
nebula
AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.

A collaborative web exploitation framework.

Gather and update all available and newest CVEs with their PoC.


Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Go-based exploit development framework with built-in phases for target verification, version scanning, exploitation, and C2. Supports multiple…

Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver…

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign…

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

Offensive security platform that automates attack surface discovery and vulnerability management

Aggregates CVE details, exploit databases, and EPSS scores with AI risk assessment and vulnerability scanner import for prioritized patching.

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…