Make your GenAI Apps Safe & Secure :rocket: Test & harden your system prompt
Monitor linux processes without root permissions
Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Fancy reverse and bind shell handler
Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a sing…
An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD doma…
A python 3 library which helps in using nmap port scanner. This is done by converting each nmap command into a callable python3 method or f…
Unauthenticated enumeration of AWS, Azure, and GCP Principals
A high performance offensive security tool for reconnaissance and vulnerability scanning
RAG/LLM Security Scanner identifies critical vulnerabilities in AI-powered applications, including chatbots, virtual assistants, and knowled…
Autonomous Privilege Escalation using AI
React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, lo…
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
Automated Recon for Pentesting & Bug Bounty
Red Team Toolkit is an Open-Source Django Offensive Web-App which is keeping the useful offensive tools used in the red-teaming together.
Tools and Techniques for Red Team / Penetration Testing
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engi…
An open-source, AI-powered application using Agentic CAG to chat with any public GitHub repository or developer profile, offering deep code …
Reverse engineering software using a full system simulator
Detects the use of JavaScript libraries with known vulnerabilities. Available as a CLI tool, browser extension, Grunt plugin, and Burp Suite…
➡️ [Discord][discord] | [Installation Guide][toc-install] | [Usage Guide][usage-guide] ⬅️
Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.