
NeuroSploit
AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Automated reconnaissance tool that performs subdomain enumeration, vulnerability scanning, OSINT, port scanning, and web analysis to map attack…

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Manual black-box penetration test of hosting provider infrastructure using curl_cffi and Python. Identifies exposed databases, default credentials,…

Agent dispatcher that launches security tools and sends structured results to the Faraday platform. Supports custom executors and integrates with…

Enumerates valid Microsoft 365 users via OneDrive URL status codes (403 vs 404). Supports threaded wordlists, username mutation, tenant lookup, and…

Customizable password spraying tool for Microsoft accounts (Office 365/Azure AD) with execution plans, Smart Lockout bypass, and audit mode for…

Terraform-based Azure security lab generator for purple teaming, creating customizable environments with Active Directory, Sentinel, managed…

SSRF (Server Side Request Forgery) testing resources

Username enumeration and password spraying tool aimed at Microsoft O365.

The Swiss Army Container for Cloud Native Security. Container with all the list of useful tools/commands while hacking and securing Containers,…

A fast enumeration tool for publicly exposed Azure Storage blobs.

My cheatsheet notes to pentest AWS infrastructure