
malicious-pdf
Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Vulnerability checker for Callstranger (CVE-2020-12695)

Automating Host Exploitation with AI

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Pillage filesystems for sensitive information with Go 🔍

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

Finding exposed secrets and personal data in GitLab

OSS Vulnerability Scanner for Windows Platform

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…


OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

Scan for open S3 buckets and dump

a Fedora remix focused on pentesting and purple hat tooling