
owasp-cstg
Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

An advanced graphical search engine for Exploit-DB

Local file inclusion exploitation tool

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

Comprehensive offensive security toolkit covering penetration testing, exploitation, and red teaming operations with modular attack workflows.

Gather and update all available and newest CVEs with their PoC.

AI / LLM Red Team Field Manual & Consultant’s Handbook

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

A byte code analyzer for finding deserialization gadget chains in Java applications

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

a lightweight, flexible and novel open source poc verification framework

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

A Modular Penetration Testing Framework

cs扫描ms17-010的一个插件

Aggregates CVE details, exploit databases, and EPSS scores with AI risk assessment and vulnerability scanner import for prioritized patching.

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

application server attack toolkit

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more