SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
★ 1PHPForks 0
Android video player
★ 0Forks 0
★ 0Forks 0
OpenSSF Scorecard - Security health metrics for Open Source
★ 0Forks 0
Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂
★ 0Forks 0
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
★ 0OCamlForks 0
grep rough audit - source code auditing tool
★ 0Forks 0
https://alvinsmith.gitbook.io/progressive-oscp/
★ 38HTMLForks 13
★ 0Forks 0
Extract uncompiled, uncompressed SPA code from Webpack source maps.
★ 0Forks 0
VASSAL, the open-source boardgame engine
★ 0Forks 0
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
★ 0Forks 0
The fastest, litest AI Gateway. Rust core with Python SDK. Call 100+ LLM APIs in OpenAI (or native) format with cost tracking, guardrails, load balancing, and logging [Bedrock, Azure, OpenAI, Anthropic, OpenAI, VertexAI, vLLM, Nvidia NIM]
★ 0Forks 0
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
★ 0PythonForks 0
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
★ 0GoForks 0
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
★ 0Forks 0
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
★ 0Forks 0
CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)
★ 18PythonForks 0
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
★ 0Forks 0
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
★ 0Forks 0
Orchestrate AI agents to find real vulnerabilities in code.
★ 0Forks 0
★ 0Forks 0
★ 0Forks 0
Analyze HTTP, DNS and SMTP requests and create custom responses and DNS records for your subdomain
★ 0Forks 0
HTTP requests collector to test webhooks, notifications, REST clients and more ...
★ 0Forks 0
Command-line tool to customize Spotify client. Supports Windows, macOS, and Linux.
★ 0Forks 0
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
★ 0Forks 0
AirPods liberated from Apple's ecosystem.
★ 0Forks 0
Automate the creation of a lab environment complete with security tooling and logging best practices
★ 0Forks 0
The official Windows Driver Kit documentation sources
★ 0Forks 0