Open-source repositories gaining traction right now.
42 repositories

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

ALL IN ONE Hacking Tool For Hackers

Hunt down social media accounts by username across social networks

Fast and accurate AI powered file content types detection

holehe allows you to check if the mail is used on different sites like twitter, instagram and will retrieve information on sites with the forgotten password function.

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.

The authentication glue you need.

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Common User Passwords Profiler (CUPP)

Open-source intelligence for the global theater. Track everything from the corporate/private jets of the wealthy, and spy satellites, to seismic events in one unified interface. Hook an AI agent up to have it parse through data and find previously unseen correlations. The knowledge is available to all but rarely aggregated in the open, until now.

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

🛜 ESPectre 👻 - Motion detection system based on Wi-Fi spectre analysis (CSI), with Home Assistant integration.

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

Star 0x4m4 / hexstrike-ai HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

Star kaifcodec / user-scanner 🕵️ (2-in-1) Emaill and Username OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investigations, legitimate analysis

Useful tool to track location or mobile number

Star GH05TCREW / pentestagent PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

Security Scanner for Agent Skills

DPI detection tool for internet censorship testing. Identifies TLS, TCP, HTTP blocking and 16-20KB connection drops


Bluetooth Low Energy (BLE) scanner with Resolvable Private Address (RPA) resolution using Identity Resolving Keys (IRKs)

Active Directory information dumper via ADWS for evasion purposes

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier



ByPassTamperPlus / SQLMap加强绕WAF / Code By:Tas9er

A Bloodhound alternative. BloodBash will ingest the same files bloodhound does but no server is required to use this tool. It's great for quick AD enumeration.

300 lines eBPF tool that shows which pods are reading your K8s secrets and how often.

基于 PyQt5 的 Nuclei 漏洞扫描图形化工具,支持 POC 管理、FOFA/Hunter/Shodan 资产搜索、AI 辅助分析、漏洞报告生成等功能

Suite de auditoría de red automatizada. Detecta dispositivos, identifica fabricantes y busca vulnerabilidades (CVEs). Incluye versiones optimizadas para PC (Multi-hilo), Raspberry Pi Zero 2W (Low Power) y scripts Legacy en Bash. Genera reportes con integración a Telegram.


Check the CVE,CCE,CWE vulnerabilities with AI Analyzer.

A high-fidelity, educational cybersecurity sandbox for simulating ransomware attacks and deploying multi-layered Défense mechanisms in a safe, controlled environment.

Implementation of Zero Trust Network Access using Keycloak, WireGuard and Flask.

Per-application VPN split tunneling for Windows. Route specific apps outside or inside your VPN at the packet level.

a small discord token grabber made for education purpose only

Obfuscation ToolV2

一款基于格密码的抗量子数字资产保护系统


Sistema de login desenvolvido em Python, simulando o acesso a um banco governamental com controle de segurança por limite de 3 tentativas de senha.

Paste a github.com URL. Submissions are reviewed before they are tracked.