This is your work, valued
F R A G I L E - Handle with care π¨βπ» Senior Penetration Tester at @SECFORCE π Incurable nerd ποΈ Movie/TV Show addicted π© CTF Player @napwnli
portswigger-labs. A collection of solutions for every PortSwigger Academy Lab (in progress)
β 119secbutler. The perfect butler for pentesters, bug-bounty hunters and security researchers
β 95frida-compatibility-matrix. Compatible versions of the frida package for each version of the frida-tools package. Automatically updated through CI/CD
β 36fire. Take domains on stdin and output them on stdout if they get resolved
β 31asciified. A simple ASCII Art API with a good-looking Web App.
β 24react-file-manager. A simple React component to build a Web File Manager
β 22friman. Frida version management tool
β 16paprika-vdagent. A standalone Wayland clipboard bridge for SPICE/QEMU Linux guests.
β 10pino-rotating-file-stream. A transport for pino that rotates logs
β 8waybackshots. Get screenshots of URLs stored in the Wayback Machine in a smart way
β 5cyberchallenge-writeups. A collection of writeups for the Italian CyberChallenge CTFs (Jeopardy)
β 4ya-pickledb. Yet another PickleDB (thread-safe!)
β 3thelicato. A README about me.
β 3ForcAD-Vulnboxes. ForcAD compatible vulnboxes
β 2full-stack-monorepo-starter. A full-stack monorepo starter project
β 2ts2py. Convert TypeScript Interfaces to Python TypedDict
β 2bff-types. A generic template to provide types to both BE and FE (Best Friends Forever)
β 1py-sorting-algorithms. A set of sorting algorithms implemented in Python.
β 1frida-interception-and-unpinning. Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
β 1android-poc-app. Empty project to quick start Proof of Concept app development
β 1parsex. Parse and extract key data across multiple security tools
β 1gf. A wrapper around grep, to help you grep for things
β 2.1kscriptc. TypeScript-to-Native Compiler
β 2.6kjumpserver. JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser.
β 31kgopacket. A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free binary.
β 701droidground. A flexible playground for Android CTF challenges.
β 117Samsung_Vulnerabilities. 176 vulnerabilities in Samsung preinstalled Android apps
β 311colibri. Run frontier MoE models on hardware you already own β pure C, zero deps, experts streamed from disk. Tiny engine, immense model. π¦
β 21kbad-epoll.
β 504headroom. Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
β 64kthreat-tiger. Threat Tiger is a modern Threat Modeling tool
β 63lore. Lore is a next-generation, open source version control system
β 8.2kreact-server. Run React anywhere
β 443ds4. DeepSeek 4 Flash and PRO local inference engine for Metal, CUDA and ROCm
β 20kLSPlant. A hook framework for Android Runtime (ART)
β 1.3kponytail. Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
β 93krmux. Universal Rust multiplexer with a typed SDK β drive any CLI or TUI app from code. Native on Linux, macOS, and Windows.
β 2.5kRTranslator. Open source real-time translation app for Android that runs locally
β 10kGlass. Glass - a fast and free IDA Pro alternative
β 192odysseus. Self-hosted AI workspace.
β 84kCryptoBook. A community driven resource for learning CryptoGraphy
β 77Liho. Hooking tool for libart.so and libdl.so, enabling instrumentation of both DEX and native code on Android.
β 11iris. Intent Runtime Inspection System
β 72uploadserver. Python's http.server extended to include a file upload page
β 350CVE-2026-0073. An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debugging ports on Android 13+ and establishes a fully interactive raw PTY shell.
β 26audit. An 8-stage vulnerability-discovery agent.
β 788opengrep. π Static code analysis engine to find security issues in code.
β 2.9kNginx-Rift. NGINX RCE exploits
β 910blint. blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.
β 452dexhound. Dump DEX files from a running Android process without instrumentation
β 31tiptap. The headless rich text editor framework for web artisans.
β 38ksandblaster. Reversing the Apple sandbox
β 191go-ios. This is an operating system independent implementation of iOS device features. You can run UI tests, launch or kill apps, install apps etc. with it.
β 2.2kredlyne. Detect and patch vulnerabilities in AI-generated Python code β VS Code extension
β 40watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py. Python
β 416libvirt. Read-only mirror. Please submit merge requests / issues to https://gitlab.com/libvirt/libvirt
β 1.7kOpenMythos. A theoretical reconstruction of the Claude Mythos architecture, built from first principles using the available research literature.
β 15knoctalia. A sleek, customizable desktop shell crafted for Wayland.
β 9.1kgraphify. Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing, every edge explained, no vector store.
β 100kpyGPOAbuse. Partial python implementation of SharpGPOAbuse
β 584DetectFrida. Detect Frida for Android
β 797mise. dev tools, env vars, task runner
β 31kDroidspaces-OSS. A lightweight, LXC-like container runtime for Android and Linux. Run full Linux distributions natively with zero performance penalty
β 1.6kligolo-mp. Multiplayer pivoting solution
β 529SEBASTiAn. A Static and Extensible Black-box Application Security Testing tool for iOS and Android applications
β 39rbcd-attack. Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket
β 646ocd-mindmaps. Orange Cyberdefense mindmaps
β 1.6ksandboxec. A lightweight command sandbox for Linux, secure-by-default, built on Landlock.
β 68pylnk. Python library for reading and writing Windows shortcut files (.lnk). Python 3 only.
β 111krbrelayx. Kerberos relaying and unconstrained delegation abuse toolkit
β 1.6knowafpls. Burp Plugin to Bypass WAFs through the insertion of Junk Data
β 1.5kbasalt. TUI Application to manage Obsidian notes directly from the terminal
β 1.3krxdb. The local-first database that runs on every JS runtime and replicates with your existing backend - no vendor, no lock-in - https://rxdb.info/
β 23knoir. Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
β 1.4kbug-reaper. Web2 bug bounty Agent Skill β evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.
β 66no-exit-please_Frida_Script_Android. A universal Frida Script that prevents application self-termination at Java and native layers on Android.
β 10klodd. CTF challenge per-team instance runner
β 43pentagi. Fully autonomous AI Agents system capable of performing complex penetration testing tasks
β 21kpacu. The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
β 5.3kpenelope. Penelope Shell Handler
β 1.9kcloud_enum. Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
β 2.1kCloudBrute. Awesome cloud enumerator
β 1.1kghidra-frida-hook-gen. Frida hook generator for Ghidra
β 132promon-string-deobfuscator. Promon Shield String Deobfuscator
β 48SSTImap. Automatic SSTI detection tool with interactive interface
β 1.6kclsdumper. Android Dynamic Class Dumper β dump all DEX files from running Android apps using Frida
β 55heresy. Inspect and instrument React Native applications at runtime
β 125hermes_rs. Hermes bytecode disassembler and assembler
β 181feroxbuster. A fast, simple, recursive content discovery tool written in Rust.
β 8kAuthMatrix. AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
β 10Empire. Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
β 5.2kshannon. Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
β 46kdnscat2. PHP
β 3.9kchisel. A fast TCP/UDP tunnel over HTTP
β 16kGhostKatz. Dump LSASS via physical memory read primitives in vulnerable kernel drivers
β 338plist_recon. This tool parses the binary or XML `Info.plist` file found in Apple applications (IPA/APP) to extract critical security configurations, identify potential vulnerabilities, and generate instant hooking snippets for Frida and Objection.
β 2vulnerability-rating-taxonomy. Bugcrowdβs baseline priority ratings for common security vulnerabilities
β 550uber-apk-signer. A cli tool that helps signing and zip aligning single or multiple Android application packages (APKs) with either debug or provided release certificates. It supports v1, v2 and v3 Android signing scheme has an embedded debug keystore and auto verifies after signing.
β 2.7kcontent-type-research. Content-Type Research
β 669traitor. :arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
β 7.2klastsignal. A self-hosted dead man's switch for delivering encrypted messages (E2EE) to your loved ones β when you're gone or unresponsive.
β 690ntconthwbp-rs. Assembly
β 3mcp-security-hub. A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
β 754pywerview. A (partial) Python rewriting of PowerSploit's PowerView
β 1.1kpromon-reversal. Analysis and proof-of-concept bypass of Promon SHIELD's Android application protection
β 215HideDroid. HideDroid is an Android app that allows the per-app anonymization of collected personal data according to a privacy level chosen by the user.
β 216PAPIMonitor. Python API Monitor for Android apps
β 87Hooky. Hooky is a dynamic analysis tool for mobile application security testing and runtime instrumentation.
β 10x64dbg. An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
β 49kswaks. Swaks - Swiss Army Knife for SMTP
β 1.3kLiveContainer. Run iOS apps without actually installing them!
β 10kcuddlephish. Weaponized Browser-in-the-Middle (BitM) for Penetration Testers
β 668chisel-ng. Chisel new generation, written in rust. SSH under WSS with some customization.
β 136powercat. netshell features all in version 2 powershell
β 2.4kanamnesis-release. Automatic Exploit Generation with LLMs
β 628awesome-note-taking. A curated list of 100+ awesome note-taking apps, PKM tools & knowledge management software β open source and proprietary. Updated regularly.
β 925proxypin. Open source free capture HTTP(S) traffic software ProxyPin, supporting full platform systems
β 14kadb-enhanced. πͺSwiss-army knife for Android testing and development πͺ βΊ
β 1.4kvmlinux-to-elf. A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)
β 1.8kkatana. A next-generation crawling and spidering framework.
β 17knuclei. Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
β 30ksubfinder. Fast passive subdomain enumeration tool.
β 14kandroid-security-awesome. A collection of android security related resources
β 9.6kdeadend-cli. Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)
β 282nginx-analytics. A flexible & privacy-focused analytics solution for NGINX.
β 21frida-ui. Interact with Frida devices, processes, and scripts directly from your browser.
β 237Awesome-Blackhat-Tools. A curated list of tools officially presented at Black Hat events
β 936chronomaly. Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.
β 309scanopy. Network diagrams that update themselves
β 5.2kawesome-blackhat-arsenal. Curated collection of cybersecurity tools featured in Black Hat Arsenal events.
β 163Hardening-Audit-Tool-AuditTAP. FBPro Audit Test Automation Package allows you to create compliance reports for your systems. The resulting HTML-reports provide a transparent overview of your devices' security configuration compared to international security standards and hardening guides.
β 170spikee. Simple Prompt Injection Kit for Evaluation and Exploitation
β 229PwnPad. PwnPad is an affordable, hands-on hardware hacking platform built for practical learning. It features a range of challenges that walk users through key hardware security concepts, from PCB design to side-channel attacks.
β 1.2kkubernetes-goat. Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground π
β 5.7kreact2shell-scanner. High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
β 2.5kfizzy. Kanban as it should be. Not as it has been.
β 8kvirt-manager. Desktop tool for managing virtual machines via libvirt
β 3.2ksysreptor. A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
β 2.6kpSlip. pSlip is an Android static analysis tool kit designed to find potentially vulnerable escalation paths by analyzing exported components, intent filters, provider permissions and cryptographic misuse
β 27frida-script-gen. Generate Frida bypass scripts for Android APK root and SSL checks.
β 215mobapp-storage-inspector. A tool for inspecting and analyzing mobile application storage files.
β 50Frida-Launcher. An Android app to easily manage Frida server on your device or emulator
β 134KarelWebAssemblyIDE. A modern, web-based integrated development environment for learning programming with Karel the Robot using C and WebAssembly.
β 12LLMGoat. This project is a deliberately vulnerable environment to learn about LLM-specific risks based on the OWASP Top 10 for LLM Applications.
β 57conquest. Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.
β 413Coercer. A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
β 2.3kcai. Cybersecurity AI (CAI), the framework for AI Security
β 9.6kbofhound. Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel
β 410toon. π Token-Oriented Object Notation (TOON) β compact, human-readable serialization of JSON data for LLM prompts. TypeScript SDK, CLI, benchmarks.
β 25kShellcode-IDE. Shellcode IDE β makes developing and analyzing shellcode much more convenient.
β 125beerus-android. BEERUS Framework for Android
β 617nushell. A new type of shell
β 40kevershop. ποΈ Typescript E-commerce Platform
β 10khetty. An HTTP toolkit for security research.
β 12kwinboat. Run Windows apps on π§ Linux with β¨ seamless integration
β 22kCSPBypass. CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocked by CSPs that only allow certain whitelisted domains.
β 709allsafe-android. Intentionally vulnerable Android application.
β 408dont-kill-my-app. Android vendors, don't kill my app!
β 1.7kgollama.cpp. A high-performance Go binding for llama.cpp using purego for cross-platform compatibility without CGO.
β 34datapizza-ai. Build reliable Gen AI solutions without overhead π
β 2.2kagentic_security. Agentic LLM Vulnerability Scanner / AI red teaming kit π§ͺ
β 1.9kdive. A tool for exploring each layer in a docker image
β 54kfrida-gadget. Automated tool for patching APKs to enable the use of Frida gadget by downloading the library and injecting code into the main activity.
β 446gmapsapiscanner. Python
β 1.2kARSCLib. Android binary resources read/write library
β 398dtop. Terminal dashboard for Docker monitoring across multiple hosts with Dozzle integration.
β 1.3klibvirt-hook-qemu. Libvirt hook for setting up iptables port-forwarding rules when using NAT-ed networking.
β 258ttyd. Share your terminal over the web
β 12kunrasp_guard. Anti Tamper & Anti Frida Bypass For Our Lovely LolGuard
β 110landrun. Run any Linux process in a secure, unprivileged sandbox using Landlock. Think firejail, but lightweight, user-friendly, and baked into the kernel.
β 2.2kandroid-webview-research. This app runs various webview tests to explore the attack surface and exploit techniques
β 34libsu. A complete solution for apps using root permissions
β 2.1kandroid-rasp. RASP (Runtime Application Self-Protection) solution for protecting Android apps against being run on vulnerable devices.
β 143Free-RASP-Android. SDK providing threat detection and security monitoring for Android devices. Shield your app with free RASP for Android. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.
β 258frida-interception-and-unpinning. Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
β 2.2ktaptrap. TapTrap is a new attack on Android that lures you into performing actions you did not intend to do. This allows an app to silently access your camera or location, or even erase your entire device β all without your consent.
β 79whonow. A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)
β 660rbndr. Simple DNS Rebinding Service
β 754flareprox. Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox
β 791frida-scripts. A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.
β 1.6kandroid-re-ctfs. Reverse engineering CTFs.
β 69llamator. Red Teaming python-framework for testing chatbots and GenAI systems.
β 214omarchy. Beautiful, Modern & Opinionated Linux
β 24kTaskTrove. TaskTrove is a modern Todo Manager that is fully self-hostable.
β 1.1kPySpector. PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. It leverages a powerful Rust core to deliver high-speed, accurate vulnerability scanning, wrapped in a developer-friendly Python CLI.
β 141ipsw. iOS/macOS Research Swiss Army Knife
β 3.6kWeb-Cache-Vulnerability-Scanner. Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
β 1.2kfrida-ios-dump. pull decrypted ipa from jailbreak device
β 23Ghost. Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.
β 3.4kdittobytes. Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
β 641dots-hyprland. Usability-first dotfiles
β 15kSpoofy. Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
β 770CrackMapExec. A swiss army knife for pentesting networks
β 9.2kstrix. Open-source AI penetration testing tool to find and fix your appβs vulnerabilities.
β 46kandroid-emulator-container-scripts. This is a set of minimal scripts to run the emulator in a container for various systems such as Docker, for external consumption
β 2.1kJamfHound. JamfHound is a python3 project designed to collect and identify attack paths in Jamf Pro tenants based on existing object permissions by outputting data as JSON for ingestion into BloodHound.
β 134CVE-2025-50154. POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
β 55CVE-2025-6543_CitrixNetScaler_PoC. Multi-host, multi-port scanner and auditor for CVE-2025-6543-affected NetScaler devices. Supports SNMP and SSH enumeration with optional CSV reporting and exploit stubs.
β 6gpt-oss. gpt-oss-120b and gpt-oss-20b are two open-weight language models by OpenAI
β 20kwakaru. πͺπ¦ Javascript decompiler for modern frontend
β 939frida-non-root. Add frida-gadgets into APK for non rooted devices.
β 96ysonet. Deserialization payload generator for a variety of .NET formatters
β 213deptective. Deptective automatically determines the native dependencies required to run any arbitrary program or command.
β 132wscan. Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.
β 708nomad. Nomad is an easy-to-use, flexible, and performant workload orchestrator that can deploy a mix of microservice, batch, containerized, and non-containerized applications. Nomad is easy to operate and scale and has native Consul and Vault integrations.
β 17kMBE. Course materials for Modern Binary Exploitation by RPISEC
β 6kS3Scanner. Scan for misconfigured S3 buckets across S3-compatible APIs!
β 3.2kbambdas. Bambdas collection for Burp Suite Professional and Community.
β 527commit-watcher. Find interesting and potentially hazardous commits in git projects
β 352obfuscation_analysis. Binary Ninja plugin to analyze and simplify obfuscated code
β 254AndroGoat. AndroGoat
β 383shell_exec. Cross platform library to execute shell scripts
β 7bitchat. bluetooth mesh chat, IRC vibes
β 34khistorical-redis-versions. Very early versions of Redis with some backstory in the README
β 159APKEditor. Powerful android apk editor - aapt/aapt2 independent
β 2.2kflutter-reverse-engineer. Reverse engineering flutter apps
β 4reFlutter. Flutter Reverse Engineering Framework
β 2.7kCyberSources. A curated list of cybersecurity tools and resources.
β 2.4khttp-request-smuggler. Java
β 1.2kdroidground-samples. Sample applications to showcase DroidGround
β 5marvin. Marvin is a CLI tool that scans a k8s cluster by performing CEL expressions to report potential issues, misconfigurations and vulnerabilities.
β 206