This is your work, valued
One who wants to wear the crown, Bears the crown
Neo-reGeorg. Neo-reGeorg is a project that seeks to aggressively refactor reGeorg
★ 3.4kpwcrack-framework. Password Crack Framework
★ 515MX1014. MX1014 is a flexible, lightweight and fast port scanner.
★ 173oneshellcrack. a very very fast brute force webshell password tool
★ 45ctf-scripts. Some of CTF scripts
★ 35LTProxy. Linux Transparent Proxy (Similar to Proxifiter)
★ 33LLK. a linux login log check & fake tool
★ 25CmccKeepConn. a CMCC-FREE automatic connection tool
★ 6my-nse. My NSE Scripts
★ 5metasploit-framework. Metasploit Framework
★ 4ecdict. 📚 ecdict dictionary (Ruby Powered)
★ 1exe2hex. Inline file transfer using in-built Windows tools (DEBUG.exe or PowerShell).
★ 1spinel. C
★ 1.7kRatatuiRuby. 💎 Unofficial Ruby wrapper for Ratatui 👨🍳🐀.
★ 76ruby_llm. One delightful Ruby framework for every major AI provider. Build AI agents, chatbots, RAG apps, and multimodal workflows in beautiful, expressive code.
★ 4.3kmlx-ruby. Ruby Bindings for the MLX Framework
★ 45openclaw. Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
★ 385kwails. Create beautiful applications using Go
★ 36ktauri. Build smaller, faster, and more secure desktop and mobile applications with a web frontend.
★ 110kViewState-Cracker. ASP.net ViewState密钥被动扫描爆破BurpSuite插件
★ 237red-candle. Ruby gem for running state-of-the-art language models locally. Access LLMs, embeddings, rerankers, and NER models directly from Ruby using Rust-powered Candle with Metal/CUDA acceleration.
★ 202sgkrank. 2026最新免费社工库排行
★ 3.6kptcpdump. Process-aware, eBPF-based tcpdump
★ 1.3kkyanos. Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes troubleshooting more efficient.
★ 5.1klinux-firmware. C
★ 46chsrc. chsrc 全平台通用换源工具与框架. Change Source everywhere for every software
★ 6.8kbtop. A monitor of resources
★ 34kunisec. Unicode Security Toolkit
★ 22DllToShellCode. Fast Conversion Windows Dynamic Link Library To ShellCode
★ 420xaes256gcm. Package xaes256gcm implements the XAES-256-GCM extended-nonce AEAD.
★ 21arthas. Alibaba Java Diagnostic Tool Arthas/Alibaba Java诊断利器Arthas
★ 37krelay. 高性能、低资源开销的 relay/proxy 工具
★ 13awesome-free-chatgpt. 🆓免费的 ChatGPT 镜像网站列表,持续更新。List of free ChatGPT mirror sites, continuously updated.
★ 21kjava-echo-generator. 一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.
★ 464java-memshell-generator. 一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.
★ 2.2ktorch.rb. Deep learning for Ruby, powered by LibTorch
★ 836Awesome-Domain-LLM. 收集和梳理垂直领域的开源模型、数据集及评测基准。
★ 2.6kpicker. 将repo变成RSS订阅,文章整理归档, 讨论的社区
★ 236deobfuscator. The real deal
★ 1.8kprotocol-quic. C++
★ 10pics. File formats dissections and more...
★ 11kzeek. Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
★ 7.8kspeedscope. 🔬 A fast, interactive web-based viewer for performance profiles.
★ 6.7krbspy. Sampling CPU profiler for Ruby
★ 2.6kcli. GitHub’s official command line tool
★ 46kcreate_ap. [NOT MAINTAINED] This script creates a NATed or Bridged WiFi Access Point.
★ 4.5kbettercap. The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
★ 20kstackprof. a sampling call-stack profiler for ruby 2.2+
★ 2.2knsproxy. A Linux tool that forces apps to use a SOCKS/HTTP proxy
★ 260Good-MITM. Rule-based MITM engine. Rewriting, redirecting and rejecting on HTTP(S) requests and responses, supports JavaScript rule.
★ 857nali. An offline tool for querying IP geographic information and CDN provider. 一个查询IP地理信息和CDN服务提供商的离线终端工具.
★ 4.1kalacritty. A cross-platform, OpenGL terminal emulator.
★ 65kcarbonyl. Chromium running inside your terminal
★ 19kBilibiliVideoDownload. Cross-platform download bilibili video desktop software, support windows, macOS, Linux
★ 3.5kfzf. :cherry_blossom: A command-line fuzzy finder
★ 82kre0-kubernetes-sec-archive. :atom: [WIP] 整理过去我和K8s、容器、虚拟化相关的分享 🧐
★ 3.2kronin. Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of code, exploits, payloads, etc, via 3rd-party git repositories.
★ 753zeitwerk. Efficient and thread-safe code loader for Ruby
★ 2.1kmsgpack-ruby. MessagePack implementation for Ruby / msgpack.org[Ruby]
★ 790ppspoofing. Rust编写的父进程PID欺骗技术测试工具
★ 51goweight. A tool to analyze and troubleshoot a Go binary size.
★ 1.7klearnjavabug. Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。
★ 2.7kkatana. A next-generation crawling and spidering framework.
★ 17kcnzhnet.music_decrypt. 中国国内音乐 app 会员下载的无损音乐解密工具.
★ 65WechatExporter. Wechat Chat History Exporter 微信聊天记录导出备份程序
★ 8.3kwsMemShell. WebSocket 内存马/Webshell,一种新型内存马/WebShell技术
★ 1.5klux. 👾 Fast and simple video download library and CLI tool written in Go
★ 32kbore. 🕳 bore is a simple CLI tool for making tunnels to localhost
★ 11kr0capture. 安卓应用层抓包通杀脚本
★ 7.7kBash-Oneliner. A collection of handy Bash One-Liners and terminal tricks for data processing and Linux system maintenance.
★ 11kjava-memshell-scanner. 通过jsp脚本扫描java web Filter/Servlet型内存马
★ 1kchatViewTool. 基于Java实现的图形化微信聊天记录解密查看器
★ 581Graph-Easy. Convert or render graphs (as ASCII, HTML, SVG or via Graphviz)
★ 691hacktricks. Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
★ 12kAwesome-Redteam. 一个攻防知识库。A knowledge base for red teaming and offensive security.
★ 4.3kPentest101. 一些关于渗透测试的Tips
★ 608Neo-reGeorg. Neo-reGeorg is a project that seeks to aggressively refactor reGeorg
★ 3.4kHackJava. 《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.
★ 2.9kbad-bpf. A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29
★ 695sysdig. Linux system exploration and troubleshooting tool with first class support for containers
★ 8.3kbpftrace. High-level tracing language for Linux
★ 10kbpf_study. bpf 学习仓库
★ 1.5kdll_to_exe. Converts a DLL into EXE
★ 813hertzbeat. An AI-powered next-generation open source real-time observability system.
★ 7.3kvulbase. 各大漏洞文库合集
★ 756PentestDB. 各种数据库的利用姿势
★ 1kzkar. ZKar is a Java serialization protocol analysis tool implement in Go.
★ 654ecapture. Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
★ 15kexpert_readed_books. 2021年最新总结,推荐工程师合适读本,计算机科学,软件技术,创业,思想类,数学类,人物传记书籍
★ 12kconcurrent-ruby. Modern concurrency tools including agents, futures, promises, thread pools, supervisors, and more. Inspired by Erlang, Clojure, Scala, Go, Java, JavaScript, and classic concurrency patterns.
★ 5.8kkernel_new_features. 一个深挖 Linux 内核的新功能特性,以 io_uring, cgroup, ebpf, llvm 为代表,包含开源项目,代码案例,文章,视频,架构脑图等
★ 1.9krakkess. Review Access - kubectl plugin to show an access matrix for k8s server resources
★ 3rakkess. Review Access - kubectl plugin to show an access matrix for k8s server resources
★ 1.4kStopDefender. Stop Windows Defender programmatically
★ 987golang-shellcode-bypassav. 2021.12.9 使用go语言免杀360、微软、腾讯、火绒
★ 72massdns. A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
★ 3.6kIoT-vulhub. IoT固件漏洞复现环境
★ 1.3kImpost3r. 👻Impost3r -- A linux password thief
★ 663PowerRemoteDesktop. Remote Desktop entirely coded in PowerShell.
★ 2.2kShhhloader. Syscall Shellcode Loader (Work in Progress)
★ 1.3kArmariris. 孤挺花(Armariris) -- 由上海交通大学密码与计算机安全实验室维护的LLVM混淆框架
★ 1.3krogue-jndi. A malicious LDAP server for JNDI injection attacks
★ 1.1kfq. jq for binary formats - tool, language and decoders for working with binary and text formats
★ 11kmosh. Mobile Shell
★ 14kRemmina. Mirror of https://gitlab.com/Remmina/Remmina The GTK+ Remmina Remote Desktop Client
★ 2.5kOffensiveRust. Rust Weaponization for Red Team Engagements.
★ 3kthe-art-of-command-line. Master the command line, in one page
★ 162knuclei. Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
★ 30klearn-hack. 打造超人學習
★ 1.6kLTProxy. Linux Transparent Proxy (Similar to Proxifiter)
★ 32awesome-console-services. A curated list of awesome console services (reachable via HTTP, HTTPS and other network protocols)
★ 6.5kmodern-unix. A collection of modern/faster/saner alternatives to common unix commands.
★ 33kfapro. Fake Protocol Server
★ 1.6kvulfocus. 🚀Vulfocus 是一个漏洞集成平台,将漏洞环境 docker 镜像,放入即可使用,开箱即用。
★ 3.5kjq. Command-line JSON processor
★ 35kfd. A simple, fast and user-friendly alternative to 'find'
★ 44kdog. A command-line DNS client.
★ 6.7kyjit. Optimizing JIT compiler built inside CRuby
★ 729age. A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
★ 23kremote-method-guesser. Java RMI Vulnerability Scanner
★ 927MetasploitModules_0x727. Metasploit Modules Development
★ 71Seatbelt. Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
★ 4.6kMemoryShell. JavaWeb MemoryShell Inject/Scan/Killer/Protect Research & Exploring
★ 661UTM. Virtual machines for iOS and macOS
★ 35kartichoke. 💎 Artichoke is a Ruby made with Rust
★ 3.1kawesome-compose. Awesome Docker Compose samples
★ 46kphpggc. PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
★ 3.9krjb. Ruby Java Bridge
★ 119ysoserial-for-woodpecker. 给woodpecker框架量身定制的ysoserial
★ 632ctf-scripts. Some of CTF scripts
★ 35pwcrack-framework. Password Crack Framework
★ 515MX1014. MX1014 is a flexible, lightweight and fast port scanner.
★ 173pentest_study. 从零开始内网渗透学习
★ 3kAs-Exploits. 中国蚁剑后渗透框架
★ 942linux. Linux kernel source tree
★ 241kGadgetProbe. Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
★ 620PEx64-Injector. A tool for injecting 64-bit executables into legitimate processes. Users can specify a local file or download one from a URL, with all operations performed in memory to evade antivirus detection.
★ 205ProcessInjection. This program is designed to demonstrate various process injection techniques
★ 1.3kiox. Tool for port forwarding & intranet proxy
★ 1.2kRedTeamCCode. Red Team C code repo
★ 573Stowaway. 👻Stowaway -- Multi-hop Proxy Tool for pentesters
★ 3.4kLLK. a linux login log check & fake tool
★ 25herpaderping. Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of a process.
★ 1.2kJava-Rce-Echo. Java RCE 回显测试代码
★ 1kdelete-self-poc. A way to delete a locked file, or current running executable, on disk.
★ 620bof-collection. Collection of Beacon Object Files (BOF) for Cobalt Strike
★ 185MacHack. Hidden Tools in macOS
★ 763DefaultCreds-cheat-sheet. One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
★ 6.7kvcpkg. C++ Library Manager for Windows, Linux, and MacOS
★ 27kPentesterSpecialDict. 构建优化高效的渗透 fuzz 字典合集
★ 1.9kcpr. C++ Requests: Curl for People, a spiritual port of Python Requests.
★ 7.4k360SafeBrowsergetpass. 这是一个一键辅助抓取360安全浏览器密码的CobaltStrike脚本以及解密小工具,用于节省红队工作量,通过下载浏览器数据库、记录密钥来离线解密浏览器密码。
★ 633Active-Directory-Pentest-Notes. 个人域渗透学习笔记
★ 1.8kJspMaster-Deprecated. 一款基于webshell命令执行功能实现的GUI webshell管理工具,支持流量加密
★ 220portfwd. User-space TCP/UDP port forwarding services
★ 294redteam_vul. 红队作战中比较常遇到的一些重点系统漏洞整理。
★ 2.5kshellcodeloader. shellcodeloader
★ 1.7kr77-rootkit. Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
★ 2.2kOffensiveNim. My experiments in weaponizing Nim (https://nim-lang.org/)
★ 3.1kdomainTools. 内网域渗透小工具
★ 734RustScan. 🤖 The Modern Port Scanner 🤖
★ 20kWhatsMyName. Community-maintained dataset of 700+ websites for finding accounts by username — powers OSINT and digital footprint tools.
★ 2.7kEventlogedit-evtx--Evolution. Remove individual lines from Windows XML Event Log (EVTX) files
★ 273HackBrowserData. Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
★ 14kpurple-team-attack-automation. Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs
★ 729PowerShdll. Run PowerShell with rundll32. Bypass software restrictions.
★ 1.8kWMIHACKER. A Bypass Anti-virus Software Lateral Movement Command Execution Tool
★ 1.5kPowershell-Attack-Guide. Powershell攻击指南----黑客后渗透之道
★ 867tsh. Tiny SHell is an open-source UNIX backdoor.
★ 713Erebus. CobaltStrike后渗透测试插件
★ 1.6kfakelogonscreen. Fake Windows logon screen to steal passwords
★ 1.4kxsv. A fast CSV command line toolkit written in Rust.
★ 11ktmuxinator. Manage complex tmux sessions easily
★ 14klsassy. Extract credentials from lsass remotely
★ 2.2kbcc. BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more
★ 23kslim. Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
★ 23kfuzzDicts. You Know, For WEB Fuzzing !
★ 8.4knnn. n³ The unorthodox terminal file manager
★ 22kmimikatz. A little tool to play with Windows security
★ 22kruler. A tool to abuse Exchange services
★ 2.3kmetasploit-framework. Metasploit Framework
★ 39kBaiduYunVIP. 百度云百度网盘超级会员账号SVIP账号 分享, 另分享多款百度网盘不限速下载工具以及各大平台会员账号(迅雷 优酷 爱奇艺 腾讯视频等).
★ 4.2kairgeddon. This is a multi-use bash script for Linux systems to audit wireless networks.
★ 7.9kctftool. Interactive CTF Exploration Tool
★ 1.7kwatir. Watir Powered By Selenium
★ 1.5kshodan-python. The official Python library for Shodan
★ 2.9ktty. Toolkit for developing sleek command line apps.
★ 2.5kradare2. UNIX-like reverse engineering framework and command-line toolset
★ 24kCyberChef. The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
★ 35kgophish. Open-Source Phishing Toolkit
★ 14kFastjsonExploit. Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)
★ 1.4kSSRF-Testing. SSRF (Server Side Request Forgery) testing resources
★ 2.5kBaiduNetdiskPlugin-macOS. For macOS.百度网盘 破解SVIP、下载速度限制~
★ 8.9khigh-speed-downloader. 已不再维护
★ 7.1kPicGo. :rocket: The Ultimate Image Uploader for Efficient Creators. Supports Obsidian, Typora, VS Code etc. and 60+ image hosting services (S3, GitHub, Cloudflare R2, Imgur, Aliyun OSS...). Paste, upload, done.
★ 27khuginn. Create agents that monitor and act on your behalf. Your agents are standing by!
★ 50kRsaCtfTool. RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data
★ 7kalgorithms. algorithms playground for common questions
★ 3.2kEnterpriseWifiPasswordRecover. This is a tool that recovers WPA2 Enterprise Wifi Credentials from a machine.
★ 109WeChatExtension-ForMac. A plugin for Mac WeChat
★ 23kpatator. Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
★ 3.9kffuf. Fast web fuzzer written in Go
★ 16kexploits. Some of my exploits.
★ 602CheckPlease. Sandbox evasion modules written in PowerShell, Python, Go, Ruby, C, C#, Perl, and Rust.
★ 932ChinaMobilePhoneNumberRegex. Regular expressions that match the mobile phone number in mainland China. / 一组匹配中国大陆手机号码的正则表达式。
★ 4.8kCarHackingTools. Install and Configure Common Car Hacking Tools.
★ 969pupy. Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
★ 9kAwesome-WAF. Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
★ 7.6kjadx. Dex to Java decompiler
★ 50kJava-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
★ 3.2kthe-practical-linux-hardening-guide. This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
★ 11kIntruderPayloads. A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
★ 4k