Lists (25)
Sort Name ascending (A-Z)
AD - Enumeration
Tools to collect AD dataAD - Exploitation
Bunch of tools for AD testingAI
Azure AD
Azure AD exploitation and enumeration toolkitsBypass Utils
C2 Inf
C2 Utils
Various utils and BOFsCloud Testing
Tools to aid could config reviewsImplants Coding
Bunch of tools to (try to) bypass thingsInitial_Access
Local PrivEsc
MCP AI
Offensive Utils
Various Utils for PentestersOSINT
General OSINT toolsPhishing
Proxy stuff
PT - Mitre
RE
Reporting
Stuff to save time reportingsdr*
Shellcode Utils
Shellcode Manipulation (fancy term to say pretty print bin data)Sysadmin Utils
Various good to know utilitiesTest Lab
Test lab tools for both creating and detectingTTP
Web-API-Misc
Stars
Run frontier MoE models on hardware you already own — pure C, zero deps, experts streamed from disk. Tiny engine, immense model. 🐦
TimesFM (Time Series Foundation Model) is a pretrained time-series foundation model developed by Google Research for time-series forecasting.
Fine-tune LLMs from one YAML. Layer streaming trains an 8B model on a 4 GB laptop GPU.
Run iOS/ macOS in Qemu. Virtual iPhone 17, 16, 15, 14, 13, 12 and M5-M1 Apple Si Macs supported.
The most powerful and modular diffusion model GUI, api and backend with a graph/nodes interface.
Undetectable offensive toolkit inside Chrome
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills b…
Documentation on building an at home budget 48 GB VRAM AI server.
TradingAgents: Multi-Agents LLM Financial Trading Framework
Turn any technical book PDF into a Claude Code skill — ready to study, reference, and use while you work.
Turn any codebase, with its docs, SQL schemas, configs, and PDFs, into a queryable knowledge graph. A /graphify skill for Claude Code, Cursor, Codex, and Gemini CLI: local deterministic AST parsing…
EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.
Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and per…
autonomous red teaming platform; multi-agent offensive-security meta-harness
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with C…
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
Jailbreaker is a local evaluation tool for testing chatbot and agent-style systems against jailbreak, prompt-injection, and related failure modes.
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we confi…
Send and receive SMS messages using your Android phone programmatically via a simple HTTP API
An overview of LLMs for cybersecurity.
The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers across function-level, repository-level, agentic, a…