Kwetsbaarhedenbeheer
152 projecten in Beveiliging & identiteit
pentagi
@vxcontrolFully autonomous AI Agents system capable of performing complex penetration testing tasks
vuls
@future-architectAgent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
Osintgram
@DataluxOsintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
emba
@e-m-b-aEMBA - The firmware security analyzer
openvas-scanner
@greenboneThis repository contains the scanner component for Greenbone Community Edition.
strix
@usestrixOpen-source AI penetration testing tool to find and fix your app’s vulnerabilities.
thc-hydra
@vanhauser-thchydra
codex-security
@openaiOpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
reconftw
@six2dezreconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
cve
@trickestGather and update all available and newest CVEs with their PoC.
PhoneSploit-Pro
@AzeemIdrisiAn all-in-one hacking tool to remotely take over Android devices.
AllHackingTools
@mishakorzikAll-in-One Hacking Tools For Hackers! And more hacking tools! For termux.
osv.dev
@googleOpen source vulnerability DB and triage service.
Nettacker
@OWASPAutomated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
cameradar
@UllaakutCameradar hacks its way into RTSP videosurveillance cameras
Awesome-Hacking
@Hack-with-GithubA collection of various awesome lists for hackers, pentesters and security researchers
Awesome-Cybersecurity-Handbooks
@0xsyr0A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
Penetration_Testing_POC
@Mr-xn渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
awesome-web-hacking
@infoslackA list of web application security
brutespray
@x90skysn3kFast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
Active-Directory-Exploitation-Cheat-Sheet
@S1ckB0y1337A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Learn-Web-Hacking
@LyleMiStudy Notes For Web Hacking / Web安全学习笔记
Agentic-Bug-Hunter
@awarexoneAI-powered bug bounty hunting toolkit that works with or without subscription.
knockpy
@guelfowebKnock Subdomain Scan
VulnClaw
@Netw0rkNoob基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。
CyberStrike
@CyberStrikeusOpen-source AI-powered offensive security harness for automated penetration testing.
AngryOxide
@Ragnt802.11 Attack Tool
copacetic
@project-copacetic🧵 CLI tool for directly patching container images!
h4cker
@The-Art-of-HackingThis repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
malicious-pdf
@jonaslejon💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
cariddi
@edoardotttTake a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
Pentest-Swarm-AI
@Armur-AiAutonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.
medusa
@Ch0pinMobile Edge-Dynamic Unified Security Analysis
SSTImap
@vladko312Automatic SSTI detection tool with interactive interface
ssh-mitm
@ssh-mitmSSH-MITM - ssh audits made simple
DedSec
@dedsec1121fkOfficial repository of the DedSec Project.
gitxray
@kulkansecurityA multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.
Awesome-Hacking-Resources
@vitalysimA collection of hacking / penetration testing resources to make you better!
redamon
@samugit83An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
mutillidae
@webpwnizedOWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.
rengine
@yogeshojhareNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
afrog
@zan8inA Security Tool for Bug Bounty, Pentest and Red Teaming.
pentest-ai-agents
@0xStephTurn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
linWinPwn
@lefayjeylinWinPwn is a bash script that streamlines the use of a number of Active Directory tools
AutoCVE
@larlaruaAgent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.
wordlists
@trickestReal-world infosec wordlists, updated regularly
cve-mcp-server
@mukul975Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
Hunting-Queries-Detection-Rules
@Bert-JanPKQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
pentest-ai
@0xStephOpen-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
awesome-vulnerable-apps
@vavkamilAwesome Vulnerable Applications
pwneye
@HackerestYour ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥
WhatWeb
@urbanadventurerNext generation web scanner
pacu
@RhinoSecurityLabsThe AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
DSInternals
@MichaelGrafnetterDirectory Services Internals (DSInternals) PowerShell Module and Framework
guac
@guacsecGUAC aggregates software security metadata into a high fidelity graph database.
PayloadsAllTheThings
@swisskyrepoA list of useful payloads and bypass for Web Application Security and Pentest/CTF
awesome-ethical-hacking-resources
@husnainfareed😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.
Exegol
@ThePorgsFully featured and community-driven hacking environment
cloud_enum
@initstringMulti-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
agent
@PentesterFlowAgentic offensive-security in your terminal
Scanners-Box
@We5terThe Ultimate Open-Source Security Arsenal for Hackers, Enterprises, and AI Agents——面向极客、企业与 AI 智能体的全域开源网络安全工具矩阵
commando-vm
@mandiantComplete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
opencve
@opencveVulnerability Intelligence Platform
linkedin2username
@initstringOSINT Tool: Generate username lists for companies on LinkedIn
inql
@doyensecInQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
GooFuzz
@m3n0sd0n4ldGooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).
dirsearch
@maurosoriaWeb path scanner
awesome-hacking
@jekilAwesome hacking is an awesome collection of hacking tools.
ISMS-PUBLIC
@Hack23Hack23 Public Information Security Management System:Security Through Transparency and Open Documentation Demonstrating Security Excellence Through Public ISMS Disclosure
awesome-infosec
@onlurkingA curated list of awesome infosec courses and training resources.
NoSQLMap
@codingoAutomated NoSQL database enumeration and web application exploitation tool.
cynative
@cynativeOpen-source security agents for cloud, code and runtime. 45 built-in agents audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab for privilege escalation, public exposure, supply chain and more, or build your own in one markdown file. Live, read-only access to your infrastructure.
awesome-web-security
@qazbnm456🐶 A curated list of Web Security materials and resources.
clairvoyance
@nikitastupinObtain GraphQL API schema even if the introspection is disabled
awesome-vulnerable
@kaiiyerA curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.
OSCP
@0xsyr0OSCP Cheat Sheet
pwnagotchi
@jayofelony(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.
PlumHound
@PlumHoundBloodhound Reporting for Blue and Purple Teams
sbom-tools
@sbom-toolSemantic SBOM/CBOM/AI-BOM diff, quality scoring, and compliance validation for CycloneDX/SPDX — component, license, and vulnerability change analysis, cryptographic inventory grading, PQC readiness (CNSA 2.0, NIST IR 8547), and regulatory gates for NTIA, FDA, EU CRA, BSI TR-03183, EUCC, SSDF, EO 14028, and the EU AI Act.
RedTeam-Tools
@A-pocTools and Techniques for Red Team / Penetration Testing
hackingthe.cloud
@Hacking-the-CloudAn encyclopedia for offensive and defensive security knowledge in cloud native technologies.
cent
@xm1k3Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
evillimiter
@bitbruteTool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access
fsociety
@fsociety-teamA Modular Penetration Testing Framework
ezXSS
@sslezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
wstg
@OWASPThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Infosec_Reference
@rmusser01An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
scope
@rix4uniAn automated GitHub Actions-based crawler that fetches and updates public scopes from popular bug bounty platforms (like Hackerone/Bugcrowd/Intigriti/etc) (updates every 10 minutes)
Active-Directory-Exploitation-Cheat-Sheet
@Integration-ITA cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Sn1per
@1N3Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
crlfuzz
@dwisiswant0A fast tool to scan CRLF vulnerability written in Go
Buildware-Tools
@v4lkyr0Buildware-Tools is an all-in-one multitool for security research and automation.
Web-Fuzzing-Box
@gh0stkeyWeb Fuzzing Box - Web 模糊测试字典与一些Payloads
ScanCannon
@johnnyxmasA script for credentials-based attack surface enumeration and general reconnaissance of massive external networks
monkey
@guardicoreInfection Monkey - An open-source adversary emulation platform
PentestTools
@arch3rProAwesome Pentest Tools Collection
EasY_HaCk
@sabri-zakiHack the World using Termux
hoaxshell
@t3l3machusA Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.
masvs
@OWASPThe OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
devguard
@l3montree-devDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
awesome-shodan-queries
@jakejarvis🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
changeme
@ztgraceA default credential scanner.
pentest-guide
@VoorivexPenetration tests guide based on OWASP including test cases, resources and examples.
AboutSecurity
@wgpsecEverything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。
Damn-Vulnerable-GraphQL-Application
@dolevfDamn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
vulscan
@scipagAdvanced vulnerability scanning with Nmap NSE
gitjacker
@liamg🔪 :octocat: Leak git repositories from misconfigured websites
Penetration-Testing-Tools
@mgeekyA collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
A-Red-Teamer-diaries
@ihebskiRedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
psudohash
@t3l3machusGenerates millions of keyword-based password mutations in seconds.
inventory
@trickestAsset inventory of over 800 public bug bounty programs.
Lockdoor-Framework
@SofianeHamlaoui🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
passphrase-wordlist
@initstringPassphrase wordlist and hashcat rules for offline cracking of long, complex passwords
Reconnoitre
@codingoA security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
OSCPRepo
@rewardoneA list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.
rapidscan
@skavngr:new: The Multi-Tool Web Vulnerability Scanner.
ADB-Toolkit
@ASHWIN990ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!
pwncat
@cytopiapwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)
toxssin
@t3l3machusAn XSS exploitation command-line interface and payload generator.
badKarma
@r3vnnetwork reconnaissance toolkit
slowloris
@gkbrkLow bandwidth DoS tool. Slowloris rewrite in Python.
vulnerable-AD
@safebufferCreate a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
DigiSpark-Scripts
@CedArcticUSB Rubber Ducky type scripts written for the DigiSpark.
Villain
@t3l3machusVillain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
buster
@sham00nAn advanced tool for email reconnaissance
HostHunter
@SpiderLabsHostHunter a recon tool for discovering hostnames using OSINT techniques.
hacktronian
@thehackingsageTools for Pentesting
hackerpro
@jaykaliAll in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog
awesome-software-supply-chain-security
@bureadoA compilation of resources in the software supply chain security domain, with emphasis on open source
eJPT-notes
@edoardotttNotes I took while preparing for eJPT certification by INE Security (passed 19/20, fka eLearn Security)
AWSBucketDump
@jordanpottiSecurity Tool to Look For Interesting Files in S3 Buckets
nishang
@samratashokNishang - Offensive PowerShell for red team, penetration testing and offensive security.
Cheatsheet-God
@OlivierLaflammePenetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
watchdog
@flipkart-incubatorWatchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
FBI-tools
@danieldurnea🕵️ OSINT Tools for gathering information and actions forensics 🕵️
sublert
@yassineaboukirSublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
fuxi
@jeffzh3ngPenetration Testing Platform
Software-Supply-Chain-Security
@vishalgarg-secA compilation of Software Supply Chain Security resources including initiatives, standards, regulations, organizations, vendors, tooling, books, articles and a plethora of learning resources from the web.
AllAboutBugBounty
@daffainfoAll about bug bounty (bypasses, payloads, and etc)
Hacking-Security-Ebooks
@yeahhubTop 100 Hacking & Security E-Books (Free Download)
awesome-termux-hacking
@may215⚡️An awesome list of the best Termux hacking tools
OSWA
@bastynA collection of useful commands, scripts and resources for the OSWA (WEB-200) exam of Offensive Security
Ethical-Hacking-Labs
@Samsar4Practical Ethical Hacking Labs 🗡🛡
awesome-oscp
@0x4D31A curated list of awesome OSCP resources
the_cyber_plumbers_handbook
@opsdiskFree copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.
GScan
@grayddq本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。
jackhammer
@olacabsJackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
Chimera
@tokyoneonChimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
PowerShell-for-Hackers
@I-Am-JakobyThis repository is a collection of powershell functions every hacker should know
ejpt-roadmap
@nyxragonThis repository contains a roadmap for preparing for the EJPTv2 exam.
API-SecurityEmpire
@Cyber-Guy1API Security Project aims to present unique attack & defense methods in API Security field
RubyFu
@rubyfuRubyfu, where Ruby goes evil!