This is your work, valued
OSINT, threat intelligence, AI workflow security, and defensive research. Building CSINT Research.
SSL-bypass. SSL bypass check
★ 316AssemblyX86. This repository contains a collection of code examples and tutorials for programming in x86 assembly language
★ 31kernel-ctf-lab. Linux Kernel Exploitation CTF Lab
★ 26N4TIVE. Android Native CTF. Six challenges focused on reversing .so libraries: buffer overflow, heap exploitation, anti-debug bypass, custom VM, and more.
★ 22Projects. Python
★ 19Low-Level-Projects. just for fun
★ 18OWASPLLMsecurity. Python
★ 9kernel-rpg. JavaScript
★ 6Rust-Programming. Enhancing my skills in Cryptography with Rust
★ 5Kernel-Linux. C
★ 4Portswigger-SQL. Python
★ 20xCD4.github.io. HTML
★ 2csint-osint-archive. TypeScript
★ 2Python-Exploit. Python
★ 13d-automata-simulator. 3d-automata-simulator
★ 1MobilDev. Dart
★ 1Malware-Analysis. Malware projects
★ 1n8n-ai-agent-security-lab. CSINT Research side project for static and staging-safe security regression checks of n8n AI workflows.
★ 1sec-gemini. Sec-Gemini is a cutting-edge AI model designed to enhance cybersecurity capabilities and empower defenders in the ongoing battle against cyber threats.
★ 649worldmonitor. Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
★ 77kOpenOSINT. AI-powered OSINT agent with interactive REPL, MCP server, and CLI. 19 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
★ 1.2ktaranis-ai. Taranis AI is an advanced Open-Source Intelligence (OSINT) tool, leveraging Artificial Intelligence to revolutionize information gathering and situational analysis.
★ 1.2kopencode. The open source coding agent.
★ 192kacademic-research-skills-codex. Codex-native Academic Research Skills suite for human-in-the-loop academic research workflows
★ 7.5kdefending-code-reference-harness. Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
★ 6.9kwhisper. Robust Speech Recognition via Large-Scale Weak Supervision
★ 106kproject-learnops. Cloud and Devops Learning Platform
★ 10Shadowbroker. Open-source intelligence for the global theater. Track everything from the corporate/private jets of the wealthy, and spy satellites, to seismic events in one unified interface. Hook an AI agent up to have it parse through data and find previously unseen correlations. The knowledge is available to all but rarely aggregated in the open, until now.
★ 10kx-algorithm. Algorithm powering the For You feed on X
★ 27kcountries-states-cities-database. 🌍 Discover our global repository of countries, states, and cities! 🏙️ Get comprehensive data in JSON, SQL, PSQL, SQLSERVER, MONGODB, SQLITE, XML, YAML, and CSV formats. Access ISO2, ISO3 codes, country code, capital, native language, timezones (for countries), and more. #countries #states #cities
★ 9.8kOpenMythos. A theoretical reconstruction of the Claude Mythos architecture, built from first principles using the available research literature.
★ 15kautoware. Autoware - the world's leading open-source software project for autonomous driving
★ 12kdamn-vulnerable-llm-agent. Python
★ 496promptfoo. Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
★ 24kgarak. the LLM vulnerability scanner
★ 8.6kai-data-extraction. extract all your personal data history from cursor, codex, claude-code, windsurf, and trae
★ 845awesome-ai-security. A collection of awesome resources related AI security
★ 1.3kkernel-ctf-lab. Linux Kernel Exploitation CTF Lab
★ 26Awesome-CV. :page_facing_up: Awesome CV is LaTeX template for your outstanding job application
★ 28kN4TIVE. Android Native CTF. Six challenges focused on reversing .so libraries: buffer overflow, heap exploitation, anti-debug bypass, custom VM, and more.
★ 22OSINT_Collection. Maintained collection of OSINT related resources. (All Free & Actionable)
★ 2.4kEpsteOut. See which of your LinkedIn connections appear in the Epstein files.
★ 641open-notebook. An Open Source implementation of Notebook LM with more flexibility and features
★ 36kSentryRadio. [XPOSED|MAGISK|KSU] A Android forensic tool designed to detect, analyze, and map cellular network anomalies, including potential IMSI Catchers (Stingrays), cell site simulators, and suspicious network downgrades and Silent SMS.
★ 73PwnAdventure3. PwnAdventure3 Server
★ 683Singularity. Stealthy Linux Kernel Rootkit for modern kernels (6x)
★ 1.7kopenclaw. Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
★ 385kMathSathi-Helping-RAG-AI-Agent. OUR MATH HElping AGenT
★ 23AI-Researcher. [NeurIPS2025] "AI-Researcher: Autonomous Scientific Innovation" -- A production-ready version: https://novix.science/chat
★ 5.6kDolphin. The official repo for “Dolphin: Document Image Parsing via Heterogeneous Anchor Prompting”, ACL, 2025.
★ 9kHacking-guide. HTML
★ 451Awesome-OSINT-List. 📡 Comprehensive collection of OSINT tools for cybersecurity professionals, researchers, and bug bounty hunters. Topics: information gathering, reverse search, red team, trust & safety, AI.
★ 3.9kinternet_archive_downloader. A chrome/firefox extension that download books from Internet Archive(archive.org) and HathiTrust Digital Library (hathitrust.org)
★ 1.5khow2heap. A repository for learning various heap exploitation techniques.
★ 8.8klpic3book. LPIC3 Study Guide in plain English
★ 58DeepSeek-OCR. Contexts Optical Compression
★ 24kchatterbox. SoTA open-source TTS
★ 26kapk-mitm. 🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection
★ 5.1kevilgophish. evilginx3 + gophish
★ 2kBITB. Browser In The Browser (BITB) Templates
★ 2.9kScoutSuite. Multi-Cloud Security Auditing Tool
★ 7.8kDeepFaceLive. Real-time face swap for PC streaming or video calls
★ 31kGhidraMCP. MCP Server for Ghidra
★ 9.7kiOS_Reverse_Engineering. The iOS IPA file Reverse Engineering reference
★ 555google-dorks-bug-bounty. A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting
★ 1.9kamILearningEnough. Low-Level Programming Roadmap and Resources
★ 1.3kimpacket. Impacket is a collection of Python classes for working with network protocols.
★ 16ksimurai. Shell
★ 254Certified-Red-Team-Professional-CRTP---Notes. Certified Red Team Professional (CRTP) - Notes
★ 94Vahaka. JavaScript
★ 24codex. Lightweight coding agent that runs in your terminal
★ 103kRed-Teaming. Collection of Notes and CheatSheets used for Red teaming Certs
★ 502LLM4Decompile. Reverse Engineering: Decompiling Binary Code with Large Language Models
★ 6.8kPenetrationTesting_Notes-. My Notes about Penetration Testing
★ 739mdmz_book. The result of research and investigation of malware development tricks, techniques, evasion, cryptography and linux malware
★ 96OSEE. Collection of resources for my preparation to take the OSEE certification.
★ 325Detect-It-Easy. Program for determining types of files for Windows, Linux and MacOS.
★ 11kmedusa. Mobile Edge-Dynamic Unified Security Analysis
★ 2.3kwindows-security-research-resources. Compiled by !cpuid from the OffSec Discord server!
★ 8every-programmer-should-know. A collection of (mostly) technical things every software developer should know about
★ 100kmalwoverview. Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
★ 4kpayload-wizard. AI assistant that utilizes GPT language models to interpret and generate cybersecurity payloads 🪄
★ 285Nightingale. Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes preconfigured with all essential tools and utilities required for efficient Vulnerability Assessment and Penetration Testing (VAPT), streamlining the setup process for security professionals.
★ 313vulnserver. Vulnerable server used for learning software exploitation
★ 1.1kreFlutter. Flutter Reverse Engineering Framework
★ 1.5kCORS-one-liner. A one liner Bash command which finds CORS in every possible endpoint.
★ 152tweet-machine. This tool can retrieve : 1.Deleted tweets and replies ,Even if The account is suspended 2 .Old bios and Timestamp of The tweets
★ 272SSL-bypass. SSL bypass check
★ 316Best-websites-a-programmer-should-visit. :link: Some useful websites for programmers.
★ 76kcode_caver. Python based WinDbg script to automate the search for code caves in binaries and libraries.
★ 56windbg-readable-theme. Windbg Readable & Dark Green Theme - Own Use
★ 48OSED. Containing my notes, practice binaries + solutions, blog posts, etc. for the Offensive Security Exploit Developer (OSED/EXP-301)
★ 829Malimite. iOS and macOS Decompiler
★ 3.1kBadUnboxing. Automated Android custom unpacker generator
★ 380prompts.chat. f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
★ 167kawesome-cursorrules. 📄 Configuration files that enhance Cursor AI editor experience with custom rules and behaviors
★ 40kawesome-ai-agents. A list of AI autonomous agents
★ 29kUSBArmyKnife. USB Army Knife – the ultimate close access tool for penetration testers and red teamers.
★ 2.8kfrida-interception-and-unpinning. Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
★ 2.2krush. A cross-platform command-line tool for executing jobs in parallel
★ 1.1khttpx. httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
★ 10kassetfinder. Find domains and subdomains related to a given domain
★ 3.7kevilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
★ 15kowasp-mstg. The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security development, testing and reverse engineering.
★ 82qark. Tool to look for several security related Android application vulnerabilities
★ 3.4kmatlog. Material Logcat reader based on CatLog
★ 363drozer-agent. The Android Agent for the Drozer Security Assessment Framework.
★ 242Android-InsecureBankv2. Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities
★ 1.5kawesome-mobile-security. An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
★ 3.5kawesome-android-root. Discover best root apps, Magisk, KernelSu & LSPosed(xposed) modules & rooting guides
★ 4.2kawesome-oscp. A curated list of awesome OSCP resources
★ 3.4kfrida-ue4dump. UE4 dump frida script
★ 190mastg. The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
★ 13kawesome-adb. ADB Usage Complete / ADB 用法大全
★ 12kAndroid-Security-Teryaagh. Android security guides, roadmap, docs, courses, write-ups, and teryaagh.
★ 802cline. Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
★ 65kOSCP-Preparation-Material. All in One OSCP Preparation Material
★ 593ImHex. 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
★ 54kmarkitdown. Python tool for converting files and office documents to Markdown.
★ 171kjan. Jan is an open source alternative to ChatGPT that runs 100% offline on your computer.
★ 44ke9patch. A powerful static binary rewriting tool
★ 1.1kkasld. KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration, and confinement — allows.
★ 520LinuxKernelExploitation. Old and new CTFs about Linux kernel exploitation.
★ 64linux-kernel-exploitation. A collection of links related to Linux kernel security and exploitation
★ 6.6kQu1cksc0pe. All-in-One malware analysis tool.
★ 2kDeepSeek-V3. Python
★ 104kpatch-apk. Wrapper to inject an Objection/Frida gadget into an APK, with support for app bundles/split APKs.
★ 417Kernel-Linux. C
★ 4security-research. This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
★ 4.6kDependency-Confusion. All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)
★ 304mal_unpack. Dynamic unpacker based on PE-sieve
★ 824eLearnSecurity-Mobile-Application-Penetration-Tester-eMAPT. eLearnSecurity Mobile Application Penetration Tester (eMAPT)
★ 36InjuredAndroid. A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
★ 761Buffer-Overflow-Exploit-Development. This repo explains in details about buffer overflow exploit development for windows executable.
★ 52Security-101. 8 Lessons, Kick-start Your Cybersecurity Learning.
★ 6.7kDopamine. Dopamine is a semi-untethered jailbreak for iOS 15 and 16
★ 5.4kPEASS-ng. PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
★ 20kpspy. Monitor linux processes without root permissions
★ 6.1kAndroidPentest101. The motive to build this repo is to help beginner to start learn Android Pentesting by providing a roadmap.
★ 437MobileApp-Pentest-Cheatsheet. The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
★ 5.2kbootOS. bootOS is a monolithic operating system in 512 bytes of x86 machine code.
★ 2.1kdrozer. The Leading Security Assessment Framework for Android.
★ 4.6kghost-1. Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device. Ghost Framework gives you the power and convenience of remote Android device administration.
★ 77sunfish. Sunfish: a Python Chess Engine in 111 lines of code
★ 3.3kVMware-Workstation-Pro-17-Licence-Keys. Free VMware Workstation Pro 17 full license keys. We've meticulously organized thousands of keys, catering to all major versions of VMware Workstation Pro 17 Choose from our curated selection to enhance your virtualization experience.
★ 1.3kmdk3-master. Modifications to MDK3 to reboot Access Points
★ 94aircrack-ng. WiFi security auditing tools suite
★ 7.4kflareon2024. Python
★ 39vulnerability-Checklist. This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
★ 3.6kAwesome_Math_Books.
★ 6.8kpwnlook. An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it.
★ 166BlackObfuscator. Black Obfuscator is an obfuscator for Android APK DexFile, it can help developer to protect source code by control flow flattening, and make it difficult to analyze the actual program control flow.
★ 1.1kEmbedPayloadInPng. Embed a payload inside a PNG file
★ 373MTProxy. C
★ 6.9kPentestGPT. Automated Penetration Testing Agentic Framework Powered by Large Language Models
★ 15kEDRSilencer. A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
★ 1.9kobjection. 📱 objection - runtime mobile exploration
★ 9.3k100-redteam-projects. Projects for security students
★ 2.9kdrmemtrace_samples. Memory trace samples from DynamoRIO's drmemtrace tracer for its drcachesim analyzer
★ 10Online-Crawler-Wayback-Machine. Online-Crawler-Wayback-Machine
★ 27Vertex. iOS kernel exploit for iOS 14 and 15
★ 107Kraken. All-in-One Toolkit for BruteForce Attacks
★ 1.2knexfil. OSINT tool for finding profiles by username
★ 2.6ksecurity-tools. My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
★ 923UEFITool. UEFI firmware image viewer and editor
★ 5.6ksmart-contract-vulnerabilities. A collection of smart contract vulnerabilities along with prevention methods
★ 2.5kdynamorio. Dynamic Instrumentation Tool Platform
★ 3.1keJPTv2-Notes. eLearnSecurity Junior Penetration Tester (eJPT) v2 Notes
★ 380awesome-malware-development. Curated resources for malware dev, reverse engineering, and defensive security research.
★ 1.8kthe-art-of-fuzzing. Application Fuzzing: Tools, Techniques, and Best Practices
★ 176loxs. best tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect
★ 1.6kbinwalk. Firmware Analysis Tool
★ 14kOne-Liners. A collection of one-liners for bug bounty hunting.
★ 1.6kBlueTeam-Tools. Tools and Techniques for Blue Team / Incident Response
★ 4.3ktosint. Tosint is a Telegram OSINT tool that extracts actionable intelligence from bot tokens and chat IDs for security investigations.
★ 841bughunter. Tools for BugHunting
★ 251WADark. WADark - Whatsapp Phishing Tool via OTP Code
★ 44kxss. This a adaption of tomnomnom's kxss tool with a different output format
★ 537osint_stuff_tool_collection. A collection of several hundred online tools for OSINT
★ 8.6kMobile-Security-Framework-MobSF. Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
★ 22khackerone-reports. Top disclosed reports from HackerOne
★ 6.4kinformer. A Telegram Mass Surveillance Bot in Python
★ 1.7kRE-iOS-Apps. A completely free, open source and online course about Reverse Engineering iOS Applications.
★ 2.9kDVIA-v2. Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment. This project is developed and maintained by @prateekg147. The vulnerabilities and solutions covered in this app are tested up to iOS 11. The current version is writen in Swift and has the following vulnerabilities.
★ 1.1kInvoke-Stealth. Simple & Powerful PowerShell Script Obfuscator
★ 595CTF-Game-Challenges. A curated list of Game Challenges from various CTFs
★ 196windows-api-function-cheatsheets. A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management, dynamic-link library (DLL) management, synchronization, interprocess communication, Unicode string manipulation, error handling, Winsock networking operations, and registry operations.
★ 1.5kOffSec-Reporting. Offensive Security OSCP+, OSEP, OSWP, OSWA, OSWE, OSED, OSMR, OSEE, OSDA, OSIR, OSTH Exam and Lab Reporting / Note-Taking Tool
★ 931minhook. The Minimalistic x86/x64 API Hooking Library for Windows
★ 5.9kDetours. Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
★ 6.3khooking-by-example. A series of increasingly complex programs demonstrating function hooking on 64 bit Windows. Culminating in a program that hooks mspaint to make it always paint orange.
★ 335osint-repos-list. List of OSINT Repositories starred from GitHub (limited access version)
★ 97reversing-list. Reversing list
★ 148awesome-security. A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
★ 15kAwesome-GPT-Agents. A curated list of GPT agents for cybersecurity
★ 6.6khollows_hunter. Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
★ 2.4kTitanHide. Hiding kernel-driver for x86/x64.
★ 2.8kpyinstxtractor-ng. PyInstaller Extractor Next Generation
★ 690Docker-OSX. Run macOS VM in a Docker! Run near native OSX-KVM in Docker! X11 Forwarding! CI/CD for OS X Security Research! Docker mac Containers.
★ 53kOSWP. Notes and cheatsheets for the OffSec Wireless Professional (OSWP) certification
★ 53Red-Team-Exercises. C++
★ 721OSCP-Exam-Report-Template-Markdown. :orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report
★ 4.2kbof-scripts. A combination of some scripts that may assist during OSCP Buffer Overflow.
★ 7TelAnalysis. TelAnalysis - Telegram Analysis tool
★ 153toutatis. Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails, phone numbers and more
★ 4.1kthe-definite-guide-to-arm-exploitation. Code Samples for the book "The Definite Guide to ARM Exploitation"
★ 52eCPPT-resources. A compilation of resources for studying for the eCPPTv2
★ 19Offsec-Practice-Labs. Offsec Practice Labs is a curated training arsenal for hands-on prep across eCPPTv3, OSCP, and CPTS.
★ 247meow. Cybersecurity research results. Simple C/C++ and Python implementations
★ 336paper_collection. Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read
★ 1.4kawesome-lists. Awesome Security lists for SOC/CERT/CTI
★ 1.8krust-blog. Educational blog posts for Rust beginners
★ 8.4kSocial-Media-OSINT-Tools-Collection. A collection of most useful osint tools for SOCINT.
★ 1.9kHellsGate. Original C Implementation of the Hell's Gate VX Technique
★ 1.2kROPgadget. This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, and RISC-V Compressed architectures.
★ 4.5k30-Days-Of-Python. The 30 Days of Python programming challenge is a step-by-step guide to learn the Python programming language in 30 days. This challenge may take more than 100 days. Follow your own pace. These videos may help too: https://www.youtube.com/channel/UC7PNRuno1rzYPb1xLa4yktw
★ 70ksemantic-kernel. Integrate cutting-edge LLM technology quickly and easily into your apps
★ 28k