
lynis
Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Open Source Vulnerability Management Platform

Audits Windows security settings against CIS, Microsoft, STIG, and BSI baselines, scores compliance, and applies hardening changes via registry or…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Authentication, authorization, traceability and auditability for SSH accesses.

Find exploits in local and online databases instantly

Static binary vulnerability scanner using abstract interpretation on Ghidra Pcode. Detects CWE classes like buffer overflows, use-after-free, and…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒


WPScan rewritten in Python + some WPSeku ideas

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Octoscan is a static vulnerability scanner for GitHub action workflows.

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

Static Analyzer for Starknet smart contracts

A wrapper for Nmap to quickly run network scans