Category · 150 repos
Security & Pentesting
Offensive and defensive security: pentesting, scanning, crypto, auth and OSINT. Ranked by star velocity over the last 24 hours.
Showing 1–50 of 150
Point Claude at any game. Skills, tools and the fal MCP that let Claude Code mod almost any PC game you own: recon, reverse engineering, fal-generated art/3D/audio, in-game testing, showcase videos.
Useful tool to track location or mobile number
Secure, fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
🥷🏻 0 is the open-source AI security agent that finds, exploits, and fixes vulnerabilities across your stack. [Research Preview - by the Swiss Applied AI & Cybersecurity Research Lab]
Advanced anti-reverse-engineering library made in C++26
Building 70 Projects ranging from beginner to advanced so anyone can — learn from, build upon, use as a reference, or even copy directly. Gamified Cybersecurity learning 👇
Python terminal multitool — OSINT, network utilities, Rich TUI dashboard. Educational use only.
Self-hosted OpenAI-compatible API for Qoder CLI login,workbuddy, with SQLite multi-account routing
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
A production-grade OSINT platform that provides situational awareness across multiple intelligence domains.
Interactive map of OAuth, Conditional Access, Entra Agent ID and MCP authentication flows, step by step
Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, PowerPC, RiscV, S390x, TriCore, X86)
📥 Game Tracker: Counter-Strike 2
Exploit chain for PS5 7.00 - 13.60
Suitable for Android APK reverse engineering analysis
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Cla
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
🚗 A curated list of resources for learning about vehicle security and car hacking.
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Downloads videos and playlists from YouTube
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative - 2nZNHm3Lr9umG3DVrzYwHgktwkuKuJRXqqRqs3ewpump
A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
A spy satellite simulator in your browser, except the data is real. Live open source spatial intelligence on a photorealistic 3D globe.
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Ghidra is a software reverse engineering (SRE) framework
Cloud-native SIEM for intelligent security analytics for your entire enterprise.
AI-driven IoT threat detection mesh — hand-written neural net trained live in the browser, visualized in 3D. No backend.
App version of pixiv-viewer. Another third-party Pixiv app that requires no login, for browsing Pixiv illustrations, animations, manga, novels, and other works. Supports layouts for multiple devices and various browsing layouts, direct connections without a proxy, custom APIs and image hosts, and login via RefreshToken/OAuth/Cookie.
Use openai-codex models and image generation via ChatGPT OAuth for DeepSeek Harness.
A secure, headless Model Context Protocol (MCP) server for automated retro-reversing and bare-metal firmware triage. Utilizes PyGhidra for in-process P-code micro-emulation and multi-generation console ROM auto-triage (Nintendo, PlayStation, Sega) over secure stdio transport
DNS-Blocklists: For a better internet - keep the internet clean!
Hunt down social media accounts by username across social networks
A playable PC port of Sly Cooper and the Thievius Raccoonus, rebuilt through reverse engineering.
Export iMessage data + run iMessage Diagnostics
🕵️♂️ All-in-one OSINT tool for analysing any website
Recon + secret-scanning tool for GitHub orgs - maps an org's public repos plus every contributor's personal repos, then runs TruffleHog's verified-secrets scan across all of it in one resumable pass.
Web path scanner
Reverse engineering the classic GTA Vice City game
A security scanner for your LLM agentic workflows
Decompile, optimize, recompile, and integrate spyware and remote control features into Android Apps with LurkerX, the ultimate tool for security researchers, penetration testers, and ethical hackers.
VeraCrypt EFI Bootloader for EFI Windows system encryption (LGPL)
The official gpt4free repository | various collection of powerful language models | opus 4.6 gpt 5.3 kimi 2.5 deepseek v3.2 gemini 3
The objective of this project is to build a production-grade, Python-based reverse-proxy security firewall that stands between users (or external systems) and Large Language Models (LLMs). Rather than integrating security logic deeply within a specific chat application, this tool intercepts raw HTTP
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
IoT static scanner for secrets, SBOM, CVEs and more.
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
🔍 Interactive Instagram OSINT CLI with pluggable HikerAPI and aiograpi backends