
hexstrike-ai
MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

A collection of awesome penetration testing resources, tools and other shiny things

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)

Intentionally vulnerable open-world MMORPG server for practicing binary exploitation, reverse engineering, network protocol analysis, and web…

Exploit chain for Safari + macOS exploiting JIT type confusion, launchd sandbox escape, and XNU IPC MitM for kernel code execution.

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

An strace-like program for the Windows 'native' API

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

Public repository for improvements to the EXTRABACON exploit

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.

Intentionally vulnerable Android banking app for practicing mobile security testing. Covers OWASP Mobile Top 10 with hardcoded credentials, insecure…

Linux distribution built from source for penetration testing, forensics, and reverse engineering. Provides hundreds of CLI-based security tools for…

MAPS cloud scanner and response parser for Microsoft Defender research.

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Proof-of-concept exploit for CVE-2024-21633 demonstrating remote code execution in MobSF by abusing apktool arbitrary file write to overwrite a…