
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Unified task and workflow runner for security assessments, integrating 40+ tools for reconnaissance, vulnerability scanning, fuzzing, secret…


Generate mutations (variations) of a wordlist for password cracking and fuzzing.

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

A Chrome extension that demonstrates bypassing Widevine L3 DRM

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A script used to create a whonix like gateway/workstation environment with docker containers.

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Unified task and workflow runner for security assessments, integrating 40+ tools for reconnaissance, vulnerability scanning, fuzzing, secret…


Generate mutations (variations) of a wordlist for password cracking and fuzzing.

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

A Chrome extension that demonstrates bypassing Widevine L3 DRM

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A script used to create a whonix like gateway/workstation environment with docker containers.

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

Open-source IPAM and DCIM platform providing a centralized source of truth for modeling, documenting, and automating network infrastructure with…

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

safely install npm packages by auditing them pre-install stage

A rewrite of YARA in Rust.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…