Stars
AboutCode project: tools and data to uncover things about code: the provenance, origin, license, and more (packages, security, quality, etc.) of FOSS code. Get started at https://aboutcode.readthe…
Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.
Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to proactively identify risks in generative AI systems.
The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).
Security middleware to defend against SQL injection in Active Record.
FitM, the Fuzzer in the Middle, can fuzz client and server binaries at the same time using userspace snapshot-fuzzing and network emulation. It's fast and comparably easy to set up.
Software for Nebra (and third party) Helium Miners
ClusterFuzzLite - Simple continuous fuzzing that runs in CI.
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Pre-Built Vulnerable Environments Based on Docker-Compose
Bring your own print driver privilege escalation tool
Triton is a dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software verification or just emulate code.
Binary code static analyser, with IDA integration. Performs value and taint analysis, type reconstruction, use-after-free and double-free detection
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.
XSS spider - 66/66 wavsep XSS detected
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
Master programming by recreating your favorite technologies from scratch.
A powerful and user-friendly binary analysis platform!
A WIP "Vulnerable by Design" kext for iOS/macOS to play & learn *OS kernel exploitation
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Develo…