-
drozer
The Leading Security Assessment Framework for Android.
Python ★ 4.5k 2mo agoExplain → -
C3
Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.
C++ ★ 1.8k 5mo agoExplain → -
needle ▣
The iOS Security Testing Framework
Python ★ 1.4k 5y agoExplain → -
SharpGPOAbuse
SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
C# ★ 1.3k 5y agoExplain → -
awspx
A graph-based tool for visualizing effective access and resource relationships in AWS environments.
Python ★ 1.0k 3y agoExplain → -
leonidas
Automated Attack Simulation in the Cloud, complete with detection use cases.
Python ★ 617 1y agoExplain → -
dref
DNS Rebinding Exploitation Framework
JavaScript ★ 493 5y agoExplain → -
damn-vulnerable-llm-agent
No description.
Python ★ 476 1y agoExplain → -
android-keystore-audit
No description.
JavaScript ★ 472 11mo agoExplain → -
KernelFuzzer
Cross Platform Kernel Fuzzer Framework
C ★ 456 7y agoExplain → -
physmem2profit
Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely
C# ★ 424 3y agoExplain → -
lolcerts
A repository of code signing certificates known to have been leaked or stolen, then abused by threat actors
YARA ★ 411 2y agoExplain → -
Jandroid
No description.
Python ★ 356 1y agoExplain → -
wePWNise
WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and exploit mitigation software.
Python ★ 350 7y agoExplain → -
captcha22
CAPTCHA22 is a toolset for building, and training, CAPTCHA cracking models using neural networks.
Python ★ 337 4y agoExplain → -
bitlocker-spi-toolkit
Tools for decoding TPM SPI transaction and extracting the BitLocker key from them.
Python ★ 322 4y agoExplain → -
OSXFuzz
macOS Kernel Fuzzer
C ★ 259 8y agoExplain → -
Azurite
Enumeration and reconnaissance activities in the Microsoft Azure Cloud.
PowerShell ★ 255 7y agoExplain → -
Ninjasploit
A meterpreter extension for applying hooks to avoid windows defender memory scans
C ★ 249 5y agoExplain → -
drozer-agent
The Android Agent for the Drozer Security Assessment Framework.
Java ★ 237 2mo agoExplain → -
z3_and_angr_binary_analysis_workshop
Code and exercises for a workshop on z3 and angr
Python ★ 236 5y agoExplain → -
IAMSpy
No description.
Python ★ 232 14d agoExplain → -
spikee
Simple Prompt Injection Kit for Evaluation and Exploitation
Python ★ 206 12d agoExplain → -
SharpClipHistory
SharpClipHistory is a .NET application written in C# that can be used to read the contents of a user's clipboard history in Windows 10 starting from the 1809 Build.
C# ★ 200 6y agoExplain → -
IceKube
No description.
Python ★ 191 26d agoExplain → -
Jamf-Attack-Toolkit
Suite of tools to facilitate attacks against the Jamf macOS management platform.
Python ★ 190 5y agoExplain → -
peas
PEAS is a Python 2 library and command line application for running commands on an ActiveSync server e.g. Microsoft Exchange.
Python ★ 186 3y agoExplain → -
XRulez
A command line tool for creating malicious outlook rules
C ★ 165 7y agoExplain → -
incognito
One Token To Rule Them All https://labs.reversec.com/posts/2012/07/incognito-v20-released
C ★ 161 6y agoExplain → -
drozer-modules
No description.
Python ★ 158 2y agoExplain → -
cloud-security-vm
Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments
HCL ★ 146 1y agoExplain → -
GWTMap
No description.
Python ★ 114 1y agoExplain → -
IAMGraph
No description.
Python ★ 74 3d agoExplain → -
cloud-wiki
A public cloud security knowledgebase - https://www.secwiki.cloud/
CSS ★ 52 1y agoExplain → -
usb-consumer-control
No description.
C ★ 51 2y agoExplain → -
CVE-2021-25374_Samsung-Account-Access
This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung Device, and if the victim's device is from the US or Korea region.
Python ★ 31 2y agoExplain → -
llm-vulnerable-recruitment-app
An example vulnerable app that integrates an LLM
Python ★ 27 2y agoExplain → -
encap-attack
Sniff and attack networks that use IP-in-IP or VXLAN encapsulation protocols.
Python ★ 24 1mo agoExplain → -
weasel ▣
No description.
C ★ 19 12y agoExplain → -
sieve
No description.
Java ★ 18 2y agoExplain → -
design-patterns-for-securing-llm-agents-code-samples
No description.
Python ★ 17 1y agoExplain → -
FixerUpper
A Burp extension to enable modification of FIX messages when relayed from MitM_Relay
Python ★ 16 3y agoExplain → -
TheExtendables
No description.
C++ ★ 10 11mo agoExplain → -
workout-planner
No description.
Python ★ 8 11mo agoExplain → -
azure-iam-enum
No description.
Python ★ 7 3mo agoExplain → -
keywe-tooling
Tools that can be used to interact with the KeyWe Smart Lock device.
Python ★ 7 2mo agoExplain → -
freezer
Rust implementation of IceKube download functionality
Rust ★ 6 28d agoExplain → -
llama-3-prompt-injection-fine-tuning
No description.
Python ★ 6 1y agoExplain → -
slide-decks
No description.
★ 5 2y agoExplain → -
llm-webmail
No description.
Python ★ 4 1mo agoExplain → -
oracrawl
No description.
Python ★ 4 11mo agoExplain → -
2025-07-llm-noise-based-attacks-workspace
No description.
Python ★ 3 11mo agoExplain → -
strifebot
No description.
HCL ★ 3 9mo agoExplain → -
boops-boops-android-agent
No description.
Java ★ 3 4y agoExplain → -
azuredevops-enum
No description.
Python ★ 2 3mo agoExplain → -
megafeis-palm
PoC Code for Vulnerabilities Found in MEGAFEIS-branded Smart Locks & their Mobile Companion App: DBD+
Python ★ 2 3y agoExplain → -
fixit
No description.
Python ★ 2 1y agoExplain → -
boops-boops-docker-container
No description.
Dockerfile ★ 1 4y agoExplain → -
ibm-sterling-b2b-integrator-poc
PoC code for the LPE and RCE (CVE-2024-31903) attacks against the IBM Sterling B2B Integrator
Java ★ 1 1y agoExplain → -
spikee-test-chatbot
A minimal chatbot application designed for testing multi-turn targets in Spikee. This tool provides a simple interface to interact with various LLM providers (OpenAI, Anthropic, Gemini, Bedrock, TogetherAI) to facilitate prompt injection and security testing workflows.
HTML ★ 0 3mo agoExplain → -
vpc-peering-nat-example
No description.
HCL ★ 0 3mo agoExplain → -
prototype-pollution
No description.
JavaScript ★ 0 1y agoExplain → -
azure-service-tag-abuse
Scripts and other content to go with Aled Mehta's talk "Tag You're Exposed" at DEF CON Cloud Village 2023
HCL ★ 0 2y agoExplain → -
Cue-COVID-Test_Research-Files
No description.
JavaScript ★ 0 4y agoExplain →
No repos match these filters.