Open-source repositories gaining traction right now.
17 repositories
#cybersecurity
Hunt down social media accounts by username across social networks

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

🕵️♂️ Collect a dossier on a person by username from 3000+ sites

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Useful tool to track location or mobile number

Star OpenCTI-Platform / opencti Open Cyber Threat Intelligence Platform

Star kaifcodec / user-scanner 🕵️ (2-in-1) Emaill and Username OSINT tool that analyzes username and email presence across multiple platforms, intended for security research, investigations, legitimate analysis

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

Star thalesgroup-cert / Watcher Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native fingerprintx/naabu pipeline integration.

Secure Wireless Data-Transfer over BLE and USB for Passwords, Pentesting and Media Control.

Full-stack LinkedIn OSINT toolkit. Four-phase funnel: discover companies by region, batch scrape employees, classify roles by hierarchy/department, and deep dive into profiles. Interactive D3.js org chart viewer, Groq AI enhancement, anti-detection stealth, proxy support, and graceful partial-save on interruption.

A high-fidelity, educational cybersecurity sandbox for simulating ransomware attacks and deploying multi-layered Défense mechanisms in a safe, controlled environment.

QuestExploit 是一款基于 Go 语言开发的自动化安全测试工具。它针对 QuestDB 数据库的身份验证机制进行深度探测,能够自动验证多种绕过手段,并演示在成功绕过身份验证后,攻击者可能执行的恶意操作(如数据窃取、表删除、任意文件写入等)。 本项目是 QuestDB 身份验证绕过漏洞利用工具 的详细文档。该工具专门用于演示和测试 QuestDB 在特定配置下存在的安全风险,帮助安全研究人员理解身份验证绕过机制及其潜在后果。

The server codebase for our deep fake extension.
Paste a github.com URL. Submissions are reviewed before they are tracked.