
w3af
Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Deep learning framework for object detection, segmentation, classification, pose estimation, and tracking using pre-trained YOLO models and…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Open-source web application security scanner that identifies and exploits 200+ vulnerabilities including XSS, SQL injection, and OS commanding.…

Deep learning framework for object detection, segmentation, classification, pose estimation, and tracking using pre-trained YOLO models and…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…


Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Security training for the apps you actually ship. Open your browser and start hacking.

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

Hashtopolis - distributed password cracking with Hashcat

An AWS tool to help you create a point in time assessment of your AWS account using Prowler.

No-root network monitor, firewall and PCAP dumper for Android

CLI and Go framework for end-to-end testing of threat detection rules. Detonates attack techniques and verifies alerts in security platforms like…

Hunt down social media accounts by username across social networks

A suite of WiFi/Bluetooth offensive and defensive tools for the ESP32

AI red-team platform. Autonomous LLM agents run a penetration test end to end inside a Kali container and write the report. LangGraph plan/act…

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…