Stars
A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven f…
This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC, MIPS, RISC-V 64, a…
Skills for Real Engineers. Straight from my .agents directory.
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK,…
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
A kernel-assisted shared-library injector for Android. Loads any .so into a target process without ptrace, in-process dlopen, or visible traces in /proc/<pid>/maps. GKI 2.0 (Android 12-16).
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Llama Server Studio is a single-binary Go web application that helps users manage llama.cpp's llama-server without manually dealing with hundreds of command-line flags. The app provides a guided UI…
Automating situational awareness for cloud penetration tests.
a lightweight, single-binary webapp that lets you leave your AI agents running 24/7. You can check in on their progress, review their work, and prompt them for the next features from anywhere. It b…
Stealth Chromium that passes every bot detection test. Drop-in Playwright replacement with source-level fingerprint patches. 30/30 tests passed.
A curated toolkit for Open-Source Intelligence (OSINT) investigations. This repository contains a collection of scripts, resources, and methodologies to aid in gathering and analyzing publicly avai…
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
Tools that can be useful for OSEP exam and PEN300 studies.
Claude Code skill to support Android app's reverse engineering
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
A demonstration of how to use BuildKit to build anything you want.
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
A Burp Suite extension for GraphQL security testing.
eBPF-based egress audit tool for CI environments. Captures outbound network connections with executable paths and DNS hostnames.
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…
Search for all leaked keys/secrets using one regex! bugbounty