
akca
Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

0-day malware detection for binaries, source & scripts (that doesn't suck)

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Fix-Like Artifacts With Embedded Defects

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Read-only Python checker that validates CVE-2026-20079 Cisco FMC authentication-bypass behavior by comparing unauthenticated and csm_processes…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Docker lab reproducing CVE-2026-42533, a pre-auth nginx heap overflow and info leak via two-pass capture clobbering, with PoC scripts and patched…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

Fast and easy-to-use directory brute-forcer written in Go.

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

A passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.