Showing 36 of 41 projects
An open-source penetration testing framework for developing and executing exploit code against remote targets.
An open-source penetration testing framework for developing and executing exploit code against remote targets.
A CLI and library for evaluating, red-teaming, and comparing LLM prompts, agents, and RAGs with simple declarative configs.
A Windows security tool for extracting credentials, hashes, and Kerberos tickets from memory and performing various post-exploitation techniques.
A portable, extensible framework for network reconnaissance and MITM attacks on WiFi, BLE, HID, CAN-bus, IPv4, and IPv6 networks.
A PowerShell post-exploitation framework for penetration testers, providing modules for code execution, persistence, reconnaissance, and credential theft.
A penetration testing framework that exploits web browsers as beachheads for client-side attacks.
A PowerShell framework for offensive security, penetration testing, and red teaming with scripts for all phases.
A command-line tool for red-teaming and vulnerability scanning of large language models (LLMs).
A post-exploitation framework with PowerShell and Python agents for cryptographically secure communications and flexible modules.
An automated cyber security platform for adversary emulation, red teaming, and incident response built on the MITRE ATT&CK framework.
An open-source adversary emulation platform that simulates malware attacks to test and improve network security defenses.
A highly customizable USB attack platform for penetration testing, based on a Raspberry Pi Zero.
An OSINT tool that uses facial recognition to correlate social media profiles across multiple platforms for security professionals.
A DNS-based encrypted command-and-control (C&C) tunnel for secure communication and data exfiltration.
A weaponized PHP web shell for post-exploitation with over 30 modules for remote administration, auditing, and network pivoting.
A PowerShell toolkit for attacking, auditing, and securing Microsoft SQL Server environments during penetration tests.
A stealthy command and control framework that persists on webservers via a polymorphic PHP one-liner backdoor.
A modern, asynchronous, multiplayer command and control (C2) framework for post-exploitation using Python and .NET's DLR.
A deprecated collection of PowerShell tools for offensive security operations and penetration testing.
A collection of notes, scripts, and techniques for exploiting vulnerabilities and attacking Jenkins servers.
A Python RDP man-in-the-middle tool and library for intercepting, monitoring, and analyzing Remote Desktop Protocol connections.
A PowerShell runspace post-exploitation toolkit written in C# that bypasses security mitigations and includes offensive modules.
A reflective PE packer for in-memory execution of Windows executables to bypass security products.
A modular Linux persistence framework for security research, detection engineering, and penetration testing.
Framework for creating environmental keyed payloads that only execute on specific target systems.
A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.
A fast scanning and attack toolkit for identifying and exploiting GitHub Actions vulnerabilities at scale.
A curated list of resources for understanding, detecting, and mitigating prompt injection attacks against machine learning models.
A tool for extracting secrets from CI/CD environments by deploying malicious pipelines, supporting Azure DevOps, GitHub, and GitLab.
A modular attack toolkit for Azure DevOps Services that leverages the REST API for reconnaissance, privilege escalation, and persistence.
A curated list of tools and resources for understanding, detecting, and removing malware persistence techniques across operating systems.
A framework for automating offensive security testing by scripting security tool APIs like Empire and Metasploit.
A penetration testing tool that bypasses wired 802.1x network protection to gain access to target networks.
A command-line tool for macOS persistence mechanism emulation, designed for threat hunters and security testing.
A command-line tool for macOS persistence mechanism emulation and testing, designed for threat hunters.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.