This is your work, valued
RIP.
★ 1.4kDefenderYara. Extracted Yara rules from Windows Defender mpavbase and mpasbase
★ 534cve-search_mcp. A Model Context Protocol (MCP) server for querying the CVE-Search API
★ 102SideloadFinder. frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can later be weaponized during Red Team Operations to evade AV/EDR's.
★ 60Record. C
★ 16SIGNATURE_TYPE_LUASTANDALONE. Extracted lua script from Defender mpavbase.vdm and mpasbase.vdm
★ 16Game-Cheating-Tutorial. 热门网络游戏辅助开发教程
★ 14hf-2011. Automatically exported from code.google.com/p/hf-2011
★ 7DataRecovery. 数据恢复相关
★ 3NGLite. A major platform RAT Tool based by Blockchain/P2P.Now support Windows/Linux/MacOS
★ 3View8. View8 - Decompiles serialized V8 objects back into high-level readable code.
★ 2wdbgark. WinDBG Anti-RootKit Extension
★ 1kuna. An agent-first decompiler designed to be refined by other agents. Kuna is written in Rust and was originally ported from Ghidra.
★ 202agentflow. Orchestrate thousands of agents and harnesses as a graph programatically
★ 1.4kRuView. π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.
★ 88kKDU. Kernel Driver Utility
★ 2.7kOpenCut. The open-source CapCut alternative
★ 80kVulnGym. VulnGym: A Real-World, Project-Level Vulnerability Benchmark for White-Box Vulnerability-Hunting Agents
★ 209EasyEdit. [ACL 2024] An Easy-to-use Knowledge Editing Framework for LLMs.
★ 2.9kcrackmes-re-dataset. Labeled reverse-engineering dataset over 4,598 crackmes: flags, verifier scripts, and normalized obfuscation tags.
★ 109AntiVE-BehaviorWatch. AntiVE-BehaviorWatch is an advanced behavioral analysis malware that detects automated analysis systems through real-time mouse movement pattern recognition. Leveraging GRU neural networks, it provides high-accuracy classification of user behavior while identifying potential virtual machine, sandbox, or emulation environments.
★ 34strix. Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
★ 46kgt_ai_gateway. 轻量高性能 AI 网关,支持协议转换和请求可视化,以及缓存优化功能。并可以运行在 Serverless、Docker 和桌面端环境
★ 215cve-mcp-server. Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
★ 1.1kICSFieldID. Python
★ 1ProcmonMCP. An MCP server for procmon
★ 48meow. Cybersecurity research results. Simple C/C++ and Python implementations
★ 335skills. Skills for coding agents
★ 3.9kpi-skills. Skills for pi coding agent (compatible with Claude Code and Codex CLI)
★ 2.3kFormAI-dataset.
★ 51retain-pdf. 在保留版面、公式与结构的前提下进行 PDF 翻译,适用于科研与技术文档
★ 2.1kChorus. The Agent Harness for AI-Human Collaboration, inspired by the AI-DLC (AI-Driven Development Lifecycle)
★ 1.1kclaude-code. JavaScript
★ 249GordenPPTSkill. AI-friendly PPT builder skill: 17 hand-polished Chinese PPTX templates + non-destructive text-only editing tools (python-pptx based). Pick a template, write edits.json, build a real .pptx with the layout intact. Personal/research use only.
★ 2.8kandroid-reverse-engineering-skill. Claude Code skill to support Android app's reverse engineering
★ 6.6kvscode-restclient. REST Client Extension for Visual Studio Code
★ 6knuma. Portable DNS resolver in Rust — .numa local domains, ad blocking, developer overrides
★ 1.4kmindfs. Access your personal AI agents and workstation data anywhere, anytime through MindFS.
★ 1.5kds4. DeepSeek 4 Flash and PRO local inference engine for Metal, CUDA and ROCm
★ 19kagent-threat-rules. Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents. 768 rules across 10 categories; merged into Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H, FINOS & SigmaHQ. MIT-licensed.
★ 355donutbrowser. Simple Yet Powerful Anti-Detect Browser 🍩
★ 3.5ksherpa. Security Harness Engineering for Robust Program Analysis
★ 138qt-minimalistic-builds. Precompiled x64 Qt 5/6 library in minimalistic configuration for Windows.
★ 364CubeSandbox. Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
★ 11kvectorscan. A portable fork of the high-performance regular expression matching library
★ 717build-bindiff-for-ida-9. Use GitHub Actions to build BinDiff 8 and BinExport 12 for various IDA Pro 9.x on Windows, macOS, and Linux.
★ 230rophi. Injecting code by recompiling shellcode into a ROP chain.
★ 144multica. The open-source managed agents platform. Turn coding agents into real teammates — assign tasks, track progress, compound skills.
★ 43khack-skills. Helping AI Agent become an awesome practical hacker!
★ 1.5keasy_proxies. A proxy node pool management tool based on sing-box, supporting multiple protocols, automatic failover and load balancing. 基于 sing-box 的代理节点池管理工具,支持多协议、多节点自动故障转移和负载均衡。
★ 1.6kShinigami. A dynamic unpacking tool
★ 152GLM-skills. Official skills for the GLM family of models.
★ 455HydraDragonAntivirus. Dynamic and static analysis with Real Time Malware Analysis with Antivirus for Windows, including open-source XDR (3 EDR projects), ClamAV, YARA-X, machine learning AI, behavioral analysis, Unpacker, Deobfuscator, Decompiler, website signatures, Ghidra, Suricata, Sigma, Kernel, Hypervisior based protection and much more than you can imagine.
★ 217AgentRE-Bench. AgentRE-Bench is an agentic benchmark that evaluates state-of-the-art models on long-horizon reverse engineering tasks, measuring their ability to analyze binaries, use tooling effectively, and reason over multi-step execution artifacts
★ 89gitweekly. 收集各种有趣的github项目
★ 101Rikugan. A reverse-engineering agent for IDA Pro and Binary Ninja
★ 665Practical-Guide-to-Context-Engineering. 大模型应用开发的方向,上下文工程是设计原则,Agent Harness 是构建目标,本项目的目标,是为开发者和研究者提供一份大模型应用开发的骨架思路
★ 746VulnMCP. A modular MCP server providing AI-driven vulnerability management skills, including severity classification and automated insights.
★ 33VMkatz. Extract Windows credentials directly from VM memory snapshots and virtual disks
★ 1.5kIDAssist. AI-Powered Reverse Engineering Plugin for IDA Pro
★ 703cpueaxh. Lightweight, dependency-free x86-64 CPU emulation library with Unicorn-like guest mode and direct host-memory execution.
★ 218camoufox. 🦊 Anti-detect browser
★ 11kAI-ML-Free-Resources-for-Security-and-Prompt-Injection. AI/ML Pentesting Roadmap for Beginners
★ 661speakeasy. Windows kernel and user mode emulation.
★ 2kironclaw. IronClaw is an Agent OS focused on privacy, security and extensibility
★ 13kheretic. Fully automatic censorship removal for language models
★ 27kAegis. Open-source EDR for AI agents. Monitor processes, files, network, and behavior of autonomous AI agents.
★ 140claude-code-best-practice. from vibe coding to agentic engineering - practice makes claude perfect
★ 64kInviZzzible. InviZzzible is a tool for assessment of your virtual environments in an easy and reliable way. It contains the most recent and up to date detection and evasion techniques as well as fixes for them.
★ 590ida-mcp-rs. Headless IDA Pro MCP Server
★ 677OpenSandbox. Secure, Fast, and Extensible Sandbox runtime for AI agents.
★ 12kYARAify. Open YARA scan- and search engine
★ 26remill. Library for lifting machine code to LLVM bitcode
★ 1.8kmcp-windbg. Model Context Protocol for WinDbg.
★ 1.5kzituoguan.
★ 84patchdiff-ai. Python
★ 183misp-ghidra. Ghidra and MISP
★ 9Pensieve. tore your decisions and principles. Claude reads them to make better choices.
★ 2.5kBoxPwnr. A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench, picoCTF and more.
★ 435DeTTECT. Detect Tactics, Techniques & Combat Threats
★ 2.3kSOC. Intelligent SOC automation framework powered by LangGraph multi-agent workflows for alert triage, correlation, and incident response
★ 14tgbot-verify. 一个基于 Python Telegram Bot 的自动化认证工具,能够自动完成 SheerID 平台的学生/教师身份验证流程。
★ 3kVidBee. Download videos from almost any website worldwide
★ 10khvmi. Hypervisor Memory Introspection Core Library
★ 689Ryujin. Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool
★ 336kvc. KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch, skci.dll hijack, SeCiCallbacks redirection) and PP/PPL manipulation for LSASS memory dumping on modern Windows with HVCI/VBS.
★ 302ollvm_arkari_ex. Yet another llvm based obfuscator based on arkari
★ 4mtga. 基于本地代理的方式,绕过 IDE 的固定模型服务商限制
★ 1.2kvxsig. Automatically generate AV byte signatures from sets of similar binaries.
★ 286BettaFish. 微舆:人人可用的多Agent舆情分析助手,打破信息茧房,还原舆情原貌,预测未来走向,辅助决策!从0实现,不依赖任何框架。
★ 42kSIEM. SIEM Tactics, Techiques, and Procedures
★ 723SmallVmp. 简单的基于llvm实现vmp保护
★ 264yarr. yet another rss reader
★ 3.9kPoC-in-GitHub. 📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
★ 7.9kcapa-rules. Standard collection of rules for capa: the tool for enumerating the capabilities of programs
★ 726capa-testfiles. Data to test capa's code and rules.
★ 49simple-container-network-book. 面向网络小白的基础网络和容器网络的科普
★ 957linux-kernel-exploitation. A collection of links related to Linux kernel security and exploitation
★ 6.6ktenrec. A headless, extendable, multi-session, IDA Pro MCP framework.
★ 179DNSGrep. Quickly Search Large DNS Datasets
★ 586emuit. Easy-to-use IDA plugin for code emulation
★ 73yarka. IDA plugin for YARA signature creation
★ 25iris. A neurosymbolic framework for vulnerability detection in code
★ 409mcp-run-python. MCP server to run Python code in a sandbox.
★ 192awesome-LangGraph. An index of the LangChain + LangGraph ecosystem: concepts, projects, tools, templates, and guides for LLM & multi-agent apps.
★ 1.9ksecurity_content. Splunk Security Content
★ 1.7klangextract. A Python library for extracting structured information from unstructured text using LLMs with precise source grounding and interactive visualization.
★ 38kMalDev-Analyzer-MCP. Built for red teamers, by red teamers - an MCP tool for malware development, OPSEC testing, and supporting custom loader design during red team engagements.
★ 45elfspirit. ELF static analysis and injection framework that parse, manipulate, patch and camouflage ELF files.
★ 147dots.ocr. Multilingual Document Layout Parsing in a Single Vision-Language Model
★ 9kBamboozlEDR. A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
★ 275Overt. Overt是一款功能强大的Android设备安全检测工具
★ 248cuddlephish. Weaponized Browser-in-the-Middle (BitM) for Penetration Testers
★ 667gpt-load. Multi-channel AI proxy with intelligent key rotation. 智能密钥轮询的多渠道 AI 代理。
★ 6.3kserena. A powerful MCP toolkit for coding, providing semantic retrieval and editing capabilities - the IDE for your agent
★ 27kagents. Multi-harness agentic plugin marketplace for Claude Code, Codex CLI, Cursor, OpenCode, GitHub Copilot, and Gemini CLI
★ 38kMBE. Course materials for Modern Binary Exploitation by RPISEC
★ 6kmemos. Open-source, self-hosted note-taking tool built for quick capture. Markdown-native, lightweight, and fully yours.
★ 62kEasyUKey. 一个基于USB设备的开源高安全性认证服务解决方案,提供简易U盾实现。将任何U盘变为您的专属安全密钥 (U盾),无需特定硬件,即插即用。
★ 73CookieCloud. CookieCloud是一个和自架服务器同步浏览器Cookie和LocalStorage的小工具,支持端对端加密,可设定同步时间间隔。本仓库包含了插件和服务器端源码。CookieCloud is a small tool for synchronizing browser cookies and LocalStorage with a self-hosted server. It supports end-to-end encryption and allows for setting the synchronization interval. This repository contains both the plugin and the server-side source code
★ 3.1kevilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
★ 15ksubtitle-translator. ⚡ Blazing-fast batch subtitle translation, .srt/.ass/.vtt/.lrc, 17+ LLM providers | 批量字幕翻译,支持 120+ 语言
★ 988VideoLingo. Netflix-level subtitle cutting, translation, alignment, and even dubbing - one-click fully automated AI video subtitle team | Netflix级字幕切割、翻译、对齐、甚至加上配音,一键全自动视频搬运AI字幕组
★ 18kpyvideotrans. Translate the video from one language to another and embed dubbing & subtitles.
★ 18kpspy. Monitor linux processes without root permissions
★ 6.1kAdGuardHome. Network-wide ads & trackers blocking DNS server
★ 36kdnsproxy. Simple DNS proxy with DoH, DoT, DoQ and DNSCrypt support
★ 3.2kmemgraph. High-performance open-source in-memory graph database for GraphRAG, AI memory, agentic AI, and real-time graph analytics. Cypher-compatible, built in C++.
★ 4.3kcrawl4ai. 🚀🤖 Crawl4AI: Open-source LLM Friendly Web Crawler & Scraper. Don't be shy, join here: https://discord.gg/jP8KfhDhyN
★ 76kminivm. A VM That is Dynamic and Fast
★ 1.7kchipsec. Platform Security Assessment Framework
★ 3.3kvm-trace-release. vmtrace的发布仓库,相关so 调用脚本例子都会放在里面
★ 594SecDictionary. 实战沉淀字典
★ 1.6kchangedetection.io. Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price drops, restock alerts, and website defacement monitoring—all for free or enjoy our SaaS plan!
★ 33khachimi. 哈基米 一个分布式蜜网系统 | hachimi A Distributed Honeypot System
★ 199HivisionIDPhotos. ⚡️HivisionIDPhotos: a lightweight and efficient AI ID photos tools. 一个轻量级的AI证件照制作算法。
★ 21kView8. View8 - Decompiles serialized V8 objects back into high-level readable code.
★ 3webcrack. Deobfuscate obfuscator.io, unminify and unpack bundled javascript
★ 2.8kgo-exploit. A Go-based Exploit Framework
★ 447homelab. Fully automated homelab from empty disk to running services with a single command.
★ 9.5kArion. A high-performance C++ framework for emulating executable binaries
★ 131tiny_tracer. A Pin Tool for tracing API calls etc
★ 1.7knanoVLM. The simplest, fastest repository for training/finetuning small-sized VLMs.
★ 5kreq. Simple Go HTTP client with Black Magic
★ 4.8kwxauto. Windows版本微信客户端(非网页版)自动化,可实现简单的发送、接收微信消息,简单微信机器人
★ 7.2kLitterBox. A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.
★ 1.5kBOAZ_beta. Multilayered AV/EDR Evasion Framework (no longer actively maintained)
★ 974All-Defense-Tool. 本项目集成了全网优秀的攻防武器工具项目,包含自动化利用,子域名、目录扫描、端口扫描等信息收集工具,各大中间件、cms、OA漏洞利用工具,爆破工具、内网横向、免杀、社工钓鱼以及应急响应、甲方安全资料等其他安全攻防资料。
★ 7.8kMalConfScan. Volatility plugin for extracts configuration data of known malware
★ 498homarr. A modern and easy to use dashboard. 40+ integrations. 20K+ icons built in. Authentication out of the box. No YAML, drag and drop configuration.
★ 4.4kd3fend-ontology. This repository holds the necessary content to produce the D3FEND ontology distribution.
★ 112PDFMathTranslate. [EMNLP 2025 Demo] PDF scientific paper translation with preserved formats - 基于 AI 完整保留排版的 PDF 文档全文双语翻译,支持 Google/DeepL/Ollama/OpenAI 等服务,提供 CLI/GUI/MCP/Docker/Zotero
★ 36kHyperCE. Bypass protection and hide CE via VT-x hypervisor and ept hook to use cheat engine .
★ 220cai. Cybersecurity AI (CAI), the framework for AI Security
★ 9.6kNoScreen. Hiding the window from screenshots using the function win32kfull::GreProtectSpriteContent
★ 649reverse-ssh. Statically-linked ssh server with reverse shell functionality for CTFs and such
★ 1.1kthread-call-stack-scanner. Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussions/15
★ 83markdir. A simple HTTP server for rendering markdown files
★ 69nanobind. nanobind: tiny and efficient C++/Python bindings
★ 6yek. A fast Rust based tool to serialize text-based files in a repository or directory for LLM consumption
★ 2.5kbrowser-use. 🌐 Make websites accessible for AI agents. Automate tasks online with ease.
★ 107kmonolith. ⬛️ CLI tool and library for saving complete web pages as a single HTML file
★ 15kida-pro-mcp. AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
★ 11kawesome-mcp-servers. A collection of MCP servers.
★ 92kGhidraMCP. MCP Server for Ghidra
★ 9.6kgritql. GritQL is a query language for searching, linting, and modifying code.
★ 4.6kollama-mcp-bridge. Bridge between Ollama and MCP servers, enabling local LLMs to use Model Context Protocol tools
★ 977garak. the LLM vulnerability scanner
★ 8.6kEasyJailbreak. An easy-to-use Python framework to generate adversarial jailbreak prompts.
★ 876cve-search_mcp. A Model Context Protocol (MCP) server for querying the CVE-Search API
★ 102owl. 🦉 OWL: Optimized Workforce Learning for General Multi-Agent Assistance in Real-World Task Automation
★ 20kdspy. DSPy: The framework for programming—not prompting—language models
★ 36kagno. Build, run, and manage agent platforms.
★ 42kdeep-searcher. Open Source Deep Research Alternative to Reason and Search on Private Data. Written in Python.
★ 8kwechat-article-exporter. 一款在线的 微信公众号文章批量下载 工具,支持导出阅读量与评论数据,无需搭建任何环境,可通过 在线网站 使用,支持 docker 私有化部署和 Cloudflare 部署。 支持下载各种文件格式,其中 HTML 格式可100%还原文章排版与样式。
★ 13kunsloth. Unsloth is a local UI for training and running Kimi K3, Gemma 4, Qwen3.6, DeepSeek, GLM and other models.
★ 69kLightHook. Single-header, minimalistic, cross-platform hook library written in pure C
★ 399Browser-Pwning-. A proper well structured documentation for getting started with chrome pwning & v8 pwning
★ 197Nuitka. Nuitka is a Python compiler written in Python. It's fully compatible with Python 2.6, 2.7, 3.4-3.14. You feed it your Python app, it does a lot of clever things, and spits out an executable or extension module.
★ 15kAntiOllvm. AntiOllvm Fla with Fake Runtime
★ 190new-api. A unified AI model hub for aggregation & distribution. It supports cross-converting various LLMs into OpenAI-compatible, Claude-compatible, or Gemini-compatible formats. A centralized gateway for personal and enterprise model management. 🍥
★ 44kikos. Static analyzer for C/C++ based on the theory of Abstract Interpretation.
★ 3.2kFindETWProviderImage. Quickly search for references to a GUID in DLLs, EXEs, and drivers
★ 75MajorPrivacy. Advanced Privacy Tool for Windows
★ 651qt-sbie-builds. Open source Qt LTS builds for Windows
★ 9WuKongIM. More than just IM 不只是即时通讯(IM)
★ 4.9kmimipenguin. A tool to dump the login password from the current linux user
★ 4.1kalgs4. Algorithms, 4th edition textbook code in C++
★ 2inline_syscall. Inline syscalls made easy for windows on clang
★ 739Supernova. Shellcode encryptor & obfuscator tool
★ 1kq3vm. Q3VM - Single file (vm.c) bytecode virtual machine/interpreter for C-language input
★ 942ThreatHunting-Keywords. Awesome list of keywords and artifacts for Threat Hunting sessions
★ 670system-design-primer. Learn how to design large-scale systems. Prep for the system design interview. Includes Anki flashcards.
★ 360kklara. Kaspersky's GReAT KLara
★ 728dnstwist. Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
★ 5.7kMalConfScan-with-Cuckoo. Cuckoo Sandbox plugin for extracts configuration data of known malware
★ 131SharpShooter. Payload Generation Framework
★ 2kvulnhuntr. Zero shot vulnerability discovery using LLMs
★ 2.7kE-Decompiler. 用来辅助分析易语言程序的IDA插件
★ 524next-auth. Authentication for the Web.
★ 28kCyberThreatHunting. A collection of resources for Threat Hunters
★ 916droid. A pySigma wrapper to manage detection rules.
★ 46aidapal. aiDAPal is an IDA Pro plugin that uses a locally running LLM that has been fine-tuned for Hex-Rays pseudocode to assist with code analysis.
★ 391RmTools. 蓝队应急工具
★ 545detect-lkm-rootkit-cheatsheet. Cheat sheet to detect and remove linux kernel rootkit
★ 81ast-grep. ⚡A CLI tool for code structural search, lint and rewriting. Written in Rust
★ 15kkunai. Threat-hunting tool for Linux
★ 1.1kSIGNATURE_TYPE_LUASTANDALONE. Extracted lua script from Defender mpavbase.vdm and mpasbase.vdm
★ 16FakePDB. Tool for PDB generation from IDA Pro database
★ 643ollvm17. Obfuscation LLVM 17
★ 659ProcMon-for-Linux. A Linux version of the Procmon Sysinternals tool
★ 4.7kE2B. Open-source, secure environment with real-world tools for enterprise-grade agents.
★ 13k