This is your work, valued
dvka. Damn Vulnerable Kubernetes App (DVKA) is a series of apps deployed on Kubernetes that are damn vulnerable.
★ 204rmm. Recon MindMap (RMM)
★ 185startup-security-with-opensource-tools. Compilation of open source security tools & platforms to implement in your startup
★ 8rbac-scope. RBAC-Scope is a tool for analyzing RBAC policies used by Kubernetes Operators, helping identify permissions, potential risks, and abuse scenarios.
★ 6reverse-bytes. A simple command line tool written in python for reversing the bytes of a file
★ 5FFFExtractor. Facebook Fanpage Fans Extractor: since facebook does not provide developers / social engineers / hackers with a graph api to get all the fans of an specific facebook fan page I have decided to make my own python script that automatically iterate between ajax request, using valid cookies and stuff
★ 5Git-Hack-Recovery. This scripts allow you to automatically recover your company website or blog in case of being hacked
★ 4itc-coding-questions. Go
★ 3radio. Self-taught Radio Hacking learning / personal notes
★ 3FacebookBot. A simple facebook bot using selenium webdriver, my idea with this project is to create a simple facebook bot / crawler, first implementing a spam functionality (just as a poc) and a message repeater, and then looking for a most complex menu interaction with the bot
★ 3rbac-atlas. RBAC Atlas is a curated database of identities and the Role Based Access Control (RBAC) policies associated with them in popular Kubernetes open-source projects.
★ 3Java-Genetic-Algorithm. A Java based genetic algorithm for my artificial intelligence course
★ 2loopware. PoC of a ransomware that encrypts your files using AES and unlocks them only after you have seen a 10 hours loop youtube video
★ 2CPP-Yacc-Flex-Assembler. An Assembler designed using yacc and flex
★ 1google-ctf-2019. My solutions for google ctf beginners quest 2019
★ 1sequelize-auto-migrations. Migration generator && runner for sequelize
★ 1CTF-CPMX9. CTF challenges for winning CPMX9 free tickets :)
★ 1LG-SmartTv. A simple PHP script to brute force LG SmartTv pairing Key
★ 1portfolio. My personal page on the Internet
★ 1speaker. Speaker notes and bio
★ 1CPP-Disassembler-simulator. CPP Disassembler simulator for my compilers course
★ 1local-agent-sandbox. A local emulator to develop with the agent-sandbox SDK locally
★ 1sdd-govplan. Governance Planning for Spec-Driven Development — conversational requirement gathering, project brief, features, ADRs, acceptance criteria
★ 1kbs. SkillVault: Knowledge Operating System — Go binary · SQLite+FTS5 · MCP stdio · CLI · HTTP API
★ 1chisel. A fast TCP/UDP tunnel over HTTP
★ 16ktukituki. A format and TUI to simplify running development processes
★ 4spec-kit. 💫 Toolkit to help you get started with Spec-Driven Development
★ 125kmempalace. The best-benchmarked open-source AI memory system. And it's free.
★ 58kAgentCore. ARCHIVED — consolidated into QuantumEdu/sdd-govplan
★ 1mailpit. An email and SMTP testing tool with API for developers
★ 10kECC. The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
★ 236kOpenSpec. Spec-driven development (SDD) for AI coding assistants.
★ 63kguardian-cli. Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate intelligent, step-by-step penetration testing workflows while maintaining ethical hacking standards.
★ 1.8kccusage. npx ccusage
★ 18ksuperpowers. An agentic skills framework & software development methodology that works.
★ 264kLifeOS. ⛰️A General Hill-climbing AI harness that helps you move from Current State to Ideal State in both Life and Work.
★ 17kclaude-mem. Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
★ 89kCybersecurity-Engineer-Handbook. This repo has all the resources you need to become an amazing security engineer!
★ 133awesome-mcp-servers. A collection of MCP servers.
★ 92knocodb. 🔥 🔥 🔥 A Free & Self-hostable Airtable Alternative
★ 64kawesome-claude-code. A hand-picked collection of the finest of resources for the most awesome of agents, Claude Code, the undisputed champion of coding companions, from the unstoppable team at Anthropic PBC. A delectable showcase of top tier skills, ambidextrous agents, scintillating status lines, top notch developer tooling, and also we have plugins
★ 51kollama. Get up and running with Kimi-K2.6, GLM-5.2, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.
★ 177krql. A rest filter parser for Go that returns built queries
★ 8kubecolor. Colorize your kubectl output
★ 1.4kFabric. Fabric is an open-source framework for augmenting humans using AI. It provides a modular system for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere.
★ 43kspiderfoot. SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
★ 20kuptime-kuma. A fancy self-hosted monitoring tool
★ 90kCyberChef. The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
★ 35kjuicefs. JuiceFS is a distributed POSIX file system built on top of Redis and S3.
★ 14kk3sup. bootstrap K3s over SSH in < 60s 🚀
★ 7.4kpicfit. An image resizing server written in Go
★ 2.3kexcalidraw. Virtual whiteboard for sketching hand-drawn like diagrams
★ 129karsenal. Arsenal is just a quick inventory and launcher for hacking programs
★ 3.8kAwesome-GPT-Agents. A curated list of GPT agents for cybersecurity
★ 6.6kkubeshark. eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
★ 12kcilium. eBPF-based Networking, Security, and Observability
★ 25kgrype. A vulnerability scanner for container images and filesystems
★ 13kMeshCentral. A complete web-based remote monitoring and management web site. Once setup you can install agents and perform remote desktop session to devices on the local network or over the Internet.
★ 7kbbot. The recursive internet scanner for hackers. 🧡
★ 10kkube-hunter. Hunt for security weaknesses in Kubernetes clusters
★ 5.1kwww-project-kubernetes-top-ten. OWASP Foundation Web Respository
★ 615manageiq. ManageIQ Open-Source Management Platform
★ 1.4kproxmark3. Iceman Fork - Proxmark3
★ 5.9ksemaphore. Modern UI and powerful API for Ansible, Terraform/OpenTofu/Terragrunt, PowerShell and other DevOps tools.
★ 14kprompts.chat. f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
★ 167kdeveloper-community-projects. Go
★ 24mailspoof. Scans SPF and DMARC records for issues that could allow email spoofing.
★ 136magicRecon. MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.
★ 1kkatana. A next-generation crawling and spidering framework.
★ 17kaxiom. The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
★ 4.4khomer. A very simple static homepage for your server.
★ 12kpassbolt_api. Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
★ 6kOnionSearch. OnionSearch is a script that scrapes urls on different .onion search engines.
★ 1.7kStratosphereLinuxIPS. Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.
★ 882gh-workflow-auditor. Script to audit GitHub Action Workflow files for potential vulnerabilities.
★ 152upx. UPX - the Ultimate Packer for eXecutables
★ 18kdvka. Damn Vulnerable Kubernetes App (DVKA) is a series of apps deployed on Kubernetes that are damn vulnerable.
★ 204certgen. A dead simple tool to generate self signed certificates for MinIO TLS deployments
★ 202CTF. CTF challenge (mostly pwn) files, scripts etc
★ 2.5kfor-open-source. Get a 1Password team account for free to support your open source initiatives!
★ 1.9klf. Terminal file manager
★ 9.4kduckhunt. :dart: Prevent RubberDucky (or other keystroke injection) attacks
★ 538virtual-kubelet. Virtual Kubelet is an open source Kubernetes kubelet implementation.
★ 4.5khighwayhash. Native Go version of HighwayHash with optimized assembly implementations on Intel and ARM. Able to process over 10 GB/sec on a single core on Intel CPUs - https://en.wikipedia.org/wiki/HighwayHash
★ 956certified-operators. Production catalog for Red Hat Certified Operator Bundles
★ 82hperf. Distributed HTTP Speed Test.
★ 62kubesploit. Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.
★ 1.2kitc-coding-questions. Go
★ 3madmin-go. The MinIO Admin Go Client SDK provides APIs to manage MinIO services
★ 121minio-iam-testing. Shell
★ 14uuid. Go package for UUIDs based on RFC 4122 and DCE 1.1: Authentication and Security Services.
★ 6.1kmemguard. Software sandbox for storage of sensitive information in memory.
★ 2.8kopenapi-fuzzer. Black-box fuzzer that fuzzes APIs based on OpenAPI specification. Find bugs for free!
★ 576kalidokit. Blendshape and kinematics calculator for Mediapipe/Tensorflow.js Face, Eyes, Pose, and Finger tracking models.
★ 5.7kreact-syntax-highlighter. syntax highlighting component for react with prismjs or highlightjs ast using inline styles
★ 4.7kkubescape. Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
★ 12ktsunami-security-scanner. Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
★ 8.6kpkg. Repository to hold all the common packages imported by MinIO projects
★ 32directpv. Kubernetes CSI driver for Direct Attached Storage :minidisc:
★ 701krew-index. Plugin index for https://github.com/kubernetes-sigs/krew. This repo is for plugin maintainers.
★ 692go-ethereum. Go implementation of the Ethereum protocol
★ 51ksidekick. High Performance HTTP Sidecar Load Balancer
★ 584testssl.sh. Testing TLS/SSL encryption anywhere on any port
★ 9.1klocust. Write scalable load tests in plain Python 🚗💨
★ 28kbottlenet. Find bottlenecks in distributed network
★ 23gitignore. A collection of useful .gitignore templates
★ 175kRustScan. 🤖 The Modern Port Scanner 🤖
★ 20kkubebuilder. Kubebuilder - SDK for building Kubernetes APIs using CRDs
★ 9.3kbeautiful-react-diagrams. 💎 A collection of lightweight React components and hooks to build diagrams with ease 💎
★ 2.7kprometheus-operator. Prometheus Operator creates/configures/manages Prometheus clusters atop Kubernetes
★ 10kdmt. Direct MinIO Tunnel
★ 7gift. Go Image Filtering Toolkit
★ 1.8kproject-layout. Standard Go Project Layout
★ 56kpixel. A hand-crafted 2D game library in Go
★ 4.5kenviro-monitor. Indoor/outdoor environmental monitor project for the Enviro+ environmental monitoring board for Raspberry Pi Zero/W
★ 4hetty. An HTTP toolkit for security research.
★ 12kpresent. A terminal-based presentation tool with colors and effects.
★ 4.3khackaday-u. Course materials for hackaday.io Ghidra training
★ 440radare2. UNIX-like reverse engineering framework and command-line toolset
★ 24kWebKit-http. Deprecated unofficial http mirror of the WebKit SVN repository
★ 5kgf. A wrapper around grep, to help you grep for things
★ 2.1kmeg. Fetch many paths for many hosts - without killing the hosts
★ 1.7khttprobe. Take a list of domains and probe for working HTTP and HTTPS servers
★ 3.1kgobuster. Directory/File, DNS and VHost busting tool written in Go
★ 14kassetfinder. Find domains and subdomains related to a given domain
★ 3.7kscapy. Scapy: the Python-based interactive packet manipulation program & library.
★ 12kcadvisor. Analyzes resource usage and performance characteristics of running containers.
★ 19kFindomain. The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
★ 3.8kselfupdate. Build self-updating Go programs
★ 925dns. DNS library in Go
★ 8.7kgoquery. A little like that j-thing, only in Go.
★ 15kvault. A tool for secrets management, encryption as a service, and privileged access management
★ 36kcommunity-operators. The canonical source for Kubernetes Operators that appear on OperatorHub.io, OpenShift Container Platform and OKD.
★ 420hyper-scale-tensorflow-with-minio. Hyper-Scale Machine Learning with MinIO and TensorFlow
★ 11operator. Simple Kubernetes Operator for MinIO clusters :computer:
★ 1.4kminio-go. MinIO Go client SDK for S3 compatible object storage
★ 3kStartFlagExploit. A local Android DoS Exploit for API 29 and API 30
★ 64kubectl. Issue tracker and mirror of kubectl code
★ 3.3kkubeletmein. Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.
★ 164md5-simd. Accelerate aggregated MD5 hashing performance up to 8x for AVX512 and 4x for AVX2. Useful for server applications that need to compute many MD5 sums in parallel.
★ 216jwt-go. ARCHIVE - Golang implementation of JSON Web Tokens (JWT). This project is now maintained at:
★ 11ksemgrep. Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
★ 16ksecure. HTTP middleware for Go that facilitates some quick security wins.
★ 2.3kzdns. Fast DNS Lookup Library and CLI Tool
★ 1.1kvim-fugitive. fugitive.vim: A Git wrapper so awesome, it should be illegal
★ 22kYouCompleteMe. A code-completion engine for Vim
★ 26kvim-go. Go development plugin for Vim
★ 16kVundle.vim. Vundle, the plug-in manager for Vim
★ 24klightline.vim. A light and configurable statusline/tabline plugin for Vim
★ 6.9kvimrc. The ultimate Vim configuration (vimrc)
★ 32kvim-colors-solarized. precision colorscheme for the vim text editor
★ 6.6kvim-plug. :hibiscus: Minimalist Vim Plugin Manager
★ 36kemotion. 👩🎤 CSS-in-JS library designed for high performance style composition
★ 18kreact-diagrams. a super simple, no-nonsense diagramming library written in react that just works
★ 9.4kprotobuf. Protocol Buffers - Google's data interchange format
★ 72kgo-swagger. Swagger 2.0 implementation for go
★ 10kmultipass. Multipass orchestrates virtual Ubuntu instances
★ 9.2kwarp. S3 benchmarking tool
★ 804redirect. Easily expose ports on live/running containers
★ 20cli. 🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.
★ 4.3kbcc. BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more
★ 23kkops. Kubernetes Operations (kOps) - Production Grade k8s Installation, Upgrades and Management
★ 17kcompress. Optimized Go Compression Packages
★ 5.6kcharts. ⚠️(OBSOLETE) Curated applications for Kubernetes
★ 15kcert-manager. Automatically provision and manage TLS certificates in Kubernetes
★ 14kServerless-Workshop. Serverless Workshop
★ 16keywhiz. A system for distributing and managing secrets
★ 2.6kauditd. Best Practice Auditd Configuration
★ 1.9kclair-scanner. Docker containers vulnerability scan
★ 861dive. A tool for exploring each layer in a docker image
★ 54kdockerscan. The Most Comprehensive Docker Security Scanner
★ 1.7kautocert. ⚓ A kubernetes add-on that automatically injects TLS/HTTPS certificates into your containers
★ 797HackingNeuralNetworks. A small course on exploiting and defending neural networks
★ 2.6kbane. Custom & better AppArmor profile generator for Docker containers.
★ 1.2kmkcert. A simple zero-config tool to make locally trusted development certificates with any names you'd like.
★ 59kbank-vaults. A Vault swiss-army knife: A CLI tool to init, unseal and configure Vault (auth methods, secret engines).
★ 2.3kkes. [Deprecated] Key Encryption Server
★ 498accounting.js. A lightweight JavaScript library for number, money and currency formatting - fully localisable, zero dependencies.
★ 5krecharts. Redefined chart library built with React and D3
★ 27kyara. The pattern matching swiss knife
★ 9.8knebula. A scalable overlay networking tool with a focus on performance, simplicity and security
★ 18kdelve. Delve is a debugger for the Go programming language.
★ 25kkubernetes. Production-Grade Container Scheduling and Management
★ 124kclient-go. Go client for Kubernetes.
★ 9.9kceryx. Dynamic reverse proxy based on NGINX OpenResty with an API
★ 815openresty. High Performance Web Platform Based on Nginx and LuaJIT
★ 14kgo. OpenAPI based generated Go Client for Kubernetes
★ 244kind. Kubernetes IN Docker - local clusters for testing Kubernetes
★ 15km3. MinIO Kubernetes Cloud
★ 28fuzzit. CLI to integrate continuous fuzzing with Fuzzit (no longer available)
★ 223minio. MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license.
★ 61kmc. Unix like utilities for object store
★ 3.5kNotes.
★ 2.7kpwnjs. A Javascript library for browser exploitation
★ 902lazydocker. The lazier way to manage everything docker
★ 52kgosec. Go security checker
★ 8.9kCBM. Car Backdoor Maker
★ 219google-ctf. Google CTF
★ 5kcapirca. Multi-platform ACL generation system
★ 854todo_redux_to_not. Let's remove Redux from the Redux todo example 😂
★ 7API-Security. OWASP API Security Project
★ 2.3kBloodHound-Legacy. Six Degrees of Domain Admin
★ 11kssrf_filter. A ruby gem for defending against Server Side Request Forgery (SSRF) attacks
★ 122GTFOBins.github.io. GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
★ 14kevilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
★ 15ktakeover.sh. Wipe and reinstall a running Linux system via SSH, without rebooting. You know you want to.
★ 7.3kghidra. Ghidra is a software reverse engineering (SRE) framework
★ 72ksystem-design-primer. Learn how to design large-scale systems. Prep for the system design interview. Includes Anki flashcards.
★ 360kexploit-exercises. Mirror for exploit-exercises.com
★ 13LinEnum. Scripted Local Linux Enumeration & Privilege Escalation Checks
★ 8kohmyzsh. 🙃 A delightful community-driven (with 2,500+ contributors) framework for managing your zsh configuration. Includes 300+ optional plugins (rails, git, macOS, hub, docker, homebrew, node, php, python, etc), 140+ themes to spice up your morning, and an auto-update tool that makes it easy to keep up with the latest updates from the community.
★ 189kmigrate. Database migrations. CLI and Golang library.
★ 19ktweepy. Twitter for Python!
★ 11kgolang-webapp. Write a Web App in Go.
★ 86assembly-intro. Intro to x86 Assembly Language.
★ 295accesscontrol. Role and Attribute based Access Control for Node.js
★ 2.3knode_acl. Access control lists for node applications
★ 2.6kretire.js. scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
★ 4.2kmeltdown. This repository contains several applications, demonstrating the Meltdown bug.
★ 4.2kmeltdown-poc. A quick PoC to try out the "meltdown" timing attack.
★ 151dotenv. Loads environment variables from .env for nodejs projects.
★ 21k