Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Offensive Security GitHub Repositories
Explore popular GitHub repositories tagged “offensive-security”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
Bjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.
autonomous red teaming platform; multi-agent offensive-security meta-harness
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Red Teaming Tactics and Techniques
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
Applied offensive security with Rust - https://kerkour.com/black-hat-rust
:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report
A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
A high performance offensive security tool for reconnaissance and vulnerability scanning
OSWE, OSEP, OSED, OSEE
OSCP Cheat Sheet
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
A curated list of awesome OSCP resources
Automated NoSQL database enumeration and web application exploitation tool.
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools.
A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
:new: The Multi-Tool Web Vulnerability Scanner.
Repository for advanced Red Team techniques focused on Rust
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.
:no_entry: offsec batteries included