Stars
Cheatsheet, Notes, Payloads and Mayhem for Burp Suite Practitioner Exam (BSCP)
Verbalized Sampling, a training-free prompting strategy to mitigate mode collapse in LLMs by requesting responses with probabilities. Achieves 2-3x diversity improvement while maintaining quality. …
AI Security Shared Responsibility Model
Playbook-NG is a stateless web-based application used to match incident findings with countermeasures for adversary containment and eviction.
Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀
A fun POC that is built to understand AI security agents.
attacksurge / ax
Forked from pry0cc/axiomThe Distributed Scanning Framework for Everybody! Control Your Infrastructure, Scale Your Scanning-On Your Terms. Easily distribute arbitrary binaries and scripts using any of our nine supported cl…
Open source templates you can use to bootstrap your security programs
Fragtunnel is a proof-of-concept (PoC) TCP tunnel tool that you can use to tunnel your application's traffic and bypass next-generation firewalls en route to the target.
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be compiled and used for learning purposes, without having to …
Collection of cheat sheets useful for pentesting
OWASP Foundation Web Respository
This is a companion to the Security Engineer Questions
A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities
ServiceNow widge-simple-list misconfiguration scanner
dnSpyEx / dnSpy
Forked from dnSpy/dnSpyUnofficial revival of the well known .NET debugger and assembly editor, dnSpy
A Repository dedicated to creating modular and automated penetration testing frameworks utilizing Jupyter Notebooks
A modular vulnerability scanner with automatic report generation capabilities.
A collection of Active Directory, phishing, mobile technology, system, service, web application, and wireless technology weaknesses that may be discovered during a penetration test.
Complete API layer for private AI applications on local models: RAG, skills, tools, MCP, text-to-sql, and more. Works with any OpenAI-compatible inference server.