
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A script used to create a whonix like gateway/workstation environment with docker containers.

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

A static + runtime security scanner for MCP (Model Context Protocol) servers

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A script used to create a whonix like gateway/workstation environment with docker containers.

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…



Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

A static + runtime security scanner for MCP (Model Context Protocol) servers

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

Obfuscation module for Cobalt Strike Beacon sleep states, enabling evasion of memory-based detection and endpoint security controls.

A rootless Android app that boots Alpine Linux: run containers (Podman/Docker/LXC) and GUI desktop apps.

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

Offensive security platform that automates attack surface discovery and vulnerability management

Comprehensive offensive security toolkit covering penetration testing, exploitation, and red teaming operations with modular attack workflows.

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them

Tool for testing and auditing Bluetooth device pairing security, identifying vulnerabilities in wireless pairing protocols and hardware IoT…

PHP Static Analysis Tool - discover bugs in your code without running it!