4-day longest streak
-
whitesnow
An experimental rootkit for Android
C ★ 25 13y agoExplain → -
Tapjacking-Framework-for-Android
An experimental tapjacking framework for Android platform
Java ★ 17 13y agoExplain → -
FirefoxExploit
PoC used to exploit some Firefox vulnerabilities
Java ★ 13 13y agoExplain → -
ADEL ⑂
Android Data Extractor Lite
Python ★ 5 13y agoExplain → -
ethernaut
Solutions for Ethernaut CTF using Brownie
Solidity ★ 3 3y agoExplain → -
LKM-Protect
No description.
C ★ 3 13y agoExplain → -
aamo ⑂
AAMO: Another Android Malware Obfuscator
Python ★ 2 11y agoExplain → -
setools3 ⑂
SELinux Policy Analysis Tools v3
★ 2 12y agoExplain → -
EvernotePoC
No description.
Java ★ 2 12y agoExplain → -
vdevices
Create a virtual device for testing purposes on Android devices
C ★ 2 13y agoExplain → -
Blackphone-BP1-Kernel
Blackphone BP1 Kernel
★ 1 12y agoExplain → -
awesome-list ⑂
Cybersecurity oriented awesome list
★ 1 2y agoExplain → -
Smali-CFGs ⑂
Smali Control Flow Graph's
★ 1 12y agoExplain → -
SSLStrip-for-Android ⑂
SSLStrip for Android
C ★ 1 14y agoExplain → -
radare2 ⑂
unix-like reverse engineering framework and commandline tools
C ★ 1 13y agoExplain → -
p0sixspwn ⑂
Released in accordance with GPL licensing.
C++ ★ 1 12y agoExplain → -
ldpreloadhook ⑂
a quick open/close/ioctl/read/write/free function hooker
C ★ 1 13y agoExplain → -
DendroidSource ⑂
This is an updated version of Dendroid with a working panel & APK, I hope that everyone enjoys this download.
★ 1 12y agoExplain → -
libmsm_acdb_exploit ⑂
No description.
C ★ 1 13y agoExplain → -
android-forensics ⑂
Open source Android Forensics app and framework
Java ★ 1 14y agoExplain → -
RootTools ⑂
Root Tools
Java ★ 1 14y agoExplain → -
suterusu ⑂
Fork from http://redmine.poppopret.org/projects/suterusu. An LKM rootkit targeting Linux 2.6/3.x on x86 and ARM. Supports privilege escalation, process hiding, connection hiding (TCP/UDP v4/v6), file/directory hiding, keylogging, and screen unlocking. Under active development.
C ★ 1 14y agoExplain → -
googleplay-api ⑂
Google Play Unofficial Python API
Python ★ 1 14y agoExplain → -
exploitarium ⑂
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
★ 0 1mo agoExplain → -
scrutineer ⑂
Security through scrutiny
★ 0 1mo agoExplain → -
goose ⑂
Goose Swift proof-of-concept README
★ 0 2mo agoExplain → -
ctf-agent ⑂
Autonomous CTF solver that races multiple AI models in parallel. 1st place BSidesSF 2026.
★ 0 4mo agoExplain → -
wooyun-legacy ⑂
wooyun-legacy skill for claude code
★ 0 6mo agoExplain → -
vphone-cli ⑂
No description.
★ 0 4mo agoExplain → -
red-run ⑂
Offensive security toolkit for Claude Code
★ 0 5mo agoExplain → -
public-pentesting-reports ⑂
A list of public penetration test reports published by several consulting firms and academic security groups.
★ 0 8mo agoExplain → -
reinforce-2025-summaries ⑂
Summaries, transcripts, key points, and other useful insights from AWS re:inforce 2025 talks for those of us who don't have time to watch every presentation!
★ 0 1y agoExplain → -
investigations ⑂
Indicators of Compromise from Amnesty International's cyber investigations
★ 0 1y agoExplain → -
pegasus_false_positive ⑂
No description.
★ 0 4y agoExplain → -
android-keystore-audit ⑂
No description.
★ 0 2y agoExplain → -
validation-benchmarks ⑂
XBOW Validation Benchmarks
★ 0 1y agoExplain → -
subjs ⑂
Fetches javascript file from a list of URLS or subdomains.
★ 0 3y agoExplain → -
Azure-Sentinel ⑂
Cloud-native SIEM for intelligent security analytics for your entire enterprise.
★ 0 1y agoExplain → -
libprejailbreak ⑂
A pre-jailbreak library for devices running iOS 12 - 14.
★ 0 1y agoExplain → -
Attacking-and-Defending-Generative-AI ⑂
Reference notes for Attacking and Defending Generative AI presentation
★ 0 2y agoExplain → -
InjuredAndroid ⑂
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
★ 0 5y agoExplain → -
frida-ios-playground ⑂
An iOS app that lets you practice your Frida skills
★ 0 3y agoExplain → -
Black-Hat-GraphQL ⑂
The Black Hat GraphQL Book Repository
★ 0 2y agoExplain → -
testing-netlify-andromeda
No description.
JavaScript ★ 0 1y agoExplain → -
com.learn.frida ⑂
App for learnfrida.info
★ 0 4y agoExplain → -
Crash-iOS-Exploit ⑂
Repository dedicated to storing a multitude of iOS/macOS/OSX/watchOS crash bugs. Some samples need to be viewed as raw in order to see the Unicode. Please do not intentionally abuse these exploits.
★ 0 7y agoExplain → -
ios_debugger_challenge ⑂
A playground for run-time iOS app inspection
★ 0 3y agoExplain → -
Blog-resources ⑂
No description.
★ 0 2y agoExplain → -
Azure-Red-Team ⑂
Azure Security Resources and Notes
★ 0 2y agoExplain → -
pecoret ⑂
A Pentest Collaboration and Reporting Tool
★ 0 1y agoExplain → -
sectemplates ⑂
Open source templates you can use to bootstrap your security programs
★ 0 1y agoExplain → -
Exploit-Challenges ⑂
A collection of vulnerable ARM binaries for practicing exploit development
★ 0 4y agoExplain → -
binder-trace ⑂
Binder Trace is a tool for intercepting and parsing Android Binder messages. Think of it as "Wireshark for Binder".
★ 0 2y agoExplain → -
aws-threat-hunting ⑂
Short deep dive into Threat Hunting on AWS
★ 0 2y agoExplain → -
playbooks ⑂
External Playbooks for Public Access
★ 0 2y agoExplain → -
TInjA ⑂
TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight different programming languages.
★ 0 2y agoExplain → -
template-injection-playground ⑂
The Template Injection Playground allows to test a large number of the most relevant template engines for template injection possibilities.
★ 0 2y agoExplain → -
damn-exploitable-android-app-public-apk ⑂
damn-exploitable-android-app-apk
★ 0 3y agoExplain → -
nmap-grep ⑂
Comprehensive parsing script for grepable Nmap output files. Provides a summary table, split hosts files, and URLs for web and SMB hosts.
★ 0 6y agoExplain → -
vuln-nodejs-app ⑂
No description.
★ 0 4y agoExplain → -
Flipper ⑂
Playground (and dump) of stuff I make or modify for the Flipper Zero
★ 0 3y agoExplain → -
ovaa ⑂
Oversecured Vulnerable Android App
★ 0 4y agoExplain → -
infosec-opml ⑂
My very personal and opinionatedly organized infosec/cybersec sources in one OPML file
★ 0 3y agoExplain → -
palera1n ⑂
iOS 15.0-15.7.1 (semi-)tethered checkm8 "jailbreak"
★ 0 3y agoExplain → -
generative-art-nft ⑂
A generative art library for NFT avatar and collectible projects.
★ 0 4y agoExplain → -
paradigm-ctf-2022 ⑂
No description.
★ 0 3y agoExplain → -
smart_contract_security ⑂
No description.
★ 0 3y agoExplain → -
digital-garden-hugo-theme ⑂
Build your own personal Digital Garden effortlessly with this Hugo theme
★ 0 4y agoExplain → -
awesome-security-newsletters ⑂
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events, vulnerabilities, and analysis of trending threats and attacks
★ 0 3y agoExplain → -
cve-search ⑂
cve-search is a tool to import CVE (Common Vulnerabilities and Exposures) and CPE (Common Platform Enumeration) into a MongoDB to facilitate search and processing of CVEs.
CSS ★ 0 12y agoExplain → -
OctoPrint ⑂
OctoPrint provides a responsive web interface for controlling a 3D printer (RepRap, Ultimaker, ...).
JavaScript ★ 0 13y agoExplain → -
pentest-tools ⑂
Custom pentesting tools
★ 0 6y agoExplain → -
Tiny-URL-Fuzzer ⑂
A tiny and cute URL fuzzer
★ 0 6y agoExplain → -
the-art-of-subdomain-enumeration ⑂
This repository contains all the supplement material for the book "The art of sub-domain enumeration"
★ 0 7y agoExplain → -
bugcrowd-levelup-subdomain-enumeration ⑂
This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtual conference
★ 0 7y agoExplain → -
ffuf ⑂
Fast web fuzzer written in Go
★ 0 6y agoExplain → -
commonspeak2 ⑂
Leverages publicly available datasets from Google BigQuery to generate content discovery and subdomain wordlists
Go ★ 0 6y agoExplain → -
go-get-rce
No description.
Go ★ 0 8y agoExplain → -
ida_kernelcache ⑂
An IDA Toolkit for analyzing iOS kernelcaches.
Python ★ 0 8y agoExplain → -
Linux_Exploit_Suggester ⑂
Linux Exploit Suggester; based on operating system release number
Perl ★ 0 12y agoExplain → -
idat-png
No description.
HTML ★ 0 9y agoExplain → -
aws_pwn ⑂
A collection of AWS penetration testing junk
Python ★ 0 9y agoExplain → -
owasp-mstg ⑂
The Mobile Security Testing Guide (MSTG) is the ultimate guide for mobile app security testing and reverse engineering.
HTML ★ 0 9y agoExplain → -
TSA-Travel-Sentry-master-keys ⑂
3D reproduction of TSA Master keys
★ 0 11y agoExplain → -
core-ios ⑂
iOS RCS (Hackedteam fork)
Objective-C ★ 0 11y agoExplain → -
JustTrustMe ⑂
An xposed module that disables SSL certificate checking for the purposes of auditing and app with cert pinning
Java ★ 0 12y agoExplain → -
usb-device-fuzzing ⑂
Some tools for testing USB devices
★ 0 13y agoExplain → -
ibrute ⑂
No description.
★ 0 12y agoExplain → -
pidcat ⑂
Colored logcat script which only shows log entries for a specific application package.
★ 0 12y agoExplain → -
FinFly-Web ⑂
No description.
★ 0 12y agoExplain → -
IDA-IOS-Toolkit ⑂
Collection of idapython scripts for dealing with the iOS kernelcache
★ 0 15y agoExplain → -
FakeID_poc_by_retme_bug_13678484 ⑂
PoC binary file of FakeID,with some source code
★ 0 12y agoExplain → -
android-lkms ⑂
Android Loadable Kernel Modules - mostly used for reversing and debugging on controlled systems/emulators
★ 0 12y agoExplain → -
dexterity ⑂
Dex manipulation library
C ★ 0 12y agoExplain → -
WalletCracker ⑂
Google Wallet PIN Cracking App
★ 0 14y agoExplain → -
dockerfile-androguard ⑂
No description.
Shell ★ 0 12y agoExplain → -
droidsec.github.io ⑂
The www.droidsec.org Web Site!
CSS ★ 0 12y agoExplain → -
ructfe-2013 ⑂
RuCTFE 2013
CSS ★ 0 12y agoExplain → -
AndroidEmulatorDetection ⑂
Contains many different ways to identify hostile environments.
C ★ 0 13y agoExplain → -
threat-intel-templates ⑂
A set of templates for documenting threat intelligence
★ 0 13y agoExplain → -
dumpdecrypted ⑂
Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption.
C ★ 0 14y agoExplain → -
libdiagexploit ⑂
No description.
C ★ 0 13y agoExplain → -
libperf_event_exploit ⑂
CVE-2013-2094 exploit for android
C ★ 0 13y agoExplain → -
androrat ⑂
Remote Administration Tool for Android devices
Java ★ 0 13y agoExplain → -
Protod ⑂
Protobuf metadata extraction tool
★ 0 14y agoExplain → -
dalvik-obfuscator ⑂
a set of tools/scripts to obfuscate and manipulate dex files
Python ★ 0 14y agoExplain → -
radare-installer ⑂
Application to easily download and install radare2 on android devices
Java ★ 0 14y agoExplain →
No repos match these filters.