
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

AI red-team platform. Autonomous LLM agents run a penetration test end to end inside a Kali container and write the report. LangGraph plan/act…

AI-Powered Reverse Engineering Plugin for IDA Pro

Tool for advanced mining for content on Github

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Main repo for hosting release binaries

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Python script to scan Git repos for interesting strings

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

OWASP Foundation Web Respository

A wrapper around grep, to help you grep for things

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Tool to search secrets in various filetypes.

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…