Skip to content
Change the repository type filter

All

    Repositories list

    • otto-support

      Public
      An implementation of a vulnerable MCP server using mcp-go
      Go
      GNU General Public License v3.0
      0000Updated Apr 21, 2026Apr 21, 2026
    • cloudfox

      Public
      Automating situational awareness for cloud penetration tests.
      Go
      MIT License
      2272.3k61Updated Apr 21, 2026Apr 21, 2026
    • sliver

      Public
      Adversary Emulation Framework
      Go
      GNU General Public License v3.0
      1.5k11k1986Updated Apr 19, 2026Apr 19, 2026
    • cirro

      Public
      Creating attacks paths across management and data planes
      Rust
      GNU General Public License v3.0
      14410Updated Apr 13, 2026Apr 13, 2026
    • install-aws-cli-action

      Public
      Install AWS CLI on a GitHub Actions Linux host
      Shell
      MIT License
      39200Updated Apr 13, 2026Apr 13, 2026
    • cirro-azcli-ext

      Public
      Azure CLI extension for Cirro collection
      Python
      Apache License 2.0
      1600Updated Apr 10, 2026Apr 10, 2026
    • aws-signing

      Public
      CLI that allows user to submit http requests using AWS request signing
      Go
      MIT License
      7600Updated Apr 10, 2026Apr 10, 2026
    • cirrodash

      Public
      Dashboard for Cirro
      TypeScript
      GNU General Public License v3.0
      11100Updated Apr 7, 2026Apr 7, 2026
    • CVE-2026-35616-check

      Public
      Python
      MIT License
      0100Updated Apr 6, 2026Apr 6, 2026
    • CVE-2026-25075-check

      Public
      Python
      MIT License
      0200Updated Mar 26, 2026Mar 26, 2026
    • sj

      Public
      A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
      Go
      MIT License
      11084130Updated Mar 24, 2026Mar 24, 2026
    • iam-vulnerable

      Public
      Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
      HCL
      MIT License
      10456300Updated Mar 12, 2026Mar 12, 2026
    • eyeballer

      Public
      Convolutional neural network for analyzing pentest screenshots
      Python
      GNU General Public License v3.0
      1461.3k63Updated Mar 8, 2026Mar 8, 2026
    • cloudfoxable

      Public
      Create your own vulnerable by design AWS penetration testing playground
      Python
      MIT License
      5144110Updated Feb 16, 2026Feb 16, 2026
    • sliver-wasm-stager

      Public archive
      A stager and implant that executes remote Web Assembly
      Rust
      GNU General Public License v3.0
      106400Updated Feb 4, 2026Feb 4, 2026
    • badPods

      Public
      A collection of manifests that will create pods with elevated privileges.
      Shell
      MIT License
      11969300Updated Dec 30, 2025Dec 30, 2025
    • awsservicemap

      Public
      Go module that returns supported regions for a service or supported services for a region
      Go
      MIT License
      61800Updated Dec 12, 2025Dec 12, 2025
    • Safely test Arista NGFW for information disclosure
      Python
      MIT License
      0300Updated Dec 4, 2025Dec 4, 2025
    • Python
      MIT License
      0500Updated Dec 3, 2025Dec 3, 2025
    • shining-mask

      Public
      Python
      01200Updated Oct 30, 2025Oct 30, 2025
    • raink

      Public
      Use LLMs for document ranking
      Go
      MIT License
      616910Updated Apr 17, 2025Apr 17, 2025
    • sonicrack

      Public
      Decrypt encrypted SonicOSX firmware images
      Python
      GNU General Public License v3.0
      31900Updated Feb 24, 2025Feb 24, 2025
    • BrokenHill

      Public
      A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)
      Python
      MIT License
      2315911Updated Dec 18, 2024Dec 18, 2024
    • local-llm-ctf

      Public
      A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow
      Go
      MIT License
      01700Updated Sep 10, 2024Sep 10, 2024
    • Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
      Python
      GNU General Public License v3.0
      1710831Updated Jul 5, 2024Jul 5, 2024
    • jsluice

      Public
      Extract URLs, paths, secrets, and other interesting bits from JavaScript
      Go
      MIT License
      1371.8k72Updated May 22, 2024May 22, 2024
    • gcp-terraform-cloud-connector

      Public
      This repo provides a terraform module for customers looking to implement Google Cloud connector support for Bishop Fox Cosmos
      HCL
      Apache License 2.0
      0100Updated May 20, 2024May 20, 2024
    • CVE-2023-27997-check

      Public
      Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
      Python
      GNU General Public License v3.0
      2413500Updated May 8, 2024May 8, 2024
    • Never ever ever use pixelation as a redaction technique
      TypeScript
      GNU General Public License v3.0
      8008.3k2213Updated Mar 15, 2024Mar 15, 2024
    • GitGot

      Public
      Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.
      Python
      GNU Lesser General Public License v3.0
      2171.6k30Updated Mar 7, 2024Mar 7, 2024
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.