
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling


Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Open-source adversary emulation for AI agents and MCP servers.

Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Improved DOS exploit for wordpress websites (CVE-2018-6389)

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

POC for Veeam Backup and Replication CVE-2023-27532

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.


CyberArk Security Audit

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具