Found 27,550 repositories(showing 30)
swisskyrepo
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
enaqx
A collection of awesome penetration testing resources, tools and other shiny things
qeeqbox
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
promptfoo
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
sundowndev
A collection of hacking tools, resources and references to practice ethical hacking.
blaCCkHatHacEEkr
articles
GreyDGL
Automated Penetration Testing Agentic Framework Powered by Large Language Models
A list of resources for those interested in getting started in bug bounties
vanhauser-thc
hydra
horsicq
Program for determining types of files for Windows, Linux and MacOS.
juliocesarfort
A list of public penetration test reports published by several consulting firms and academic security groups.
byt3bl33d3r
A swiss army knife for pentesting networks
sensepost
📱 objection - runtime mobile exploration
A-poc
Tools and Techniques for Red Team / Penetration Testing
SecWiki
windows-kernel-exploits Windows平台提权漏洞集合
0x4m4
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
Orange-Cyberdefense
game of active directory
epi052
A fast, simple, recursive content discovery tool written in Rust.
mandiant
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
six2dez
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
yaklang
Cyber Security ALL-IN-ONE Platform
daffainfo
All about bug bounty (bypasses, payloads, and etc)
urbanadventurer
Next generation web scanner
ihebski
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
hmaverickadams
Notes for Beginner Network Pentesting Course
k8gege
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
androguard
Reverse engineering and pentesting for Android applications
projectdiscovery
A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
alpkeskin
An automated e-mail OSINT tool
ffffffff0x
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup