Kwetsbaarhedenbeheer

231 projecten in Beveiliging & identiteit

Toont top 200 van 231 op Atlas Score; verfijn met de filters hierboven.

Osintgram

@Datalux

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

Maintainer in de EU Commit 14 dagen geleden ★ 14.695
75 4/5 gemeten

openvas-scanner

@greenbone

This repository contains the scanner component for Greenbone Community Edition.

Maintainer in de EU Commit 3 dagen geleden ★ 4.838
73 4/5 gemeten

emba

@e-m-b-a

EMBA - The firmware security analyzer

GPL-3.0 Commit vandaag ★ 3.680
72 4/5 gemeten

osv.dev

@google

Open source vulnerability DB and triage service.

Apache-2.0 Commit 3 dagen geleden ★ 2.947
71 5/5 gemeten

AllHackingTools

@mishakorzik

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

GPL-3.0 Commit 11 dagen geleden ★ 6.247
70 4/5 gemeten

PhoneSploit-Pro

@AzeemIdrisi

An all-in-one hacking tool to remotely take over Android devices.

GPL-3.0 Commit 14 dagen geleden ★ 6.313
70 4/5 gemeten

Copa

@project-copacetic

🧵 CLI tool for directly patching container images!

Apache-2.0 Commit 3 dagen geleden ★ 1.715
70 4/5 gemeten

thc-hydra

@vanhauser-thc

hydra

Maintainer in de EU Commit 2 maanden geleden ★ 12.319
69 5/5 gemeten

Awesome-Cybersecurity-Handbooks

@0xsyr0

A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.

GPL-3.0 Commit 9 dagen geleden ★ 4.107
69 4/5 gemeten

AngryOxide

@Ragnt

802.11 Attack Tool

GPL-3.0 Commit 1 dag geleden ★ 1.972
69 4/5 gemeten

cve

@trickest

Gather and update all available and newest CVEs with their PoC.

MIT Commit 1 dag geleden ★ 8.105
69 4/5 gemeten

cameradar

@Ullaakut

Cameradar hacks its way into RTSP videosurveillance cameras

Maintainer in de EU Commit 5 dagen geleden ★ 5.228
68 5/5 gemeten

Pentest-Swarm-AI

@Armur-Ai

Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.

AGPL-3.0 Commit 1 dag geleden ★ 2.650
68 4/5 gemeten

SSTImap

@vladko312

Automatic SSTI detection tool with interactive interface

GPL-3.0 Commit 1 maand geleden ★ 1.671
68 4/5 gemeten

reconftw

@six2dez

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Maintainer in de EU Commit 2 dagen geleden ★ 8.152
68 5/5 gemeten

Nettacker

@OWASP

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Apache-2.0 Commit 3 dagen geleden ★ 5.625
68 5/5 gemeten

mutillidae

@webpwnized

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.

GPL-3.0 Commit 4 dagen geleden ★ 1.526
67 4/5 gemeten

AutoCVE

@larlarua

Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.

AGPL-3.0 Commit 25 dagen geleden ★ 1.418
67 4/5 gemeten

Penetration_Testing_POC

@Mr-xn

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

Apache-2.0 Commit 4 dagen geleden ★ 7.501
67 4/5 gemeten

knockpy

@guelfoweb

Knock Subdomain Scan

Maintainer in de EU Commit 7 maanden geleden ★ 4.201
67 4/5 gemeten

brutespray

@x90skysn3k

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.

MIT Commit 1 dag geleden ★ 2.540
67 4/5 gemeten

medusa

@Ch0pin

Mobile Edge-Dynamic Unified Security Analysis

GPL-3.0 Commit 22 dagen geleden ★ 2.346
67 4/5 gemeten

ssh-mitm

@ssh-mitm

SSH-MITM - ssh audits made simple

Maintainer in de EU Commit 15 dagen geleden ★ 1.470
67 5/5 gemeten

DedSec

@dedsec1121fk

Official repository of the DedSec Project.

Maintainer in de EU Commit 1 dag geleden ★ 1.004
67 4/5 gemeten

malicious-pdf

@jonaslejon

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh

BSD-2-Clause Commit 1 maand geleden ★ 4.439
66 4/5 gemeten

redamon

@samugit83

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

MIT Commit 1 dag geleden ★ 2.671
66 4/5 gemeten

pwneye

@Hackerest

Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥

Maintainer in de EU Commit 22 dagen geleden ★ 321
66 4/5 gemeten

linWinPwn

@lefayjey

linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

MIT Commit 1 dag geleden ★ 2.220
65 4/5 gemeten

APKHunt

@Cyber-Buddy

APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.

GPL-3.0 Commit 4 dagen geleden ★ 985
64 4/5 gemeten

wordlists

@trickest

Real-world infosec wordlists, updated regularly

MIT Commit 1 dag geleden ★ 1.799
64 4/5 gemeten

Hunting-Queries-Detection-Rules

@Bert-JanP

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

BSD-3-Clause Commit 12 dagen geleden ★ 1.752
64 4/5 gemeten

pentest-ai

@0xSteph

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

MIT Commit 15 dagen geleden ★ 1.703
64 4/5 gemeten

guac

@guacsec

GUAC aggregates software security metadata into a high fidelity graph database.

Apache-2.0 Commit 1 dag geleden ★ 1.545
63 4/5 gemeten

afrog

@zan8in

A Security Tool for Bug Bounty, Pentest and Red Teaming.

MIT Commit 3 dagen geleden ★ 4.423
62 5/5 gemeten

cloud_enum

@initstring

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

MIT Commit 3 maanden geleden ★ 2.141
62 4/5 gemeten

L0p4Map

@HaxL0p4

Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites.

GPL-3.0 Commit 2 maanden geleden ★ 939
62 4/5 gemeten

DSInternals

@MichaelGrafnetter

Directory Services Internals (DSInternals) PowerShell Module and Framework

Maintainer in de EU Commit 17 dagen geleden ★ 1.969
62 5/5 gemeten

scilla

@edoardottt

Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

Maintainer in de EU Commit 14 dagen geleden ★ 1.273
62 5/5 gemeten

pentest

@ZishanAdThandar

Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.

GPL-3.0 Commit 8 dagen geleden ★ 741
62 4/5 gemeten

Awesome-Hacking-Resources

@vitalysim

A collection of hacking / penetration testing resources to make you better!

GPL-3.0 Commit 4 maanden geleden ★ 17.456
61 5/5 gemeten

codex-redteam-mode

@chAng-L19

针对于红队攻击思维做出的red team模式(破限项目,封号概不负责)##可自行适配其他Agent。项目问题请提issue

MIT Commit 1 maand geleden ★ 1.097
61 4/5 gemeten

rengine

@yogeshojha

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

GPL-3.0 Commit 1 dag geleden ★ 8.864
61 5/5 gemeten

xalgorix

@xalgorix

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Apache-2.0 Commit vandaag ★ 1.136
61 4/5 gemeten

GooFuzz

@m3n0sd0n4ld

GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).

GPL-3.0 Commit 9 maanden geleden ★ 1.590
60 4/5 gemeten

Exegol

@ThePorgs

Fully featured and community-driven hacking environment

Maintainer in de EU Commit 1 dag geleden ★ 3.099
60 4/5 gemeten

Ghostwriter

@GhostManager

The SpecterOps project management and reporting engine

BSD-3-Clause Commit 3 dagen geleden ★ 1.922
60 5/5 gemeten

tugarecon

@skynet0x01

TugaRecon is an advanced subdomain reconnaissance and intelligence framework built for security researchers, penetration testers and OSINT professionals. It combines OSINT enumeration, semantic analysis, temporal intelligence and automated reactions to continuously improve asset discovery and prioritization.

Maintainer in de EU Commit 6 maanden geleden ★ 223
60 4/5 gemeten

linkedin2username

@initstring

OSINT Tool: Generate username lists for companies on LinkedIn

MIT Commit 4 maanden geleden ★ 1.858
59 4/5 gemeten

nmap

@Ullaakut

Idiomatic nmap library for go developers

Maintainer in de EU Commit 2 dagen geleden ★ 1.052
59 5/5 gemeten

sysreptor

@Syslifters

A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.

Maintainer in de EU Commit 4 dagen geleden ★ 2.590
59 4/5 gemeten

inql

@doyensec

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

Maintainer in de EU Commit 19 dagen geleden ★ 1.811
59 5/5 gemeten

vuln-bank

@Commando-X

A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn pentesting and secure coding practices.

MIT Commit 6 dagen geleden ★ 937
59 4/5 gemeten

tactical-exploitation

@0xdea

Modern tactical exploitation toolkit.

Maintainer in de EU Commit 2 maanden geleden ★ 867
59 4/5 gemeten

clairvoyance

@nikitastupin

Obtain GraphQL API schema even if the introspection is disabled

Apache-2.0 Commit 10 maanden geleden ★ 1.530
58 4/5 gemeten

Sitadel

@shenril

Web Application Security Scanner

GPL-3.0 Commit 1 dag geleden ★ 611
58 4/5 gemeten

WhatWeb

@urbanadventurer

Next generation web scanner

GPL-2.0 Commit 6 maanden geleden ★ 6.861
58 5/5 gemeten

pacu

@RhinoSecurityLabs

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

BSD-3-Clause Commit 4 maanden geleden ★ 5.346
58 5/5 gemeten

DDoSlayer

@blackhatethicalhacking

An Advanced Layer 7 DDoS tool, Able to bypass CF and offers various DoS Techniques

Maintainer in de EU Commit 2 maanden geleden ★ 458
58 4/5 gemeten

PlumHound

@PlumHound

Bloodhound Reporting for Blue and Purple Teams

GPL-3.0 Commit 11 maanden geleden ★ 1.319
57 4/5 gemeten

Cybermes

@Zyrexnn

Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.

Apache-2.0 Commit 9 dagen geleden ★ 888
57 4/5 gemeten

Payloader

@3516634930

渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript

AGPL-3.0 Commit 1 dag geleden ★ 507
57 4/5 gemeten

gvmd

@greenbone

Greenbone Vulnerability Manager - The database backend for the Greenbone Community Edition

Maintainer in de EU Commit 3 dagen geleden ★ 378
57 4/5 gemeten

opencve

@opencve

Vulnerability Intelligence Platform

Commit 8 dagen geleden ★ 2.845
57 5/5 gemeten

ARL-Next

@owl234

现代化资产测绘与漏洞监控平台 (ARL-Next)。经典 ARL 架构重构,聚焦企业资产关联、异步解耦并发调度与原生 MCP 协议集成,容器化开箱部署。

GPL-3.0 Commit 2 dagen geleden ★ 445
57 4/5 gemeten

arsenal-ng

@halilkirazkaya

The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.

MIT Commit 3 dagen geleden ★ 724
56 4/5 gemeten

NoSQLMap

@codingo

Automated NoSQL database enumeration and web application exploitation tool.

GPL-3.0 Commit 2 maanden geleden ★ 3.359
55 5/5 gemeten

penetration-testing-cheat-sheet

@ivan-sincek

Work in progress...

Maintainer in de EU Commit 5 maanden geleden ★ 847
55 4/5 gemeten

php-reverse-shell

@ivan-sincek

PHP shells that work on Linux OS, macOS, and Windows OS.

Maintainer in de EU Commit 7 maanden geleden ★ 574
55 4/5 gemeten

TraceSurface

@pis10

发现藏在前端代码里的 API,验证未授权访问风险 · 动态浏览器追踪 × JavaScript 静态分析

MIT Commit 21 dagen geleden ★ 500
55 4/5 gemeten

commando-vm

@mandiant

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

Apache-2.0 Commit 12 maanden geleden ★ 7.810
55 4/5 gemeten

titus

@praetorian-inc

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Apache-2.0 Commit 1 dag geleden ★ 706
55 4/5 gemeten

missing-cve-nuclei-templates

@edoardottt

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.

Maintainer in de EU Commit 7 dagen geleden ★ 448
55 4/5 gemeten

pwnagotchi

@jayofelony

(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.

Commit 6 dagen geleden ★ 2.928
54 4/5 gemeten

dirsearch

@maurosoria

Web path scanner

Commit 1 dag geleden ★ 14.760
53 5/5 gemeten

evillimiter

@bitbrute

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

Maintainer in de EU Commit 6 maanden geleden ★ 2.021
53 4/5 gemeten

Red-Team-Playbooks

@0xsyr0

This repository contains cutting-edge open-source security notes and tools that will help you during your Red Team assessments.

GPL-3.0 Commit 3 maanden geleden ★ 468
53 4/5 gemeten

cra-agent

@kulkarnirohit123

Autonomous agentic AI for CRA (Cyber Resilience Act) compliance: scans repos, triages findings, opens Jira tickets, and auto-fixes vulnerabilities via PR.

Apache-2.0 Commit 1 maand geleden ★ 453
53 4/5 gemeten

OffSec-Reporting

@Syslifters

Offensive Security OSCP+, OSEP, OSWP, OSWA, OSWE, OSED, OSMR, OSEE, OSDA, OSIR, OSTH Exam and Lab Reporting / Note-Taking Tool

Maintainer in de EU Commit 24 dagen geleden ★ 938
53 4/5 gemeten

hackingthe.cloud

@Hacking-the-Cloud

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.

Commit 6 dagen geleden ★ 2.775
52 4/5 gemeten

xurlfind3r

@hueristiq

A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.

MIT Commit 7 maanden geleden ★ 724
52 4/5 gemeten

BCHackTool

@ByCh4n

All-in-one launcher and installer for popular penetration-testing and OSINT tools on Kali Linux and Termux.

MIT Commit 2 maanden geleden ★ 544
52 4/5 gemeten

Zen-Ai-Pentest

@SHAdd0WTAka

🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️

MIT Commit 15 dagen geleden ★ 468
52 4/5 gemeten

VulnerableApp

@SasanLabs

OWASP VulnerableApp Project: Break it. Scan it. Reproduce it. Benchmark against it. Improve it.

Apache-2.0 Commit 1 dag geleden ★ 466
52 4/5 gemeten

command

@safe6Sec

红队常用命令速查

MIT Commit 7 maanden geleden ★ 1.023
51 4/5 gemeten

AppSec-Payloads

@sh377c0d3

AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters

MIT Commit 6 maanden geleden ★ 949
51 4/5 gemeten

CVE_Prioritizer

@TURROKS

Streamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time threat information, gain a competitive advantage, and stay informed about the latest trends.

Maintainer in de EU Commit 1 maand geleden ★ 709
50 4/5 gemeten

graphql-cop

@dolevf

Security Auditor Utility for GraphQL APIs

MIT Commit 10 maanden geleden ★ 693
50 4/5 gemeten

android-penetration-testing-cheat-sheet

@ivan-sincek

Work in progress...

Maintainer in de EU Commit 5 maanden geleden ★ 491
50 4/5 gemeten

ezXSS

@ssl

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

MIT Commit 3 maanden geleden ★ 2.339
50 5/5 gemeten

Buildware-Tools

@v4lkyr0

Buildware-Tools is an all-in-one multitool for security research and automation.

Commit 3 maanden geleden ★ 1.447
49 4/5 gemeten

scant3r

@MindPatch

ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )

GPL-3.0 Commit 1 dag geleden ★ 684
49 4/5 gemeten

thc-ipv6

@vanhauser-thc

IPv6 attack toolkit

Maintainer in de EU Commit 5 maanden geleden ★ 1.198
48 5/5 gemeten

huntkit

@mcnamee

Docker - Ubuntu with a bunch of PenTesting tools and wordlists

MIT Commit 3 maanden geleden ★ 398
48 4/5 gemeten

crlfuzz

@dwisiswant0

A fast tool to scan CRLF vulnerability written in Go

MIT Commit 1 maand geleden ★ 1.566
47 5/5 gemeten

Web-Cache-Vulnerability-Scanner

@Hackmanit

Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).

Maintainer in de EU Commit 8 maanden geleden ★ 1.207
47 4/5 gemeten

Bug-Bounty-Methodology

@tuhin1729

These are my checklists which I use during my hunting.

Commit 26 dagen geleden ★ 940
47 4/5 gemeten

graphw00f

@dolevf

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

BSD-3-Clause Commit 5 maanden geleden ★ 902
47 4/5 gemeten

EtherGhost

@Marven11

新一代Webshell管理器,兼容蚁剑与冰蝎的PHP webshell

MIT Commit 2 maanden geleden ★ 689
47 4/5 gemeten

AutoPWN-Suite

@GamehunterKaan

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Commit 10 dagen geleden ★ 1.115
47 4/5 gemeten

pyhtools

@dmdhrumilmistry

A Python Hacking Library consisting of network scanner, arp spoofer and detector, dns spoofer, code injector, packet sniffer, network jammer, email sender, downloader, wireless password harvester credential harvester, keylogger, download&execute, ransomware, data harvestors, etc.

MIT Commit 10 dagen geleden ★ 656
47 5/5 gemeten

ios-penetration-testing-cheat-sheet

@ivan-sincek

Work in progress...

Maintainer in de EU Commit 7 maanden geleden ★ 424
46 4/5 gemeten

wstg

@OWASP

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Commit 5 dagen geleden ★ 9.903
46 5/5 gemeten

Infosec_Reference

@rmusser01

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

MIT Commit 11 maanden geleden ★ 5.997
46 5/5 gemeten

Web-Fuzzing-Box

@gh0stkey

Web Fuzzing Box - Web 模糊测试字典与一些Payloads

Commit 6 maanden geleden ★ 2.798
45 4/5 gemeten

PentestTools

@arch3rPro

Awesome Pentest Tools Collection

Commit 6 maanden geleden ★ 1.790
45 4/5 gemeten

adscan

@ADScanPro

Free Active Directory pentesting tool for Linux, macOS and Windows. Automates AD and LDAP enumeration, Kerberoasting, ASREPRoast, password spraying, ADCS/ESC1, DCSync, RBCD, gMSA, shadow credentials, NTLM relay and credential dumping across 104 techniques, mapping BloodHound-compatible attack paths to Domain Admin. NIS2 / ISO 27001 reports.

Commit 3 dagen geleden ★ 729
45 4/5 gemeten

MBPTL

@bayufedra

Best hands-on lab for learning the fundamentals of cybersecurity and penetration testing workflows also packaged as Docker containers for fast, safe setup.

GPL-3.0 Commit 10 maanden geleden ★ 472
45 4/5 gemeten

EasY_HaCk

@sabri-zaki

Hack the World using Termux

Apache-2.0 Commit 1 jaar geleden ★ 2.488
44 4/5 gemeten

MCP-Kali-Server

@Wh0am123

MCP configuration to connect AI agent to a Linux machine.

MIT Commit 7 maanden geleden ★ 829
44 4/5 gemeten

Garud

@R0X4R

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.

MIT Commit 5 maanden geleden ★ 810
44 4/5 gemeten

PingRAT

@umutcamliyurt

PingRAT secretly passes C2 traffic through firewalls using ICMP payloads.

GPL-3.0 Commit 4 maanden geleden ★ 473
44 4/5 gemeten

changeme

@ztgrace

A default credential scanner.

GPL-3.0 Commit 1 jaar geleden ★ 1.516
43 4/5 gemeten

dianxing

@tianchong-zerotemp

DianXing - AI-Driven End-to-End Code Security Auditing

Commit 3 maanden geleden ★ 871
43 4/5 gemeten

agartha

@volkandindar

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.

Maintainer in de EU Commit 4 maanden geleden ★ 412
43 4/5 gemeten

Sn1per

@1N3

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Commit 3 maanden geleden ★ 11.277
43 5/5 gemeten

Interlace

@codingo

Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

GPL-3.0 Commit 1 jaar geleden ★ 1.309
42 5/5 gemeten

JustTryHarder

@sinfulz

JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)

Commit 3 maanden geleden ★ 839
42 4/5 gemeten

masvs

@OWASP

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

Commit 7 dagen geleden ★ 2.452
42 4/5 gemeten

SQLiDetector

@eslam3kl

Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.

Commit 1 dag geleden ★ 644
42 4/5 gemeten

hoaxshell

@t3l3machus

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

BSD-2-Clause Commit 2 jaaren geleden ★ 3.498
41 4/5 gemeten

Damn-Vulnerable-GraphQL-Application

@dolevf

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

MIT Commit 1 jaar geleden ★ 1.713
41 4/5 gemeten

VHostScan

@codingo

A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

GPL-3.0 Commit 1 jaar geleden ★ 1.311
41 5/5 gemeten

leaky-paths

@ayoubfathi

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

Commit 6 maanden geleden ★ 1.193
41 4/5 gemeten

hackingtoolkit

@CodingRanjith

ALL IN ONE Hacking Tool For Hackers, Penetration Tester and Cybersecurity. New Version Beginner to Advanced Tool. This Tool is made for educational purpose only ! Author will not be responsible for any misuse of this toolkit !

MIT Commit 1 jaar geleden ★ 761
41 4/5 gemeten

TryHackMe

@migueltc13

Master cybersecurity skills with this free-only TryHackMe learning path, complete with a progress-tracking template and a collection of my write-ups and solutions.

GPL-3.0 Commit 1 jaar geleden ★ 397
41 4/5 gemeten

psudohash

@t3l3machus

Generates millions of keyword-based password mutations in seconds.

MIT Commit 1 jaar geleden ★ 1.469
40 4/5 gemeten

RedTeam_toolkit

@signorrayan

Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.

MIT Commit 8 maanden geleden ★ 575
40 4/5 gemeten

HackTheBox-Reporting

@Syslifters

Hack The Box CPTS, CWES, CDSA, CWEE, CAPE, CJCA Exam and Lab Reporting / Note-Taking Tool

Maintainer in de EU Commit 6 maanden geleden ★ 438
40 4/5 gemeten

lpe-toolkit

@portbuster1337

Multi-architecture Linux privilege escalation toolkit with 29 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched exploits, tries each until root.

Commit 5 dagen geleden ★ 400
40 4/5 gemeten

QuillAudit_smart_contract_audit_Reports

@Quillhash

QuillAudits — Smart Contract Audits for DeFi, RWA, DEXs, Tokens, DeAI & DApps

Commit 4 dagen geleden ★ 469
40 4/5 gemeten

pentest-guide

@Voorivex

Penetration tests guide based on OWASP including test cases, resources and examples.

GPL-3.0 Commit 5 jaaren geleden ★ 2.837
39 4/5 gemeten

gitjacker

@liamg

🔪 :octocat: Leak git repositories from misconfigured websites

Unlicense Commit 10 maanden geleden ★ 1.606
39 5/5 gemeten

SILENTCHAIN

@silentchainai

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Commit 3 maanden geleden ★ 464
39 4/5 gemeten

A-Red-Teamer-diaries

@ihebski

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

Commit 11 maanden geleden ★ 1.936
38 4/5 gemeten

passphrase-wordlist

@initstring

Passphrase wordlist and hashcat rules for offline cracking of long, complex passwords

MIT Commit 1 jaar geleden ★ 1.442
38 4/5 gemeten

Lockdoor-Framework

@SofianeHamlaoui

🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources

Maintainer in de EU Commit 1 jaar geleden ★ 1.559
38 5/5 gemeten

Penetration-Testing-Tools

@mgeeky

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.

Maintainer in de EU Commit 3 jaaren geleden ★ 3.018
37 4/5 gemeten

gmailc2

@machine1337

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Apache-2.0 Commit 1 jaar geleden ★ 489
37 4/5 gemeten

vulscan

@scipag

Advanced vulnerability scanning with Nmap NSE

Commit 8 maanden geleden ★ 3.786
37 4/5 gemeten

reversingBits

@mohitmishra786

A comprehensive collection of cheatsheets for reverse engineering, binary analysis, and assembly programming tools. This repository serves as a one-stop reference for security researchers, reverse engineers, and low-level programmers.

MIT Commit 1 jaar geleden ★ 654
37 4/5 gemeten

badKarma

@r3vn

network reconnaissance toolkit

Maintainer in de EU Commit 8 jaaren geleden ★ 436
37 4/5 gemeten

toxssin

@t3l3machus

An XSS exploitation command-line interface and payload generator.

MIT Commit 2 jaaren geleden ★ 1.444
36 4/5 gemeten

habu

@fportantier

Hacking Toolkit

BSD-3-Clause Commit 9 maanden geleden ★ 987
36 5/5 gemeten

IPRotate_Burp_Extension

@RhinoSecurityLabs

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Commit 7 maanden geleden ★ 895
36 4/5 gemeten

ADB-Toolkit

@ASHWIN990

ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!

GPL-3.0 Commit 2 jaaren geleden ★ 2.032
36 4/5 gemeten

Reconnoitre

@codingo

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

GPL-3.0 Commit 4 jaaren geleden ★ 2.193
35 5/5 gemeten

rapidscan

@skavngr

:new: The Multi-Tool Web Vulnerability Scanner.

GPL-2.0 Commit 3 jaaren geleden ★ 2.135
35 5/5 gemeten

buster

@sham00n

An advanced tool for email reconnaissance

GPL-3.0 Commit 7 jaaren geleden ★ 1.420
35 4/5 gemeten

Brutal

@screetsec

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is a toolkit to quickly create various payload,powershell attack , virus attack and launch listener for a Human Interface Device ( Payload Teensy )

GPL-3.0 Commit 7 jaaren geleden ★ 1.271
35 4/5 gemeten

Bug-bounty-Writeups

@insecrez

Repository of Bug-Bounty Writeups

Commit 4 maanden geleden ★ 430
35 4/5 gemeten

pwncat

@cytopia

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)

Maintainer in de EU Commit 4 jaaren geleden ★ 1.961
35 5/5 gemeten

vulnerable-AD

@safebuffer

Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab

MIT Commit 2 jaaren geleden ★ 2.334
34 4/5 gemeten

DigiSpark-Scripts

@CedArctic

USB Rubber Ducky type scripts written for the DigiSpark.

MIT Commit 4 jaaren geleden ★ 2.178
34 4/5 gemeten

Bug-Bounty

@AnLoMinus

Bug Bounty ~ Awesomes | Books | Cheatsheets | Checklists | Tools | Wordlists | More

Commit 11 maanden geleden ★ 666
34 4/5 gemeten

broxy

@rhaidiz

An HTTP/HTTPS intercept proxy written in Go.

GPL-3.0 Commit 5 jaaren geleden ★ 1.008
33 4/5 gemeten

subscraper

@m8sec

Subdomain and target enumeration tool built for offensive security testing

GPL-3.0 Commit 2 jaaren geleden ★ 975
33 4/5 gemeten

Passhunt

@Viralmaniar

Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.

GPL-3.0 Commit 8 jaaren geleden ★ 1.307
33 4/5 gemeten

slowloris

@gkbrk

Low bandwidth DoS tool. Slowloris rewrite in Python.

MIT Commit 2 jaaren geleden ★ 2.835
32 5/5 gemeten

AWSBucketDump

@jordanpotti

Security Tool to Look For Interesting Files in S3 Buckets

MIT Commit 2 jaaren geleden ★ 1.474
32 4/5 gemeten

ThunderSearch

@xzajyjs

macOS上的小而美【Fofa、Shodan、Hunter、Zoomeye、Quake网络空间搜索引擎】闪电搜索器;GUI图形化(Mac/Windows)渗透测试信息搜集工具;资产搜集引擎;hw红队工具hvv

GPL-3.0 Commit 2 jaaren geleden ★ 667
32 4/5 gemeten

hacktronian

@thehackingsage

Tools for Pentesting

MIT Commit 3 jaaren geleden ★ 2.204
32 4/5 gemeten

hackerpro

@jaykali

All in One Hacking Tool for Linux & Android (Termux). Make your linux environment into a Hacking Machine. Hackers are welcome in our blog

MIT Commit 2 jaaren geleden ★ 1.869
32 4/5 gemeten

HostHunter

@SpiderLabs

HostHunter a recon tool for discovering hostnames using OSINT techniques.

MIT Commit 4 jaaren geleden ★ 1.171
32 4/5 gemeten

dotdotpwn

@wireghoul

DotDotPwn - The Directory Traversal Fuzzer

GPL-3.0 Commit 4 jaaren geleden ★ 1.113
32 4/5 gemeten

htshells

@wireghoul

Self contained htaccess shells and attacks

GPL-3.0 Commit 5 jaaren geleden ★ 1.075
32 4/5 gemeten

phishing-frenzy

@pentestgeek

Ruby on Rails Phishing Framework

GPL-3.0 Commit 3 jaaren geleden ★ 898
32 4/5 gemeten

Villain

@t3l3machus

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).

Commit 1 jaar geleden ★ 4.460
31 4/5 gemeten

watchdog

@flipkart-incubator

Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.

Apache-2.0 Commit 8 jaaren geleden ★ 429
31 4/5 gemeten

SwiftnessX

@ehrishirajsharma

A cross-platform note-taking & target-tracking app for penetration testers.

GPL-3.0 Commit 4 jaaren geleden ★ 918
30 4/5 gemeten

metagoofil

@opsdisk

Search Google and download specific file types

Commit 4 maanden geleden ★ 594
30 4/5 gemeten

Gsec

@gotr00t0day

Web Security Scanner

Commit 11 maanden geleden ★ 387
30 4/5 gemeten

fuxi

@jeffzh3ng

Penetration Testing Platform

MIT Commit 4 jaaren geleden ★ 1.348
29 4/5 gemeten

HACK-CAMERA

@hackerxphantom

Hack Victim android Camera Using Link with Termux/Kali-linux

MIT Commit 3 jaaren geleden ★ 1.038
29 4/5 gemeten

sublert

@yassineaboukir

Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.

MIT Commit 6 jaaren geleden ★ 1.033
29 4/5 gemeten

netcat

@diegocr

NetCat for Windows

GPL-2.0 Commit 12 jaaren geleden ★ 897
29 4/5 gemeten

lazyaircrack

@3xploitGuy

Automated tool for WiFi hacking.

MIT Commit 5 jaaren geleden ★ 912
28 4/5 gemeten

Application-Security

@Anof-cyber

Resources for Application Security including Web, API, Android, iOS and Thick Client

GPL-3.0 Commit 3 jaaren geleden ★ 685
28 4/5 gemeten

Pentest-Everything

@The-Viper-One

A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.

Commit 1 jaar geleden ★ 629
28 4/5 gemeten

link

@postrequest

link is a command and control framework written in rust

AGPL-3.0 Commit 5 jaaren geleden ★ 579
28 4/5 gemeten

THC-Archive

@hackerschoice

All releases of the security research group (a.k.a. hackers) The Hacker's Choice

Commit 1 jaar geleden ★ 774
28 4/5 gemeten

Flask-Unsign

@Paradoxis

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Maintainer in de EU Commit 2 jaaren geleden ★ 661
28 5/5 gemeten

Pentest-Notes

@SofianeHamlaoui

Collection of Pentest Notes and Cheatsheets

Maintainer in de EU Commit 1 jaar geleden ★ 411
27 4/5 gemeten

BabySploit

@M4cs

:baby: BabySploit Beginner Pentesting Toolkit/Framework Written in Python :snake:

GPL-3.0 Commit 7 jaaren geleden ★ 1.041
26 5/5 gemeten

breaking-and-pwning-apps-and-servers-aws-azure-training

@appsecco

Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!

MIT Commit 4 jaaren geleden ★ 952
26 4/5 gemeten

wifi-penetration-testing-cheat-sheet

@ivan-sincek

Work in progress...

Maintainer in de EU Commit 2 jaaren geleden ★ 557
26 4/5 gemeten

seccubus

@seccubus

Easy automated vulnerability scanning, reporting and analysis

Apache-2.0 Commit 7 jaaren geleden ★ 709
26 4/5 gemeten

Slackor

@Coalfire-Research

A Golang implant that uses Slack as a command and control server

GPL-3.0 Commit 4 jaaren geleden ★ 460
26 4/5 gemeten

kaboom

@Leviathan36

A tool to automate penetration tests

GPL-3.0 Commit 3 jaaren geleden ★ 382
25 4/5 gemeten

nishang

@samratashok

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Commit 2 jaaren geleden ★ 10.125
24 5/5 gemeten

GodGenesis

@SaumyajeetDas

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

MIT Commit 3 jaaren geleden ★ 533
24 4/5 gemeten

Vanquish

@frizb

Vanquish is Kali Linux based Enumeration Orchestrator. Vanquish leverages the opensource enumeration tools on Kali to perform multiple active information gathering phases.

MIT Commit 8 jaaren geleden ★ 514
24 4/5 gemeten

AllAboutBugBounty

@daffainfo

All about bug bounty (bypasses, payloads, and etc)

Commit 3 jaaren geleden ★ 6.911
23 4/5 gemeten

whonow

@brannondorsey

A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

MIT Commit 5 jaaren geleden ★ 658
23 5/5 gemeten

vulscan

@vulscanteam

vulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...

MIT Commit 7 jaaren geleden ★ 634
23 4/5 gemeten

DarkAngel

@Bywalks

DarkAngel 是一款全自动白帽漏洞扫描器,从hackerone、bugcrowd资产监听到漏洞报告生成、漏洞URL截屏、消息通知。

MIT Commit 3 jaaren geleden ★ 604
23 4/5 gemeten

Redeye

@redeye-framework

Redeye is a tool intended to help you manage your data during a pentest operation

BSD-3-Clause Commit 2 jaaren geleden ★ 473
23 4/5 gemeten

GScan

@grayddq

本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。

Commit 4 jaaren geleden ★ 2.828
22 4/5 gemeten

SonarSearch

@Cgboal

A rapid API for the Project Sonar dataset

MIT Commit 3 jaaren geleden ★ 653
22 5/5 gemeten

the_cyber_plumbers_handbook

@opsdisk

Free copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.

Commit 5 jaaren geleden ★ 2.886
22 4/5 gemeten

urlcrazy

@urbanadventurer

Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.

Commit 1 jaar geleden ★ 694
21 4/5 gemeten