-
titus ★ PINNED
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go ★ 655 5d agoExplain → -
nerva ★ PINNED
Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian
Go ★ 321 1d agoExplain → -
brutus ★ PINNED
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go ★ 299 14h agoExplain → -
augustus ★ PINNED
LLM security testing framework for detecting prompt injection, jailbreaks, and adversarial attacks — 190+ probes, 28 providers, single Go binary
Go ★ 264 11h agoExplain → -
julius ★ PINNED
Simple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 60+ other AI services in seconds
Go ★ 174 10h agoExplain → -
pius ★ PINNED
Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registries.
Go ★ 87 1d agoExplain → -
noseyparker ▣
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
Rust ★ 2.3k 5mo agoExplain → -
gokart ▣
A static analysis tool for securing Go code
Go ★ 2.2k 2y agoExplain → -
Hob0Rules ▣
Password cracking rules for Hashcat based on statistics and industry patterns
★ 1.5k 7y agoExplain → -
PortBender
TCP Port Redirection Utility
C ★ 788 3y agoExplain → -
fingerprintx ▣
Standalone utility for service discovery on open ports!
Go ★ 758 6mo agoExplain → -
purple-team-attack-automation ▣
Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs
Ruby ★ 729 6y agoExplain → -
pentestly ▣
Python and Powershell internal penetration testing framework
Python ★ 721 10y agoExplain → -
DVRF ▣
The Damn Vulnerable Router Firmware Project
HTML ★ 720 5y agoExplain → -
ChromeAlone
A tool to transform Chromium browsers into a C2 Implant
JavaScript ★ 594 7mo agoExplain → -
turnt
A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such as Zoom.
Go ★ 430 1mo agoExplain → -
goffloader
A Go implementation of Cobalt Strike style BOF/COFF loaders.
Go ★ 285 1mo agoExplain → -
trudy ▣
A transparent proxy that can modify and drop traffic for arbitrary TCP connections.
Go ★ 277 6y agoExplain → -
pyshell ▣
PyShell makes interacting with web-based command injection less painful, emulating the feel of an interactive shell as much as possible.
Python ★ 251 9y agoExplain → -
GitPhish
No description.
Python ★ 205 8mo agoExplain → -
mitm-vm ▣
An easy-to-deploy virtual machine that can provide flexible man-in-the-middle capabilities.
Shell ★ 204 10y agoExplain → -
ADFSRelay
Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS
Go ★ 188 4y agoExplain → -
gladius ▣
Automated Responder/secretsdump.py cracking
Python ★ 186 10y agoExplain → -
oauthseeker
A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.
HTML ★ 177 1y agoExplain → -
snowcat
a tool to audit the istio service mesh
Go ★ 174 4y agoExplain → -
vulcan ▣
a tool to make it easy and fast to test various forms of injection
C++ ★ 170 7y agoExplain → -
trajan
A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.
Go ★ 168 13h agoExplain → -
swarmer
A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN
C# ★ 153 6mo agoExplain → -
google-redirector
A lightweight redirector for Google Cloud Run, enabling domain fronting via Google-owned infrastructure.
Go ★ 149 8mo agoExplain → -
trident ▣
automated password spraying tool
Go ★ 148 5y agoExplain → -
NTLMRecon
A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.
Go ★ 118 4mo agoExplain → -
vespasian
API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs
Go ★ 114 10h agoExplain → -
wasmforge
WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.
Go ★ 105 1mo agoExplain → -
INTRACTABLEGIRAFFE
A Proof of Concept Rootkit Demonstrating Keylogging and Virtual File System (VFS) Capabilities
C ★ 76 3y agoExplain → -
epictreasure ▣
radare, angr, pwndbg, binjitsu, ect in a box ready for pwning
Shell ★ 75 10y agoExplain → -
hadrian
API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templates
Go ★ 71 5d agoExplain → -
aurelian
Open-source cloud security reconnaissance framework
Go ★ 62 2d agoExplain → -
noseyparker-explorer
Interactive results explorer and annotation tool for Nosey Parker
Python ★ 58 1y agoExplain → -
proxylogon-exploit ▣
Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.
Python ★ 52 5y agoExplain → -
slack-c2bot ▣
Slack C2bot that executes commands and returns the output.
Go ★ 49 3y agoExplain → -
hashcatJS ▣
An implementation of the hashcat rules engine in javascript
JavaScript ★ 49 8y agoExplain → -
Matryoshka
Matryoshka loader is a tool that red team operators can leverage to generate shellcode for Microsoft Office document phishing payloads.
C ★ 43 5y agoExplain → -
ruby_hashcat ▣
Command line wrapper, Library, and Rest API for oclHashcat.
Ruby ★ 43 10y agoExplain → -
caeruleus
Caeruleus is a Bluetooth Low Energy testing toolkit for Linux/BlueZ, implemented as a single Go binary. It covers the full interaction-to-assessment lifecycle
Go ★ 42 2d agoExplain → -
Okta_Watering_Hole ▣
Next Generation Phishing Tool For Internal / Red Teams
Python ★ 37 7y agoExplain → -
dert ▣
DNS Enumeration and Reconnaissance Tool
Ruby ★ 36 10y agoExplain → -
konstellation
Konstellation is a configuration-driven CLI tool to enumerate cloud resources and store the data into Neo4j.
Cypher ★ 35 2mo agoExplain → -
MCPHammer
MCP security testing framework for evaluating Model Context Protocol server vulnerabilities
Python ★ 34 5mo agoExplain → -
glato ▣
GitLab Attack TOolkit
Python ★ 34 3mo agoExplain → -
ctf-writeups ▣
Collection of Praetorian solutions to CTF challenges
OpenEdge ABL ★ 25 8y agoExplain → -
Sulla
A command-line tool to mount SMB shares and scan them for secrets using NoseyParker.
Go ★ 23 23d agoExplain → -
reduce-golang-detections-skill
Claude Code skill for systematically reducing VirusTotal/EDR detection rates on compiled Go binaries via PE structural analysis and disciplined A/B testing.
Python ★ 17 1mo agoExplain → -
chariot-launch-nuclei-templates
No description.
★ 13 4y agoExplain → -
bsidesaustin ▣
No description.
Python ★ 13 10y agoExplain → -
burp-wcf-gzip ▣
Burp extension for decoding WCF-gzipped requests.
Python ★ 12 10y agoExplain → -
gcloud-lockdown ▣
Scripts to demonstrate VPC Service Controls between tenant and shared projects
Shell ★ 12 7y agoExplain → -
sonicwall-nsv-decrypter
No description.
C ★ 11 2y agoExplain → -
model-extraction-demo
An application to demonstrate stealing an AI model through knowledge distillation.
Python ★ 10 8mo agoExplain → -
gato ▣
GitHub Actions Pipeline Enumeration and Attack Tool
Python ★ 9 3mo agoExplain → -
simuvex ⑂ ▣
A symbolic execution engine for the VEX IR
Python ★ 9 10y agoExplain → -
highlight ▣
Text file to BMP image with box drawing and blurring from the command line
C ★ 9 10y agoExplain → -
ASVS ⑂ ▣
Application Security Verification Standard
XSLT ★ 6 1y agoExplain → -
log4j-detector ▣
Log4j detector and reporting server for scalable detection of vulnerable running processes.
Go ★ 6 4y agoExplain → -
enumerate-iam ⑂ ▣
Enumerate the permissions associated with AWS credential set
Python ★ 5 6y agoExplain → -
zeroqlik-detect
A Nuclei template to detect ZeroQlik (CVE-2023-41265 and CVE-2023-41266)
★ 5 2y agoExplain → -
0days-in-the-wild ⑂ ▣
Repository for information about 0-days exploited in-the-wild.
★ 5 5y agoExplain → -
rpi-setup ▣
set up rpi for zbwardrive
Python ★ 5 10y agoExplain → -
aws-labs ▣
No description.
Shell ★ 5 6y agoExplain → -
tpm_bound_sa_key ▣
No description.
Go ★ 5 5y agoExplain → -
praetorian-cli
CLI and SDK for interacting with the Praetorian Chariot platform
Python ★ 3 2d agoExplain → -
missing-cve-nuclei-templates ⑂
Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests and vulnerability assessments too.
Shell ★ 3 2y agoExplain → -
product-frontend-interview ▣
No description.
JavaScript ★ 3 5y agoExplain → -
AzureHound
No description.
Go ★ 2 9mo agoExplain → -
ScoutSuite ⑂
Multi-Cloud Security Auditing Tool
★ 2 4y agoExplain → -
azurehound-scenttrail
No description.
Python ★ 2 1y agoExplain → -
bundlerAuditTest ⑂ ▣
A Rails application containing multiple vulnerabilities used for demonstration purposes
Ruby ★ 2 6y agoExplain → -
BloodHound ⑂
Six Degrees of Domain Admin
★ 1 9mo agoExplain → -
AzureHound-OSS ⑂
Azure Data Exporter for BloodHound
★ 1 9mo agoExplain → -
impacket ⑂ ▣
Impacket is a collection of Python classes for working with network protocols.
★ 1 5y agoExplain → -
NPMTest ⑂ ▣
Vulnerabilities discovered in npm repository [Berkeley PL & Security Research].
Java ★ 1 7y agoExplain → -
aws-terraform-iot ⑂ ▣
Use Terraform to scaffold a reference AWS architecture for IoT usage
★ 1 5y agoExplain → -
product-backend-interview
No description.
Java ★ 1 5y agoExplain → -
public-workflows
This repo hosts shared workflows that could be called from other repos (both public or private) of Praetorian
Python ★ 0 15h agoExplain → -
capability-sdk
No description.
Go ★ 0 7d agoExplain → -
external-contrib-action
No description.
TypeScript ★ 0 3mo agoExplain → -
zodiac-z32-cipher-research
documents, scripts, output, and images related to the z32 cipher research
Python ★ 0 1y agoExplain → -
velociraptor ⑂
Digging Deeper....
Go ★ 0 1y agoExplain → -
graph-google-cloud-1 ⑂
A graph conversion tool for https://cloud.google.com/
★ 0 4y agoExplain → -
cartography ⑂
Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database.
★ 0 3y agoExplain → -
graphql ⑂ ▣
An implementation of GraphQL for Go / Golang
Go ★ 0 3y agoExplain → -
doubleqlik-detect
No description.
★ 0 2y agoExplain → -
product-golang-backend-interview
No description.
Go ★ 0 3y agoExplain →
No repos match these filters.