Lists (11)
Sort Name ascending (A-Z)
Stars
Flutter SSL Pinning Bypass Tool for Android & iOS — works on any Flutter version without pattern databases
BOF to steal browser cookies & credentials
A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven f…
Offensive knowledge, offline. One search box for every playbook.
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK,…
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
Open-source AI-augmented Security Operations Center using LLMs + Multi-Agent Orchestration | Foundation-Sec-8B | Wazuh | TheHive | RAG
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitor…
A BloodHound OpenGraph collector that models Windows local privilege escalation as interconnected attack paths.
Havoc C2 BOF — WFP kernel-space SYSTEM escalation + command execution with indirect syscalls, patchless AMSI/ETW bypass, and return address spoofing
Async BOF to automatically extract or renew Kerberos TGTs on a target system.
Modules designed to be used with the Conquest framework.
Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.
Another BYOVD process killer. works on all EDR's. fully signed.
🕵️♂️ (2-in-1) Email & Username OSINT suite for deep data extraction just from a single Email/Username. Analyzes 380+ actively maintained scan vectors (155+ email / 225+ username) for security rese…
Technical Reference to multiple relay techniques
Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)
Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-445…
A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
Security sensor for realtime threat detection and protection
Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞
An agent-managed museum exhibit, built in Rust with Gajae-Code / LazyCodex — developed and maintained with no human intervention.
Plecost - Professional WordPress Security Scanner
Goauld is a post-exploitation and remote access tool designed for restricted environments.