Highlights
Starred repositories
An opinionated list of Python frameworks, libraries, tools, and resources
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Official inference framework for 1-bit LLMs
A book-in-progress about the Linux kernel and its insides.
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
AWX provides a web-based user interface, REST API, and task engine built on top of Ansible. It is one of the upstream projects for Red Hat Ansible Automation Platform.
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…
An advanced memory forensics framework
Open Source Vulnerability Management Platform
PEDA - Python Exploit Development Assistance for GDB
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
The FLARE team's open-source tool to identify capabilities in executable files.
Adversarial Robustness Toolbox (ART) - Python Library for Machine Learning Security - Evasion, Poisoning, Extraction, Inference - Red and Blue Teams
The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to proactively identify risks in generative AI systems.
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
A DNS meta-query spider that enumerates DNS records, and subdomains.
File upload vulnerability scanner and exploitation tool.
Tweets metadata scraper & activity analyzer
Privilege Escalation Project - Windows / Linux / Mac
Decompiler Explorer! Compare tools on the forefront of static analysis, now in your web browser!
Tools & Interesting Things for RedTeam Ops
Extract credentials from lsass remotely
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.