Highlights
Starred repositories
A powerful tool for creating datasets for LLM fine-tuning 、RAG and Eval
by ex-googlers, for ex-googlers - a lookup table of similar tech & services
📦 Make security testing of K8s, Docker, and Containerd easier.
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Go HTTP client with browser-identical TLS/HTTP2 fingerprinting. Bypass bot detection by perfectly mimicking Chrome, Firefox, and Safari at the cryptographic level (JA3/JA4, Akamai fingerprint, head…
Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy
Concatenate a directory full of files into a single prompt for use with LLMs
A file server that supports static serving, uploading, searching, accessing control, webdav...
Differential testing framework for HTTP implementations
⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests and bug bounty.
"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.
Web simulation of Ubuntu 20.04, made using NEXT.js & tailwind CSS
A CLI utility to secretly copy secrets to clipboard. 🔒📝
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
Prototype Pollution - A detailed study + hands on lab.
Automation for internal Windows Penetrationtest / AD-Security
SSRF (Server Side Request Forgery) testing resources
A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering