
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Proper sandboxing for agentic coding and web browsing

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Public disclosure of TitanFTP 19.X Open Redirection vulnerability

Security advisory detailing a critical CVE in Copilot AI where RAG-based citation links are forged to a third-party domain, enabling source…

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Tools and Techniques for Red Team / Penetration Testing

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Grab cam shots & GPS location from target's phone front camera or PC webcam just sending a link.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

This is Advance Phishing Tool ! OTP PHISHING

A list of cyber-chef recipes and curated links

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with…

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names