Category · 150 repos
Security & Pentesting
Offensive and defensive security: pentesting, scanning, crypto, auth and OSINT. Ranked by star velocity over the last 24 hours.
Showing 101–150 of 150
Pure-Go offensive-security primitives library: syscalls, evasion (AMSI/ETW/unhook/sleepmask), injection, PE packer, credentials, post-ex, C2. MITRE ATT&CK mapped. Authorized research only.
“Python-based cybersecurity project for detecting and blocking malicious websites.”
Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and opens PRs that fix what it finds. MCP both ways: plug in any MCP server as a tool, or drive RedAmon from Claude Code or your o
Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found
Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
A proper approach to pentest a Web application with the mixture of all useful payloads and complete testing guidance of attacks. Designed as a quick reference cheat sheet for your pentesting and bug bounty engagement.
AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.
Google Antigravity (agy) OAuth auth + model access plugin for DeepSeek Harness: multi-account pool, 429 rotation, device fingerprinting, CLI and web login.
DSH digital forensics agent preset - based on Liang Shen mode, designed specifically for the Honglian Huoyan GoldenEyes V4 forensics competition
Bypasses Microsoft's Anti-Malware Scan Interface for a PowerShell session process started through the "Start-Job" cmdlet, the PID of which is accessed using "Enter-PSHostProcess".
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
is a tool to find as much information as possible on Instagram accounts, such as username, full username, post target, account type, number of followers, number of followings and so on.
Authentication system implementing OAuth for secure third-party login and authorization.
Knock-Knock: A Live, Multi-Protocol Honeypot Dashboard of Internet Break-in Attempts - 13 Protocols, an Extensible Framework, and a Threat-Intelligence Database Serving a Public IP Blocklist Feed
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Hacking & Reverse Engineering RTL960x-based xPON ONTs to suit your OLT
Open-source CLI for unrestricted AI - Access powerful models without censorship
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
Beginner-friendly network reconnaissance tool using Python and Nmap for educational port scanning.
Modern networking and security platform providing secure access and connectivity to apps, infrastructure, and AI workloads. Connect and protect your users.
Track Instagram users' activities, profile changes and capture content with beautiful dashboards and instant notifications
Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats
Create adversarial attacks against machine learning Windows malware detectors
The open-source wireless research platform for ESP32.
The orchestration repository for the Burnout 5 / Burnout Paradise decompilation. Includes tools, IDA databases, and reference files to assist agentic reconstruction of the game's C++ source code.
Kingdom Hearts libraries, tools, game engine and documentation
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Windows/Linux/Mac OSX, and self-configuring backdoors. With its Web interface and powerful Console Client, it is the best comb
Crucible — model-agnostic, self-hostable vulnerability discovery harness (Recon → Hunt → Validate → Report)
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud config
A hacker’s guide to FOFA dorking, packed with powerful queries and tips for bug bounty, red teaming and proactive defense - dork smart, find fast, report big.
Local HTTPS and MQTT cloud emulator for Roborock vacuums without rooting or hardware modifications
Galaxy On Fire 3D engine
An AirDrop implementation for Windows, built from scratch by reverse-engineering the protocol. Interoperates with opendrop in both directions.
Source-only Rust/Bevy Skate 3 preservation project with owned-ISO asset setup
🧑🚀 Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC and OAuth 2.1 with multi-tenancy, SSO, and RBAC.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
USB/WiFi penetration-testing platform on ESP32 — BadUSB, HID, mass storage, WiFi Marauder, remote agent, VNC. Fork of USBArmyKnife with LilyGO T-Dongle and CYD support.
Cyber Security Guide: learning paths, courses, books, channels, tools, and communities to help you enter and advance in the field.
🐚 Map a web app's JavaScript to its API — endpoints, GraphQL, routes and leaked keys from bundles and source maps, plus an OpenAPI skeleton. tree-sitter, not regex.
Abyss Engine 2.0 reconstruction
Connect your agents & product to 1,000 APIs.
Ethornell Buriko General Interpreter open source reimplementation
ARES - authorized red-team engagement automation with dashboard, campaign scope, module orchestration, OPSEC controls, encrypted vault, and reporting.
Rapidly identify and mitigate container security vulnerabilities with generative AI.
🕵️♂️ (2-in-1) Email & Username OSINT suite featuring native MCP support for deep data extraction just from a single Email/Username. Analyzes 2720+ actively maintained scan vectors (210+ email / 2510+ username) for security research, investigations, and digital footprinting.
Trace Labs OSINT VM