This is your work, valued
BridgeHead. Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.
★ 81C2Watch. C2Watch is a Threat Intelligence framework to monitor C2 in the wild
★ 1RRReporter. Rapid Rabbit Reporter
★ 1BestEdrOfTheMarket. EDR Lab for Experimentation Purposes
★ 1.5kWireTapper. WireTapper is a wireless OSINT tool that passively detects and maps Wi-Fi, Bluetooth, CCTV cameras, vehicles, headphones, TVs, IoT devices, and cell towers, turning nearby radio signals into clear situational intelligence 📡
★ 1.8kCineSeekerr. a self-hosted Telegram bot that turns the whole "organize my media library" chore into a quick chat. Confirm a title, tap a few buttons for your preferences, and it handles queuing, progress tracking, and renaming everything perfectly.
★ 3ADWS-BOF. Beacon Object File for LDAP Queries Through ADWS
★ 36librepods. AirPods liberated from Apple's ecosystem.
★ 29kRopper. Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64). For disassembly ropper uses the awesome Capstone Framework.
★ 2.1kconcealed_position. Bring your own print driver privilege escalation tool
★ 263SynthAPT. Generate malware with AI
★ 231RuView. π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.
★ 88kskuld. Next-Gen Stealer written in Go. Stealing from Discord, Chromium-Based & Firefox-Based Browsers, Crypto Wallets and more, from every user on every disk. (PoC. For educational purposes only)
★ 472LitterBox. A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.
★ 1.5kflare-floss. FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
★ 4.1kClaude-OSINT. Two paired Claude skills · 90+ recon modules · 48 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · 5,500+ lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.
★ 2.1kobscura. The headless browser for AI agents and web scraping
★ 20kflipperzero-geigercounter. ☢☢ A geiger counter application for the Flipper Zero ☢☢
★ 257FBps-lab. Intentionally vulnerable lab for exploring access control bypasses in misconfigured Nginx/Flask setups
★ 10Shadowbroker. Open-source intelligence for the global theater. Track everything from the corporate/private jets of the wealthy, and spy satellites, to seismic events in one unified interface. Hook an AI agent up to have it parse through data and find previously unseen correlations. The knowledge is available to all but rarely aggregated in the open, until now.
★ 10kinceptor. Template-Driven AV/EDR Evasion Framework
★ 1.8kFOCA. Tool to find metadata and hidden information in the documents.
★ 3.6kPLFM_RADAR. Open-source, low-cost 10.5 GHz PLFM phased array RADAR system
★ 23kheretic. Fully automatic censorship removal for language models
★ 27kclaude-subconscious. Give Claude Code a subconscious
★ 2.9kclaurst. Agentic Coding for Builders who Ship
★ 10kWindowsExploitationResources. Resources for Windows exploit development
★ 1.7khexstrike-ai. HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
★ 11kAD_Miner. AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses
★ 1.5kGorgeous-GRUB. Collection of decent Community-made GRUB themes. Contributions welcome!
★ 5.6kpentagi. Fully autonomous AI Agents system capable of performing complex penetration testing tasks
★ 21kworldmonitor. Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
★ 78kSideband. LXMF client for Android, Linux and macOS allowing you to communicate with people or LXMF-compatible systems over Reticulum networks using LoRa, Packet Radio, WiFi, I2P, or anything else Reticulum supports.
★ 1.6kreticulum-meshchat. A simple mesh network communications app powered by the Reticulum Network Stack.
★ 1.1kmimikatz-missing-manual. The Mimikatz Missing Manual
★ 461mybb. MyBB is a free and open source forum software.
★ 1.2kEpstein-Files. Public archive index for the DOJ Epstein Files releases (Datasets 1–12), aggregating official downloads, community mirrors, torrent magnets, and integrity verification to ensure long-term accessibility.
★ 581dontlookup. Python
★ 795OST-C2-Spec. Open Source C&C Specification
★ 283EDRPrison. Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry
★ 478onionscan. OnionScan is a free and open source tool for investigating the Dark Web.
★ 3.3kgogs. The painless way to host your own Git service
★ 48kReverse-Engineering. A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.
★ 14ksystem-prompts-and-models-of-ai-tools. FULL Augment Code, Claude Code, Cluely, CodeBuddy, Comet, Cursor, Devin AI, Junie, Kiro, Leap.new, Lovable, Manus, NotionAI, Orchids.app, Perplexity, Poke, Qoder, Replit, Same.dev, Trae, Traycer AI, VSCode Agent, Warp.dev, Windsurf, Xcode, Z.ai Code, Dia & v0. (And other Open Sourced) System Prompts, Internal Tools & AI Models
★ 142kgsmevil2. GsmEvil 2
★ 371AdaptixC2. AdaptixC2 is a highly modular advanced redteam toolkit
★ 3.4kOSED. Containing my notes, practice binaries + solutions, blog posts, etc. for the Offensive Security Exploit Developer (OSED/EXP-301)
★ 829code_caver. Python based WinDbg script to automate the search for code caves in binaries and libraries.
★ 56windbg-readable-theme. Windbg Readable & Dark Green Theme - Own Use
★ 48clusterfuzzlite. ClusterFuzzLite - Simple continuous fuzzing that runs in CI.
★ 531clusterfuzz. Scalable fuzzing infrastructure.
★ 5.6kWindowsInternals. Windows Internals Book 7th edition Tools
★ 2.8kgitea-automation. Scripts to automate the installation of Gitea (https://gitea.io/)
★ 2DriverAnalyzer. A static analysis tool that helps security researchers scan a list of Windows kernel drivers for common vulnerability patterns in drivers (CVE makers!)
★ 69APTs-Adversary-Simulation. This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stagers, bootloaders, and other malicious artifacts that mirror those used in real world attacks .
★ 1.1kr77-rootkit. Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
★ 2.2kESP32-DIV. ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32
★ 3.6ktsh. Tiny SHell - An open-source UNIX backdoor (I'm not the author!)
★ 637garbage. C++
★ 15Medical-Neuroscience-Duke.
★ 1Medical-Neuroscience. This is my notes of Medical Neuroscience course offered by the Duke University through Coursera
★ 3PPLFault. C
★ 567Windows-Spoofer. This is a project for spoofing windows as much as possible to become untraceable for detection purposes and others.
★ 146GOAD. game of active directory
★ 8.1ktron. Tron
★ 6.5kcheat-engine. Cheat Engine. A development environment focused on modding
★ 19kgame-hacking. Tutorials, tools, and more as related to reverse engineering video games.
★ 5.5kmvt. MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
★ 13kIce9-Keygen. A keygen for the Ice9 crackme challenge. Stylized using the retro keygen aesthetic of the early 2000s.
★ 3win98-quickinstall. A framework + installer to (very) quickly install Windows 98 on anything from a 486 up to a modern system
★ 1.6kCobalt-Strike. Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection
★ 330CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability. Microsoft-Outlook-Remote-Code-Execution-Vulnerability
★ 766Acropolis. The script to install Adobe Acrobat Pro x64
★ 93C2concealer. C2concealer is a command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike.
★ 1.1kImGUI-Advanced-Cheat-Menu. C++
★ 316euriclea. Fingerprinting TCP/IP
★ 37ImHex. 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
★ 54kPentest-Windows. ⚔️Windows11 Penetration Suite Toolkit 🔰 The First Windows Penetration Testing Environment on Mac M Chips
★ 3.5kMobile-Security-Framework-MobSF. Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
★ 22kEvilginx-Phishing-Infra-Setup. Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs
★ 598SprayingToolkit. Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient
★ 1.6kMercurial-Grabber. Grab Discord tokens, Chrome passwords and cookies, and more
★ 483Backstab. A tool to kill antimalware protected processes
★ 1files.
★ 101BYOVDKit. bring your own vulnerable driver
★ 124EDRSandblast-GodFault. EDRSandblast-GodFault
★ 273EDRSandblast. C
★ 1.8kBackstab. A tool to kill antimalware protected processes
★ 1.5kConti-Ransomware. Full source of the Conti Ransomware Including the missing Locker files from the original leak. I have fixed some of the errors intentionally introduced by the leaker to prevent the locker from being built. The Queue header file which implements a few linked list data structures that Conti uses for task scheduling in the Threadpool had several missing commas, there are still errors which I believe to be the result of a missing #ifdef pre-processsor macro in one of the header files but haven't had time to find it. Will be uploading English Translated Documentation In the future
★ 180PPLcontrol. Controlling Windows PP(L)s
★ 403awesome-osint. :scream: A curated list of amazingly awesome OSINT
★ 28kMultiDump. MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.
★ 541cobaltstrike. Code and yara rules to detect and analyze Cobalt Strike
★ 275Shodan_Pull_Cobalt_Strike_Team_Servers. This code will pull Cobalt Strike Team Servers and Metasploit Servers from Shodan's API using various criteria.
★ 4gophish. Open-Source Phishing Toolkit
★ 14kCVE-2022-39197. CobaltStrike <= 4.7.1 RCE
★ 387MalwareConfigLists. Just some lists of Malware Configs
★ 175base64. C++
★ 117LockBit-Black-Builder. Batchfile
★ 110nekros. NekRos is an Open-Source Ransomeware, with advanced Features, Which Looks Like Wannacry and Has C&C Server which can be Used to Retrive KEY
★ 131Malleable-C2-Profiles. Malleable C2 Profiles. A collection of profiles used in different projects using Cobalt Strike & Empire.
★ 406Visual-Studio-BOF-template. A Visual Studio template used to create Cobalt Strike BOFs
★ 324PersistBOF. A BOF to automate common persistence tasks for red teamers
★ 299