Category · 150 repos
Security & Pentesting
Offensive and defensive security: pentesting, scanning, crypto, auth and OSINT. Ranked by star velocity over the last 24 hours.
Showing 51–100 of 150
Secure Golang web app with best practices: authentication, authorization, input validation, CSRF protection, and secure headers. Example code for secure development.
No-root network monitor, firewall and PCAP dumper for Android
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
A fast and accurate disassembler
A collection of various awesome lists for hackers, pentesters and security researchers
A Simple android remote administration tool using sockets. It uses java on the client side and python on the server side
A modern platform for visual, flexible, and extensible graph-based investigations. For cybersecurity analysts and investigators.
Agent-Native multi-platform reverse engineering and CWE-602 client-side authorization audit workbench.
This repository contains cutting-edge open-source security notes and tools that will help you during your Red Team assessments.
Generate direct m3u playlist for all the channels subscribed in the IPTV Portal
An extensible AI Agent designed specifically for CTFs; it can solve CTF challenges automatically and also collaborate interactively with users to solve them~
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
VC-Strike — VMware vCenter CVE-2026-59310 (unauth root RCE) & CVE-2026-59309 (SRP auth bypass) authorized pentest suite. GUI+CLI, multi-session C2, stdlib-only. 授权测试专用
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
DeepSeek Harness integrated security-analysis plugin: aggregation across Android · Web · Native · Protocol · Malware · AI-Security (9 bundle + 1 preset)
A secure Flask-based web app that generates text hashes (MD5, SHA1, SHA256, SHA512) and RSA key pairs (1024–4096 bits). Perfect for cryptography and security learning.
Uncensored AI models or those fine-tuned for cybersecurity tasks.
Ghidra is a software reverse engineering (SRE) framework
A gh CLI extension that generates and verifies the GitHub Actions dependency lockfile, pinning every action your workflows use to an exact commit.
Mac Sai: the open-source Mac cleaner, optimizer, and malware scanner. A free, Apple-notarized alternative to CleanMyMac, built with Swift 6 and SwiftUI.
One browser tab for PostgreSQL, MySQL, Oracle, SQL Server, MongoDB, Redis, SQLite, Couchbase, ClickHouse, Druid, DuckDB, Turso and more. An open-source SQL IDE with SSO, audit trail and AI-assisted queries MIT licensed, with nothing held back behind an enterprise wall.
🐶 A curated list of Web Security materials and resources.
Defund the Police.
IPv6 attack toolkit
精选 LLM 破甲提示词合集 — Codex / GPT-5.x / Claude / Gemini / DeepSeek / Grok — UNFILTERED MODE · GODMODE · CTF Sandbox
🚀 In-depth research and reproduction archive of 1-day vulnerability PoCs from 2024 to the present. Covers high-value asset vulnerabilities in OA, ERP, security, data communications, large models, containers, and more; focused on practical work and supporting security research and compliance testing.
A remixer for the Elektron Octatrack's OS: modules (custom DSP56300 effects, ColdFire mods, ports of community mods) composed into one firmware image built from your own 1.40C. No firmware distributed.
A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.
Proof of concept for CVE-2026-43786, a local privilege escalation vulnerability in macOS CoreServices that allows an application to gain root privileges.
Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.
Offensive security research in Windows COM. Techniques for pentesters, red teamers, and defenders across the full attack lifecycle: recon, initial access, privilege escalation, lateral movement, persistence, and defense.
A tool for secrets management, encryption as a service, and privileged access management
Deobfuscate obfuscator.io, unminify and unpack bundled javascript
A collection of Linux CTFs to practice your CLI skills
154+ evil portal templates for Flipper Zero + ESP32 Marauder. Custom portals, US & EU brands, deploy tooling.
Xiaohongshu crawler and data collection, Xiaohongshu reverse engineering, direct messages, livestreams, and an end-to-end Xiaohongshu operations solution
Facebook hacking Tools script super fast and user friendly
🧹 Block XSS, SSTI, command injection and path traversal payloads before they reach October CMS
Pure standalone, zero-browser Meta Threads intelligence engine & CLI. Cloud API & SaaS at https://skelepel.id
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
CLI toolkit for email phishing analysis. Parses .eml files, runs heuristic checks on headers, links, and attachments, and outputs structured JSON.
Malware Mutation Using Reinforcement Learning and Generative Adversarial Networks
An AI-based WeChat group chat bot 🤖 supporting message summaries, @-mention questions and conversations, Map‑Reduce long-text chunking, proactive messaging, and long-term memory. Compatible with multiple AI backends including DeepSeek/Claude, with a built-in React web dashboard, prompt sandbox, and configuration management. Simulates keyboard input; no protocol reverse engineering required…
Gotator is a tool to generate DNS wordlists through permutations.
LLM armor tester: an automated penetration-testing tool for AI applications. 700+ payloads, multi-turn attack chains, indirect-injection vectors, context-aware assessment, PDF penetration reports, and in-depth analysis of the attack process. Authorized testing only. LLM armor tester — automated jailbreak & prompt-injection pentest toolkit for AI apps. 700+ payloads, multi-turn attack chains…
Zhàzhàsū Cybersecurity · DeepSeek Harness: an open-source framework that puts penetration testing into an AI Agent. What is it? DeepSeek Harness is a plugin-based AI Agent runtime framework—here, “everything is a plugin.” Built on Cordis, it splits sessions, tools, LLMs, sandboxes, and skills into independent capabilities that can be combined like building blocks. This project comes with 103…
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Agent skills for solving CTF challenges - web exploitation, binary pwn, crypto, reverse engineering, forensics, OSINT, and more