Skip to content
Change the repository type filter

All

    Repositories list

    • cloudfox

      Public
      Automating situational awareness for cloud penetration tests.
      Go
      MIT License
      2222.3k81Updated Mar 2, 2026Mar 2, 2026
    • sliver

      Public
      Adversary Emulation Framework
      Go
      GNU General Public License v3.0
      1.5k11k2055Updated Mar 2, 2026Mar 2, 2026
    • sj

      Public
      A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
      Go
      MIT License
      9872130Updated Feb 28, 2026Feb 28, 2026
    • Create your own vulnerable by design AWS penetration testing playground
      Python
      MIT License
      5143710Updated Feb 16, 2026Feb 16, 2026
    • sliver-wasm-stager

      Public archive
      A stager and implant that executes remote Web Assembly
      Rust
      GNU General Public License v3.0
      73700Updated Feb 4, 2026Feb 4, 2026
    • badPods

      Public
      A collection of manifests that will create pods with elevated privileges.
      Shell
      MIT License
      11868700Updated Dec 30, 2025Dec 30, 2025
    • Go module that returns supported regions for a service or supported services for a region
      Go
      MIT License
      71800Updated Dec 12, 2025Dec 12, 2025
    • Safely test Arista NGFW for information disclosure
      Python
      MIT License
      0300Updated Dec 4, 2025Dec 4, 2025
    • fortiweb-auth-bypass-check

      Public
      Python
      MIT License
      0400Updated Dec 3, 2025Dec 3, 2025
    • shining-mask

      Public
      Python
      01200Updated Oct 30, 2025Oct 30, 2025
    • Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
      HCL
      MIT License
      10155000Updated Sep 11, 2025Sep 11, 2025
    • raink

      Public
      Use LLMs for document ranking
      Go
      MIT License
      516410Updated Apr 17, 2025Apr 17, 2025
    • sonicrack

      Public
      Decrypt encrypted SonicOSX firmware images
      Python
      GNU General Public License v3.0
      32000Updated Feb 24, 2025Feb 24, 2025
    • A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)
      Python
      MIT License
      2415711Updated Dec 18, 2024Dec 18, 2024
    • local-llm-ctf

      Public
      A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow
      Go
      MIT License
      11600Updated Sep 10, 2024Sep 10, 2024
    • Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
      Python
      GNU General Public License v3.0
      1810631Updated Jul 5, 2024Jul 5, 2024
    • jsluice

      Public
      Extract URLs, paths, secrets, and other interesting bits from JavaScript
      Go
      MIT License
      1361.8k72Updated May 22, 2024May 22, 2024
    • This repo provides a terraform module for customers looking to implement Google Cloud connector support for Bishop Fox Cosmos
      HCL
      Apache License 2.0
      1100Updated May 20, 2024May 20, 2024
    • CVE-2023-27997-check

      Public
      Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
      Python
      GNU General Public License v3.0
      2513400Updated May 8, 2024May 8, 2024
    • unredacter

      Public
      Never ever ever use pixelation as a redaction technique
      TypeScript
      GNU General Public License v3.0
      8008.3k2213Updated Mar 15, 2024Mar 15, 2024
    • CLI that allows user to submit http requests using AWS request signing
      Go
      MIT License
      8600Updated Mar 14, 2024Mar 14, 2024
    • GitGot

      Public
      Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.
      Python
      GNU Lesser General Public License v3.0
      2171.5k30Updated Mar 7, 2024Mar 7, 2024
    • eyeballer

      Public
      Convolutional neural network for analyzing pentest screenshots
      Python
      GNU General Public License v3.0
      1481.3k63Updated Feb 19, 2024Feb 19, 2024
    • LLM Testing Findings Templates
      HTML
      MIT License
      177500Updated Feb 14, 2024Feb 14, 2024
    • A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
      Java
      MIT License
      1.9k3400Updated Feb 9, 2024Feb 9, 2024
    • Python
      GNU General Public License v3.0
      51900Updated Jan 12, 2024Jan 12, 2024
    • Determine the running software version of a remote F5 BIG-IP management interface.
      Python
      MIT License
      216902Updated Jan 3, 2024Jan 3, 2024
    • knownawsaccountslookup

      Public
      Go module that provides two lookup functions for the data in https://github.com/fwdcloudsec/known_aws_accounts
      Go
      MIT License
      0400Updated Dec 28, 2023Dec 28, 2023
    • An intentionally-vulnerable GWT-based web application to test tooling and techniques
      Java
      0500Updated Dec 18, 2023Dec 18, 2023
    • Kafka Connect Store Partitioner by custom fields and time; also removing topic from s3 file path
      Java
      Apache License 2.0
      31300Updated Sep 18, 2023Sep 18, 2023