This is your work, valued
rule-engine. A lightweight, optionally typed expression language with a custom grammar for matching arbitrary Python objects.
★ 590mayhem. Runtime Process Manipulation
★ 240crimson-forge. Sustainable shellcode evasion
★ 113reflective-polymorphism. Reflective Polymorphism
★ 109AdvancedHTTPServer. Standalone web server built on Python's BaseHTTPServer
★ 38driver-analysis. Python
★ 17protocon. Protocon is a socket-centric framework for rapidly prototyping connections through simple send and receive transcripts.
★ 11bandit-ss. Python
★ 9ras-2019-python-for-pentesters. Materials for the RAS 2019 Python for Pentesters Course
★ 5smoke-zephyr. Python utility collection
★ 5vulnerability-development. Bits of code to help with vulnerability development
★ 4crcelk. A pure Python implementation of the CRC algorithm.
★ 3king-phisher. Phishing Campaign Toolkit
★ 3ipy-msf-kernel. IPython Metasploit Kernel
★ 3scapy-com. Cloned from the old Scapy Community Repository
★ 3jesse-james. Python
★ 2social-engineer-toolkit. The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
★ 2metasploit-framework. Metasploit Framework
★ 2blink1. Python code for various tasks with the blink(1) USB RGB LED
★ 1oct. A t.co Reverse Lookup Utility
★ 1pyAIML. PyAIML -- The Python AIML Interpreter
★ 1github-backup. GitHub Backup Script
★ 1nokogiri. Nokogiri (鋸) makes it easy and painless to work with XML and HTML from Ruby.
★ 1cassie-bot. Cassie XMPP Bot
★ 1geOSINT. Search physical locations for geo tagged photos
★ 1Auto_EAP. Automated Brute-Force Login Attacks Against EAP Networks.
★ 1bullet. 🚅 Interactive prompts made simple. Build a prompt like stacking blocks.
★ 1ntfy. 🖥️📱🔔 A utility for sending notifications, on demand and when commands finish.
★ 1sRDI. Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
★ 1keystone. Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings
★ 1guild-wars-2. Guild Wars 2 API
★ 1ptf. The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
★ 1vphone-aio. 1 script run the vphone
★ 5kNginx-Rift. NGINX RCE exploits
★ 910supertonic. Lightning-Fast, On-Device, Multilingual TTS — running natively via ONNX.
★ 14kdeepsec. Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
★ 6.5kcve_2026_31431. Exploit POC for CVE_2026_31431
★ 565DeepZero. Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows kernel drivers for exploitable IOCTLs natively using AI agents.
★ 617certigo. Certigo - Active Directory Certificate Services enumeration and abuse in Go
★ 11fastscheduler. Decorator-first Python scheduler — cron/interval/at jobs with simple persistence and built-in run history.
★ 435Misconfiguration-Manager. Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
★ 1.2kpanda. Platform for Architecture-Neutral Dynamic Analysis
★ 2.8kTitanHide. Hiding kernel-driver for x86/x64.
★ 2.8kcred1py. A Python POC for CRED1 over SOCKS5
★ 172Kavita. Kavita is a fast, feature rich, cross platform reading server. Built with the goal of being a full solution for all your reading needs. Setup your own server and share your reading collection with your friends and family.
★ 11kromm. A beautiful, powerful, self-hosted rom manager and player.
★ 12kwrkflw. Validate and Run GitHub Actions locally.
★ 3.3kARM64-ReflectiveDLLInjection. A Proof-of-Concept implementation of Reflective DLL Injection (RDI) specifically for Windows on ARM64. Demonstrates PEB access via the x18 register and manual DLL mapping.
★ 37retrobios. Complete BIOS and firmware packs for RetroArch, Batocera, Recalbox, Lakka, RetroPie, EmuDeck, RetroBat, RetroDECK, RomM. Verified checksums, 6700+ files, 300+ emulators profiled from source code.
★ 6.6kgMSADumper. Lists who can read any gMSA password blobs and parses them if the current user has access.
★ 382Timeroast. Timeroasting scripts by Tom Tervoort
★ 406TermHound. Python
★ 26godap. A complete terminal user interface (TUI) for LDAP.
★ 966snek-sploit. Python RPC client for Metasploit Framework.
★ 3windows-api-function-cheatsheets. A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management, dynamic-link library (DLL) management, synchronization, interprocess communication, Unicode string manipulation, error handling, Winsock networking operations, and registry operations.
★ 1.5koperating-system-design-review. Operating System Design Review: A systematic analysis of modern systems architecture
★ 344sha256algorithm. Sha256 Algorithm Explained
★ 1.8kgitreposearch. Streamlit App for GitHub Repository Search Tailored to User Criteria
★ 4age. A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
★ 23kpublications. Publications from Trail of Bits
★ 1.9kJava-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
★ 3.2kEDR-Telemetry. This project aims to compare and evaluate the telemetry of various EDR products.
★ 2kpodlet. Generate Podman Quadlet files from a Podman command, compose file, or existing object
★ 1.6kPoolParty. A set of fully-undetectable process injection techniques abusing Windows Thread Pools
★ 1.3ksyscall_api. Assembly
★ 38FlipperAmiibo. Made to be used with Flipper just drag the folder into NFC
★ 3.6kscare. A multi-arch assembly REPL and emulator for your command line.
★ 311RecycledGate. Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll
★ 511terminator-editor-plugin. Terminator plugin to open files specified by a given regex in an editor
★ 75BadBlood. BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time.
★ 2.3kAmsi-Bypass-Powershell. This repo contains some Amsi Bypass methods i found on different Blog Posts.
★ 2.2kActive-Directory-Certificate-Services-abuse.
★ 55PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kenarx. Enarx: Confidential Computing with WebAssembly
★ 1.4kImHex. 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
★ 54kPoC-in-GitHub. 📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
★ 7.9kAnti-Virus-Evading-Payloads. During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system computers. Here is a simple way to evade anti-virus software when creating backdoors!
★ 750PrivExchange. Exchange your privileges for Domain Admin privs by abusing Exchange
★ 1.1kbinja_MSDN_Helper. Python
★ 2impacket. Impacket is a collection of Python classes for working with network protocols.
★ 16kCertipy. Tool for Active Directory Certificate Services enumeration and abuse
★ 3.6kKrbRelayUp. KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
★ 1.7kAtomicSyscall. Tools and PoCs for Windows syscall investigation.
★ 363Viper. Adversary simulation and Red teaming platform with AI
★ 5.2kAnime-Girls-Holding-Programming-Books. Anime Girls Holding Programming Books
★ 22kexploit_mitigations. Knowledge base of exploit mitigations available across numerous operating systems, architectures and applications and versions.
★ 927PrintNightmare. C
★ 345MicrosoftWontFixList. A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))
★ 952NetNTLMtoSilverTicket. SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket
★ 974whoamsi. An effort to track security vendors' use of Microsoft's Antimalware Scan Interface
★ 254ScareCrow. ScareCrow - Payload creation framework designed around EDR bypass.
★ 2.9kShark. Turn off PatchGuard in real time for win7 (7600) ~ later
★ 1kEfiGuard. Disable PatchGuard and Driver Signature Enforcement at boot time
★ 2.5kCredBandit. Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel
★ 219ByePg. Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.
★ 912EvasiveProcessHollowing. Evasive Process Hollowing Techniques
★ 143anybadge. A Python project for generating badges for your projects, with a focus on simplicity and flexibility.
★ 400EDRs. C
★ 2.2kPriv2Admin. Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
★ 2.5kCVE-2021-3156. Sudo Baron Samedit Exploit
★ 803minidump. Python library to parse and read Microsoft minidump file format
★ 304phpggc. PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
★ 3.9krich. Rich is a Python library for rich text and beautiful formatting in the terminal.
★ 57kCVE-2020-17530. Python
★ 64stackedit. In-browser Markdown editor
★ 23kglorp. A CLI-based HTTP intercept and replay proxy
★ 271OffensiveCSharp. Collection of Offensive C# Tooling
★ 1.5kGadgetToJScript. A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
★ 1.1kspeakeasy. Windows kernel and user mode emulation.
★ 2kBugId. Detect, analyze and uniquely identify crashes in Windows applications
★ 525xattr. Python wrapper for extended filesystem attributes
★ 220cnn-watermark-removal. Fully convolutional deep neural network to remove transparent overlays from images
★ 1.3kRpcSsImpersonator. Privilege Escalation Via RpcSs svc
★ 179proxy.py. 💫 Ngrok FRP Alternative • ⚡ Fast • 🪶 Lightweight • 0️⃣ Dependency • 🔌 Pluggable • 😈 TLS interception • 🔒 DNS-over-HTTPS • 🔥 Poor Man's VPN • ⏪ Reverse & ⏩ Forward • 👮🏿 "Proxy Server" framework • 🌐 "Web Server" framework • ➵ ➶ ➷ ➠ "PubSub" framework • 👷 "Work" acceptor & executor framework
★ 3.5kRomPatcher.js. An IPS/UPS/APS/BPS/RUP/PPF/xdelta ROM patcher made in HTML5.
★ 1.2kDefenderCheck. Identifies the bytes that Microsoft Defender flags on.
★ 2.6kkiewtai. A port of Kaitai to the Hiew hex editor
★ 149win32k-bugs. Dump of win32k POCs for bugs I've found
★ 379ruby_smb. A native Ruby implementation of the SMB Protocol Family
★ 83pipenv. Python Development Workflow for Humans.
★ 25kexploit-exercises. exploit-exercises holds my solutions and thoughts on the exercises on exploit-exercises.com
★ 31pyunifi. Python
★ 248sourcerer-app. 🦄 Sourcerer app makes a visual profile from your GitHub and git repositories.
★ 6.7kpinjectra. Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)
★ 830manul. Manul is a coverage-guided parallel fuzzer for open-source and blackbox binaries on Windows, Linux and MacOS
★ 335ShellcodeCompiler. Shellcode Compiler
★ 1.2krestincode. A memorial site for Hackers and Infosec people who have passed
★ 147protocol. An ASCII Header Generator for Network Protocols
★ 946Mobile-Security-Framework-MobSF. Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
★ 22kking-phisher-plugins. Plugins for the King Phisher open source phishing campaign toolkit.
★ 85awesome-gbdev. A curated list of Game Boy development resources such as tools, docs, emulators, related projects and open-source ROMs.
★ 4.5kgb-studio. A quick and easy to use drag and drop retro game creator for your favourite handheld video game system
★ 9.3kWindows-Kernel-Explorer. A free but powerful Windows kernel research tool.
★ 2.7kAuto_EAP. Automated Brute-Force Login Attacks Against EAP Networks.
★ 58atom-tablr. Edit CSV files using a table editor
★ 163rattle. evm binary static analysis
★ 367sh00t. Security Testing is not as simple as right click > Scan. It's messy, a tough game. What if you had missed to test just that one thing and had to regret later? Sh00t is a highly customizable, intelligent platform that understands the life of bug hunters and emphasizes on manual security testing.
★ 275Detours. Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
★ 6.3kbtlejack. Bluetooth Low Energy Swiss-army knife
★ 2.1kTDL. Driver loader for bypassing Windows x64 Driver Signature Enforcement
★ 1.2kevilginx2. Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
★ 15kraindance. Reconnaissance tool for Microsoft Office 365
★ 70gfm. [Archived] GitHub Flavored Markdown in Python
★ 20mdx_bleach. Python-Markdown extension to sanitize the output of untrusted Markdown documents.
★ 15linqit. Extend python lists operations using .NET's LINQ syntax for clean and fast coding.
★ 255al-khaser. Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
★ 7.1kvoltron. A hacky debugger UI for hackers
★ 6.3kCodeExecutionOnWindows. A list of ways to execute code on Windows using legitimate Windows tools
★ 309windows-syscalls. Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)
★ 2.6kpypykatz. Mimikatz implementation in pure Python
★ 3.3kshellen. :cherry_blossom: Interactive shellcoding environment to easily craft shellcodes
★ 907pysheeet. Python Cheat Sheet
★ 8.2kgeany-themes. A collection of colour schemes for Geany.
★ 583gnomecast. Chromecast local files from Linux - supports MKV, subtitles, 5.1 sound and 4K!
★ 1.4ktsx-tools. Header files for Intel TSX (Transactional Synchronization Extension) development
★ 134LIEF. LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
★ 5.5kOne-Lin3r. Gives you one-liners that aids in penetration testing operations, privilege escalation and more
★ 1.8kpwnjs. A Javascript library for browser exploitation
★ 902cmd2. cmd2 - quickly build feature-rich and user-friendly interactive command line applications in Python
★ 688bleah. This repository is DEPRECATED, please use bettercap as this tool has been ported to its BLE modules.
★ 1.1kYAOLO. YAOLO (Yet Another Offensive LinkedIn Obtainer)
★ 4kAFL. Code for the USENIX 2017 paper: kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels
★ 594trust. An interactive guide to the game theory of cooperation
★ 6.3ksRDI. Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
★ 2.5kReflective-Driver-Loader. C++
★ 409Awesome-Fuzzing. A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
★ 5.9ksmoke-zephyr. Python utility collection
★ 5python-email-validator. A robust email syntax and deliverability validation library for Python.
★ 1.4kguild-wars-2. Guild Wars 2 API
★ 1pipdeptree. A command line utility to display dependency tree of the installed Python packages
★ 3kgeOSINT. Search physical locations for geo tagged photos
★ 141hardentools. Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.
★ 3.1ktrump2cash. A stock trading bot powered by Trump tweets
★ 6.5khonggfuzz. Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)
★ 3.4kolefile. olefile is a Python package to parse, read and write Microsoft OLE2 files (also called Structured Storage, Compound File Binary Format or Compound Document File Format), such as Microsoft Office 97-2003 documents, vbaProject.bin in MS Office 2007+ files, Image Composer and FlashPix files, Outlook messages, StickyNotes, several Microscopy file formats, McAfee antivirus quarantine files, etc.
★ 269awesome-windows-exploitation. A curated list of awesome Windows Exploitation resources, and shiny things. Inspired by awesom
★ 4big-list-of-naughty-strings. The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
★ 48kendless-sky. Space exploration, trading, and combat game.
★ 7.5kCyberChef. The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
★ 35kpython-afl. American Fuzzy Lop fork server and instrumentation for pure-Python code
★ 373gdb-dashboard. Modular visual interface for GDB in Python
★ 12kgitsome. A supercharged Git/GitHub command line interface (CLI). An official integration for GitHub and GitHub Enterprise: https://github.com/works-with/category/desktop-tools
★ 7.7kdnSpy. .NET debugger and assembly editor
★ 30kno-more-secrets. A command line tool that recreates the famous data decryption effect seen in the 1992 movie Sneakers.
★ 7.8kpushbullet.py. A python client for http://pushbullet.com
★ 570pyAIML. PyAIML -- The Python AIML Interpreter
★ 9ntfy. 🖥️📱🔔 A utility for sending notifications, on demand and when commands finish.
★ 5kBloodHound-Legacy. Six Degrees of Domain Admin
★ 11kAblation. Ablation is a tool for augmenting static analysis by extracting information at runtime, and importing it into IDA. It can resolve virtual calls, reveal interesting code, exclude heavily traversed regions, identify untested or undocumented features, visually diff samples, or perform root cause analysis simply by running samples. My favourite however is the virtual call resolution with fully interactive x-refs. It's simple, elegant, and disassembled C++ reads like C! It helps me time and time again.
★ 50awesome-selfhosted. A list of Free Software network services and web applications which can be hosted on your own servers
★ 310kdemos. Demos of various injection techniques found in malware
★ 787aflfast. AFLFast (extends AFL with Power Schedules)
★ 422wcc. The Witchcraft Compiler Collection
★ 2kpentext. PenText system: Easily create beautiful looking penetration test quotes, reports, and documents in many formats (PDF, text, JSON, Markdown, CSV, ...)
★ 134xerosploit. Efficient and advanced man in the middle framework
★ 2.2kpywerview. A (partial) Python rewriting of PowerSploit's PowerView
★ 1.1kwdbgark. WinDBG Anti-RootKit Extension
★ 642ansible4redteams. Ansible playbooks to facilitate redteam stuff
★ 14EasyHook. EasyHook - The reinvention of Windows API Hooking
★ 3.3klog-progress. https://habr.com/ru/post/276725/
★ 564pluginbase. A simple but flexible plugin system for Python.
★ 1.1kpyenv-implict. Allow pyenv to guess the python version from the program name.
★ 123king-phisher-templates. Templates for the King Phisher open source phishing campaign toolkit.
★ 176WSL. Windows Subsystem for Linux
★ 33kownnote. Notes app for ownCloud
★ 163notes. Awesome note taking.
★ 551jsencrypt. A tiny (18.5 kB gzip), zero-dependency, Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation.
★ 6.8kbandit. Python AST-based static analyzer from OpenStack Security Group
★ 1.2knerd-fonts. Iconic font aggregator, collection, & patcher. 3,600+ icons, 50+ patched fonts: Hack, Source Code Pro, more. Glyph collections: Font Awesome, Material Design Icons, Octicons, & more
★ 64kJs2Py. JavaScript to Python Translator & JavaScript interpreter written in 100% pure Python🚀 Try it online:
★ 2.6klaboratory. Achieving confident refactoring through experimentation with Python 2.7 & 3.3+
★ 1.3kkitty. Fuzzing framework written in python
★ 433peda. PEDA - Python Exploit Development Assistance for GDB
★ 6.1kpiprot. How rotten are your requirements?
★ 427domi-owned. IBM/Lotus Domino exploitation
★ 120agate. A Python data analysis library that is optimized for humans instead of machines.
★ 1.2kborg. Deduplicating archiver with compression and authenticated encryption.
★ 14kexcel-press. Python script to compress VBA macro files
★ 24intermediatePython. Python
★ 3.9kRopper. Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64). For disassembly ropper uses the awesome Capstone Framework.
★ 2.1kcodeface. Typefaces for source code beautification
★ 6.5kHack. A typeface designed for source code
★ 17kgotty. Share your terminal as a web application
★ 20kbits. BIOS Implementation Test Suite
★ 251UnmanagedPowerShell. Executes PowerShell from an unmanaged process
★ 549Empire. Empire is a PowerShell and Python post-exploitation agent.
★ 7.9kking-phisher. Phishing Campaign Toolkit
★ 2.6kawesome. 😎 Awesome lists about all kinds of interesting topics
★ 491kdiaphora. Diaphora, the most advanced Free and Open Source program diffing tool.
★ 4.3kinteractive-coding-challenges. 120+ interactive Python coding interview challenges (algorithms and data structures). Includes Anki flashcards.
★ 32kmetasploit-payloads. Unified repository for different Metasploit Framework payloads
★ 2kthe-art-of-command-line. Master the command line, in one page
★ 162k