Shell
2026-08-30
Shell
★ 16
B1ackOS is a privacy-focused operating system based on Debian, designed to simplify software package installation while ensuring user security. Its notable features include a lightweight architecture, extensive application repositories for diverse use cases, a live operating capability, and a rolling release model that emphasizes stability and performance.
2026-08-28
Shell
★ 11
The D-Link DSP-W215 B1 OpenWrt Hacks repository provides comprehensive reverse engineering and control scripts specifically for the D-Link DSP-W215 B1 smart plug running OpenWrt. It offers detailed guidance on flashing OpenWrt, troubleshooting connectivity issues, and controlling the device's relay and power metering features via GPIO and serial communication with the PL8331 chip. Notable features include a step-by-step flashing procedure, solutions to common post-flash problems, and the ability to integrate with services like Home Assistant and MQTT for real-time monitoring.
2026-08-27
Shell
★ 56
ClusterImageScanner is a Kubernetes-native tool designed to identify vulnerabilities and misconfigurations in container images within production environments. It automates the analysis process by utilizing an image collector and orchestrator to periodically scan images with multiple security scanners, consolidating findings through a vulnerability management system like OWASP DefectDojo while providing real-time feedback to developers through communication channels. Notable features include its integration with Argo Workflows, flexible deployment options, and support for various scanning methods, ensuring comprehensive security monitoring for containerized applications.
2026-08-27
Shell
★ 32
Claude Guard is a dual-channel architecture tool for managing Claude Code versions and startup strategies, ensuring strict auditing and version control for the official Claude channel while allowing independent updates via the CC Switch channel. Notable features include comprehensive lifecycle policies, detailed security checks before launching the client, and a dry-run guardian for ongoing monitoring without consuming user tokens or resources.
2026-08-27
Shell
★ 12
Hermes Cybersecurity Lab is a comprehensive cybersecurity toolkit designed for the Hermes Agent, encompassing 2,077 skills, 131+ tools, and 28 frameworks, systematically organized across multiple repositories. Its primary use case includes security research, pentesting, forensics, and threat intelligence, with notable features like a preconfigured installation script, tool inventory awareness, and a structured methodology for tackling various phases of cybersecurity engagements. This ecosystem ensures continuous updates and knowledge accumulation, enhancing both operational efficiency and effectiveness in security practices.
2026-08-24
Shell
★ 28
OSINT Skills is an open-source intelligence tool designed for automated investigations, enabling users to pivot between various data points such as emails, domains, and social accounts. Its main use case involves conducting comprehensive reconnaissance and attribution, with 28 integrated skills that utilize techniques like reverse image search and breach checks to generate detailed reports complete with sources and confidence levels. Notably, the tool allows interaction with AI agents to streamline the investigation process and provides extensive reference materials for each skill.
2026-08-23
Shell
★ 117
CorpTrace is a framework designed for automating the collection of information about a target company during red team assessments. It integrates multiple modules from various sources, allowing users to execute diverse reconnaissance tasks while managing risk levels and API key consumption. Notable features include customizable timeout settings, thread management for concurrent execution, and visualization of collected data.
2026-08-21
Shell
★ 13
The `rockchip-npu-notes` repository provides comprehensive reverse-engineering documentation for the Rockchip RK3588 Neural Processing Unit (NPU), focusing on the hardware's register-command interface and its integration with the mainline `rocket` DRM-accel driver. It includes subsystem-organized notes detailing machine parameters, register offset maps, precision encodings, and operational quirks, aiming to assist users constructing custom compute solutions using the RK3588. Notable features include empirical observations tagged with their verification methods, alongside in-depth explanations of NPU architecture and operational capabilities.
2026-08-21
Shell
★ 10
NEO-Radar is a lightweight network scanner designed for Linux and Termux, aimed at simplifying network scanning for users without extensive networking or cybersecurity knowledge. Its primary use case is to provide essential scanning functionalities akin to more complex tools like Nmap, while also including a command reference for learning purposes. Notable features include ease of installation via a single command, compatibility with mobile devices, and a focus on user-friendly operations, making it accessible for a wider audience.
2026-08-21
Shell
★ 16
B1ackOS is a privacy-focused operating system based on Debian, designed to simplify software package installation and enhance user security. It features a lightweight and versatile environment, allowing for both live usage and easy assembly tailored to individual needs, with a rolling release model that ensures access to the latest software versions. Key functionalities include improved package management, extensive application availability, and compatibility with a wide range of hardware.
2026-08-20
Shell
★ 25
h3-cli is a command-line interface designed for seamless interaction with the Horizon3 API, enabling users to schedule and execute autonomous penetration tests via NodeZero, as well as monitor their status and access detailed reports. Notable features include comprehensive documentation for installation and usage, alongside capabilities to run and manage a locally hosted MCP Server that integrates NodeZero’s functionalities into development and security workflows.
2026-08-19
Shell
★ 11
The Apple Neural Engine (ANE) guide provides an in-depth examination of the architecture, programming, and performance characteristics of Apple's proprietary neural hardware present in its A11 and M1 silicon. It details the internal mechanisms, data pathways, and performance metrics of the ANE, with sections dedicated to model deployment and tuning as well as comprehensive documentation on the engine's programming interface, memory hierarchy, and private runtime features. This guide serves as a resource for research and development purposes, emphasizing that the methods described are not officially supported by Apple and are subject to change with operating system updates.
2026-08-19
Shell
★ 31
bugbountyrules is an AI agent skill designed for authorized bug bounty and penetration testing, emphasizing disciplined and methodical hunting behavior. It features 42 active rules to minimize false positives, avoid severity inflation, and ensure thorough surface coverage while performing tests across web, API, mobile, cloud, and LLM environments. The tool operates on a structured approach to testing, maintaining an organized flow of reconnaissance and validation while integrating a robust knowledge base for on-demand information retrieval.
2026-08-16
Shell
★ 13
Win10 LockPicker is a P4wnP1 A.L.O.A. payload designed to unlock a Windows 10 session without requiring prior knowledge of the user's password. It captures NTLMv2 hashes over poisoned LLMNR/NBT-NS traffic via a spoofed USB network adapter, cracks the hash using John the Ripper, and automatically inputs the recovered password using an HID keyboard. Additionally, it offers an SMB brute force alternative for credential recovery through Metasploit, enhancing its versatility for authorized penetration testing.
2026-08-15
Shell
★ 11
MAPG is an automated reconnaissance tool designed for penetration testing, CTFs, and security assessments, facilitating organized and efficient service enumeration. It features a modular framework that executes service detection and enumeration tools in parallel, generating structured reports while minimizing manual effort. Notable capabilities include support for various scanning modes, extensive service checks, and automatic report generation, all aimed at streamlining the initial phases of security assessments.
2026-08-15
Shell
★ 24
BloodHoundAnalyzer is a bash script that automates the deployment, data import, and analysis of BloodHound CE, an Active Directory security tool. It enables efficient setup of multi-domain BloodHound CE instances, custom container management, and integration of various analysis tools to enhance Active Directory security assessments. Notable features include automated password management, support for multiple data formats, and comprehensive project listing and status tracking.
2026-08-14
Shell
★ 15
Combo Clean is a utility designed for processing and cleaning large combolists of email and password pairs, making them ready for use in scripts. Its notable features include the ability to filter and output cleaned combinations from a specified input file, simplifying the management and utilization of credential datasets. The tool is straightforward to install and execute, providing both local and global command options.
2026-08-14
Shell
★ 21
opencode-pentester is an AI-powered penetration testing and security audit framework designed to automate bug bounty hunting and vulnerability assessments. It orchestrates 12 specialized AI agents across 69 attack categories and 17 OWASP security audits, enabling comprehensive offensive and defensive testing. Notable features include the ability to run automated tests, generate professional reports, and integrate a wide array of security tools, making it suitable for security researchers, penetration testers, and DevSecOps engineers.
2026-08-13
Shell
★ 169
The URL Shorteners tool provides a curated collection of over one thousand URL shortener domains intended for use in whitelisting, blacklisting, and assessing domain trustworthiness. Notable features include separate lists for active and inactive domains, aiding in network security and minimizing false positives in risk assessments. This resource is valuable for enhancing privacy protection across various network environments.
2026-08-12
Shell
★ 14
mxhelp is a pentesting toolkit designed to streamline the use of various scripts by automatically populating IP and target addresses into pre-defined "cheatsheets." Its notable features include easy addition of new scripts, real-time updates using the 'sed' command to prevent errors, and a simple alias system for efficient command execution. By simplifying the process of managing pentesting scripts, mxhelp enhances the workflow for security professionals.
2026-08-11
Shell
★ 127
CamSniff is an automated reconnaissance toolkit designed for discovering and profiling IP cameras and network video streams within local networks. It employs both active and passive scanning methods to generate structured and auditable datasets, while enabling users to acquire snapshots and streams from various protocols, including RTSP and ONVIF. Notable features include its mode-aware scanning capabilities, multi-protocol support, and the ability to produce comprehensive output formats such as structured JSON files and logs.
2026-08-11
Shell
★ 21
OSINT Skills is an open-source intelligence tool designed to facilitate automated investigations by agents like Cursor and Claude. It provides 28 customizable skills for various reconnaissance tasks, enabling users to pivot across data points such as emails, domains, and social accounts, all while generating reports with source citations and confidence levels. Key features include pre-defined workflows, individual techniques for advanced inquiries, and comprehensive reference materials for effective tradecraft in OSINT.
2026-08-10
Shell
★ 2518
The VPS Security Audit Script is a Bash tool designed for thoroughly auditing the security and performance of Ubuntu/Debian-based Virtual Private Servers. It conducts a variety of security checks such as SSH configuration, firewall status, and intrusion prevention settings, while also monitoring system performance metrics like CPU and memory usage. Notably, it provides real-time feedback with color-coded outputs indicating pass, warn, or fail statuses, and generates a comprehensive report with recommendations for improving the server's security and performance.
2026-08-10
Shell
★ 11
cors is a CORS misconfiguration scanner designed to identify vulnerabilities in web applications related to Cross-Origin Resource Sharing. Its primary use case includes scanning single URLs or multiple URLs from a file, with capabilities for specifying output files and concurrent scanning threads to enhance efficiency. Notable features include detailed vulnerability reporting, flexible usage options for various scanning scenarios, and easy installation on Linux systems.
2026-08-10
Shell
★ 11
Claude Pentest Skills is a specialized tool designed for structuring and automating penetration testing workflows within the Claude Code LLM environment. It features modular skill packs that provide comprehensive Active Directory reconnaissance, exploitation, and post-exploitation processes, along with robust functionalities such as checkpointing, parallel execution, and cross-platform support. Notable functionalities include automated evidence capture, JSON reporting, and seamless integration with multiple external tools for enhanced penetration testing efficacy.
2026-08-09
Shell
★ 95
The Ubuntu Security Hardening Script automates the hardening of Ubuntu servers across various subsystems, including SSH, kernel settings, and firewall configurations, ensuring compliance with CIS benchmarks. It features comprehensive safety checks, automatic backups, and detailed reporting, while supporting the latest Ubuntu versions and incorporating advanced security mechanisms such as post-quantum SSH. The tool is designed for repeatability, preserving custom configurations on re-runs, making it suitable for production environments.
2026-08-07
Shell
★ 13
Kaosagnt's Ansible Everyday provides a collection of customizable Ansible playbooks designed for daily server management tasks, streamlining automation for systems administrators. The tool features interactive playbooks for various operations, such as managing access control lists, package updates on RHEL and Debian-based systems, and setting up system tools like the nano editor. It also includes scripts for easy execution of these tasks, requiring minimal setup while accommodating a range of operating systems.
2026-08-07
Shell
★ 32
The lineageos-echo-show-camera repository facilitates the functionality of the front camera on the Amazon Echo Show 5 (2nd gen) by integrating a complete camera stack into the unofficial LineageOS 18.1 environment. Key features include image capture at 1600x1200 resolution, live preview with accurate color representation, and advanced image processing capabilities such as exposure adjustment and lens shading correction. This tool is essential for users seeking to enhance their device's multimedia capabilities within a custom Android framework.
2026-08-07
Shell
★ 17
The Sthenos Embedded Toolkit is a comprehensive solution for building static debugging and analysis tools tailored for embedded systems across over 50 architectures. Notable features include support for both musl and glibc toolchains, a range of available tools such as strace and tcpdump, and the capability to compile specific tools for designated architectures using a Docker-based build environment. This toolkit enables streamlined development and troubleshooting for embedded systems, ensuring reliable performance in diverse operating environments.
2026-08-06
Shell
★ 88
Portscan Protection is a tool designed to enhance the security of Linux systems by detecting and blocking IP addresses that perform rapid port scanning, which could lead to unauthorized access attempts. Its notable features include support for both iptables and nftables, systemd and cron operation modes, custom SSH port functionality, and the ability to manage whitelists and blacklists for IP addresses. The tool is easy to install and comes with automatic updates, ensuring continuous protection against port scan attacks.
2026-08-06
Shell
★ 302
GameTracking is a modular toolset designed to automate the tracking and updating of game repositories through GitHub Actions. Its primary use case is to manage game updates by using a reusable workflow that integrates with individual game repositories, automating the download of necessary files and the execution of update scripts. Notable features include support for manual triggers, a lightweight file downloader for selective content retrieval, and cross-platform compatibility for both Linux and Windows systems.
2026-08-05
Shell
★ 14
Atlas Trust Infrastructure is a metadata-centric framework designed to create and verify proof chains for operational integrity across various systems, such as GitHub, Nix, and SSH. Its primary use case is to enhance audit readiness and governance by recording and verifying actions' metadata, capabilities, policies, and approvals without replacing existing tools. Notable features include a proof-only recording mechanism that ensures metadata integrity and replayability, promoting transparency and reducing ambiguity in digital actions.
2026-08-04
Shell
★ 268
Sublime Platform is an open-source tool designed for detecting and preventing various email attacks, including Business Email Compromise (BEC), malware, and credential phishing. It utilizes Message Query Language (MQL), allowing users to define and share Detections-as-Code in a provider-agnostic manner, enhancing threat visibility and collaboration. The platform can be deployed via Docker for small to medium-sized environments, with recommendations for larger or production use cases in AWS cloud deployments.
2026-08-04
Shell
★ 19
`safedeps` is a command-line tool that enhances security for AI coding agents by pre-approving dependencies against vulnerabilities from multiple advisory sources before installation and ensuring no unapproved packages are introduced. It enforces compliance through re-verification of the dependency tree post-installation and can automatically roll back any that are found to be insecure. Designed for local use with no runtime dependencies, it also provides features for auditing and managing secrets within the repository.
2026-08-04
Shell
★ 89
Awesome Reverse Engineering & Malware Analysis is a comprehensive resource that serves as a curated guide for reverse engineering and malware analysis tools, methodologies, and educational content. It categorizes entries across various disciplines such as static and dynamic analysis, exploit development, and digital forensics while providing quality assurance by checking all links and content for relevance. Notable features include structured learning tracks for different areas of focus, detailed tagging for easy navigation, and inclusion of community resources to enhance collaboration and knowledge sharing.
2026-08-03
Shell
★ 1437
MagiskFrida is a tool that enables the automatic execution of the Frida server on device boot across multiple root solutions, including Magisk, KernelSU, and APatch. It supports various architectures such as arm64, arm, x86, and x86_64, and provides instant updates by integrating with the official Frida build process. This tool is particularly beneficial for developers, reverse-engineers, and security researchers looking to leverage dynamic instrumentation in rooted Android environments.
2026-08-03
Shell
★ 11
This tool demonstrates a local privilege escalation exploit for Sudo versions 1.6.x up to 1.6.9p21 and 1.7.x up to 1.7.2p4, specifically addressing the vulnerability in the sudoedit command that allows arbitrary command execution as the root user. The primary use case is to set up a vulnerable Docker environment for educational testing, enabling attackers to exploit the flaw and gain root access. Notable features include the provision of a simple Docker setup and a scripted exploit for demonstration purposes.
2026-08-03
Shell
★ 15
This repository provides a local privilege escalation exploit for the Sudo vulnerability identified as CVE-2015-5602. It utilizes a flaw in the sudoedit functionality that allows a malicious user to exploit symlink attacks, enabling them to gain root access by modifying sensitive files. The tool includes a Docker setup for mimicking a vulnerable environment, along with an exploit script for demonstration purposes.
2026-08-03
Shell
★ 208
Yodo is a cybersecurity tool designed to exploit limited sudo permissions to escalate privileges on a Unix-like system, utilizing techniques such as the dirty COW exploit and the Pa(th)zuzu vulnerability check. It features additional checks for overwrite permissions on sudo commands, the examination of command history for privilege escalation opportunities, and the capability to replace commands with root privileges.
2026-08-03
Shell
★ 20
The CVE-2020-28243 tool exploits a command injection vulnerability within SaltStack's Salt, allowing for privilege escalation on affected minions when the master executes the `restartcheck` command. Notable features include a straightforward exploit script (`exploit.sh`) for executing arbitrary commands, and the capability to utilize pre-compiled static binaries if gcc is unavailable on the target system. This tool targets SaltStack versions from 2016.3.0rc2 to 3002.2, requiring specific access permissions to function effectively.
2026-08-03
Shell
★ 33
The Docker Privesc script is designed to exploit misconfigurations in Docker environments for privilege escalation purposes. Its primary use case is to gain elevated permissions by leveraging Docker's default configurations, especially in scenarios where a user has access to run Docker on a target system. Notable features include simple usage instructions, requirements for operational conditions, and illustrations of potential mitigation strategies to prevent such attacks.
2026-08-03
Shell
★ 16
IAM-Flaws is a bash script designed to identify misconfigurations in AWS IAM User and Group Policy Permissions, facilitating privilege escalation assessments. Its primary use case involves conducting CIS Benchmark checks, enumerating IAM entities (users, groups, policies), and scanning for potential privilege escalation vulnerabilities. Notable features include a modular design for executing various checks independently, as well as an integrated output logging mechanism for comprehensive analysis.
2026-08-03
Shell
★ 167
MIDA - Multitool is a comprehensive Bash script designed for system enumeration, vulnerability identification, and privilege escalation after system compromise. It integrates features from previous scripts like SysEnum and RootHelper, allowing users to gather detailed system information, check for useful utilities, download external tools, and search for potential cleartext credentials. Notably, it provides a robust framework for facilitating various tasks crucial for post-exploitation activities.
2026-08-03
Shell
★ 18
Mobile Heavy Artillery is a comprehensive toolkit designed for red teaming operations, facilitating reconnaissance, exploitation, and privilege escalation tasks. It includes a curated collection of open-source tools for network enumeration, web vulnerability assessment, secrets discovery, and OSINT activities, all easy to install and manage through a makefile. Notable features include a wide range of utilities for various cybersecurity processes, making it a versatile choice for penetration testers and security researchers.
2026-08-03
Shell
★ 188
PE-Linux is a Linux privilege escalation tool designed to gather extensive system and environment information to identify potential vulnerabilities and misconfigurations. Its primary use case is to assist security professionals in auditing Linux systems for privilege escalation risks through features such as user enumeration, vulnerability checks, log analysis, and the collection of sensitive information like passwords and SSH keys. Notable features include kernel vulnerability checks, cron job enumeration, and detailed system information gathering to facilitate privileged access exploitation assessments.
2026-08-03
Shell
★ 82
The polkadots tool is a local privilege escalation exploit targeting CVE-2021-3560, allowing the creation of a new privileged user to gain root access on affected Linux distributions such as RHEL 8, Fedora 21, Debian testing, and Ubuntu 20.04. It includes functionality to generate hashed passwords using OpenSSL, enabling users to customize account credentials during the exploit execution. Notable features include customizable account names and password hashes, along with default settings for easy deployment.
2026-08-03
Shell
★ 505
RootHelper is a Linux privilege escalation tool that facilitates the exploitation process on compromised systems through an array of eleven scripts designed for enumeration, exploit suggestion, and deployment. Notable features include support for command-line flags for quicker access and execution, as well as a collection of additional tools for enumeration and exploit deployment, such as Auto-Root-Exploit and Linux Smart Enumeration. This comprehensive suite aids penetration testers in efficiently performing privilege escalation tasks.
2026-08-03
Shell
★ 26
SUIDer is a Linux script designed to streamline the privilege escalation process by identifying exploitable binaries with the SUID bit set. It leverages GTFObins to provide relevant exploitation methods and generates links for reference. Notably, it emphasizes caution, as some SUID binaries may require custom methods not covered by the provided resources.
2026-08-03
Shell
★ 12
Suidsploit is a penetration testing tool designed to exploit 137 files with the Suid bit set, enabling attackers to potentially gain elevated privileges on a target system. Its primary use case includes obtaining a root shell, accessing sensitive files such as /etc/shadow, and establishing reverse shells. Notable features include the ability to download the tool via a simple HTTP server and its focus on user-friendly execution on both the attacker's and victim's machines.
2026-08-03
Shell
★ 10
The Linux Privilege Escalation Cheatsheet provides a comprehensive collection of detection and exploitation methods for common privilege escalation vulnerabilities in Linux systems. It includes techniques for exploiting SUID binaries, weak file permissions, and environmentally controlled executions, along with practical command examples for each method. Notable features include links to tools like `linux-exploit-suggester`, as well as code snippets for exploits that can be compiled and executed, making it a valuable resource for penetration testers and security professionals.
2026-08-03
Shell
★ 16
MSAPer is an automated mass exploitation tool designed for identifying and exploiting the CVE-2023-3076 vulnerability in MStore API versions below 3.9.9, which enables unauthenticated privilege escalation through mass addition of admin accounts and PHP file uploads. The tool utilizes GNU Parallel for efficient execution and requires a list of target URLs as input. Notable features include the ability to run on both Linux and Windows platforms, along with installation instructions for necessary dependencies.
2026-08-03
Shell
★ 13
AKQ_0D_PE is a playful tool designed to simulate a Zero-day local privilege escalation exploit targeting a vulnerability in the Linux PipeFS subsystem. It demonstrates memory corruption techniques, ROP injection, and namespace traversal, all while providing an interactive root shell, but it is ultimately a prank and does not exploit a real vulnerability. The tool serves as an educational illustration of exploitation methodologies and is intended for demonstration purposes only.
2026-08-03
Shell
★ 80
The Archive is a continually evolving repository that curates hacking methodologies, cheatsheets, and conceptual breakdowns, specifically designed to be a human-curated alternative to the increasing reliance on LLMs. Its primary use case is to provide easily accessible, spell-checked information along with referenced content derived solely from clear-net sources. Notable features include the inclusion of alternative resources with descriptions, page differentiation for talk notes, and plans for future enhancements such as a public REST API for querying the data.
2026-08-03
Shell
★ 51
The "benchmark-privesc-linux" tool provides a comprehensive benchmarking environment for testing Linux privilege escalation vulnerabilities, where a low-privilege user attempts to gain root access. It offers both virtual machine and Docker container setups for testing various single-step privilege escalation scenarios in an isolated manner, ensuring security and reproducibility. Key features include customizable vulnerability scenarios, support for running tests in both VMs and Docker, and complete open-source access for academic and experimental use.
2026-08-03
Shell
★ 35
The Hacking Study Guide serves as a comprehensive resource for individuals preparing for cybersecurity certifications such as eJPT, PNTP, and OSCP. It encompasses essential topics including Windows and Linux privilege escalation, bug bounty techniques, and operational security intelligence (OSINT), providing checklists and detailed notes for practical learning. The tool is designed to enhance users' understanding of ethical hacking methodologies, enabling them to detect, prevent, and remediate security vulnerabilities effectively.
2026-08-03
Shell
★ 14
rfxn-defense is a Linux defense tool that provides a responsive mitigation layer against local privilege escalation (LPE) vulnerabilities by deploying kernel-level protections as soon as new vulnerabilities are identified. It supports automatic updates every four hours and requires no system reboots to apply mitigations, currently covering seven LPE classes across two families, including various techniques such as `LD_PRELOAD` and `modprobe` interventions. This tool is designed for ease of installation and ongoing security management within environments running Enterprise Linux distributions.
2026-08-03
Shell
★ 19
mOrc is a post-exploitation framework specifically designed for macOS, developed in Bash. Its primary use case is to facilitate post-exploitation activities by providing a shell environment that minimizes traceable artifacts, such as disabling the history file and preventing core dumps. Notable features include its integration as an ENV script and its capability to execute various post-exploitation commands securely.
2026-08-03
Shell
★ 17
mythic-crate is a development environment for the Mythic Command and Control (C2) framework, designed to run on Ubuntu 18.04 using VirtualBox and Vagrant. It automates the setup of Mythic dependencies, facilitates port forwarding, and enables folder sharing between the host and guest systems. Notable features include SSH access, streamlined administration via host commands, and the ability to customize VM disk size.
2026-08-03
Shell
★ 401
Orc is a post-exploitation toolkit designed for Linux environments, implemented in Bash. It provides a variety of functions for privilege escalation, system enumeration, and network analysis, while ensuring output is concealed by using a temporary directory that is auto-deleted on exit. Notable features include functionalities to check Docker access, list D-Bus services, and exploit known vulnerabilities, making it a versatile component for offensive security operations.
2026-08-03
Shell
★ 43
PXEnum is a shell script designed for automated post-exploitation enumeration on *NIX systems, facilitating the collection of essential system and network information to aid security assessments. It executes a comprehensive set of checks related to user, hardware, BIOS, network activity, and permissions, providing an organized output of findings, while ensuring compatibility across various Unix-like environments. Notable features include the ability to read directly from system files for improved reliability and the streamlined output format for enhanced readability.
2026-08-03
Shell
★ 27
SBD is a script designed to provide users with access to essential Linux utilities on compromised systems, including the ability to deploy BusyBox and download static binaries for various networking tools like Ncat, Socat, Nmap, and Ngrok. Its primary use case is to enhance functionality on a limited or compromised environment by offering a menu-driven interface for managing these utilities. Notable features include the ability to set output directories for downloads, clean up downloaded files, and a straightforward installation process using available commands like `wget` or `git`.
2026-08-03
Shell
★ 537
swap_digger is a Bash script designed for automating the analysis of Linux swap space for post-exploitation and forensic purposes. It extracts sensitive information such as user credentials, web form credentials, and WiFi keys from the swap area, and offers extensive options for customization, including extended searches and optional logging. The tool is especially useful in penetration testing scenarios and can operate on local or mounted swap devices.
2026-08-03
Shell
★ 14
Rogue is a bash script that automates penetration testing workflows by integrating tools such as Nmap, Metasploit, and John the Ripper. It streamlines the scanning, exploiting, and reporting phases of pentesting, providing a modular and customizable experience for security professionals. Notable features include automated scans, exploitation configuration, credential harvesting, and structured report generation, all initiated with a simple input of a target IP address.
2026-08-03
Shell
★ 52
Searchbins is an offline command-line tool designed to search for GTFOBins binaries that allow users to bypass local security restrictions in misconfigured systems. Its notable features include the ability to enumerate specific binary functions, display commands to exploit those functions, maintain an up-to-date GTFOBins database, and allow for file-based binary searches. This tool serves as a valuable resource for security professionals to identify and utilize potential vulnerabilities in binary applications.
2026-08-03
Shell
★ 13
linux-priv-esc-audit is a Linux system auditing script designed to identify privilege escalation vulnerabilities and enhance security. It offers dual-mode operation for both root and low-privilege users, generates comprehensive audit reports with vulnerability insights, and provides user-friendly guidance throughout the audit process. Regular updates ensure the tool remains effective against new security threats and techniques.
2026-08-03
Shell
★ 10
Delebetor is a utility designed for installing and managing penetration testing tools by organizing them based on their installation methods, such as `apt` packages and `git` repositories. Notable features include detailed per-tool installation status reporting, a dedicated toolset for web assessments, and a secure deletion option that requires confirmation to clean up installed tools and history. The tool is intended for interactive or command-line use on `apt`-based distributions like Kali Linux, Debian, or Ubuntu.
2026-08-03
Shell
★ 16
The TMAS Scan Action is a GitHub Action that integrates the TMAS (TrendAI™ Artifact Scanner) CLI tool to scan artifacts in the GitHub workspace for open-source vulnerabilities, malware, or sensitive secrets. Notable features include detailed scan results displayed in action logs, summary reports in job summaries, and automated comments on related pull requests, enhancing CI/CD pipelines with security assessments for files, directories, and container images.
2026-08-03
Shell
★ 4660
Kaitai Struct is a declarative language designed for describing binary data structures like file formats and network packet formats. Its primary use case is simplifying the parsing and representation of binary data by allowing a single format description (.ksy file) to be compiled into source files in various programming languages, thereby providing an easy-to-use API for accessing the data. Notable features include support for multiple programming languages, a visualizer for debugging format definitions, and a rich collection of pre-existing format descriptions.
2026-08-03
Shell
★ 171
Awesome is an open-source repository that aggregates a variety of tools and resources across multiple domains including communication, development, finance, and information security. Its primary use case is to provide users with a centralized catalog of high-quality software, libraries, and educational resources, aiding in quick access to knowledge and tools. Notable features include a structured table of contents for easy navigation and a focus on simplicity, readability, and collaboration best practices.
2026-08-03
Shell
★ 17
CATANA is a command-line tool designed to filter wordlists based on specified password policies, enhancing the efficiency of password cracking activities. Its primary use case is to streamline the selection of potential passwords from large datasets, allowing users to customize output through various command-line options, including colored output and file redirection. Notable features include easy input and output management, succinct help documentation, and compatibility with tools like BlackArch Linux for straightforward installation.
2026-08-03
Shell
★ 356
cgPwn is a specialized Ubuntu virtual machine designed for hardware hacking, reverse engineering (RE), and wargaming, equipped with an extensive suite of tools such as Pwndbg, Pwntools, and Radare2. Its primary use case is to provide a comprehensive environment for cybersecurity practitioners to develop, test, and exploit vulnerabilities. Notable features include easy setup using Vagrant, a sophisticated collection of debugging and exploitation tools, and customizable configurations through personal dotfiles.
2026-08-03
Shell
★ 11
Flagy is a comprehensive toolkit designed for Capture The Flag competitions, integrating a wide array of cybersecurity tools across multiple domains including cryptography, forensics, reversing, steganography, and web security. Notable features include automated cryptanalysis tools, credential dumping utilities, and advanced reversing frameworks like Ghidra and radare2, all aimed at facilitating the installation and use of essential tools for both beginners and advanced users in security challenges.
2026-08-03
Shell
★ 13
LinEnum is a bash script designed for enumerating information on Linux machines, particularly useful during initial access assessments in OSCP Labs and Capture the Flag (CTF) scenarios. It streamlines the process of gathering system and network data without focusing on kernel vulnerabilities, making it an efficient tool for reconnaissance tasks. Notable features include ease of use and targeted information retrieval to aid in privilege escalation efforts.
2026-08-03
Shell
★ 66
oscp-ctf is a collection of Bash scripts designed to streamline tasks for users engaged in OSCP labs, HackThebox, or Capture The Flag (CTF) competitions. Notable features include password cracking with John The Ripper, easy HTTP server setup, and customizable PHP reverse shell generation, among others, which enhance efficiency and convenience in penetration testing environments.
2026-08-03
Shell
★ 32
The Pentest Tools Installation Automator streamlines the setup of essential penetration testing utilities on both Debian- and Arch-based systems. It not only installs critical tools such as `nmap`, `sqlmap`, and `gobuster`, but also provides commonly used wordlists directly in the installation process. The tool supports optional installations for additional resources, enhancing flexibility for users in security assessments.
2026-08-03
Shell
★ 72
ctf-collab is a collaborative programming environment designed for solving Capture The Flag (CTF) challenges directly within GitHub Actions. This tool allows users to create ephemeral, session-based environments where they can work together in real-time, utilizing either a secure Tor connection or a lower-latency ngrok connection. Notable features include integration with git for data saving, a configurable tmux setup for multiple sessions, and easy deployment from a GitHub template repository.
2026-08-03
Shell
★ 13
Zero-Setup is a Bash script designed to automate the installation of essential tools and software for cybersecurity professionals, facilitating the rapid configuration of a hacking environment with a single command. It categorizes various utilities, including cryptography, OSINT, steganography, and digital forensics tools, streamlining the setup process while ensuring comprehensive coverage of necessary resources for penetration testing and security analysis. Notable features include easy installation steps and a structured approach to organizing tools based on their respective domains.
2026-08-03
Shell
★ 14
LibcSearcher3 is a Python tool designed for Capture The Flag (CTF) competitions, facilitating the search for function offsets in the C standard library (libc) when a function address is leaked. Its notable features include the ability to initialize a libc database, add constraints for more accurate results, and query multiple libc versions through a command-line interface or programmatically. This tool leverages the libc-database for efficient lookups and is aimed at reducing the time spent manually verifying common libc versions.
2026-08-03
Shell
★ 44
TryHackMe is a cybersecurity training tool that provides structured learning paths for users to develop their skills in various domains such as penetration testing and cyber defense. It features hands-on modules and challenges that allow learners to practice offensive and defensive security techniques, offering certifications upon completion of specific tracks. Notable capabilities include the ability to quickly download and execute training scripts, facilitating an interactive learning experience.
2026-08-03
Shell
★ 392
TryHackMe is a free cybersecurity learning path designed to advance users from novice to expert through a range of practical exercises, introductory Capture The Flag (CTF) challenges, and educational modules covering topics like OpenVPN, Linux fundamentals, web scanning, and Metasploit. This resource is suitable for both newcomers to the field and those looking to enhance their skills, and it culminates in a comprehensive foundation in cybersecurity, preparing users to address more complex challenges. Notable features include diverse content formats, hands-on labs, and accessible learning materials to foster practical experience in cybersecurity practices.
2026-08-03
Shell
★ 660
The Bug Bounty repository serves as a comprehensive resource for security researchers engaged in vulnerability discovery and reporting, aggregating tools, checklists, and cheat sheets to streamline the bug hunting process. Key features include curated lists of bug bounty programs, essential tools, and educational resources, enhancing the usability and effectiveness of cybersecurity efforts. This tool is designed to aid both novice and experienced bug bounty hunters in their pursuits.
2026-08-03
Shell
★ 35
The github-scanner-local tool enables users to locally scan all repositories of a specified GitHub organization. Its primary use case is to identify and analyze URLs within the repositories, facilitating the detection of broken links and dependency management. Notable features include repository cloning, URL extraction, and status code validation for the identified links, along with the capability to search for specific strings across all cloned repositories.
2026-08-03
Shell
★ 10
IP-Vortex is an advanced IP rotation tool designed for security professionals, enabling anonymous security testing by frequently changing public IP addresses. Its primary use case is to facilitate fuzzing and vulnerability scanning while avoiding IP-based rate limiting, featuring automatic IP rotation, timed intervals, multi-interface support, and optional MAC address randomization. Notable features include comprehensive logging, network status monitoring, and seamless integration with security testing workflows.
2026-08-03
Shell
★ 15
nucleihubquery is a bash utility designed to extract and organize search dorks from the nucleihub-templates YAML collection. Its primary use case is to facilitate reconnaissance by generating targeted search queries for multiple asset discovery platforms, enabling users to run structured scans based on vulnerability templates. Notable features include deduplication of queries, generation of severity-based outputs per provider, and a straightforward integration with standard Unix utilities.
2026-08-03
Shell
★ 218
Pentest Lab is a Docker Compose-based local pentesting environment that sets up multiple victim services alongside a Kali Linux attacker service. Its primary use case is to facilitate penetration testing and security assessments through a variety of pre-configured applications like Juice Shop and DVWA, and it includes a Heimdall interface for easy navigation of services. Notable features include automated dependency checks, customizable service configurations, and integrated monitoring capabilities using Grafana and Prometheus.
2026-08-03
Shell
★ 117
Sub-Drill is a straightforward script designed for penetration testers and bug bounty hunters to discover subdomains for a given domain using free online services, eliminating the need for API keys. It provides a pipe-able solution that aggregates subdomain data from multiple sources such as ThreatCrowd, CRT.sh, and URLscan.io, and enables optional output to a specified file. This tool is particularly useful for enhancing reconnaissance efforts in security assessments.
2026-08-03
Shell
★ 20
Vasuki is an automation tool designed for security professionals that streamlines the process of subdomain enumeration and vulnerability scanning. It aggregates multiple reconnaissance tools to identify subdomains, check for subdomain takeover potential, and detect various injection parameters including XSS and SSRF. Notable features include integration with tools like Nuclei for vulnerability scanning, notification capabilities for scan results, and an organized output of findings in text files.
2026-08-03
Shell
★ 135
CHOMTE.SH is an advanced automation framework designed for reconnaissance tasks in penetration testing, primarily serving bug bounty hunters and security professionals. Its notable features include subdomain discovery, DNS brute-forcing, quick port scanning, HTTP probing, and detailed reporting capabilities, allowing users to identify vulnerabilities and misconfigurations effectively. The tool is customizable through a flags.conf file and supports deep internet reconnaissance and JavaScript analysis to enhance security assessments.
2026-08-03
Shell
★ 38
Claude CyberSecurity Skills integrates Claude Code to assist bug bounty hunters on platforms like HackerOne and Bugcrowd through an automated end-to-end workflow encompassing reconnaissance, vulnerability hunting, validation, and reporting. The tool offers 30 production-grade skills that utilize real tools and custom payloads, allowing users to efficiently execute tasks by simply describing their objectives. Notable features include tailored report templates and a systematic approach to vulnerability identification across multiple phases including pre-hunt, reconnaissance, and vulnerability validation.
2026-08-03
Shell
★ 22
Claude Security Research Skill enhances the Claude AI with structured security assessment workflows, enabling it to effectively manage and execute security research across multiple phases, including reconnaissance, vulnerability scanning, and reporting. Notable features include tool chaining, automated phase management based on target types, and the capability for Claude to interpret tool outputs, suggest subsequent actions, and compile professional assessment reports. This skill integrates seamlessly into Claude's environment, facilitating detailed and methodical security assessments without generating payloads or exploit code.
2026-08-03
Shell
★ 60
HuntTheBug is an advanced reconnaissance framework tailored for bug bounty hunters, combining over 30 security tools into a streamlined workflow to facilitate automated vulnerability discovery. Notable features include parallel execution for enhanced speed, live domain verification, real-time Telegram notifications for immediate alerts, and comprehensive scanning capabilities for subdomains, URLs, and directories. This toolkit is specifically optimized for use on Kali Linux, ensuring efficient and effective reconnaissance processes.
2026-08-03
Shell
★ 12
ps.sh is a Bash script designed for automated port scanning on specified target hosts, enhancing scan efficiency and reducing time. It offers features such as service discovery through various workflows using Nmap and Masscan, as well as support for scanning multiple targets simultaneously. Notably, users can customize target ports and output directories, making it a versatile tool for network exploration.
2026-08-03
Shell
★ 12
ReconOps is a structured, recon-only framework designed for bug bounty hunters, focusing on mapping and understanding the attack surface before exploitation. It provides a comprehensive methodology and tools for both passive and active reconnaissance, including automated scripts and templates for effective recon operations. Notable features include tiered guidance for various stages of reconnaissance, a checklist for engagements, and extensive documentation on techniques and tools.
2026-08-03
Shell
★ 15
Web Recon Automation is an automated reconnaissance script designed for bug bounty hunters and penetration testers, enhancing the efficiency of subdomain enumeration, live host discovery, vulnerability scanning, and reporting. Key features include automated dependency checks, integration with tools like `subfinder`, `httprobe`, `nmap`, and `nuclei`, as well as comprehensive reporting that summarizes findings in a structured Markdown format. The tool simplifies the reconnaissance process by allowing users to conduct multiple security checks with a single command execution.
2026-08-03
Shell
★ 19
Facebook SSL Pinning Bypass is a tool designed to circumvent SSL/TLS certificate pinning in the Facebook app on Android devices, enabling users to intercept and analyze HTTPS traffic. It supports both rooted and non-rooted devices and functions with various proxy tools such as Burp Suite and mitmproxy. The tool provides a patched APK for different architectures, facilitating ease of use for security testing and debugging activities.
2026-08-03
Shell
★ 19
The Instagram SSL Pinning Bypass tool allows users to disable certificate pinning in the Instagram app on Android devices, enabling the interception and analysis of HTTPS traffic. It is especially useful for security researchers and developers who wish to inspect API endpoints and media delivery while supporting both rooted and non-rooted devices. Key features include compatibility with multiple Android architectures and the availability of patched APKs for specific Instagram versions.
2026-08-03
Shell
★ 13
Meta Business Suite SSL Pinning Bypass is a tool designed to circumvent SSL/TLS certificate pinning for the Meta Business Suite application on Android devices, allowing for the interception and analysis of HTTPS traffic using various proxy tools like Burp Suite and mitmproxy. The tool is compatible with both rooted and non-rooted Android devices, and it supports multiple architectures, enabling users to capture and debug network requests effectively. Notable features include a step-by-step setup guide and the provision of a patched APK for seamless operation.
2026-08-03
Shell
★ 88
The orgs-data repository is designed to assist bug bounty hunters in identifying leaked secrets, vulnerabilities in GitHub Actions workflows, and conducting reconnaissance by gathering information from organizations' repositories. Notable features include scripts for listing GitHub organization names and tracking programs for potential vulnerabilities, along with a collaborative approach to maintain an up-to-date database of organizations and bug bounty programs.
2026-08-03
Shell
★ 16
Threads SSL Pinning Bypass allows users to bypass SSL certificate pinning in the Meta Threads app on Android, enabling the interception and analysis of HTTPS traffic through various proxy tools like Burp Suite and mitmproxy. This project provides a pre-patched APK compatible with both rooted and non-rooted devices, ensuring that security researchers and penetration testers can effectively capture network requests and API responses for version 440.0.0.47.86. Notable features include support for multiple architectures and detailed setup instructions for both physical devices and emulators.
2026-08-03
Shell
★ 106
TIKTOK-SSL-Pinning-Bypass is a tool designed for security researchers and developers to bypass SSL certificate pinning in the TikTok app on Android devices, facilitating the interception and analysis of HTTPS traffic. Its notable features include compatibility with both rooted and non-rooted devices, support for various proxy tools, and recent enhancements that allow full functionality on Android 11 and above, including the capture of login and registration traffic. The tool provides a pre-patched TikTok APK, enabling users to inspect API calls and the app's network interactions seamlessly.
2026-08-03
Shell
★ 65
FireStorePwn (fsp) is a vulnerability scanner designed to analyze APK files for weaknesses in Firestore database security configurations, assessing both authenticated and unauthenticated access. Its primary use case is to identify insecure rules that could allow unauthorized data manipulation or access, potentially resulting in data theft and increased billing. Notable features include the ability to scan APKs with or without authentication using both user credentials and tokens.
2026-08-03
Shell
★ 34
R3CON is a multifunctional web reconnaissance and vulnerability scanning tool designed for rapid crawling and detailed vulnerability detection across various attack vectors, including XSS, SQL injection, and open redirections. It offers multi-threaded crawling capabilities and extensive reconnaissance features, such as DNS lookups, subdomain enumeration, and identification of vulnerable libraries. The tool allows users to perform both active and passive scans, providing a comprehensive solution for web application security assessments.
2026-08-03
Shell
★ 13
TopScan is an automated web vulnerability scanner designed to quickly identify security weaknesses in web applications. Its primary use case includes subdomain enumeration, active subdomain verification, and vulnerability checks for XSS, information disclosure, and subdomain takeover, among other features. Notable functionalities include gathering WHOIS information, extracting URLs from sitemaps, and detecting hidden servers and admin panels.
2026-08-03
Shell
★ 29
WordPress_AutoExploiter is a cybersecurity tool designed for exploiting vulnerabilities in various versions of WordPress, including Stored XSS, XML-RPC DDoS, and SQL Injection. Its primary use case is for penetration testing and security assessments to identify weaknesses in WordPress installations. Notable features include targeting specific vulnerable versions and facilitating exploitation techniques through a user-friendly interface.
2026-08-03
Shell
★ 10
StealthNewSQL is an advanced command-line tool designed for detecting, exploiting, and securing NewSQL database vulnerabilities. It features capabilities such as DNS-based data exfiltration, advanced WAF evasion techniques, automated exploitation, and seamless integration with CI/CD pipelines, making it suitable for penetration testers, security researchers, and developers focused on database security. Notable functionalities include real-time monitoring, comprehensive reporting, and a modular plugin system for extending its capabilities.
2026-08-03
Shell
★ 20
The Xray automation script is a Bash utility designed for scanning websites for vulnerabilities using the Xray tool. It provides functionalities to scan multiple URLs from a text file or a single URL, with the added capability to download and install Xray if it is not already present. Notable features include comprehensive help documentation and the ability to output scan results both to a file and the terminal.
2026-08-03
Shell
★ 50
CloudDefense.AI is an automated web application security testing tool designed to identify vulnerabilities such as SQL injection and cross-site scripting, enhancing overall application security. It supports various security assessments including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API scanning, facilitating a DevSecOps approach by integrating security assessments seamlessly into the development lifecycle. Notable features include its comprehensive application stack risk assessments and compatibility with multiple programming languages and integration points.
2026-08-03
Shell
★ 215
Claude Cybersecurity is an AI-powered code security audit tool designed to enhance vulnerability detection and compliance verification through the integration of 8 parallel specialist agents. It stands out by addressing issues often overlooked by static analysis tools, such as business logic flaws and contextual authorization checks, while supporting a broader range of programming languages and providing in-depth threat intelligence. Notable features include seamless integration with Claude Code, zero configuration requirements, and extensive coverage of vulnerabilities including IaC and container security.
2026-08-03
Shell
★ 13
JitterBug is a reconnaissance tool designed to conduct passive information gathering by querying third-party databases for basic data, open ports, and potential CVEs associated with target IPs, all without direct interaction with the targets. Its stealthy operation ensures minimal detection risk, making it suitable for pre-attack reconnaissance and security assessments. Notable features include the ability to operate without direct engagement with targets and seamless integration within the DiaLog Project.
2026-08-03
Shell
★ 67
Perseus is an interactive security assessment tool that enhances Claude Code's capabilities by facilitating autonomous penetration testing of your codebase. It supports multiple programming languages and frameworks, automatically detecting the project's environment and vulnerabilities across various dimensions, including API security and infrastructure. Notable features include smart auto-detection, engagement modes for different environments, and a structured four-phase assessment methodology to ensure comprehensive evaluation and reporting of security issues.
2026-08-03
Shell
★ 40
honey is an automated supply-chain security tool that orchestrates multiple security scanners to assess vulnerabilities across a developer's machine. It integrates the findings from various scanners, such as bumblebee for compromised packages and osv-scanner for known CVEs, providing a unified verdict and optional daily reports through a messaging system. Key features include scheduling scans, customizable reporting policies, and the ability to suppress previously acknowledged findings.
2026-08-03
Shell
★ 2659
The Awesome OSINT Arsenal is a comprehensive open-source toolkit designed for open-source intelligence (OSINT) and cybersecurity, comprising over 753 tools organized into 50 categories. It facilitates quick installations on various Linux distributions and offers targeted scripts for specific tasks such as red teaming, blue teaming, and forensics, simplifying access to essential security resources. This toolkit supports multi-distro installers and includes a Termux subset for Android, enhancing its versatility for security researchers and practitioners.
2026-08-03
Shell
★ 108
Checker-Scammer is a CLI-based investigative tool designed to ascertain the legitimacy of WhatsApp numbers before initiating transactions, thereby mitigating the risk of falling victim to scams. Notable features include comprehensive data retrieval that encompasses profile pictures, personal information analysis, and an extensive suite of OSINT capabilities for tracking, identifying, and analyzing individuals associated with phone numbers. The tool aims to provide users with a robust mechanism for online transaction security in an increasingly digital marketplace.
2026-08-03
Shell
★ 270
OWASP D4N155 is an information security auditing tool designed to generate intelligent wordlists based on the content of specified target pages. Its primary use case is to assist security professionals in identifying potential vulnerabilities by analyzing web content and extracting relevant terms for testing. Notably, it supports various input methods and custom parameters for tailored wordlist generation while being built primarily in Bash and requiring additional tools like Python and Go for full functionality.
2026-08-03
Shell
★ 50
Intel Codex is a comprehensive operational manual designed for digital investigators and security analysts, emphasizing OSINT methodologies and security protocols. It features over 40 standard operating procedures (SOPs), guides for various social media platforms, and case studies that illustrate practical applications in real-world investigations. Notable elements include legal and ethical compliance frameworks, detailed investigation techniques, and a focus on malware analysis and penetration testing methods.
2026-08-03
Shell
★ 537
BCHackTool is an all-in-one launcher and installer designed for penetration testing and OSINT (Open Source Intelligence) on Kali Linux and Termux environments. It features a menu-driven interface for easy access to a curated set of tools, automates the installation process, and includes helpful flags for managing scripts and tools. This tool streamlines the setup and execution of security testing tools while ensuring users operate within ethical boundaries.
2026-08-03
Shell
★ 329
Carpunk is an advanced CAN Injection Toolkit designed for testing and exploiting vulnerabilities within vehicle CAN (Controller Area Network) systems. Notable features include compatibility with both simulated and real vehicles, the introduction of two new types of CAN injection attacks, and operational functionality tested on Ubuntu and Parrot OS. The tool also facilitates basic sniffing capabilities and requires manual loading of CAN bus drivers for usage.
2026-08-03
Shell
★ 16
Parrot is a lightweight shell-based tool designed specifically for Termux, enabling users to maximize the potential of Linux on their Android devices. Key features include its 100% shell script implementation for compatibility, seamless integration with Termux for mobile development, and a focus on fast performance with minimal dependencies.
2026-08-03
Shell
★ 23
Termux-AutoSetup is a modular toolkit designed for efficiently setting up a Termux environment on Android devices, enabling users to install essential command-line and security tools with a single command. Notable features include a categorized selection of tools for basic functionalities, hacking applications, and custom-built utilities, streamlining the installation process for users. The script is beginner-friendly, requiring minimal initial setup and offering a straightforward execution process.
2026-08-03
Shell
★ 51
Cyberpunx is a comprehensive hacking tool designed for use on Termux or Kali Linux, featuring a wide array of useful functionality for educational purposes. Users can easily install the tool with straightforward setup instructions and access various hacking features through a guided interface. Notably, it emphasizes user responsibility and ethical use.
2026-08-03
Shell
★ 154
JAR is a cybersecurity tool designed for automated reconnaissance and vulnerability scanning of web applications. Its primary use case is to assist security professionals and penetration testers in identifying security flaws through features such as modular scanning capabilities and integration with popular development tools. The tool is built using modern technologies such as React and Docker, enhancing its usability and deployment flexibility.
2026-08-03
Shell
★ 656
M-wiz is a bash-based tool designed for users of the Metasploit Framework on Termux, facilitating the installation, repair, updating, and backing up of the Metasploit environment. It is compatible with both rooted and non-rooted Android devices and offers a user-friendly interface for beginners, as well as features to address common issues such as Ruby errors. This tool significantly streamlines the Metasploit setup process, requiring minimal user input for efficient deployment.
2026-08-03
Shell
★ 24
SMBRelay is an offensive automation tool designed to exploit SMB relay vulnerabilities by intercepting NTLM authentication requests and relaying them to compromised systems to gain remote access. Key features include complete automation of NTLM relay attacks, integration with payload delivery tools like Nishang and MSFVenom, and real-time monitoring of incoming SMB requests, making it ideal for penetration testing in Windows environments. It is specifically developed for use on Kali Linux and focuses on facilitating security assessments by simulating real-world attack scenarios.
2026-08-03
Shell
★ 290
WannaTool is a cybersecurity tool designed for performing assessments on systems, with a primary focus on analyzing and exploiting vulnerabilities. Notable features include its compatibility with various Linux distributions such as Kali, Ubuntu, and Parrot OS, and its straightforward installation process via bash scripts. The tool aims to facilitate penetration testing and vulnerability exploitation in environments where security assessments are required.
2026-08-03
Shell
★ 38
WiFi Jammer v1.3 is an advanced network testing tool designed for evaluating WiFi security with features such as an interactive user interface, automatic monitor mode setup, dual band support, and multiple attack methods including standard deauth and advanced MDK3 attacks. Its primary use case is for educational and authorized penetration testing of wireless networks, providing detailed security analysis and client detection functionalities while ensuring proper network restoration and error handling. The tool is developed for use on Kali Linux and requires essential wireless tools like the aircrack-ng suite for its operations.
2026-08-03
Shell
★ 103
Wifite2 Requirements is a professional installation script designed to set up Wifite2 along with essential penetration testing tools such as hcxtools, hashcat, and aircrack-ng on Debian/Ubuntu-based systems. The script offers features like robust error handling, dependency management, optional update skipping, and detailed logging, making it user-friendly for authorized network testing and educational purposes while ensuring compliance with legal considerations.
2026-08-03
Shell
★ 11
X-tool is a versatile hacking tool that provides a collection of utilities for various cyberattack methodologies, including phishing and DDoS attacks. It facilitates easy installation and management of these tools, enabling users to select and deploy their preferred options seamlessly. Notably, tools are automatically saved in the user's home directory for convenient access.
2026-08-03
Shell
★ 12
Dynasty-C2 is an advanced Command and Control (C2) framework designed for digital operations, primarily on Linux systems, and inspired by anime aesthetics. Key features include a built-in web server for payload distribution, support for multiple agent interactions, and unique agent identification for effective session management. Future enhancements are planned for Windows compatibility and persistent payload capabilities, making it a versatile tool for cybersecurity professionals.
2026-08-03
Shell
★ 137
The email-cracker tool is designed for the brute-force recovery of email account passwords, enabling security professionals to test password strength and enhance email account security. It automates the process of testing multiple password combinations against a specified email address and features an efficient user interface for managing target email inputs and password lists, making it suitable for penetration testing and security audits.
2026-08-03
Shell
★ 135
K-OTP-X is an advanced one-time password (OTP) phishing tool designed for security testing and educational purposes. The tool primarily facilitates the creation of phishing pages that can capture OTPs, featuring tunnelling options such as Ngrok for remote access and requiring a PHP and Apache setup. It is compatible with various Linux distributions and Termux on Android, emphasizing ease of installation and use.
2026-08-03
Shell
★ 824
LinuxDroid is a tool that provides a Linux Command Line Interface (CLI) and Graphical User Interface (GUI) for Android, enabling users to run various Linux distributions on their Android devices. It features a one-click installation script for easy setup, supports multiple distributions like Kali and Ubuntu, and includes essential security tools such as Nmap and Wireshark, making it suitable for tasks like penetration testing and server management. Additionally, it offers multiple desktop environments and window managers, enhancing the user experience across diverse use cases.
2026-08-03
Shell
★ 18
The Endpoints Extractor is a Bash script tool that efficiently retrieves and extracts URLs and API endpoints from HTML, JavaScript, and JSON content found on web pages. It allows users to scan either a single URL or a list of URLs, with the capability to save the extracted results for further analysis, and features a straightforward command-line interface. Key functionalities include the use of `curl` for fetching content, alongside utilities like `grep` and `sort` for refining output, ensuring unique entries in the results.
2026-08-03
Shell
★ 20
Evil-AP is an automation tool designed for conducting Evil Twin attacks, streamlining the process for both cybersecurity professionals and enthusiasts. Notable features include its open-source nature, allowing extensive customization, and the ability to personalize the web interface, making it adaptable for various use cases.
2026-08-03
Shell
★ 59
Hackify is a bash script designed for Debian-based systems that facilitates the rapid installation of penetration testing wordlists and tools with a single command. Its primary use case is to streamline the setup process for cybersecurity professionals and enthusiasts, offering ease of deployment for various pentesting utilities. Notable features include comprehensive installation commands, support for Docker installations, and optional enhancements like Firefox themes and addons tailored for security tasks.
2026-08-03
Shell
★ 11
Linemadpeas is a comprehensive Linux privilege escalation enumeration tool implemented in Bash, designed to thoroughly scan Linux systems for potential privilege escalation vulnerabilities. It offers a user-friendly interface, automatic detection of over 25 vulnerability categories, and detailed exploit methods with executable examples while generating two separate output files for enumeration reports and exploit strategies. This tool is particularly valuable for penetration testing, security auditing, and educational purposes in understanding escalation techniques.
2026-08-03
Shell
★ 264
Nucleimonst3r is a high-speed vulnerability scanner tailored for Red Teams and Bug Bounty Hunters, enabling rapid identification of potential attack targets by fetching and filtering URLs from a specified domain. It leverages the httpx tool for scanning and provides dynamic template generation, real-time scan statistics, and comprehensive report generation, allowing users to customize scans effectively and integrate with other security tools for enhanced testing capabilities.
2026-08-03
Shell
★ 71
setupkali.sh is a setup script designed to enhance the functionality and usability of Kali Linux, particularly for version 2026.2, by integrating features such as root login, Nemo file manager replacement, and Wayland optimization. Its primary use case is to streamline the setup process for cybersecurity professionals and students, ensuring compatibility with the latest tools and improving system management through advanced configuration and verification strategies. Notable features include a smart cleanup strategy, idempotent configuration handling, and enhanced support for various cybersecurity tools.
2026-08-03
Shell
★ 11
BST is a developing suite of security tools designed to facilitate various cybersecurity tasks. Its primary use case encompasses streamlining security assessments and enhancing defensive measures, with a focus on providing a comprehensive toolkit for security professionals. Notable features include modular architecture and the potential for integration with various security frameworks.
2026-08-03
Shell
★ 31
The "Kali-Linux-Complete-Setup" repository is a comprehensive collection of cybersecurity notes aimed at reinforcing foundational knowledge in the field. It consolidates learning materials derived from formal training sessions, offering structured content, personal insights, and practical examples to aid both personal learning and community contribution. This repository serves as an educational resource for aspiring cybersecurity professionals.
2026-08-03
Shell
★ 11
PiSquirrel is a compact, versatile tool designed for red team and offensive security operations, functioning as an inline wiretap for monitoring servers, workstations, and network equipment. Notable features include its ability to mimic Brother printer responses to enhance stealth during network scans, a simplified setup script for quick configuration, and pre-installed tools for various network and penetration testing tasks. The device leverages inexpensive ARM architecture and open-source software, making it a cost-effective solution for cybersecurity professionals.
2026-08-03
Shell
★ 14
PurpleStorm TTPs is a comprehensive repository of commands, tools, techniques, and procedures utilized by the PurpleStorm CTF team, designed to assist in various cybersecurity tasks and challenges. Its primary use case includes facilitating tasks such as file transfers, port forwarding, establishing command and control (C2) channels, and executing penetration testing exploits. Notable features include detailed command examples for tools like Swaks, Ligolo-ng, and NetExec, which enhance users' capabilities in network exploitation and data exfiltration.
2026-08-03
Shell
★ 35
CTF-Notes is a comprehensive resource repository designed for cybersecurity enthusiasts and professionals engaging in Capture The Flag (CTF) competitions. It hosts a collection of notes, code snippets, and recommended tools, along with guidance on essential skills such as reconnaissance, vulnerability identification, and effective note-taking methods. Notable features include structured checklists, various tool recommendations, and training resources to facilitate skill development in cybersecurity contexts.
2026-08-03
Shell
★ 14
Offensive security blog, projects & portfolio by Elimane D.
2026-08-03
Shell
★ 240
Secfiles is a repository that provides a collection of useful files designed for penetration testing, security assessments, and bug bounty hunting. Its primary use case is to facilitate security-related tasks by offering easily accessible resources and scripts. Notable features include a straightforward cloning process and comprehensive release notes for version tracking.
2026-08-03
Shell
★ 42
Venom is a comprehensive collection of tools, resources, and documentation focused on information security, penetration testing, and offensive cybersecurity. Its primary use case is to serve as a centralized repository for cybersecurity professionals seeking various utilities, from analysis and network reconnaissance to incident response and exploit development. Notable features include organized sections for different types of tools, such as anti-virus evasion, cloud security, and forensics, facilitating easy access to resources tailored for various cybersecurity needs.
2026-08-03
Shell
★ 22
yublueflower is a security workflow designed to identify real-world threats by integrating multiple open-source tools, such as urlfinder, katana, and nuclei, to analyze web assets and vulnerabilities. It supports functionalities like session management, web archiving, and extended workflows for optimizing bug bounty results, while mapping findings to known vulnerabilities (CWE/CVE). This tool specifically operates within a Kali Linux environment and is ideal for penetration testers and security professionals looking to enhance their threat discovery processes.
2026-08-03
Shell
★ 48
CVE-2025-32463 is a privilege escalation exploit targeting vulnerable versions of sudo (1.9.14 to 1.9.17) that allows attackers to gain root access without requiring gcc to be installed on the target system. The tool includes pre-compiled payloads for various architectures, directly executing an exploit via scripts, making it notably convenient for users who may lack compilation tools. This exploit is intended solely for educational and authorized testing purposes.
2026-08-03
Shell
★ 530
The CVE-2025-32463_chwoot repository provides a proof-of-concept implementation to demonstrate the privilege-escalation vulnerability in the chroot feature of vulnerable versions of `sudo`. It includes a Docker environment to build and run an exploit that showcases how to gain root access in affected systems. Notable features include a Dockerfile for setting up the environment and a script that facilitates the execution of the exploit inside a container.
2026-08-03
Shell
★ 11
testbuild_exploit is a tool designed to achieve elevated privileges (UID 1000) on vulnerable Android devices running test-signed ROMs by patching system apps to inject a backdoor. This allows users to execute commands with nearly root-level access, although functionality may be limited by SELinux configurations. Key features include the ability to modify any app, not just system ones, and integration with ADB for command execution.
2026-08-03
Shell
★ 20
This tool serves as a proof of concept (PoC) exploit for the Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013, which allow for path traversal and remote code execution (RCE) in versions 2.4.49 and 2.4.50. Its primary use case is to demonstrate these exploits against specified targets, facilitating security assessments and vulnerability testing. Notable features include the ability to read sensitive files and execute arbitrary commands on the server via customizable input parameters.
2026-08-03
Shell
★ 59
Sub-Ringan Framework is an automated bug hunting tool tailored for identifying vulnerabilities in web applications, primarily aimed at bug bounty hunters and cybersecurity professionals. Its notable features include comprehensive subdomain discovery, live URL scanning, detection of XSS, SSRF, SQL injection, and LFI vulnerabilities, along with the ability to efficiently organize target files for enhanced workflow.
2026-08-03
Shell
★ 10
sysnc is a bash wrapper around netcat designed for simplified remote command execution and interactive shell access, particularly on Android devices running Termux. Notably, it can exploit zygote injection (CVE-2024-31317) to establish a system-level shell, allowing for configurable command execution and interaction with a remote server. Key features include an interactive mode with a colored prompt, support for streaming scripts via stdin, and configurable options for host, port, and UID through command-line flags or environment variables.
2026-08-03
Shell
★ 39
Bash is a collection of Bash scripts designed primarily for use by Red Teamers to facilitate offensive security tasks and simplify common operations in a Linux environment. Key features include various exploit scripts targeting vulnerabilities such as CVE-2014-6271 (ShellShock) and CVE-2006-3392 for remote file disclosure, as well as utility scripts for obtaining system information and performing network reconnaissance. The toolset is easily installable via standard Linux practices, promoting accessibility and efficiency for cybersecurity professionals.
2026-08-03
Shell
★ 13
ADPhantom is an interactive Bash wrapper for NetExec, facilitating credential gathering and network enumeration during penetration testing and red team activities. It offers extensive features, including authentication tests, SMB and LDAP enumeration, credential dumping, and password spraying, while automatically generating session logs and reports for efficient documentation. Additionally, it provides advanced functionalities such as a per-step skip system, a Ctrl+C handler for command interruption, and the ability to query deleted Active Directory objects via tombstone controls.
2026-08-03
Shell
★ 12
Arsenal is a versatile cybersecurity tool designed for vulnerability discovery and web application security testing. It automates the process of scanning and identifying common web vulnerabilities such as SQL injection, XSS, and open redirects, while also generating targeted wordlists for various web applications. Notable features include integration with multiple data sources for reconnaissance and the ability to automate tests for local file inclusion and sensitive file exposure.
2026-08-03
Shell
★ 18
Cobalt-Docker is a containerization tool that simplifies the deployment of Cobalt Strike 4.12 team servers within Docker environments, enabling rapid setup and automatic startup of a REST API for interaction. It includes essential features like pre-launch configuration validation, multi-platform support for macOS and Linux, and the ability to deploy with custom Malleable C2 profiles. Additionally, the integration of a REST API enhances automation and streamlines server management.
2026-08-03
Shell
★ 10
Huntbot is a multi-model offensive security tool designed for bug bounty hunting, penetration testing, and red teaming, offering advanced capabilities for vulnerability detection and reporting. Notable features include contextual knowledge accumulation, human-like interaction with web applications, the ability to share live browser sessions, and meticulous false positive validation before report generation. It is extensible with multiple AI models and allows for dynamic steering during runs, enabling security professionals to efficiently explore and validate security vulnerabilities.
2026-08-03
Shell
★ 16
k8s-enum.sh is a toolkit designed for penetration testing and red team operations in Kubernetes environments, featuring two primary scripts: k8s-enum.sh for external enumeration using kubeconfig files and k8s-pod-enum.sh for internal enumeration from compromised pods. It provides comprehensive security enumeration with color-coded output that highlights privilege escalation vectors, misconfigurations, and actionable recommendations, making it a valuable resource for security researchers assessing Kubernetes configurations. Noteworthy features include permission enumeration, namespace and service discovery, and detailed detection of potentially dangerous permissions and settings.
2026-08-03
Shell
★ 63
Kali + OpenClaw Portable Pentest USB is a bootable USB solution that integrates Kali Linux Live with OpenClaw automation for streamlined, portable penetration testing. It addresses key challenges in traditional workflows by offering a pre-configured environment, automation capabilities, real-time documentation of findings, and forensically clean operation that leaves no trace on host systems. Notable features include persistent configurations, a selection of pre-configured templates for various testing scenarios, and support for deploying remote nodes on target networks.
2026-08-03
Shell
★ 39
Mythos Research Edition is an open-source tool designed for vulnerability discovery in software applications, utilizing the publicly available Claude Opus 4.7 model to replicate the eight-phase scaffold of Anthropic's Mythos Preview. It enables open-source maintainers, security researchers, and academics to conduct targeted scans at a low cost, facilitating coordinated vulnerability disclosure while avoiding unauthorized mass scanning. Key features include self-scanning capabilities for project audits and research, without requiring access to Anthropic's proprietary model.
2026-08-03
Shell
★ 17
NAC Bypass is a Linux-based tool designed to create a transparent Layer-2 bridge with two Ethernet interfaces that facilitates bypassing Network Access Control (NAC) mechanisms by inheriting an active authentication session from a legitimate workstation. Its primary use case centers on network penetration testing and security assessments, allowing attackers to forward traffic while maintaining authorized access. Notable features include customizable network interface assignment, built-in options for passive monitoring, and integration with tools like Responder for enhanced functionality.
2026-08-03
Shell
★ 66
NullSec is an advanced penetration testing and red team operations framework that provides a custom ParrotSec-based distribution tailored for offensive security tasks. It features over 150 custom attack modules across multiple categories, full integration with the Metasploit Framework, an AI-powered security assistant, and a user-friendly TUI launcher for easy navigation and module management. The platform supports dual operation modes for safe demos and real attacks, and allows users to build custom ISOs for deployment.
2026-08-03
Shell
★ 82
NullSec Pineapple Suite is a comprehensive payload collection for the Hak5 WiFi Pineapple Pager, featuring 125 payloads organized into 14 categories for various aspects of WiFi security testing, including reconnaissance, interception, exfiltration, and stealth operations. Notable features include an extensive range of attack and reconnaissance payloads, a fast boot optimizer, a user-friendly one-click installation process, and the option for active development support. This suite significantly expands the capabilities of the WiFi Pineapple Pager compared to official and other third-party offerings.
2026-08-03
Shell
★ 2180
pentest-ai-agents is a suite of 50 subagents designed to enhance penetration testing by utilizing Claude Code as an offensive security research assistant. Each agent specializes in areas such as reconnaissance, web applications, Active Directory, and cloud security, offering streamlined automation for various tasks without the need for extensive setup. Notable features include the ability to route tasks to specific experts, support for easy installation as a Claude Code plugin, and a robust validation process to ensure secure and efficient operation of each agent.
2026-08-03
Shell
★ 14
Omniscient V3 is a comprehensive reconnaissance and adversary simulation framework designed to enhance security assessments by consolidating over 130 best-in-class tools into a unified pipeline. Key features include AI-driven results augmentation, distributed execution across platforms such as Kubernetes and Docker, advanced stealth techniques for emulating sophisticated attacks, and immutable audit trails for compliance and reporting. This tool is primarily aimed at security professionals, providing a streamlined approach to identifying vulnerabilities in complex attack surfaces.
2026-08-03
Shell
★ 478
ScanCannon is a high-speed Bash script designed for efficient credentials-based attack surface enumeration and reconnaissance of large external networks, leveraging tools like `masscan` for rapid port detection and `nmap` for detailed service analysis. It outputs consolidated reports in HTML and CSV formats while enabling project-driven scanning that tracks changes over time, facilitating continuous monitoring of attack surfaces. Notable features include full ASN-based discovery, API detection, CVE hinting, and resilience through checkpointing and parallel scanning.
2026-08-03
Shell
★ 64
365 is a comprehensive OSINT and threat hunting tool designed for network and web reconnaissance, discovery, enumeration, vulnerability mapping, exploitation, and reporting. Its notable features include a streamlined setup process for Kali Linux and a range of scripts for automating various security assessment tasks. This tool is primarily used for enhancing security assessments and facilitating vulnerability exploitation in targeted environments.
2026-08-03
Shell
★ 4331
The "Awesome OSINT for Everything" repository provides a comprehensive list of OSINT (Open Source Intelligence) tools and websites tailored for penetration testing, information gathering, and red team operations. It encompasses a wide array of categories, including reverse searching, social media analysis, data leaks, and more, making it an invaluable resource for cybersecurity professionals and bug bounty hunters. Notable features include organized sections by topic, facilitating easy navigation and access to relevant tools across diverse OSINT areas.
2026-08-03
Shell
★ 22
SimpleVenom is a versatile tool for generating Metasploit payloads, featuring multiple user interfaces including a graphical interface (Zenity), a terminal menu interface (Dialog), and a command-line wizard. It intelligently auto-detects the best available interface based on installed tools and supports payload generation for Windows, Android, and Linux systems. The tool is designed for authorized penetration testing and educational purposes, ensuring a user-friendly experience while managing dependencies effectively.
2026-08-03
Shell
★ 33
SnowCorp Lab is a local Active Directory training environment designed for cybersecurity professionals to practice advanced attack techniques. It features a dual-domain setup with two isolated networks and a dual-homed pivot host, allowing users to simulate real-world scenarios safely on their machines without cloud dependencies. The lab is equipped with five virtual machines and multiple flags to enhance learning experiences and is optimized for hardware specifications that support high-performance virtualization.
2026-08-03
Shell
★ 22
DomXssFinder is a tool designed to identify potential sources and sinks within JavaScript code that can lead to DOM-based cross-site scripting (XSS) vulnerabilities. It features two primary commands, `fsource` for locating user-controlled data inputs and `fsink` for spotting dangerous JavaScript functions or DOM objects, aiding developers in securing their web applications against XSS attacks. Notably, it provides context enhancement for findings and integrates with JSextractor for comprehensive JavaScript code retrieval from URLs.
2026-08-03
Shell
★ 382
Kaboom is an automated penetration testing tool focused on information gathering and vulnerability assessment. It integrates multiple utilities such as Nmap, Dirb, Nikto, and Hydra to conduct comprehensive scans and assessments, with results organized in an easily navigable directory. Notable features include support for both interactive and non-interactive modes, extensive customization options, multi-target scanning, and automatic identification of relevant Metasploit modules for vulnerabilities found.
2026-08-03
Shell
★ 10
Minerva is an automated reconnaissance and penetration testing script that streamlines the assessment of a target by integrating multiple tools for tasks such as Nmap scanning, OSINT gathering, and vulnerability enumeration. Notable features include automated Google Dorking for targeting potential admin pages and the use of established tools like theHarvester, amass, and nikto for comprehensive analysis. This tool simplifies the penetration testing workflow, making it accessible for users to execute complex assessments with minimal setup.
2026-08-03
Shell
★ 668
Open-Redirect-Payloads is a tool designed to generate exploit payloads for testing Open Redirect vulnerabilities within web applications. Its primary use case is to assist security professionals in identifying and mitigating open redirect issues by generating URL payloads targeting specific whitelisted domains. Notable features include a simple script (make-payloads.sh) that allows users to customize payload generation based on specified domains.
2026-08-03
Shell
★ 46
The "s3-buckets-aio-pwn" tool is designed to identify vulnerable Amazon S3 buckets as part of penetration testing and bug bounty efforts. It uniquely allows users to scan multiple S3 bucket entries from a text file while employing various attack scenarios to assess their vulnerability. Key features include its command-line usage, integration with AWS CLI, and the capability to quickly filter out false positives during vulnerability assessments.
2026-08-03
Shell
★ 39
Vide.sh is a versatile tool designed for probing and crawling targets to enumerate their attack surface through various scanning engines, such as nmap, httpx, and whatweb. It can process input from various sources, including XML files, lists of targets, standard input, and direct strings, while offering a range of configurable scanning options to tailor the attack surface enumeration according to user needs. Notable features include the ability to skip probing and crawling, run multiple types of scans, and generate organized output, including screenshots and detailed logs of the scanning results.
2026-08-03
Shell
★ 182
Air Script is an automated Wi-Fi network penetration testing tool that simplifies the process of network scanning, handshake capturing, and brute-force password cracking. It features automated attacks on nearby networks, email notifications for successful handshake captures, and compatibility with devices like Raspberry Pi for discreet operation. Users can enhance their workflows by selecting from a variety of additional tools provided within the script.
2026-08-03
Shell
★ 378
Bug-Bounty-Agents provides a collection of specialized AI agent prompts designed for enhancing bug bounty hunting, penetration testing, and offensive security workflows. This tool enables users to deploy focused, production-ready agent personas into various agent-capable LLM clients such as Claude Code, GitHub Copilot Chat, and Cursor, facilitating tasks like reconnaissance, web application testing, and exploit planning without any additional framework dependencies. Notable features include strict scope enforcement and a diverse catalog of 43 agents tailored for different engagement phases, enabling efficient and targeted security assessments.
2026-08-03
Shell
★ 266
GarudRecon is a bash-based reconnaissance automation framework designed for security professionals and bug bounty hunters, facilitating asset discovery and vulnerability assessment through the integration of over 80 open-source security tools. It offers multiple operational modes, such as SmallScope, MediumScope, and LargeScope, to tailor the reconnaissance process according to different engagement scopes, alongside advanced capabilities for automated monitoring and vulnerability detection including subdomain enumeration, port scanning, and exploitation checks. Noteworthy features include a workflow mode for tool chaining, fleet mode for distributed scans, and cron job scheduling for recurring tasks.
2026-08-03
Shell
★ 34
The iOS Binary Security Analyzer is a script designed for performing static analysis on iOS application binaries to identify security weaknesses such as insecure functions, weak cryptographic implementations, and missing security features like code signatures and PIE. Notable features include checks for core binary security mitigations, dynamic library dependencies analysis, and detection of anti-analysis indicators, making it a valuable tool for assessing the security posture of iOS applications on jailbroken devices.
2026-08-03
Shell
★ 94
ScanPro is a menu-driven tool that enhances the functionality of Nmap for network scanning purposes. Its primary use case involves simplifying the scanning process by allowing users to select target IPs, ports, and scan types through an interactive menu, while also facilitating service detection and output formatting. Notable features include support for NSE scripting and HTTP information gathering, making it a versatile utility for penetration testing and network analysis.
2026-08-03
Shell
★ 40
CamHawk is an advanced camera phishing tool designed for security research and penetration testing that simulates an attack by tricking users into granting webcam access. Once access is obtained, it captures images in real-time and sends them to the attacker's machine, offering features like automated dependency installation, multiple tunneling options, and a customizable phishing page. This tool serves as a valuable resource for developers and cybersecurity professionals to understand and mitigate risks associated with webcam exploitation.
2026-08-03
Shell
★ 38
Medusa is a Bash-based orchestration toolkit designed to deploy and manage 35 open-source cybersecurity tools through an interactive menu or command line interface. Its primary use case encompasses environments for Security Operations Center (SOC), Governance, Risk Management, and Compliance (GRC), among others, with notable features such as environment isolation via Docker, pure Bash execution without runtime dependencies, and the ability to run each tool in its own dedicated directory.
2026-08-03
Shell
★ 8039
**reconFTW** is an automated reconnaissance tool aimed at security researchers and penetration testers, streamlining the information-gathering process. It integrates a variety of scanning and enumeration techniques, allowing users to gather extensive details on target domains through an intuitive interface. Notable features include support for multiple platforms, Docker compatibility, and an array of built-in reconnaissance modules that enhance operational efficiency.
2026-08-03
Shell
★ 571
The Samurai Web Training Framework (SamuraiWTF) is a virtual machine framework designed for quickly setting up training environments containing various security tools and intentionally vulnerable applications. Its primary use case is to facilitate cybersecurity training by enabling instructors to create and distribute configured virtual machine images, using tools such as OWASP ZAP and Juice Shop. Notable features include integration with the Samurai Katana project for streamlined tool management and support for deployment on platforms like VirtualBox and Hyper-V.
2026-08-03
Shell
★ 17
autoDeploy is a Bash script designed for customizing Kali Linux by automating the installation of various plugins, applications, and utilities to enhance the user environment. It offers three installation modes: a complete setup, terminal and desktop customization, and installation of third-party applications, with automated error logging for troubleshooting. This tool streamlines the setup process, making it easier for users to tailor their Kali Linux experience.
2026-08-03
Shell
★ 32
bf_active_sub is a subdomain enumeration tool designed for active scanning through brute-force techniques. It efficiently verifies the existence of subdomains by attempting various combinations from a provided wordlist, ensuring zero false positives, and allowing results to be outputted directly in the terminal or saved to a file. Notable features include support for various wordlist sizes and compatibility with Debian-based systems, making it a valuable asset for penetration testing and bug bounty efforts.
2026-08-03
Shell
★ 380
HuntKit is a Dockerized collection of tools designed for penetration testing, bug bounty hunting, red teaming, and capture the flag challenges, enabling rapid deployment and usage without the overhead of a virtual machine. It offers notable features such as quick execution, easy updates, and disposable environments, allowing users to quickly run tools like nmap and commix with minimal setup. The containerization approach streamlines security assessments while providing a convenient method for maintaining the latest versions of essential penetration testing tools.
2026-08-03
Shell
★ 47
OpenRediWrecked is a sophisticated tool designed for security professionals to detect and exploit open redirect vulnerabilities by automating the injection of carefully crafted payloads using the sed utility. Its notable features include parameter cleaning, support for various encoding techniques to bypass filters, and an intuitive output format that highlights vulnerable URLs in a color-coded manner. This makes it an essential asset for Red Teams and Bug Bounty Hunters seeking to improve their testing methodologies.
2026-08-03
Shell
★ 77
ScopeHunter is a targeted reconnaissance tool designed for Red Teams and bug bounty hunters, leveraging up-to-date databases from platforms like HackerOne, BugCrowd, Intigriti, and YesWeHack to facilitate efficient target discovery. Its key features include an intuitive command-line interface, rapid execution, and access to the latest bug bounty program data. The tool is compatible with major operating systems, making it an essential asset for security professionals seeking to streamline their target identification process.
2026-08-03
Shell
★ 163
SQLMutant is a mutation testing tool designed for Red Teams and Bug Bounty Hunters that automates the process of identifying SQL injection vulnerabilities within a specified domain. It leverages tools like Waybackurls, HTTPX, Arjun, and SQLMAP to perform domain enumeration, URL fetching, and SQL injection testing, while providing various fuzzing capabilities for URLs, headers, and form data. Notable features include integration with historical web page archives and aggressive parameter extraction to enhance vulnerability detection.
2026-08-03
Shell
★ 337
TerminatorZ is an Offensive CVE Exploitation Framework specifically designed for red teamers and offensive security professionals, focusing on active exploitation rather than mere vulnerability scanning. It automates reconnaissance across multiple sources, validates live endpoints, and executes 31 deterministic CVE checks, providing real-time feedback with zero false positives and proof-of-concept URLs for confirmed vulnerabilities. With its modular Bash architecture and unique features like asset-type intelligence and production-quality reporting, TerminatorZ streamlines the exploitation process for faster and more credible results.
2026-08-03
Shell
★ 422
WiFiChallengeLab-docker is a containerized environment designed for security practitioners to simulate and practice WiFi attacks on various types of networks, including OPN, WPA2, WPA3, and Enterprise setups. It features a range of updated challenges with new attack vectors, such as WPA3 brute-force and captive portal evasion, alongside enhanced stability by using Docker instead of nested virtual machines. The tool also incorporates nzyme for monitoring and detection, making it a comprehensive solution for hands-on learning in WiFi security.
2026-08-03
Shell
★ 168
XSSRocket is a cybersecurity tool designed for conducting offensive security assessments, primarily focusing on Cross-Site Scripting (XSS) vulnerabilities. It leverages the Wayback Machine to retrieve and filter URLs, uses httpx for live URL verification, and employs a remote XSS payload list to perform GET requests, potentially exposing vulnerabilities. Notable features include stealth mode scanning, automated result storage, customizable payload lists for other injection types, and a user-friendly interface that enriches the output with random security quotes.
2026-08-03
Shell
★ 59
Yggdrasil is a cybersecurity tool designed to automate the installation of missing tools and streamline the configuration of Kali Linux following a fresh setup. Its primary use case is enhancing setup efficiency for cybersecurity professionals by providing automation scripts for various cybersecurity tools, alongside features like systemd service monitoring and deployment category additions. Notable features include customizable installation paths, hardening options, and support for multiple programming environments, making it a versatile resource for security practitioners.
2026-08-03
Shell
★ 11
Chirpy Starter is a Jekyll theme starter repository designed to facilitate the setup and deployment of websites using the Chirpy theme. It streamlines the process by providing essential files and configurations extracted from the theme’s gem, enabling users to quickly deploy feature-rich Jekyll sites while retaining customization options. Notable features include an automated update mechanism for new releases and a focus on user-friendly setup.
2026-08-03
Shell
★ 10
The 5G-Pentest-UE is a penetration testing framework designed to identify vulnerabilities within 5G systems from the perspective of a user equipment (UE), requiring no prior knowledge or access to the network. Its notable features include the ability to configure and run tests against the 5G protocol stack, alongside the integration of patched Open Air Interface implementations to facilitate comprehensive security testing. This framework is particularly useful for assessing security in closed-source and proprietary 5G networks.
2026-08-03
Shell
★ 27
Weaponize-CobaltStrike is an automated toolkit designed to streamline the setup and configuration of Cobalt Strike, enhancing its capabilities with a wide array of Beacon Object Files (BOFs) and offensive security tools. Key features include the automation of dependency installation and compilation of various community-driven tools, such as the CS-Aggressor-Kit and situational awareness BOFs, making it easier for security professionals to extend their Cobalt Strike operations. This tool aims to facilitate authorized security testing and educational purposes while also providing a platform for contributions and improvements from the community.
2026-08-03
Shell
★ 18
LinEnum-ng is a targeted, stable enumeration script designed for Linux privilege escalation, particularly suited for OSCP examinations. Its notable features include kernel CVE detection for various exploits, comprehensive checks for SUID and sudo vulnerabilities with GTFOBins integration, as well as support for container escape assessments in Docker and Kubernetes environments. The output is structured and color-coded for efficient triaging, minimizing information overload.
2026-08-03
Shell
★ 125
mac-cyber-bootstrap is a robust setup script designed to transform a fresh macOS environment into a fully functional security workstation specifically for cybersecurity professionals, CTF participants, and bug bounty hunters. It automates the installation of essential tools, libraries, and configurations under a structured directory, ensuring an organized workspace for various tasks such as OSINT, penetration testing, and malware analysis. Notable features include comprehensive toolchain installations across multiple domains, such as reconnaissance, red teaming, and reverse engineering, all managed through a single command.
2026-08-03
Shell
★ 446
The "missing-cve-nuclei-templates" tool automates the identification and cataloging of missing CVEs in the official Nuclei templates repository, analyzing over 164,000 CVEs to produce a comprehensive list of 65,840 missing entries. It categorizes vulnerabilities by type and year, offering detailed data files for specific threats such as XSS, RCE, SQL Injection, and more, enhancing vulnerability management and template development for cybersecurity professionals. This tool facilitates better detection capabilities by flagging gaps in existing Nuclei templates.
2026-08-03
Shell
★ 16
B1ackOS is a Debian-based international operating system designed to simplify software installation while emphasizing user privacy and security. It features a lightweight setup, live usage capability, a rolling release model for up-to-date software, and extensive repositories catering to a wide range of applications from mundane tasks to advanced programming and penetration testing. The system prioritizes stability and compatibility, making it a robust choice for users seeking a secure computing environment.
2026-08-03
Shell
★ 3619
EMBA is a comprehensive security analyzer specifically designed for the firmware of embedded devices, catering to penetration testers, product security teams, and developers. The tool facilitates the entire security analysis workflow, including firmware extraction, static and dynamic analysis through emulation, SBOM generation, and the creation of web-based vulnerability reports, effectively identifying potential weaknesses such as insecure components or hard-coded passwords. Its command-line interface and ability to present findings in an accessible web format enhance usability and streamline the security assessment process.
2026-08-03
Shell
★ 116
Hacknetics is a comprehensive resource repository designed for OSCP students and Red Teaming professionals, offering a curated collection of code snippets, guides, and pentesting tools. Notable features include ready-to-use code in multiple programming languages, high-level strategies, step-by-step guides, and regular updates to ensure access to the latest techniques and tools essential for penetration testing.
2026-08-03
Shell
★ 98
scope is a CLI tool that provides a curated dataset for querying bug bounty program scopes across various platforms, including Bugcrowd and HackerOne. It enables security researchers to efficiently identify in-scope domains and assets through regular automated updates and a command-line interface for targeted searches. Notable features include categorized files for wildcards, domains, and GitHub repositories, along with a comprehensive list of in-scope and out-of-scope targets for enhanced usability in bug bounty activities.
2026-03-30
Shell
★ 753
Bashark 2.0 is a post-exploitation toolkit designed for penetration testers and security researchers to facilitate operations during the post-exploitation phase of security audits. It offers a simple command-line interface, where users can source the bashark.sh script to access various functions and commands, streamlining the process of managing compromised hosts. Key features include ease of use through a help menu and support for Bash scripting, making it a practical tool for enhancing post-exploitation activities.
2026-03-30
Shell
★ 740
GooHak is an automated tool designed for launching Google hacking queries against specified target domains to uncover vulnerabilities and facilitate enumeration. Its primary use case is to streamline the process of gathering information through tailored search queries, leveraging Google’s search capabilities. Notable features include straightforward command-line usage and dependencies tailored for Linux environments.
2026-03-30
Shell
★ 727
ReconPi is a lightweight reconnaissance tool designed for extensive domain analysis and asset discovery using a Raspberry Pi or a VPS. Its primary functionality includes resolving domain names, subdomain enumeration, vulnerability scanning using Nmap, and integrating tools like Nuclei for template-based security assessments. Notable features include automated reporting, Slack notifications, and easy installation through a straightforward script, making it accessible for cyber reconnaissance tasks.
2026-03-30
Shell
★ 716
The Shark Jack Payload Library provides a collection of community-driven payloads and extensions specifically designed for the Hak5 Shark Jack device, utilizing DuckyScript™ and Bash. Its primary use case is to enrich the functionality of the Shark Jack with customizable scripts for cybersecurity tasks, while also encouraging developer contributions for new payloads. Notable features include a platform for community collaboration and integration with Payload Studio for seamless payload creation.
2026-03-30
Shell
★ 1706
TermuxCyberArmy is a cybersecurity toolkit designed for Termux, primarily facilitating various hacking and scripting tasks. Notable features include compatibility with multiple Linux distributions such as Kali Linux and Parrot OS, as well as ease of installation using basic command-line operations. The tool is particularly suited for security practitioners seeking to enhance their skills in penetration testing and ethical hacking.
2026-03-30
Shell
★ 732
TOP is a vulnerability cataloging tool designed for bug bounty hunters and penetration testers, focusing on proof-of-concept (PoC) exploits for various Common Vulnerabilities and Exposures (CVEs) from recent years. It compiles a list of notable CVEs along with their respective exploits and corresponding GitHub repositories, thereby facilitating ease of access and research for security professionals. Key features include organized yearly summaries of significant vulnerabilities, making it an essential resource for monitoring and exploiting security weaknesses.
2026-03-30
Shell
★ 753
Vegile is a post-exploitation tool designed for maintaining stealthy backdoor/rootkit access on Linux systems. Its primary use case involves establishing persistent access to compromised hosts while enabling features such as process hiding and session unlimited capabilities in Metasploit. Notable functionalities include the ability to automatically restart hidden processes, ensuring persistent access even after termination, and support for various backdoor implementations, including those created with msfvenom.
2026-03-22
Shell
★ 1950
ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!
2026-03-22
Shell
★ 897
today we will hack the admin panel of the site.
2026-03-22
Shell
★ 7958
This is a multi-use bash script for Linux systems to audit wireless networks.
2026-03-22
Shell
★ 1408
Albanian Hacking Tool!! Tools to help you with ethical hacking, Social media hack, phone info, Gmail attack, phone number attack, user discovery, Anonymous-sms, Webcam Hack • Powerful DDOS attack tool!! Operating System Requirements works on any of the following operating systems: • Android • Linux • Unix
2026-03-22
Shell
★ 6114
All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.
2026-03-22
Shell
★ 4584
Unlock an Android phone (or device) by bruteforcing the lockscreen PIN. Turn your Kali Nethunter phone into a bruteforce PIN cracker for Android devices! (no root, no adb)
2026-03-22
Shell
★ 3768
Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK.
2026-03-22
Shell
★ 1010
一键提取安卓应用中可能存在的敏感信息。
2026-03-22
Shell
★ 982
基于ARL-V2.6.2修改后的版本
2026-03-22
Shell
★ 1926
ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server
2026-03-22
Shell
★ 11108
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
2026-03-22
Shell
★ 2269
OSINT tools for Information gathering, Cybersecurity, Reverse searching, bugbounty, trust and safety, red team oprations and more.
2026-03-22
Shell
★ 3475
An ArchLinux based distribution for penetration testers and security researchers.
2026-03-22
Shell
★ 1275
Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
2026-03-22
Shell
★ 2568
🚀 Caido releases, wiki and roadmap
2026-03-22
Shell
★ 2796
Security automation content in SCAP, Bash, Ansible, and other formats
2026-03-22
Shell
★ 1167
Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.
2026-03-22
Shell
★ 881
A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
2026-03-22
Shell
★ 1567
Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)
2026-03-22
Shell
★ 2037
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
2026-03-22
Shell
★ 3931
Custom bash scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux.
2026-03-22
Shell
★ 2012
reverse engineering tools for android(android 逆向工程工具集)
2026-03-22
Shell
★ 2157
红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool
2026-03-22
Shell
★ 812
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
2026-03-22
Shell
★ 800
Insta BruteForce { GH05T-INSTA 7.01 } Fork it...
2026-03-22
Shell
★ 1856
Hardening Ubuntu. Systemd edition.
2026-03-22
Shell
★ 3851
My simple Swiss Army knife for http/https troubleshooting and profiling.
2026-03-22
Shell
★ 1074
Self contained htaccess shells and attacks
2026-03-22
Shell
★ 1114
ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location coordinates an attacker can perform preliminary reconnaissance which will help them in performing further targeted attacks.
2026-03-22
Shell
★ 2142
Hack Instagram From Termux With Help of Tor
2026-03-22
Shell
★ 1059
All in one Instagram hacking tool available (Insta information gathering, Insta brute force, Insta account auto repoter)
2026-03-22
Shell
★ 1891
instahack is a bash & python based script which is officially made to test password strength of Instagram account from termux and kali with bruteforce attack and. it based on tor This tool works on both rooted Android device and Non-rooted Android device. Best Tool For Instagram Bruteforce hacking Tool By Waseem Akram.
2026-03-22
Shell
★ 1603
Asset inventory of over 800 public bug bounty programs.
2026-03-22
Shell
★ 902
Track Location With Live Address And City in Termux
2026-03-22
Shell
★ 1171
🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), OpenAI (GPTBot) and other with daily updates.
2026-03-22
Shell
★ 954
⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)
2026-03-22
Shell
★ 1870
Build a database of libc offsets to simplify exploitation
2026-03-22
Shell
★ 6597
Linux privilege escalation auditing tool
2026-03-22
Shell
★ 3974
Linux enumeration tool for pentesting and CTFs with verbosity levels
2026-03-22
Shell
★ 2201
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
2026-03-22
Shell
★ 1392
Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/
2026-03-22
Shell
★ 16137
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
2026-03-22
Shell
★ 3195
Introducing "URL Making Technology" to the world for the very FIRST TIME. Give a Mask to Phishing URL like a PRO.. A MUST have tool for Phishing.
2026-03-22
Shell
★ 9415
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
2026-03-22
Shell
★ 1156
Open Source research tool to search, browse, analyze and explore large document collections by Semantic Search Engine and Open Source Text Mining & Text Analytics platform (Integrates ETL for document processing, OCR for images & PDF, named entity recognition for persons, organizations & locations, metadata management by thesaurus & ontologies, search user interface & search apps for fulltext search, faceted search & knowledge graph)
2026-03-22
Shell
★ 2098
Homemade Pwnbox :rocket: / Rogue AP :satellite: based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap :bulb:
2026-03-22
Shell
★ 1933
pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)
2026-03-22
Shell
★ 1023
"Randar" is an exploit for Minecraft which uses LLL lattice reduction to crack the internal state of an incorrectly reused java.util.Random in the Minecraft server, then works backwards from that to locate other players currently loaded into the world.
2026-03-22
Shell
★ 876
Ransomwares Collection. Don't Run Them on Your Device.
2026-03-22
Shell
★ 843
Quickly analyze and reverse engineer Android packages
2026-03-22
Shell
★ 1820
Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.
2026-03-22
Shell
★ 4856
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
2026-03-22
Shell
★ 11175
Attack Surface Management Platform
2026-03-22
Shell
★ 4500
SocialBox is a Bruteforce Attack Framework [ Facebook , Gmail , Instagram ,Twitter ] , Coded By Belahsan Ouerghi Edit By samsesh for termux on android
2026-03-22
Shell
★ 2688
Collection of steganography tools - helps with CTF challenges
2026-03-22
Shell
★ 2482
A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
2026-03-22
Shell
★ 2350
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
2026-03-22
Shell
★ 848
New Interface And Loading Screen For Termux Users
2026-03-22
Shell
★ 842
uDork is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories, find IoT devices, detect versions of web applications, and so on.
2026-03-22
Shell
★ 1350
OSINT tool for finding profiles by username
2026-03-22
Shell
★ 1961
venom - C2 shellcode generator/compiler/handler
2026-03-22
Shell
★ 1881
lightweight, dependency-free bash script for security, performance auditing and infrastructure monitoring of Linux servers.
2026-03-22
Shell
★ 1271
An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.
2026-03-22
Shell
★ 848
CPlay2Air / Carlinkit Wireless Apple CarPlay Dongle reverse engineering
2026-03-22
Shell
★ 915
Android Penetration Tool [ RAT for Android ]