Stars
Frida scripts to directly MitM all HTTPS traffic from a target mobile application
A self-hosted SPA to simplify course creation and management
the transparent ransomware claim tracker 🥷🏼🧅🖥️
📚 Freely available programming books
A swiss army knife for pentesting networks
This project is about creating and publishing threat model examples.
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
The official gpt4free repository | various collection of powerful language models | o3 and deepseek r1, gpt-4.5
TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!
An open source threat modeling tool from OWASP
Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
Vulnerable app with examples showing how to not use secrets
Identify privilege escalation paths within and across different clouds
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
A security tool for grabbing screenshots of many web hosts
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Low bandwidth DoS tool. Slowloris rewrite in Python.
Automated Integration Testing and Live Documentation for your API
Open Source Continuous File Synchronization
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.