Kwetsbaarhedenbeheer

152 projecten in Beveiliging & identiteit

pentagi

@vxcontrol

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

Zelf te hosten MIT Commit 3 dagen geleden ★ 24.982
77 4/5 gemeten

vuls

@future-architect

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

GPL-3.0 Commit 1 dag geleden ★ 12.269
75 5/5 gemeten

Osintgram

@Datalux

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

Maintainer in de EU GPL-3.0 Commit 12 dagen geleden ★ 14.671
74 4/5 gemeten

emba

@e-m-b-a

EMBA - The firmware security analyzer

GPL-3.0 Commit 2 dagen geleden ★ 3.679
71 4/5 gemeten

openvas-scanner

@greenbone

This repository contains the scanner component for Greenbone Community Edition.

Maintainer in de EU GPL-2.0 Commit 1 dag geleden ★ 4.837
71 4/5 gemeten

strix

@usestrix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Apache-2.0 Commit 1 dag geleden ★ 64.952
70 4/5 gemeten

thc-hydra

@vanhauser-thc

hydra

Maintainer in de EU AGPL-3.0 Commit 2 maanden geleden ★ 12.312
68 5/5 gemeten

codex-security

@openai

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security

Apache-2.0 Commit vandaag ★ 10.853
68 4/5 gemeten

reconftw

@six2dez

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Maintainer in de EU MIT Commit vandaag ★ 8.147
68 5/5 gemeten

cve

@trickest

Gather and update all available and newest CVEs with their PoC.

MIT Commit vandaag ★ 8.100
68 4/5 gemeten

PhoneSploit-Pro

@AzeemIdrisi

An all-in-one hacking tool to remotely take over Android devices.

GPL-3.0 Commit 12 dagen geleden ★ 6.308
68 4/5 gemeten

AllHackingTools

@mishakorzik

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

GPL-3.0 Commit 9 dagen geleden ★ 6.237
68 4/5 gemeten

osv.dev

@google

Open source vulnerability DB and triage service.

Apache-2.0 Commit 1 dag geleden ★ 2.945
68 5/5 gemeten

Nettacker

@OWASP

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Apache-2.0 Commit 1 dag geleden ★ 5.624
67 5/5 gemeten

cameradar

@Ullaakut

Cameradar hacks its way into RTSP videosurveillance cameras

Maintainer in de EU MIT Commit 3 dagen geleden ★ 5.227
67 5/5 gemeten

Awesome-Hacking

@Hack-with-Github

A collection of various awesome lists for hackers, pentesters and security researchers

CC0-1.0 Commit 2 maanden geleden ★ 121.248
66 4/5 gemeten

Awesome-Cybersecurity-Handbooks

@0xsyr0

A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.

GPL-3.0 Commit 7 dagen geleden ★ 4.105
66 4/5 gemeten

Penetration_Testing_POC

@Mr-xn

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

Apache-2.0 Commit 2 dagen geleden ★ 7.500
65 4/5 gemeten

awesome-web-hacking

@infoslack

A list of web application security

MIT Commit 8 dagen geleden ★ 7.278
65 4/5 gemeten

brutespray

@x90skysn3k

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.

MIT Commit vandaag ★ 2.538
65 4/5 gemeten

Active-Directory-Exploitation-Cheat-Sheet

@S1ckB0y1337

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Maintainer in de EU MIT Commit 4 maanden geleden ★ 6.751
64 4/5 gemeten

Learn-Web-Hacking

@LyleMi

Study Notes For Web Hacking / Web安全学习笔记

CC0-1.0 Commit 1 maand geleden ★ 5.550
64 4/5 gemeten

Agentic-Bug-Hunter

@awarexone

AI-powered bug bounty hunting toolkit that works with or without subscription.

MIT Commit 2 dagen geleden ★ 5.176
64 4/5 gemeten

knockpy

@guelfoweb

Knock Subdomain Scan

Maintainer in de EU GPL-3.0 Commit 7 maanden geleden ★ 4.201
64 4/5 gemeten

VulnClaw

@Netw0rkNoob

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

MIT Commit 3 dagen geleden ★ 3.452
64 4/5 gemeten

CyberStrike

@CyberStrikeus

Open-source AI-powered offensive security harness for automated penetration testing.

AGPL-3.0 Commit vandaag ★ 2.877
64 4/5 gemeten

AngryOxide

@Ragnt

802.11 Attack Tool

GPL-3.0 Commit vandaag ★ 1.968
64 4/5 gemeten

copacetic

@project-copacetic

🧵 CLI tool for directly patching container images!

Apache-2.0 Commit 1 dag geleden ★ 1.713
64 4/5 gemeten

h4cker

@The-Art-of-Hacking

This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org

MIT Commit 3 dagen geleden ★ 29.537
63 5/5 gemeten

malicious-pdf

@jonaslejon

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh

BSD-2-Clause Commit 1 maand geleden ★ 4.434
63 4/5 gemeten

cariddi

@edoardottt

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Maintainer in de EU GPL-3.0 Commit 5 dagen geleden ★ 3.780
63 5/5 gemeten

Pentest-Swarm-AI

@Armur-Ai

Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.

AGPL-3.0 Commit 1 dag geleden ★ 2.627
63 4/5 gemeten

medusa

@Ch0pin

Mobile Edge-Dynamic Unified Security Analysis

GPL-3.0 Commit 20 dagen geleden ★ 2.347
63 4/5 gemeten

SSTImap

@vladko312

Automatic SSTI detection tool with interactive interface

GPL-3.0 Commit 1 maand geleden ★ 1.660
62 4/5 gemeten

ssh-mitm

@ssh-mitm

SSH-MITM - ssh audits made simple

Maintainer in de EU GPL-3.0 Commit 13 dagen geleden ★ 1.470
62 5/5 gemeten

DedSec

@dedsec1121fk

Official repository of the DedSec Project.

Maintainer in de EU MIT Commit 5 dagen geleden ★ 1.003
62 4/5 gemeten

gitxray

@kulkansecurity

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

AGPL-3.0 Commit 9 maanden geleden ★ 184
61 4/5 gemeten

Awesome-Hacking-Resources

@vitalysim

A collection of hacking / penetration testing resources to make you better!

GPL-3.0 Commit 4 maanden geleden ★ 17.448
61 5/5 gemeten

redamon

@samugit83

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

MIT Commit 1 dag geleden ★ 2.600
61 4/5 gemeten

mutillidae

@webpwnized

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.

GPL-3.0 Commit 2 dagen geleden ★ 1.525
61 4/5 gemeten

rengine

@yogeshojha

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

GPL-3.0 Commit 5 dagen geleden ★ 8.862
60 5/5 gemeten

afrog

@zan8in

A Security Tool for Bug Bounty, Pentest and Red Teaming.

MIT Commit 1 dag geleden ★ 4.420
60 5/5 gemeten

pentest-ai-agents

@0xSteph

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.

MIT Commit 1 maand geleden ★ 2.274
60 4/5 gemeten

linWinPwn

@lefayjey

linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

MIT Commit 6 dagen geleden ★ 2.220
60 4/5 gemeten

AutoCVE

@larlarua

Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.

AGPL-3.0 Commit 23 dagen geleden ★ 1.416
60 4/5 gemeten

wordlists

@trickest

Real-world infosec wordlists, updated regularly

MIT Commit vandaag ★ 1.799
59 4/5 gemeten

cve-mcp-server

@mukul975

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

Maintainer in de EU Apache-2.0 Commit 8 dagen geleden ★ 1.587
59 4/5 gemeten

Hunting-Queries-Detection-Rules

@Bert-JanP

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

BSD-3-Clause Commit 10 dagen geleden ★ 1.751
58 4/5 gemeten

pentest-ai

@0xSteph

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

MIT Commit 13 dagen geleden ★ 1.700
58 4/5 gemeten

awesome-vulnerable-apps

@vavkamil

Awesome Vulnerable Applications

Maintainer in de EU CC0-1.0 Commit 2 dagen geleden ★ 1.484
58 4/5 gemeten

pwneye

@Hackerest

Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥

Maintainer in de EU GPL-3.0 Commit 20 dagen geleden ★ 303
58 4/5 gemeten

WhatWeb

@urbanadventurer

Next generation web scanner

GPL-2.0 Commit 6 maanden geleden ★ 6.858
57 5/5 gemeten

pacu

@RhinoSecurityLabs

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

BSD-3-Clause Commit 4 maanden geleden ★ 5.343
57 5/5 gemeten

DSInternals

@MichaelGrafnetter

Directory Services Internals (DSInternals) PowerShell Module and Framework

Maintainer in de EU MIT Commit 15 dagen geleden ★ 1.969
57 5/5 gemeten

guac

@guacsec

GUAC aggregates software security metadata into a high fidelity graph database.

Apache-2.0 Commit 1 dag geleden ★ 1.544
57 4/5 gemeten

PayloadsAllTheThings

@swisskyrepo

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

MIT Commit 1 maand geleden ★ 81.227
56 5/5 gemeten

awesome-ethical-hacking-resources

@husnainfareed

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

MIT Commit 5 maanden geleden ★ 3.784
56 4/5 gemeten

Exegol

@ThePorgs

Fully featured and community-driven hacking environment

Maintainer in de EU Commit 6 dagen geleden ★ 3.096
56 4/5 gemeten

cloud_enum

@initstring

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

MIT Commit 3 maanden geleden ★ 2.140
56 4/5 gemeten

agent

@PentesterFlow

Agentic offensive-security in your terminal

Apache-2.0 Commit 26 dagen geleden ★ 1.376
55 4/5 gemeten

Scanners-Box

@We5ter

The Ultimate Open-Source Security Arsenal for Hackers, Enterprises, and AI Agents——面向极客、企业与 AI 智能体的全域开源网络安全工具矩阵

Commit 2 dagen geleden ★ 9.064
54 4/5 gemeten

commando-vm

@mandiant

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

Apache-2.0 Commit 12 maanden geleden ★ 7.809
54 4/5 gemeten

opencve

@opencve

Vulnerability Intelligence Platform

Commit 6 dagen geleden ★ 2.845
54 5/5 gemeten

linkedin2username

@initstring

OSINT Tool: Generate username lists for companies on LinkedIn

MIT Commit 4 maanden geleden ★ 1.857
54 4/5 gemeten

inql

@doyensec

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

Maintainer in de EU Apache-2.0 Commit 17 dagen geleden ★ 1.811
54 5/5 gemeten

GooFuzz

@m3n0sd0n4ld

GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).

GPL-3.0 Commit 9 maanden geleden ★ 1.589
54 4/5 gemeten

dirsearch

@maurosoria

Web path scanner

Commit vandaag ★ 14.760
53 5/5 gemeten

awesome-hacking

@jekil

Awesome hacking is an awesome collection of hacking tools.

Maintainer in de EU Commit 4 maanden geleden ★ 3.996
53 4/5 gemeten

ISMS-PUBLIC

@Hack23

Hack23 Public Information Security Management System:Security Through Transparency and Open Documentation Demonstrating Security Excellence Through Public ISMS Disclosure

Maintainer in de EU Apache-2.0 Commit 8 dagen geleden ★ 67
53 4/5 gemeten

awesome-infosec

@onlurking

A curated list of awesome infosec courses and training resources.

Commit 29 dagen geleden ★ 5.752
52 4/5 gemeten

NoSQLMap

@codingo

Automated NoSQL database enumeration and web application exploitation tool.

GPL-3.0 Commit 2 maanden geleden ★ 3.357
52 5/5 gemeten

cynative

@cynative

Open-source security agents for cloud, code and runtime. 45 built-in agents audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab for privilege escalation, public exposure, supply chain and more, or build your own in one markdown file. Live, read-only access to your infrastructure.

Apache-2.0 Commit 1 dag geleden ★ 209
52 4/5 gemeten

awesome-web-security

@qazbnm456

🐶 A curated list of Web Security materials and resources.

Commit 12 dagen geleden ★ 13.823
51 5/5 gemeten

clairvoyance

@nikitastupin

Obtain GraphQL API schema even if the introspection is disabled

Apache-2.0 Commit 10 maanden geleden ★ 1.529
51 4/5 gemeten

awesome-vulnerable

@kaiiyer

A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.

MIT Commit 3 maanden geleden ★ 1.397
51 4/5 gemeten

OSCP

@0xsyr0

OSCP Cheat Sheet

Commit 14 dagen geleden ★ 3.851
50 4/5 gemeten

pwnagotchi

@jayofelony

(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.

Commit 4 dagen geleden ★ 2.928
50 4/5 gemeten

PlumHound

@PlumHound

Bloodhound Reporting for Blue and Purple Teams

GPL-3.0 Commit 11 maanden geleden ★ 1.319
50 4/5 gemeten

sbom-tools

@sbom-tool

Semantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.

MIT Commit 2 dagen geleden ★ 244
50 4/5 gemeten

RedTeam-Tools

@A-poc

Tools and Techniques for Red Team / Penetration Testing

Commit 5 maanden geleden ★ 9.773
49 4/5 gemeten

hackingthe.cloud

@Hacking-the-Cloud

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.

Commit 4 dagen geleden ★ 2.775
48 4/5 gemeten

cent

@xm1k3

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

Apache-2.0 Commit 4 maanden geleden ★ 1.047
48 5/5 gemeten

evillimiter

@bitbrute

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

Maintainer in de EU MIT Commit 6 maanden geleden ★ 2.021
47 4/5 gemeten

fsociety

@fsociety-team

A Modular Penetration Testing Framework

MIT Commit 26 dagen geleden ★ 1.837
47 5/5 gemeten

ezXSS

@ssl

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

MIT Commit 3 maanden geleden ★ 2.339
46 5/5 gemeten

wstg

@OWASP

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Commit 3 dagen geleden ★ 9.893
45 5/5 gemeten

Infosec_Reference

@rmusser01

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

MIT Commit 11 maanden geleden ★ 5.996
45 5/5 gemeten

scope

@rix4uni

An automated GitHub Actions-based crawler that fetches and updates public scopes from popular bug bounty platforms (like Hackerone/Bugcrowd/Intigriti/etc) (updates every 10 minutes)

Commit vandaag ★ 100
45 4/5 gemeten

Active-Directory-Exploitation-Cheat-Sheet

@Integration-IT

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

MIT Commit 1 jaar geleden ★ 2.768
43 4/5 gemeten

Sn1per

@1N3

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Commit 3 maanden geleden ★ 11.272
42 5/5 gemeten

crlfuzz

@dwisiswant0

A fast tool to scan CRLF vulnerability written in Go

MIT Commit 29 dagen geleden ★ 1.566
42 5/5 gemeten

Buildware-Tools

@v4lkyr0

Buildware-Tools is an all-in-one multitool for security research and automation.

Commit 2 maanden geleden ★ 1.432
42 4/5 gemeten

Web-Fuzzing-Box

@gh0stkey

Web Fuzzing Box - Web 模糊测试字典与一些Payloads

Commit 6 maanden geleden ★ 2.798
41 4/5 gemeten

ScanCannon

@johnnyxmas

A script for credentials-based attack surface enumeration and general reconnaissance of massive external networks

Commit 2 maanden geleden ★ 482
41 4/5 gemeten

monkey

@guardicore

Infection Monkey - An open-source adversary emulation platform

GPL-3.0 Commit 1 jaar geleden ★ 7.096
40 5/5 gemeten

PentestTools

@arch3rPro

Awesome Pentest Tools Collection

Commit 6 maanden geleden ★ 1.790
40 4/5 gemeten

EasY_HaCk

@sabri-zaki

Hack the World using Termux

Apache-2.0 Commit 1 jaar geleden ★ 2.486
39 4/5 gemeten

hoaxshell

@t3l3machus

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

BSD-2-Clause Commit 2 jaaren geleden ★ 3.499
37 4/5 gemeten

masvs

@OWASP

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Commit 5 dagen geleden ★ 2.453
37 4/5 gemeten

devguard

@l3montree-dev

DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project

Commit vandaag ★ 163
37 4/5 gemeten

awesome-shodan-queries

@jakejarvis

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

CC0-1.0 Commit 2 jaaren geleden ★ 7.753
36 4/5 gemeten

changeme

@ztgrace

A default credential scanner.

GPL-3.0 Commit 1 jaar geleden ★ 1.516
36 4/5 gemeten

pentest-guide

@Voorivex

Penetration tests guide based on OWASP including test cases, resources and examples.

GPL-3.0 Commit 5 jaaren geleden ★ 2.837
35 4/5 gemeten

AboutSecurity

@wgpsec

Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。

Commit 8 dagen geleden ★ 1.760
35 4/5 gemeten

Damn-Vulnerable-GraphQL-Application

@dolevf

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

MIT Commit 1 jaar geleden ★ 1.713
35 4/5 gemeten

vulscan

@scipag

Advanced vulnerability scanning with Nmap NSE

Commit 8 maanden geleden ★ 3.786
34 4/5 gemeten

gitjacker

@liamg

🔪 :octocat: Leak git repositories from misconfigured websites

Unlicense Commit 10 maanden geleden ★ 1.606
34 5/5 gemeten

Penetration-Testing-Tools

@mgeeky

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.

Maintainer in de EU MIT Commit 3 jaaren geleden ★ 3.018
33 4/5 gemeten

A-Red-Teamer-diaries

@ihebski

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

Commit 11 maanden geleden ★ 1.936
33 4/5 gemeten

psudohash

@t3l3machus

Generates millions of keyword-based password mutations in seconds.

MIT Commit 1 jaar geleden ★ 1.469
33 4/5 gemeten

inventory

@trickest

Asset inventory of over 800 public bug bounty programs.

MIT Commit 2 jaaren geleden ★ 1.613
32 4/5 gemeten

Lockdoor-Framework

@SofianeHamlaoui

🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources

Maintainer in de EU AGPL-3.0 Commit 1 jaar geleden ★ 1.559
32 5/5 gemeten

passphrase-wordlist

@initstring

Passphrase wordlist and hashcat rules for offline cracking of long, complex passwords

MIT Commit 1 jaar geleden ★ 1.441
32 4/5 gemeten

Reconnoitre

@codingo

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

GPL-3.0 Commit 4 jaaren geleden ★ 2.193
31 5/5 gemeten

OSCPRepo

@rewardone

A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.

MIT Commit 6 jaaren geleden ★ 2.752
30 4/5 gemeten

rapidscan

@skavngr

:new: The Multi-Tool Web Vulnerability Scanner.

GPL-2.0 Commit 3 jaaren geleden ★ 2.135
30 5/5 gemeten

ADB-Toolkit

@ASHWIN990

ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!

GPL-3.0 Commit 2 jaaren geleden ★ 2.031
30 4/5 gemeten

pwncat

@cytopia

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)

Maintainer in de EU MIT Commit 4 jaaren geleden ★ 1.961
30 5/5 gemeten

toxssin

@t3l3machus

An XSS exploitation command-line interface and payload generator.

MIT Commit 2 jaaren geleden ★ 1.444
30 4/5 gemeten

badKarma

@r3vn

network reconnaissance toolkit

Maintainer in de EU GPL-3.0 Commit 8 jaaren geleden ★ 436
30 4/5 gemeten

slowloris

@gkbrk

Low bandwidth DoS tool. Slowloris rewrite in Python.

MIT Commit 2 jaaren geleden ★ 2.835
29 5/5 gemeten

vulnerable-AD

@safebuffer

Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab

MIT Commit 2 jaaren geleden ★ 2.333
29 4/5 gemeten

DigiSpark-Scripts

@CedArctic

USB Rubber Ducky type scripts written for the DigiSpark.

MIT Commit 4 jaaren geleden ★ 2.179
29 4/5 gemeten

Villain

@t3l3machus

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).

Commit 1 jaar geleden ★ 4.459
28 4/5 gemeten

buster

@sham00n

An advanced tool for email reconnaissance

GPL-3.0 Commit 7 jaaren geleden ★ 1.417
28 4/5 gemeten

HostHunter

@SpiderLabs

HostHunter a recon tool for discovering hostnames using OSINT techniques.

MIT Commit 3 jaaren geleden ★ 1.172
28 4/5 gemeten

hacktronian

@thehackingsage

Tools for Pentesting

MIT Commit 3 jaaren geleden ★ 2.203
27 4/5 gemeten

hackerpro

@jaykali

All in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog

MIT Commit 2 jaaren geleden ★ 1.868
26 4/5 gemeten

awesome-software-supply-chain-security

@bureado

A compilation of resources in the software supply chain security domain, with emphasis on open source

Commit 4 maanden geleden ★ 381
26 4/5 gemeten

eJPT-notes

@edoardottt

Notes I took while preparing for eJPT certification by INE Security (passed 19/20, fka eLearn Security)

Maintainer in de EU Commit 11 maanden geleden ★ 164
26 4/5 gemeten

AWSBucketDump

@jordanpotti

Security Tool to Look For Interesting Files in S3 Buckets

MIT Commit 2 jaaren geleden ★ 1.474
25 4/5 gemeten

nishang

@samratashok

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Commit 2 jaaren geleden ★ 10.121
24 5/5 gemeten

Cheatsheet-God

@OlivierLaflamme

Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet

Commit 2 jaaren geleden ★ 5.641
24 4/5 gemeten

watchdog

@flipkart-incubator

Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.

Apache-2.0 Commit 8 jaaren geleden ★ 429
24 4/5 gemeten

FBI-tools

@danieldurnea

🕵️ OSINT Tools for gathering information and actions forensics 🕵️

Commit 2 jaaren geleden ★ 2.675
23 4/5 gemeten

sublert

@yassineaboukir

Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.

MIT Commit 6 jaaren geleden ★ 1.033
23 4/5 gemeten

fuxi

@jeffzh3ng

Penetration Testing Platform

MIT Commit 4 jaaren geleden ★ 1.348
22 4/5 gemeten

Software-Supply-Chain-Security

@vishalgarg-sec

A compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.

Commit 3 jaaren geleden ★ 151
22 4/5 gemeten

AllAboutBugBounty

@daffainfo

All about bug bounty (bypasses, payloads, and etc)

Commit 3 jaaren geleden ★ 6.913
21 4/5 gemeten

Hacking-Security-Ebooks

@yeahhub

Top 100 Hacking & Security E-Books (Free Download)

Commit 2 jaaren geleden ★ 6.489
21 4/5 gemeten

awesome-termux-hacking

@may215

⚡️An awesome list of the best Termux hacking tools

Commit 3 jaaren geleden ★ 4.833
20 4/5 gemeten

OSWA

@bastyn

A collection of useful commands, scripts and resources for the OSWA (WEB-200) exam of Offensive Security

MIT Commit 4 jaaren geleden ★ 119
20 4/5 gemeten

Ethical-Hacking-Labs

@Samsar4

Practical Ethical Hacking Labs 🗡🛡

Commit 2 jaaren geleden ★ 3.909
19 4/5 gemeten

awesome-oscp

@0x4D31

A curated list of awesome OSCP resources

Commit 2 jaaren geleden ★ 3.495
18 4/5 gemeten

the_cyber_plumbers_handbook

@opsdisk

Free copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.

Commit 5 jaaren geleden ★ 2.886
18 4/5 gemeten

GScan

@grayddq

本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。

Commit 4 jaaren geleden ★ 2.828
18 4/5 gemeten

jackhammer

@olacabs

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Commit 3 jaaren geleden ★ 739
15 4/5 gemeten

Chimera

@tokyoneon

Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.

Commit 5 jaaren geleden ★ 1.598
13 4/5 gemeten

PowerShell-for-Hackers

@I-Am-Jakoby

This repository is a collection of powershell functions every hacker should know

Commit 2 jaaren geleden ★ 1.527
13 4/5 gemeten

ejpt-roadmap

@nyxragon

This repository contains a roadmap for preparing for the EJPTv2 exam.

Commit 2 jaaren geleden ★ 205
11 4/5 gemeten

API-SecurityEmpire

@Cyber-Guy1

API Security Project aims to present unique attack & defense methods in API Security field

Commit 3 jaaren geleden ★ 1.448
10 4/5 gemeten

RubyFu

@rubyfu

Rubyfu, where Ruby goes evil!

Commit 3 jaaren geleden ★ 357
8 4/5 gemeten