
sublime-rules
Sublime rules for email attack detection, prevention, and threat hunting.

Sublime rules for email attack detection, prevention, and threat hunting.

Proper sandboxing for agentic coding and web browsing

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

The Browser Exploitation Framework Project

Advanced Phishing Protection: Suricata rulesets open and free

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

Red team framework and multi-operator C2 platform with AI agents, malleable implants, rootkits, phishing engine, and 741 CLI commands covering the…

Spam filtering and email processing framework with regex rules, statistical analysis, custom Lua plugins, and external blocklists for MTA integration.

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Open .eml test set for evaluating how email security controls and AI mailbox assistants handle indirect prompt injection across disclosure,…

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with…

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Browser extension that warns users about recently registered domains to prevent phishing attacks. Queries RDAP to check domain age and displays…

Hunt down social media accounts by username across social networks

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Go toolkit for authorized Azure security assessments: enumerates subscriptions and resources, audits misconfigurations, and attacks public Blob…