Skip to content
Change the repository type filter

All

    Repositories list

    • sj

      Public
      A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
      Go
      9771240Updated Nov 25, 2025Nov 25, 2025
    • sliver

      Public
      Adversary Emulation Framework
      Go
      1.4k10k24316Updated Nov 24, 2025Nov 24, 2025
    • fortiweb-auth-bypass-check

      Public
      Python
      0200Updated Nov 20, 2025Nov 20, 2025
    • cloudfox

      Public
      Automating situational awareness for cloud penetration tests.
      Go
      2122.3k91Updated Nov 12, 2025Nov 12, 2025
    • shining-mask

      Public
      Python
      0800Updated Oct 30, 2025Oct 30, 2025
    • iam-vulnerable

      Public
      Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
      HCL
      9352300Updated Sep 11, 2025Sep 11, 2025
    • cloudfoxable

      Public
      Create your own vulnerable by design AWS penetration testing playground
      Python
      4540600Updated Aug 26, 2025Aug 26, 2025
    • raink

      Public
      Use LLMs for document ranking
      Go
      415910Updated Apr 17, 2025Apr 17, 2025
    • sonicrack

      Public
      Decrypt encrypted SonicOSX firmware images
      Python
      31900Updated Feb 24, 2025Feb 24, 2025
    • A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)
      Python
      2415011Updated Dec 18, 2024Dec 18, 2024
    • A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow
      Go
      11300Updated Sep 10, 2024Sep 10, 2024
    • cve-2024-21762-check

      Public
      Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
      Python
      1710631Updated Jul 5, 2024Jul 5, 2024
    • Go module that returns supported regions for a service or supported services for a region
      Go
      61701Updated Jun 4, 2024Jun 4, 2024
    • jsluice

      Public
      Extract URLs, paths, secrets, and other interesting bits from JavaScript
      Go
      1281.7k71Updated May 22, 2024May 22, 2024
    • gcp-terraform-cloud-connector

      Public
      This repo provides a terraform module for customers looking to implement Google Cloud connector support for Bishop Fox Cosmos
      HCL
      1100Updated May 20, 2024May 20, 2024
    • CVE-2023-27997-check

      Public
      Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
      Python
      2613400Updated May 8, 2024May 8, 2024
    • Never ever ever use pixelation as a redaction technique
      TypeScript
      8028.2k2213Updated Mar 15, 2024Mar 15, 2024
    • aws-signing

      Public
      CLI that allows user to submit http requests using AWS request signing
      Go
      8600Updated Mar 14, 2024Mar 14, 2024
    • GitGot

      Public
      Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.
      Python
      2181.5k30Updated Mar 7, 2024Mar 7, 2024
    • eyeballer

      Public
      Convolutional neural network for analyzing pentest screenshots
      Python
      1461.3k63Updated Feb 19, 2024Feb 19, 2024
    • llm-testing-findings

      Public
      LLM Testing Findings Templates
      HTML
      167500Updated Feb 14, 2024Feb 14, 2024
    • ysoserial-bf

      Public
      A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
      Java
      1.8k3100Updated Feb 9, 2024Feb 9, 2024
    • CVE-2022-22274_CVE-2023-0656

      Public
      Python
      52000Updated Jan 12, 2024Jan 12, 2024
    • Determine the running software version of a remote F5 BIG-IP management interface.
      Python
      226902Updated Jan 3, 2024Jan 3, 2024
    • knownawsaccountslookup

      Public
      Go module that provides two lookup functions for the data in https://github.com/fwdcloudsec/known_aws_accounts
      Go
      0400Updated Dec 28, 2023Dec 28, 2023
    • VulnerableGWTApp

      Public
      An intentionally-vulnerable GWT-based web application to test tooling and techniques
      Java
      0400Updated Dec 18, 2023Dec 18, 2023
    • Kafka Connect Store Partitioner by custom fields and time; also removing topic from s3 file path
      Java
      31300Updated Sep 18, 2023Sep 18, 2023
    • 📦 :octocat: GitHub Action for creating GitHub Releases
      TypeScript
      564100Updated Aug 24, 2023Aug 24, 2023
    • RCE exploit for CVE-2023-3519
      Python
      4323040Updated Aug 23, 2023Aug 23, 2023
    • mellon

      Public
      OSDP attack tool (and the Elvish word for friend)
      HTML
      810710Updated Aug 15, 2023Aug 15, 2023