This is your work, valued
Pentest-Service-Enumeration. Suggests programs to run against services found during the enumeration phase of a Pentest
★ 117aolunderground-proggies. Visual Basic Source Code and Proggies/Progz for AOL Instant Messenger (AIM) and America Online (AOL). Aohell, Fatex, punters, bas files, etc.
★ 78oscp-scripts. Scripts created to use with the OSCP exercises
★ 48log4j-scan-turbo. Multithreaded log4j vulnerability scanner using only bash! Tests all JNDI protocols, HTTP GET/POST, and 84 headers.
★ 25braker-scripts. Scripts written by Steve Stonebraker for Administration
★ 24meltdown_spectre. Meldown/Spectre proof of concept
★ 17pentest-pwn. Tools to help with your pentest
★ 1PythonCheatSheet. A Cheat Sheet 📜 to revise Python syntax. Particularly useful for solving Data Structure and Algorithmic problems with Python.
★ 1OSWA. A collection of useful commands, scripts and resources for the OSWA (WEB-200) exam of Offensive Security
★ 1h2spacex. HTTP/2 Last Frame Synchronization (also known as Single Packet Attack) low Level Library / Tool based on Scapy + Exploit Timing Attacks
★ 226noir. Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
★ 1.4ktoken-saver. Content-aware output compression for AI coding assistants. Replaces blind truncation with intelligent strategies per file type: structural summaries for code, schema extraction for configs, error-focused filtering for logs, and smart sampling for CSVs. Saves tokens while preserving what the model actually needs.
★ 128burp-mcp-server. MCP server, standalone CLI, and extension orchestrator
★ 8bughunter-ai. Autonomous Bug Bounty Hunting Framework powered by Claude Code. 20 AI agents, state-machine orchestration, Burp Suite MCP, credential vault, LLM security track. Type 'hunt target.com' and let AI find the bugs.
★ 57gograbber. A horizontal and vertical web content enumerator
★ 52burp-mcp-server. Kotlin
★ 17chisel. A fast TCP/UDP tunnel over HTTP
★ 16kAILab. AI Pen testing lab
★ 3claude-plugins. Intercept security for Claude Code — deep AI security scans that supplement your scanners and write findings back to the Intercept platform. OAuth 2.1, no API key.
★ 2burpparse. Go
★ 6Jailbreaking-Master-Guide.
★ 2arc_pi_taxonomy. The Arcanum Prompt Injection Taxonomy
★ 736aimap. Discover Exposed AI Services
★ 277andrej-karpathy-skills. A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
★ 198kinkwave. JavaScript
★ 1LLMtary. Autonomous AI-powered penetration testing platform. LLM-driven recon, vulnerability analysis, and exploit validation for internal & external targets. Supports local AI (Ollama, LM Studio) and cloud models (Claude, GPT-4, Gemini). Linux · macOS · Windows
★ 26gstack. Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
★ 125kOpenbrowser. A browser designed for agent
★ 112dialtone. AOL Dialtone Server - Java implementation of AOL 3.0 protocol server
★ 11wiretap. AOL Protocol Wiretap Tool - Packet capture and analysis for AOL protocol reverse engineering
★ 11oh-my-kiro. Shell
★ 104garak. the LLM vulnerability scanner
★ 8.6kadversarial-robustness-toolbox. Adversarial Robustness Toolbox (ART) - Python Library for Machine Learning Security - Evasion, Poisoning, Extraction, Inference - Red and Blue Teams
★ 6.1kBasicBox. A 486-class PC emulator written entirely in Visual Basic 6
★ 61macdown3000. A modern, lightweight Markdown editor for macOS.
★ 396VB-Decompiler-Server. Socket Server for VB Decompiler (both Free and Pro)
★ 4OBLITERATUS. OBLITERATE THE CHAINS THAT BIND YOU
★ 7.3kmemory-palace. Persistent memory system for agentic AI via MCP - remember, recall, forget with semantic search with knowledge graph
★ 45atomforge. AtomForge: FDO compiler and decompiler with a simple web UI. Compile FDO source to binary and decompile binaries back to source. Includes hex input/output and Docker support.
★ 6configmgr-cryptderivekey-hashcat-module. Hashcat module that can crack a password used to derive an AES-128 key with CryptDeriveKey from CryptoAPI
★ 45Pentest-Everything. A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.
★ 619Invoke-FindEventCreds. PowerShell script to parse Sysmon Event ID 1 and Security Event Log ID 4688 for command line credentials
★ 8Burp-Issue-Exporter. Burp Issue Exporter is a Burp Suite extension designed to simplify the process of exporting or copying issue details from the Scanner tab
★ 1BurpCopyIssues. Burp suite extension that lets you easily copy issues
★ 17pxethiefy. Python
★ 89Coercer. A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
★ 2.3kMisconfiguration-Manager. Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
★ 1.2karsenal. Arsenal is just a quick inventory and launcher for hacking programs
★ 3.8kCertipy. Tool for Active Directory Certificate Services enumeration and abuse
★ 3.6khaptyc. Python
★ 94Snaffler. a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
★ 2.9kMax. Maximizing BloodHound. Max is a good boy.
★ 534GitPhish. Python
★ 205client-side-bugs-resources. A resources for who want to learn and get deep into client-side bugs
★ 551GraphSpy. Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI
★ 1.4kMarauder. Python
★ 4Blazor-Server-Testing-Jmeter.
★ 4mallet. Mallet is an intercepting proxy for arbitrary protocols
★ 292BridgeKeeper. Scrape, Hunt, and Transform names and usernames
★ 130misconfig-mapper. Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!
★ 906certified-aws-solutions-architect-professional. AWS Certified Solutions Architect – Professional (SAP-C02) Notes
★ 626damn-vulnerable-llm-agent. Python
★ 496ReportGen. Documentation and Support for AttackForge ReportGen
★ 22Mist. A Mac utility that automatically downloads macOS Firmwares / Installers.
★ 5.1kHExHTTP. Header Exploitation HTTP
★ 760github-secrets. This tool analyzes a given Github repository and searches for dangling or force-pushed commits containing potential secret or interesting information.
★ 185semgr8s. Semgrep-based Policy Controller for Kubernetes
★ 47doompdf. A port of Doom (1993) that runs inside a PDF file
★ 3.9kAvaloniaVisualBasic6. A recreation of the classic Visual Basic 6 IDE and language in C# with Avalonia
★ 1.6kMultiTapBurp. A Burp Suite extension that helps track and manage multiple sessions simultaneously by color-coding HTTP requests based on custom patterns.
★ 28CVE-2022-22965. Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)
★ 99follina.py. POC to replicate the full 'Follina' Office RCE vulnerability for testing purposes
★ 1.1knuclei-templates. Community curated list of templates for the nuclei engine to find security vulnerabilities.
★ 13kPythonCheatSheet. A Cheat Sheet 📜 to revise Python syntax. Particularly useful for solving Data Structure and Algorithmic problems with Python.
★ 1.3kHellHall. Performing Indirect Clean Syscalls
★ 617google_RAT. A Remote Access Tool using Google Apps Script as the proxy for command and control.
★ 113fileless-elf-exec. Execute ELF files without dropping them on disk
★ 504LsassReflectDumping. This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created, it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process
★ 219EDRSilencer. A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
★ 1.9kDDexec. A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
★ 892certainly. Certainly is a offensive security toolkit to capture large amounts of traffic in various network protocols in bitflip and typosquat scenarios.
★ 227peirates. Peirates - Kubernetes Penetration Testing tool
★ 1.5ksrum-dump. A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
★ 760CrowdStrike_RTR_Powershell_Scripts. PowerShell
★ 84nmap-parse-output. Converts/manipulates/extracts data from a Nmap scan output.
★ 554evilarc. Create tar/zip archives that can exploit directory traversal vulnerabilities
★ 1.1kwifi-agent. :signal_strength: Rogue access point tool.
★ 56exploit-writing-for-oswe. Tips on how to write exploit scripts (faster!)
★ 591BypassFuzzer. Fuzz 401/403/404 pages for bypasses
★ 429sourcemapper. Extract JavaScript source trees from Sourcemap files
★ 1.4kaws-s3-secret-scanner. BluBracket CLI Recipes
★ 12cli. GitHub’s official command line tool
★ 46kshortscan. An IIS short filename enumeration tool
★ 1.2ksudistark.github.io. HTML
★ 2attack-surface-detector. The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
★ 14burp-suite-error-message-checks. Burp Suite extension to passively scan for applications revealing server error messages
★ 65bbot. The recursive internet scanner for hackers. 🧡
★ 10kawesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources
★ 11kBug_Bounty_Notes. A collection of notes for bug bounty hunting
★ 291OSWA. A collection of useful commands, scripts and resources for the OSWA (WEB-200) exam of Offensive Security
★ 120pacu. The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
★ 5.3kREST_in_bash. A simple REST server in Bash
★ 33mac-monitor. "The missing ProcMon for macOS": Mac Monitor records Endpoint Security events and displays them for analysis.
★ 1.4k4n6-scripts. Forensic Scripts
★ 157falcon-helm. Helm Charts for running CrowdStrike Falcon with Kubernetes
★ 114tell-me-your-secrets. Find secrets on any machine from over 120 Different Signatures.
★ 47openvas. Containers for running the Greenbone Vulnerability Manager. Run as a single container with all services or separate single applications containers via docker-compose.
★ 471censys-cloud-connector. The Censys Unified Cloud Connector is a standalone connector that gathers assets from various cloud providers and stores them in Censys ASM. This Connector offers users the ability to supercharge our ASM Platform with total cloud visibility.
★ 8ScubaGear. Automation to assess the state of your M365 tenant against CISA's baselines
★ 2.6kferoxbuster. A fast, simple, recursive content discovery tool written in Rust.
★ 8kbocker. Docker implemented in around 100 lines of bash
★ 13kDccwBypassUAC. Windows 8.1 and 10 UAC bypass abusing WinSxS in "dccw.exe".
★ 398Freeze. Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods
★ 1.5kJava-Android-Magisk-Burp-Objection-Root-Emulator-Easy. Java Android Magisk Burp Objection Root Emulator Easy (JAMBOREE)
★ 269bypass-403. A simple script just made for self use for bypassing 403
★ 2.2khttpx. httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
★ 10krescope. Bugbounty scope tool
★ 330awesome-censys-queries. A collection of fascinating and bizarre Censys Search Queries
★ 1.2kanew. A tool for adding new lines to files, skipping duplicates
★ 1.7kultimate-nmap-parser. parse nmap files
★ 162wpLockPicker. A CLI tool used for bruteforcing WordPress by exploiting the XMLRPC interfaces.
★ 6GBucketDump. Tool for enumerating and exploring data in Google Storage Buckets
★ 6ptf. The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
★ 5.5kgoGetBucket. A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.
★ 116AWS. Shell
★ 2hibp-downloader. Download all the HIBP passwords
★ 12dispatch-docker. Shell
★ 214ArchiveBot. ArchiveBot, an IRC bot for archiving websites
★ 419ProgzRescue. Repository to help with archival and recovery of AOL Progs from the 1990s
★ 6the-book-of-secret-knowledge. A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
★ 236kDeepFaceLive. Real-time face swap for PC streaming or video calls
★ 31kaolunderground-proggies. Visual Basic Source Code and Proggies/Progz for AOL Instant Messenger (AIM) and America Online (AOL). Aohell, Fatex, punters, bas files, etc.
★ 78iot. Resources for IoT security research
★ 98waymore. Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!
★ 2.7kPhishingTemplates. This is a collection of phishing templates and a landing page to be used with goPhish
★ 458chatter. internet monitoring osint telegram bot for windows
★ 150smogcloud. Find cloud assets that no one wants exposed 🔎 ☁️
★ 351aws_public_ips. Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services
★ 641ThreatMapper. Open Source Cloud Native Application Protection Platform (CNAPP)
★ 5.3kssl_logger. Decrypts and logs a process's SSL traffic.
★ 1.1kcontainer-security-checklist. Checklist for container security - devsecops practices
★ 1.6kred-detector. Scan your EC2 instance to find its vulnerabilities using Vuls (https://vuls.io/en/)
★ 89red-shadow. Lightspin AWS IAM Vulnerability Scanner
★ 95xvs-mvc-bb-a1up. X-men vs Street Fighter/Marvel-vs-Capcom/Big Blue/Yoga Flame/Shinkuu Arcade 1Up Software Modding Resources
★ 6osmedeus. A Modern Orchestration Engine for Security
★ 6.5kjaeles. The Swiss Army knife for automated Web Application Testing
★ 2.4kunfurl. Pull out bits of URLs provided on stdin
★ 1.3kmetabigor. OSINT tools and more but without API key
★ 1.7kwarhorse. Infrastructure Automation
★ 361inceptor. Template-Driven AV/EDR Evasion Framework
★ 1.8kIOSSecuritySuite. iOS platform security & anti-tampering Swift library
★ 2.7kFenrir. Simple Bash IOC Scanner
★ 776Crescendo. Crescendo is a swift based, real time event viewer for macOS. It utilizes Apple's Endpoint Security Framework.
★ 1.1kOSXMon. OSX Events Monitor
★ 22peacemakr-cli. CLI for Peacemakr's Secure Data Platform (Dockerhub: https://hub.docker.com/r/peacemakr/peacemakr-cli )
★ 6Pentest-Tools-Framework. Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of tools for beginners. You can explore kernel vulnerabilities, network vulnerabilities
★ 460Ninja. Open source C2 server created for stealth red team operations
★ 842devreorder. A utility for reordering and hiding DirectInput controllers
★ 409evilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
★ 15kevilginx. PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2
★ 1.2knuclei. Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
★ 30kBloodhound-Portable. Bloodhound Portable for Windows
★ 55td. Your todo list in your terminal
★ 303palo-xdr-testing. Batchfile
★ 7caldera. Automated Adversary Emulation Platform
★ 7.2kpwncat. Fancy reverse and bind shell handler
★ 2.9kattack_range. A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
★ 2.5knpm-initial-access. Easy to extend initial access scenario to help with EDR testing on Linux and Mac
★ 27threat-tools. Tools for simulating threats
★ 203laurel. Transform Linux Audit logs for SIEM usage
★ 841auditd-attack. A Linux Auditd rule set mapped to MITRE's Attack Framework
★ 821atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
★ 12kPENTESTING-BIBLE. articles
★ 14kPoC-in-GitHub. 📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
★ 7.9kHackTools. The all-in-one browser extension for offensive security professionals 🛠
★ 6.9kgimme-aws-creds. A CLI that utilizes Okta IdP via SAML to acquire temporary AWS credentials
★ 971poc. Proof of Concepts
★ 1.3kcilium. eBPF-based Networking, Security, and Observability
★ 25kghhdb-Github-Hacking-Database. Github Hacking Database - My personal collection of Github Dorks to search for Confidential Information (Yes, it's a Github version of Google Dorks)
★ 251imdsv2_wall_of_shame. List of vendors that do not allow IMDSv2 enforcement
★ 143Spotlight. A Super Mario 3D World Level Editor using the GL_EditorFramework
★ 79nginx-honeypot. NGINX honeypot with lots of honey
★ 12RdpGamepad. Remote Desktop Plugin for Xbox Gamepads
★ 443LogMePwn. A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
★ 395arcade1up-mods. Mods for arcade1up cabinet
★ 2log4j-cve-2021-44228. Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...
★ 5log4jcheck. A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.
★ 126log4shell-vulnerable-app. Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
★ 1.1klog4j-scan. A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
★ 3.4klog4j-scan-turbo. Multithreaded log4j vulnerability scanner using only bash! Tests all JNDI protocols, HTTP GET/POST, and 84 headers.
★ 25S3-Listable. S3 Buckets that will let you list all files inside them
★ 14Fast-Google-Dorks-Scan. The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the specific web-site: common admin panels, the widespread file types and path traversal. The 100% automated.
★ 1.7keb-ssm. SSH into an AWS Elastic Beanstalk environment instance using AWS Systems Manager Agent. This removes the need to configure and share private keys on Elastic Beanstalk instances.
★ 20tfwriter. Terraform HCL code generator.
★ 96prismacloud_terraform_w_modules. HCL
★ 4aws-remote. AWS Remote is a command line tool to view and interact with AWS instances via SSM
★ 4ivre. Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.
★ 4.1kterraform-aws-secure-baseline. Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
★ 1.2kAIL-framework. AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project
★ 1.4kawesome-nmap-grep. Awesome Nmap Grep
★ 414ScanCannon. A script for credentials-based attack surface enumeration and general reconnaissance of massive external networks
★ 476terraform-aws-ecs-web-app. Terraform module that implements a web app on ECS and supports autoscaling, CI/CD, monitoring, ALB integration, and much more.
★ 254slack-export. A python slack exporter
★ 36cloud_enum. Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
★ 2.1kterraform-ecs. AWS ECS terraform module
★ 810minikube. Run Kubernetes locally
★ 32kopen-source-mac-os-apps. 🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps
★ 50kZettlr. Your One-Stop Publication Workbench
★ 13ksmokescreen. A simple HTTP proxy that fogs over naughty URLs
★ 1.3k