This is your work, valued
TTPRunner. Run TTPs, with AI!
★ 140ConstructingDefenseLab. Ludus range for the Constructing Defense Lab
★ 134DockerDetectionNotes. Some of my rough notes for Docker threat detection
★ 51SysmonConfigPusher2. Sysmon Config Pusher - Modernized
★ 45SANSTHS2021. Hunting Malicious Macros SANS Threathunting Summit 2021 Materials
★ 39fishbowl. Containerized credential auditing perimeter for AI coding agents. Wraps Codex/Claude Code in Docker, audits every credential access via eBPF.
★ 9BTV30. Blue Team Village 30 Talk Materials
★ 5random.
★ 1BSides2019.
★ 1LinuxVisibilityContainer. An Ubuntu container with Sysmon for Linux Configured
★ 1aten. Always-on, cross-platform telemetry daemon for AI agent activity. Sysmon for AI agents.
★ 1codex-mcp-server. Codex Mcp Server
★ 178endpoint-ai-agent-abuse. EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.
★ 37ADACLScanner. Repo for ADACLScan.ps1 - Your number one script for ACL's in Active Directory
★ 1.2kTraceTree. TraceTree - Runtime behavioral analysis tool that maps the process cascade of suspicious packages into a directed tree, catching supply chain attacks that install-time scanners miss.
★ 41cuddlephish. Weaponized Browser-in-the-Middle (BitM) for Penetration Testers
★ 668agent-directory. Python
★ 18Dorothy. Dorothy, the wife your AI agents needs.
★ 327remnux-mcp-server. MCP server for using the REMnux malware analysis toolkit via AI assistants
★ 107mission-control. Self-hosted control plane for AI agents: dispatch tasks, review runs, track spend, and operate OpenClaw, Claude Code, Codex, and other runtimes.
★ 5.9kcli. Google Workspace CLI — one command-line tool for Drive, Gmail, Calendar, Sheets, Docs, Chat, Admin, and more. Dynamically built from Google Discovery Service. Includes AI agent skills.
★ 30kobsidian-skills. Agent skills for Obsidian. Teach your agent to use Obsidian CLI and open formats including Markdown, Bases, JSON Canvas.
★ 44kFindMeAccess. Python
★ 230vscode-dark-islands. VSCode theme based off the easemate IDE and Jetbrains islands theme
★ 8.6kClickOnceBlobber. Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of ProxyBlob Agent.
★ 168yara-rule-skill. LLM Agent Skill for YARA rule authoring and review
★ 60claude-mem. Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
★ 89kMCPControl. MCP server for Windows OS automation
★ 331mcp-vnc. Remote desktop control for AI
★ 53agent-browser. Browser automation CLI for AI agents
★ 40kLifeOS. ⛰️A General Hill-climbing AI harness that helps you move from Current State to Ideal State in both Life and Work.
★ 17kSysmonConfigPusher2. Sysmon Config Pusher - Modernized
★ 45ConstructingDefenseLab. Ludus range for the Constructing Defense Lab
★ 134thermoptic. A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.
★ 1kiii. Effortlessly compose, extend, and observe every service in real-time for the first time ever.
★ 19kRunAs-Stealer. RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging
★ 210HF-Agents-Course-Notes. My Notes from Hugging Face AI Agents Course
★ 20massdns. A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
★ 3.6kPowerShell-Hunter. PowerShell tools to help defenders hunt smarter, hunt harder.
★ 486BrokenHill. A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)
★ 172text-extract-api. Document (PDF, Word, PPTX ...) extraction and parse API using state of the art modern OCRs + Ollama supported models. Anonymize documents. Remove PII. Convert any document or picture to structured JSON or Markdown
★ 3.2kChrome-App-Bound-Encryption-Decryption. Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-mode, no admin required.
★ 1.7koffensive-azure. Collection of offensive tools targeting Microsoft Azure
★ 226GlobalUnProtect. Decrypt GlobalProtect configuration and cookie files.
★ 160osdfir-infrastructure. Helm charts for running open source digital forensic tools in Kubernetes
★ 210turbinia. Automation and Scaling of Digital Forensics Tools
★ 792hindsight. Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox
★ 1.5kimpacket-shell-integration. Bash and ZSH integration for Impacket
★ 74Efflanrs. Efflanrs - GUI for Snaffler Output
★ 27block-parser. Parser for Windows PowerShell script block logs
★ 15PowerDecode. PowerDecode is a PowerShell-based tool that allows to deobfuscate PowerShell scripts obfuscated across multiple layers. The tool performs code dynamic analysis, extracting malware hosting URLs and checking http response.It can also detect if the malware attempts to inject shellcode into memory.
★ 238Graphpython. Modular cross-platform Microsoft Graph API (Entra, o365, and Intune) enumeration and exploitation toolkit
★ 169mdeproxy. Microsoft Defender for Endpoint Proxy (Device Timeline, ...)
★ 5k8s-sniff-https. A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes
★ 75RemoteKrbRelay. Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework
★ 650chromedb. Read Chromium data (namely, cookies and local storage) straight from disk, without spinning up the browser.
★ 138crtdumper. crtdumper is a Go application designed to interact directly with Certificate Transparency (CT) logs servers and extract domain names from certificates. Perfect for security researchers and developers interested in massively extracting domain names from CT logs.
★ 41firefox_decrypt. Firefox Decrypt is a tool to extract passwords from Mozilla (Firefox™, Waterfox™, Thunderbird®, SeaMonkey®) profiles
★ 2.5kNebula. Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to allow testing other Cloud Providers and DevOps Components.
★ 634Evilginx-Phishing-Infra-Setup. Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs
★ 598NetExec. The Network Execution Tool
★ 5.7ksubcrawl. SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data with optional output modules, such as MISP.
★ 150ChromeKatz. Dump cookies and credentials directly from Chrome/Edge process memory
★ 1.5kVolWeb. A centralized and enhanced memory analysis platform
★ 537Aladdin. C#
★ 224rigging. Lightweight LLM Interaction Framework
★ 417ETWInspector. C#
★ 210AutoAppDomainHijack. Automated .NET AppDomain hijack payload generation
★ 129lsa-whisperer. Tools for interacting with authentication packages using their individual message protocols
★ 438NativeDump. Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
★ 744GraphSpy. Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI
★ 1.4kBlauhaunt. A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
★ 187syft. CLI tool and library for generating a Software Bill of Materials from container images and filesystems
★ 9.3kharview. A commandline tool which takes as input a .har (HTTP Archive) file and dumps a human-readable summary of it to the console
★ 65cloud-active-defense. Add a layer of active defense to your cloud applications.
★ 106EntraAuth. PowerShell
★ 67AzTokenFinder. C#
★ 109TrailDiscover. An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and security implications
★ 174Azure-AD-Password-Checker. Azure AD Password Checker
★ 86ViperMonkey. A VBA parser and emulation engine to analyze malicious macros.
★ 1.1kedgeshark. Discover and capture container network traffic from your comfy desktop Wireshark, using a containerized service and a Wireshark plugin.
★ 586IMDSpoof. IMDSPOOF is a cyber deception tool that spoofs the AWS IMDS service to return HoneyTokens that can be alerted on.
★ 106Notebooks. Jupyter notebook
★ 2ysoserial.net-docker. ysoserial.net docker image
★ 33365-Stealer. 365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.
★ 583IntelRAGU. Intel Retrieval Augmented Generation (RAG) Utilities
★ 91RoleCrawl. PowerShell
★ 21vger. An interactive CLI application for interacting with authenticated Jupyter instances.
★ 58bf-aws-perms-simulate. Python
★ 21kunai. Threat-hunting tool for Linux
★ 1.1kOneClick-macOS-Simple-KVM. Tools to set up a easy, quick macOS VM in QEMU, accelerated by KVM. Works on Linux AND Windows.
★ 922kubetap. Kubectl plugin to interactively proxy Kubernetes Services with ease
★ 642gpt4all. GPT4All: Run Local LLMs on Any Device. Open-source and available for commercial use.
★ 77kpwnhub. How GitHub Actions workflows can be hacked
★ 185galah. Galah: An LLM-powered web honeypot.
★ 656CloudIntel. This repo contains IOC, malware and malware analysis associated with Public cloud
★ 251EDRSilencer. A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
★ 1.9kshutter. C++
★ 125Kape2ADX. This is a project for automating your KAPE process. Currently, this project takes KAPE .zips found in blob storage, turns the artefacts into super timelines, then uploads the .csv back to Blob. You can optionally connect blob as a data source to Azure Data Explorer to then do forensics via KQL.
★ 6PoolParty. A set of fully-undetectable process injection techniques abusing Windows Thread Pools
★ 1.3kscrapedown. A simple worker for extracting page content for a given URL
★ 131k8scheck. Shell
★ 3cloudtrail2sightings. Convert cloudtrail data to MITRE ATT&CK Sightings
★ 82teams_dump. PoC for dumping and decrypting cookies in the latest version of Microsoft Teams
★ 131ClickOnce-AppDomain-Manager-Injection. Click Once + App Domain
★ 69m365-fatigue. Python
★ 75Cookie-and-Handle-Stealer. C or BOF file to extract WebKit master key to decrypt user cookie
★ 210arsenal. Arsenal is just a quick inventory and launcher for hacking programs
★ 3.8kBadZure. BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.
★ 514macos-image-templates. HCL
★ 354websec-answers. Websec interview questions by tib3rius answered
★ 310sigma. Main Sigma Rule Repository
★ 11kpwngraph. A simple tool to help the service principal abuse, using Microsoft Graph API.
★ 4security_content. Splunk Security Content
★ 1.7kcloudgrep. cloudgrep is grep for cloud storage
★ 333GCP-Pentest-Checklist.
★ 247JonMon. C++
★ 267TTPForge. The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).
★ 437FuncoPop. Tools for attacking Azure Function Apps
★ 89TierZeroTable. Table of AD and Azure assets and whether they belong to Tier Zero
★ 268AWS-Attack-Scenarios. A collection of real-world scenarios and code samples demonstrating potential exploitation techniques in AWS services. Designed for educational purposes and security awareness.
★ 12act. Run your GitHub Actions locally 🚀
★ 71kneo4cyclone. Python
★ 26llm-opstower. DevOps AI Assistant CLI. Ask questions about your AWS services, cloudwatch metrics, and billing.
★ 71sensitive_iam_actions. Crowdsourced list of sensitive IAM Actions
★ 158ADCSKiller. An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer
★ 749llama_index. LlamaIndex is the leading document agent and OCR platform
★ 51kyoink. Yoink is a quick tool for use with Obsidian that will allow you to take a markdown file and package it up into a folder that will allow you to share an entire markdown document with someone else without having to manually copy all the attachments to a folder.
★ 18ligolo-ng. An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
★ 4.8kurl_genie. Malicious URL Detection Model NN optimized by Genetic Algorithms 🧬
★ 36aftermath. Aftermath is a free macOS IR framework
★ 594Abusing_Weak_ACL_on_Certificate_Templates. Investigation about ACL abusing for Active Directory Certificate Services (AD CS)
★ 135GenAI-Security-Adventures. Jupyter Notebook
★ 108InsightEngineering. Hardcore Debugging
★ 945microsoft-info. Repository hosting a static list of Microsoft First party apps and Graph permissions that's updated daily
★ 241electroniz3r. Take over macOS Electron apps' TCC permissions
★ 224ContainYourself. A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.
★ 319power-pwn. An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
★ 1.2kmalicious-chrome-extension-scanner. Collect chrome extensions from various devices and find out if they are malicious
★ 25kubefuzz. Generative and mutative fuzzer for Kubernetes admission controller chains by automatically parsing the cluster api specification.
★ 77ACCD. Active C&C Detector
★ 155ThreatMapper. Open Source Cloud Native Application Protection Platform (CNAPP)
★ 5.3kBucketLoot. BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text.
★ 446OffensiveCloud. Offensive security and Penetration Testing TTP for Cloud based environment (AWS / Azure / GCP)
★ 353BlackLotus. BlackLotus UEFI Windows Bootkit
★ 2.2kGIUDA. Ask a TGS on behalf of another user without password
★ 481Scripts. A collection of miscellaneous scripts
★ 2curlshell. reverse shell using curl
★ 478LimitsOfML4Vuln. Python
★ 26flightsim. A utility to safely generate malicious network traffic patterns and evaluate controls.
★ 1.4kPerfExec. C#
★ 78fileless-elf-exec. Execute ELF files without dropping them on disk
★ 504detection-and-response-pipeline. ✨ A compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The purpose is to create a reference hub for designing effective threat detection and response pipelines. 👷 🏗
★ 297kbom. KBOM - Kubernetes Bill of Materials
★ 331ALFA. ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework
★ 183llm-course. Course to get into Large Language Models (LLMs) with roadmaps and Colab notebooks.
★ 81kproxy. Security and compliance proxy for LLM APIs
★ 51engineer-manager. A list of engineering manager resource links.
★ 11kSSH-Harvester. Harvest passwords automatically from OpenSSH server
★ 378wmiexec-Pro. New generation of wmiexec.py
★ 1.3kAwesome-CloudSec-Labs. Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.
★ 2.2kgithub-actions-goat. GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment
★ 512AzureAD-Attack-Defense. This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
★ 2.5kLOOBins. Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in "living off the land" macOS binaries and how they can be used by threat actors for malicious purposes.
★ 544WebView2-Cookie-Stealer. C++
★ 265aws-customer-security-incidents. A repository of breaches of AWS customers
★ 812monkey365. Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID. It helps security professionals identify misconfigurations, review cloud security posture, and evaluate environments against industry security best practices and compliance standards.
★ 1.3kawesome-kubernetes-threat-detection. A curated list of resources about detecting threats and defending Kubernetes systems.
★ 409aws-incident-response. HCL
★ 378Amsi-Killer. Lifetime AMSI bypass
★ 680okta_scim_attack_tool. Go
★ 41ccat. Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.
★ 652modern-unix. A collection of modern/faster/saner alternatives to common unix commands.
★ 33kSloth. Mac app that shows all open files, directories, sockets, pipes and devices in use by all running processes. Nice GUI for lsof.
★ 8.9koffensive-docker. Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
★ 767kubernetes-goof. Kubernetes Stranger Danger
★ 68KeePwn. A python tool to automate KeePass discovery and secret extraction.
★ 526amd-ryzen-master-driver-v17-exploit. Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).
★ 160deepce. Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)
★ 1.5kmacOS-Security-Research. macOS Security Research
★ 122undetected-chromedriver. Custom Selenium Chromedriver | Zero-Config | Passes ALL bot mitigation systems (like Distil / Imperva/ Datadadome / CloudFlare IUAM)
★ 13kInterceptor. Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space
★ 135PfxViewer. C++
★ 10Spartacus. Spartacus DLL/COM Hijacking Toolkit
★ 1.1kKubernetes-security. Kubernetes pentesting, hardening and hunting tools.
★ 81Cloud-Security-Attacks. Azure and AWS Attacks
★ 1.1kpeirates. Peirates - Kubernetes Penetration Testing tool
★ 1.5kdploot. DPAPI looting remotely and locally in Python
★ 554go-audit. go-audit is an alternative to the auditd daemon that ships with many distros
★ 1.7kLsass-Shtinkering. C++
★ 383GCPGoat. GCPGoat : A Damn Vulnerable GCP Infrastructure
★ 450Lnk2Vbs. A Python script that embeds Target VBS into LNK and when executed runs the VBS script from within.
★ 33WonkaVision. C#
★ 89ofelia. A docker job scheduler (aka. crontab for docker)
★ 3.9ktraining-devenv-security. Hands-on Exercises for "Dangerous attack paths: Modern Development Environment Security - Devices and CI/CD pipelines"
★ 45AzureGoat. AzureGoat : A Damn Vulnerable Azure Infrastructure
★ 956wevade. C#
★ 8osquery-defense-kit. Production-ready detection & response queries for osquery
★ 610KeeFarceReborn. A standalone DLL that exports databases in cleartext once injected in the KeePass process.
★ 299serverless-prey. Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions
★ 248emblem. Archived: Emblem Giving is a sample application that demonstrates a serverless architecture with continuous delivery, and trouble recovery. :diamond_shape_with_a_dot_inside:
★ 241DEFCON-CICD-pipelines-workshop. HCL
★ 94DLLirant. DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.
★ 503Teamsniper. Teamsniper is a tool for fetching keywords in a Microsoft Teams such as (passwords, emails, database, etc.).
★ 198jsoncrack.com. ✨ Innovative and open-source visualization application that transforms various data formats, such as JSON, YAML, XML and CSV into interactive graphs.
★ 44krdpy. Remote Desktop Protocol in Twisted Python
★ 1.7kSnaffPoint. A tool for pointesters to find candies in SharePoint
★ 288RedisHoneyPot. High Interaction Honeypot Solution for Redis protocol
★ 25Log4Pot. A honeypot for the Log4Shell vulnerability (CVE-2021-44228).
★ 94ciscoasa_honeypot. A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
★ 57CitrixHoneypot. Detect and log CVE-2019-19781 scan and exploitation attempts.
★ 120