

A Chrome extension that demonstrates bypassing Widevine L3 DRM

A script used to create a whonix like gateway/workstation environment with docker containers.


Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…


A Chrome extension that demonstrates bypassing Widevine L3 DRM

A script used to create a whonix like gateway/workstation environment with docker containers.


Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…


Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A utility to detect various technology for a given IP address.

A modern git based age-encrypted secrets manager for teams.

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Curated archive of public exploits, shellcode, and papers with SearchSploit CLI for offline searching, CVE lookup, and Nmap integration.…

Automatic SSTI detection tool with interactive interface