Skip to content
Change the repository type filter

All

    Repositories list

    • agent_asteroid

      Public
      Agent responsible for detecting remote vulnerabilities, a robust scanner.
      Python
      53600Updated Dec 18, 2025Dec 18, 2025
    • agent_zap

      Public
      Agent implementation of the Zed Attack Proxy (ZAP) security scanner. ZAP is a very popular web scanner and proxy maintained by the OWASP org.
      Python
      21100Updated Dec 17, 2025Dec 17, 2025
    • KB

      Public
      Knowledge Base collects, stores, and retrieves known vulnerabilities.
      Python
      1900Updated Dec 16, 2025Dec 16, 2025
    • oxo

      Public
      OXO is a security scanning orchestrator for the modern age.
      Python
      6055910Updated Dec 5, 2025Dec 5, 2025
    • oxotitan

      Public
      UI of the OXO open-source Vulnerability Scanner.
      Vue
      0600Updated Dec 4, 2025Dec 4, 2025
    • agent_whatweb

      Public
      Agent responsible for fingerprinting websites.
      Python
      1100Updated Dec 3, 2025Dec 3, 2025
    • benchmarks

      Public
      Ostorlab Pentest Benchmarks
      Kotlin
      11400Updated Dec 2, 2025Dec 2, 2025
    • agent_osv

      Public
      OSV Agent to find existing vulnerabilities affecting projects dependencies
      Python
      1400Updated Nov 20, 2025Nov 20, 2025
    • Ostorlab Azure DevOps extension to complement your CI/CD with Security Testing.
      TypeScript
      1200Updated Nov 19, 2025Nov 19, 2025
    • agent_nmap

      Public
      Agent responsible for network discovery and security auditing using Nmap.
      Python
      32200Updated Oct 31, 2025Oct 31, 2025
    • Agent responsible for fast vulnerability scanning using Nuclei.
      Python
      21010Updated Oct 31, 2025Oct 31, 2025
    • agent_trufflehog

      Public
      Python
      0000Updated Oct 10, 2025Oct 10, 2025
    • KEV

      Public
      Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
      4459600Updated Oct 10, 2025Oct 10, 2025
    • agent_nebula

      Public
      The Nebula Agent is responsible of persisting all types of messages locally.
      Python
      0100Updated Oct 8, 2025Oct 8, 2025
    • Ostorlab Github Actions to complement your CI/CD with Security Testing.
      12000Updated Oct 2, 2025Oct 2, 2025
    • gitlabci

      Public
      This is the source repository to build the docker image to be used within GitLab CI. This image gives you the ability to integrate Ostorlab automonomus security testing for Android and iOS mobile apps to your build process.
      Shell
      2100Updated Sep 24, 2025Sep 24, 2025
    • Python
      1100Updated May 13, 2025May 13, 2025
    • Vulnerable Android application for Ostolab Security Scanner
      Java
      173500Updated May 13, 2025May 13, 2025
    • agent_tracker

      Public
      Agent responsible for tracking a scan in the local runtime.
      Python
      1300Updated Apr 30, 2025Apr 30, 2025
    • Agent responsible for persisting vulnerabilities in the local runtime.
      Python
      0000Updated Apr 30, 2025Apr 30, 2025
    • agent_openvas

      Public
      Agent responsible for network security and vulnerability scanning using OpenVas.
      Shell
      3700Updated Mar 14, 2025Mar 14, 2025
    • Python
      1000Updated Mar 13, 2025Mar 13, 2025
    • Agent metasploit
      PowerShell
      0200Updated Mar 12, 2025Mar 12, 2025
    • Vulnerable Ios application for Ostolab Security Scanner
      Dart
      11700Updated Mar 12, 2025Mar 12, 2025
    • py3chrome

      Public
      A Python Package for the Google Chrome Dev Protocol.
      Python
      119000Updated Mar 12, 2025Mar 12, 2025
    • Agent responsible for retrieving registry and information of an IP.
      Python
      1100Updated Mar 12, 2025Mar 12, 2025
    • Agent responsible for injecting an asset into the bus from the runtime.
      Python
      0200Updated Mar 12, 2025Mar 12, 2025
    • agent_amass

      Public
      Agent for OWASP for network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.
      Python
      0100Updated Mar 12, 2025Mar 12, 2025
    • Python
      0000Updated Mar 11, 2025Mar 11, 2025
    • Injects all domains names of all known TLD from a source domain.
      Python
      0000Updated Mar 11, 2025Mar 11, 2025