Topic: offensive-security

2,207 repositories

usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

★ 65,881PythonForks 7,220

x64dbg/x64dbg

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

★ 49,668C++Forks 2,848

KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

★ 48,515TypeScriptForks 5,556

vxcontrol/pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

★ 25,171GoForks 3,238

ihebski/DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

★ 6,766PythonForks 788

infinition/Bjorn

Bjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.

★ 6,315PythonForks 369

elder-plinius/T3MP3ST

autonomous red teaming platform; multi-agent offensive-security meta-harness

★ 6,297TypeScriptForks 1,316

nicocha30/ligolo-ng

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

★ 5,036GoForks 483

elementalsouls/Claude-BugHunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.

★ 4,741PythonForks 710

t3l3machus/Villain

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).

★ 4,460PythonForks 696

skerkour/black-hat-rust

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

★ 4,428RustForks 440

evyatarmeged/Raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning

★ 4,041PythonForks 506

0xsyr0/OSCP

OSCP Cheat Sheet

★ 3,855PowerShellForks 768

codingo/NoSQLMap

Automated NoSQL database enumeration and web application exploitation tool.

★ 3,359PythonForks 626

mikeroyal/Digital-Forensics-Guide

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

★ 3,166PythonForks 399

CyberStrikeus/CyberStrike

Open-source AI-powered offensive security harness for automated penetration testing.

★ 2,916TypeScriptForks 458

aydinnyunus/Keylogger

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

★ 2,853PythonForks 550

Armur-Ai/Pentest-Swarm-AI

Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.

★ 2,676GoForks 492

x90skysn3k/brutespray

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.

★ 2,542GoForks 438

0xSteph/pentest-ai-agents

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.

★ 2,300ShellForks 434

codingo/Reconnoitre

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

★ 2,196PythonForks 447

skavngr/rapidscan

:new: The Multi-Tool Web Vulnerability Scanner.

★ 2,133PythonForks 433

vulnersCom/getsploit

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

★ 1,823PythonForks 245

JesseCHale/HaleHound-CYD

ESP32-DIV HaleHound Edition for Cheap Yellow Display - Multi-protocol offensive security toolkit

★ 1,770Forks 137