-03-22 Python ★ 1077
⛏️ Extract accounts info from personal pages on various sites for OSINT purpose

SpringBoot-Scan

2026-03-22 Python ★ 2247
针对SpringBoot的开源渗透框架,以及Spring相关高危漏洞利用工具

sqlmap

2026-03-22 Python ★ 38321
Automatic SQL injection and database takeover tool

ssh-mitm

2026-03-22 Python ★ 1464
SSH-MITM - ssh audits made simple

SSRF-Testing

2026-03-22 Python ★ 2507
SSRF (Server Side Request Forgery) testing resources

SSTImap

2026-03-22 Python ★ 1624
Automatic SSTI detection tool with interactive interface

SubDomainizer

2026-03-22 Python ★ 1887
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

sublert

2026-03-22 Python ★ 1026
Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.

subscraper

2026-03-22 Python ★ 973
Subdomain and target enumeration tool built for offensive security testing

taranis-ai

2026-03-22 Python ★ 1207
Taranis AI is an advanced Open-Source Intelligence (OSINT) tool, leveraging Artificial Intelligence to revolutionize information gathering and situational analysis.

tenet

2026-03-22 Python ★ 1528
A Trace Explorer for Reverse Engineers

theHarvester

2026-03-22 Python ★ 17247
E-mails, subdomains and names Harvester - OSINT

theZoo

2026-03-22 Python ★ 13282
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

thug

2026-03-22 Python ★ 1041
Python low-interaction honeyclient

TIDoS-Framework

2026-03-22 Python ★ 1847
The Offensive Manual Web Application Penetration Testing Framework.

tinfoleak

2026-03-22 Python ★ 1968
The most complete open-source tool for Twitter intelligence analysis

tookie-osint

2026-03-22 Python ★ 2880
Tookie is a advanced OSINT information gathering tool that finds social media accounts based on inputs.

TorBot

2026-03-22 Python ★ 4744
Dark Web OSINT Tool

toutatis

2026-03-22 Python ★ 3809
Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails, phone numbers and more

trape

2026-03-22 Python ★ 8625
People tracker on the Internet: OSINT analysis and research tool by Jose Pino

unlicense

2026-03-22 Python ★ 1361
Dynamic unpacker and import fixer for Themida/WinLicense 2.x and 3.x.

Uscrapper

2026-03-22 Python ★ 773
Uscrapper Vanta: Dive deeper into the web with this powerful open-source tool. Extract valuable insights with ease and efficiency, from both surface and deep web sources. Empower your data mining and analysis with Vanta's advanced capabilities. Fast, reliable, and user-friendly, Uscrapper Vanta is the ultimate choice for researchers and analysts.

user-scanner

2026-03-22 Python ★ 4008
🕵️🫆 (2-in-1) Emaill and Username OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investigations, legitimate analysis

V3n0M-Scanner

2026-03-22 Python ★ 1562
Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

VAmPI

2026-03-22 Python ★ 1191
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

VHostScan

2026-03-22 Python ★ 1310
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

Villain

2026-03-22 Python ★ 4441
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).

ViperMonkey

2026-03-22 Python ★ 1117
A VBA parser and emulation engine to analyze malicious macros.

vmlinux-to-elf

2026-03-22 Python ★ 1701
A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)

vulmap

2026-03-22 Python ★ 3505
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

vulnx

2026-03-22 Python ★ 2091
vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information collection (including sub-domain name, ip address, country information, organizational information and time zone, etc.) and vulnerability scanning.

Vxscan

2026-03-22 Python ★ 1758
python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

w5

2026-03-22 Python ★ 1544
Security Orchestration, Automation and Response (SOAR) Platform. 安全编排与自动化响应平台,无需编写代码的安全自动化,使用 SOAR 可以让团队工作更加高效

weird_proxies

2026-03-22 Python ★ 1854
Reverse proxies cheatsheet

weirdAAL

2026-03-22 Python ★ 844
WeirdAAL (AWS Attack Library)

wesng

2026-03-22 Python ★ 4924
Windows Exploit Suggester - Next Generation

WhatBreach

2026-03-22 Python ★ 1527
OSINT tool to find breached emails, databases, pastes, and relevant information

whatsapp-osint

2026-03-22 Python ★ 1514
WhatsApp spy - logs online/offline events from ANYONE in the world

WhatsMyName

2026-03-22 Python ★ 2817
This repository has the JSON file required to perform user enumeration on various websites.

wifi-deauth

2026-03-22 Python ★ 806
A deauth attack that disconnects all devices from the target wifi network (2.4Ghz & 5Ghz), WPA3 also supported (PMF not tested)

Wifi-Hacking

2026-03-22 Python ★ 2674
Cyber Security Tool For Hacking Wireless Connections Using Built-In Kali Tools. Supports All Securities (WEP, WPS, WPA, WPA2/TKIP/IES)

WPeChatGPT

2026-03-22 Python ★ 1293
A plugin for IDA that can help to analyze binary file, it can be based on commonly used AI big models such as OpenAI and DeepSeek.

WPForce

2026-03-22 Python ★ 974
Wordpress Attack Suite

X-osint

2026-03-22 Python ★ 2560
This is an Open source intelligent framework ie an osint tool which gathers valid information about a phone number, user's email address, perform VIN Osint, and reverse, perform subdomain enumeration, able to find email from a name, and so much more. Best osint tool for Termux and linux

xeuledoc

2026-03-22 Python ★ 993
Fetch information about a public Google document.

xmir-patcher

2026-03-22 Python ★ 3422
Firmware patcher for Xiaomi routers

xsser

2026-03-22 Python ★ 1462
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.

Xteam

2026-03-22 Python ★ 1142
Xteam All in one Instagram,Android,phishing osint and wifi hacking tool available

xunfeng

2026-03-22 Python ★ 3595
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

yarGen

2026-03-22 Python ★ 1782
yarGen is a generator for YARA rules

yark

2026-03-22 Python ★ 2183
OSINT for YouTube made simple.

yesitsme

2026-03-22 Python ★ 2624
Simple OSINT script to find Instagram profiles by name and e-mail/phone

Zehef

2026-03-22 Python ★ 992
Zehef is an osint tool to track emails

Zero-attacker

2026-03-22 Python ★ 1025
Zero-attacker is an multipurpose hacking tool with over 15+ multifunction tools

ZipCracker

2026-03-22 Python ★ 811
ZipCracker是Hx0战队出品的一款功能强大的Zip密码破解工具。它集成了字典攻击、掩码攻击和CRC32碰撞等多种破解模式,并能自动修复伪加密文件。凭借其高性能与多功能的特点,ZipCracker已成为CTF比赛中的一把利器。(ZipCracker by Hx0 team is a tool for cracking passwords on Zip files, great for CTF competitions.)