Stars
Dragon-GPT uses Chat-GPT, or local LLM, to execute automatic and AI-powered threat modeling analysis on a given OWASP Threat Dragon diagram.
Shostack's 4 Question Frame for Threat Modeling
Helping allocate resources to secure the critical open source projects we all depend on.
TRADES Tool for designing and analysing the security posture of systems
A theoretical reconstruction of the Claude Mythos architecture, built from first principles using the available research literature.
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works w…
An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks.
Check any website (or set of websites) for insecure security headers.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug b…
Security Scanner for Agent Skills
Guardian is a production-ready AI-powered penetration testing automation CLI tool that leverages Google Gemini and LangChain to orchestrate intelligent, step-by-step penetration testing workflows w…
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Reverse Engineering 101 training from our Vulnerability Researcher Development Program (VRDP)
The Azure Cloud Native Architecture Mapbook, Second Edition, Published by Packt
This project simulates trading strategies using Pine Editor scripts on TradingView and visualizes performance metrics.
CodeQL zero to hero blog post series challenges
Curated Collection of Popular Community Rules for Semgrep
Semgrep queries developed by Trail of Bits.
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command li…
LLM-powered system that discovers and patches zero-day vulnerabilities in open source projects. 4th place, DARPA AIxCC.
The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers across function-level, repository-level, agentic, a…
Exploit Development and Reverse Engineering with GDB & LLDB Made Easy
OWASP Code Review Guide Web Repository
The Firmware Security Testing Methodology (FSTM) is composed of nine stages tailored to enable security researchers, software developers, consultants, and Information Security professionals with co…
Reverse engineering and pentesting for Android applications