
owasp-cstg
Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

An advanced graphical search engine for Exploit-DB

Local file inclusion exploitation tool

Comprehensive offensive security toolkit covering penetration testing, exploitation, and red teaming operations with modular attack workflows.

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Gather and update all available and newest CVEs with their PoC.

AI / LLM Red Team Field Manual & Consultant’s Handbook

A byte code analyzer for finding deserialization gadget chains in Java applications

cve-exploit is a hub for finding CVEs and exploits

a lightweight, flexible and novel open source poc verification framework

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Aggregates CVE details, exploit databases, and EPSS scores with AI risk assessment and vulnerability scanner import for prioritized patching.

application server attack toolkit

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Ethereum recon and exploitation tool.