Showing 33 of 69 projects
A vulnerable Android CTF application demonstrating real-world security vulnerabilities and exploitation techniques.
A curated collection of resources for security research, vulnerability discovery, and pentesting of Electron.js applications.
A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.
A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.
A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.
A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.
A CLI tool to export OWASP Juice Shop security challenges into CTFd, RootTheBox, or FBCTF compatible formats.
A bug hunting tool that scans websites for exposed .git repositories and dumps their contents for security analysis.
A Python toolkit for security Capture The Flag (CTF) challenges, providing utilities for crypto, shellcodes, and network connections.
An automated security testing toolkit for GraphQL endpoints that discovers, analyzes, and scores vulnerabilities.
A collection of French and English wordlists specifically curated for cracking French passwords.
A web interface for Hashcat that enables distributed password cracking sessions across multiple servers with real-time results.
Visualizes AWS IAM and Organizations as a graph using Neo4j to identify security anomalies and privilege escalation paths.
A terminal-based manager for handling multiple reverse shell sessions and clients during penetration testing.
An open-source Java proxy for penetration testing, enabling traffic analysis and modification of TCP/UDP application protocols.
A minimal command-line utility for connecting to and exploiting exposed CEF/Electron debuggers during security assessments.
A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.
A Python script that generates graphs and charts from password cracking results (hashcat/john potfiles) for security analysis.
A pentest tool that checks Cloudflare-protected sites for origin IP leaks and misconfigurations.
A fast GraphQL discovery and fingerprinting toolbox for security testing and reconnaissance.
A Python script that implements security testing attacks against AWS Cognito, including account oracle and privilege escalation.
An automated IAST fuzzer for discovering vulnerabilities in CakePHP web applications with minimal false positives.
A standardized methodology for performing security assessments in robotics across physical, network, firmware, and application layers.
A Python-based honeypot suite for SSH, FTP, and Telnet that captures credentials to build attack dictionaries.
A modular, script-friendly multithreaded bruteforce framework for penetration testing and security auditing.
A Rust command-line tool to find social media accounts by username across 400+ networks.
A collection of optimized hashcat masks, rules, and PowerShell scripts for efficient password cracking.
A comprehensive mobile security framework for device exploitation, bootloader unlocking, firmware analysis, and cellular security research across 18 manufacturers.
A collection of Capture The Flag (CTF) competition challenge write-ups from the SababaSec cybersecurity team.
A CLI tool to quickly look up hash plaintexts using the HashMob API directly from your terminal.
Generates wordlists of Danish phone numbers filtered by area code and line type for security testing.
A Zsh-based pentesting framework with shell integrations for workflow automation, featuring 50+ modules and 500+ commands.
Integrates Bright's DAST security scan engine directly into .NET unit tests to find vulnerabilities early.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.