
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Main repo for hosting release binaries

AI-Powered Reverse Engineering Plugin for IDA Pro

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Tool for advanced mining for content on Github

Binary Ninja plugin to analyze and simplify obfuscated code

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

a static analysis tool for finding vulnerabilities in C/C++ source code

Python script to scan Git repos for interesting strings

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.