
garak
Modular LLM vulnerability scanner that probes for hallucination, data leakage, prompt injection, jailbreaks, and toxicity using static, dynamic, and…

Modular LLM vulnerability scanner that probes for hallucination, data leakage, prompt injection, jailbreaks, and toxicity using static, dynamic, and…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Modular LLM vulnerability scanner that probes for hallucination, data leakage, prompt injection, jailbreaks, and toxicity using static, dynamic, and…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.


Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Wide-spectrum content blocker for browsers that blocks ads, trackers, coin miners, and malicious sites using filter lists and customizable privacy…

One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.

Incident Response Documentation Platform

Some bugs found via binary instrumentation and fuzzing

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Crypto bounties, puzzles and challenges data library

Autonomous AI-driven red team agent that executes realistic attack chains—reconnaissance, exploitation, privilege escalation, lateral movement, and…

Secure agents in seconds with permissions enforced at runtime.

ZX-DDoS is a Distributed Denial of Service (DDoS) tool, written in Python, to help understand the mechanics of network stress testing and security…

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

Trap AI web scrapers in an endless poison pit.