Stars
Homemade Pwnbox 🚀 / Rogue AP 📡 based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap 💡
Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registries.
MCP security testing framework for evaluating Model Context Protocol server vulnerabilities
Sysmon configuration file template with default high-quality event tracing
A repository of sysmon configuration modules
AI-powered OSINT agent with interactive REPL, MCP server, and CLI. 16 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
AI-powered offensive security agent with 7,300+ actionable security skills. Autonomous pentesting powered by MITRE ATT&CK (2,000+ Atomic tests), CIS Benchmarks (1,500+ controls), OWASP, NIST. Lazy-…
A Password Spraying tool for Active Directory Credentials by Jacob Wilkin(Greenwolf)
Fast and lightweight, UDPX is a single-packet UDP scanner written in Go that supports the discovery of over 45 services with the ability to add custom ones. It is easy to use and portable, and can …
🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.
Fetch all the URLs that the Wayback Machine knows about for a domain
API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs
Offensive security toolkit for Claude Code
🎒 Token-Oriented Object Notation (TOON) – Compact, human-readable, schema-aware JSON for LLM prompts. Spec, benchmarks, TypeScript SDK.
dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
Visual testing tool for MCP servers
Tyche is a Mythic HTTPX Profile Generator used to create Malleable C2 Profiles.
Adaptix C2 agent using Crystal Palace PIC linker and PICO module system
Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.