Hunt down social media accounts by username across social networks
Infosec GitHub Repositories
Explore popular GitHub repositories tagged “infosec”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Fast web fuzzer written in Go
Web path scanner
Damn Vulnerable Web Application (DVWA)
Exploitation Framework for Embedded Devices
An HTTP toolkit for security research.
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
Gather and update all available and newest CVEs with their PoC.
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
All about bug bounty (bypasses, payloads, and etc)
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
Open Source Vulnerability Management Platform
A curated list of GPT agents for cybersecurity
A list of interesting payloads, tips and tricks for bug bounty hunters.
A collection of awesome security hardening guides, tools and other resources
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
The Network Execution Tool
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
A curated list of awesome infosec courses and training resources.
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
Cameradar hacks its way into RTSP videosurveillance cameras