Highlights
Stars
Scapy: the Python-based interactive packet manipulation program & library.
Go-based SBOM, vulnerability, and secret scanner with MCP support.
ThreatByte is a vulnerable Python (Flask) web application designed to demonstrate some Web Application and API Security risks.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Organize your API security assessment by using MindAPI. It's free and open for community collaboration.
Fork of SafetyKatz that dynamically fetches the latest pre-compiled release of Mimikatz directly from gentilkiwi GitHub repo, runtime patches signatures and uses SharpSploit DInvoke to PE-Load into…
A tool which scrapes public github repositories for common naming conventions in variables, folders and files
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
lateral movement techniques that can be used during red team exercises
A curated list of awesome social engineering resources.
USB MitM Wifi keylogger with keyboard and mouse injection capabilities
Extract WhatsApp private key from any non-rooted Android device (Android 7+ supported)
🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection
A pwnagotchi plugin that sends status messages encapsulated inside a valid beacon frame. They are easy to process from an Android/iOS application
A list of interesting payloads, tips and tricks for bug bounty hunters.
An "Awesome" list of code review resources - articles, papers, tools, etc
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
A python script that finds endpoints in JavaScript files
clviper / droidstatx
Forked from devoteam-cybertrust/droidstatxPython tool that generates an Xmind map with all the information gathered and any evidence of possible vulnerabilities identified via static analysis. The map itself is an Android Application Pente…
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Email recon made fast and easy, with a framework to build on
pull decrypted ipa from jailbreak device
Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.
DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.