
SecLists
Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

AI-powered skill router pack for reverse engineering, penetration testing, and security research. Routes AI agents to correct methodologies and…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

AI agent framework for black-box security testing with autonomous multi-agent orchestration, built-in pentesting tools, and MCP integration for bug…

Multi-threaded network reconnaissance tool that automates service enumeration, port scanning, and information gathering for penetration testing and…

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Penetration Testing and Hacking CTF's Swiss Army Knife with: Reverse Shell Handling - Encoding/Decoding - Encryption/Decryption - Cracking Hashes /…

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

Personal collection of exploits including n-days, 0-days, CTFs, kernel and browser vulnerabilities for security research and penetration testing.

Writeup of the Hackthebox Helix machine, detailing exploitation of CVE-2023-34468 and penetration testing steps.

AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration…

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

Proof-of-concept exploit for CVE-2025-55182, demonstrating vulnerability exploitation techniques for educational and penetration testing purposes.

Proof-of-concept exploit for CVE-2022-44268 enabling arbitrary file read via crafted PNG images processed by ImageMagick. Includes generation and…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…