Stars
Swiss army knife Webserver in Golang. Keep simple like the python SimpleHTTPServer but with many features
A Frida powered testing library designed to assist with security assesments of iOS applications written in Swift 5.
A Blazing fast Security Auditing tool for Kubernetes
Scanning APK file for URIs, endpoints & secrets.
Bandit is a tool designed to find common security issues in Python code.
Superion is a fuzzer which extends the famous AFL to support structured inputs such as JavaScript and XML.
The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
Adversary tradecraft detection, protection, and hunting
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
🔪
Leak git repositories from misconfigured websites
A repository with 3 tools for pwn'ing websites with .git repositories available
A tool designed to make physical devices detectable by malware and make system look like virtual machine.
Public scripts and examples for managing JumpCloud managed systems and service endpoints
Combination of multiple linters to run as a GitHub Action or standalone
A comprehensive binary emulation and instrumentation platform.
A vulnerable version of Rails that follows the OWASP Top 10
Kubectl plugin to interactively proxy Kubernetes Services with ease
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
Empire is a PowerShell and Python post-exploitation agent.
Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
A list of Reverse Engineering articles, books, and papers


