Showing 36 of 138 projects
A free and open-source Ruby toolkit for security research and development, featuring CLI commands and libraries for encoding, networking, exploits, and more.
A vulnerable Android app aggregating known security vulnerabilities for testing and educational purposes.
A collection of CAPTCHA-breaking implementations using OpenCV, Tesseract OCR, and machine learning algorithms.
A Python tool to analyze, explore, and revive malicious HTTP traffic from PCAP files for security research.
A curated database of Universal Cross-Site Scripting (UXSS) vulnerabilities and browser security research resources.
A centralized repository summarizing practical and proposed defenses against prompt injection attacks on large language models.
A curated collection of Event ID resources for digital forensics and incident response professionals.
A WinDBG extension for viewing and analyzing Windows kernel anomalies to detect rootkits and system modifications.
An optimized hashcat rule set for password cracking with reduced rule count and zero performance loss against major breach datasets.
A hardware-assisted feedback fuzzing framework for discovering vulnerabilities in x86-64 OS kernels.
A collection of password cracking rules and masks for hashcat, generated from analysis of real breached password data.
A collection of public exploits targeting malware infrastructure for security research and analysis.
A collection of CTF challenge write-ups that demonstrate solutions using the pwntools exploit development library.
A curated list of resources for understanding, detecting, and mitigating prompt injection attacks against machine learning models.
A tool for real-time SSL/TLS key extraction and traffic decryption to simplify encrypted network analysis for security researchers.
A Python wrapper for Intel Pin that uses instruction counting side-channel analysis to solve reverse engineering CTF challenges.
A collection of useful notes and reference materials for penetration testing hardware and related topics.
A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.
A Python tool for extracting malware family names and tags from antivirus engine labels, designed for large-scale malware analysis.
A Node.js sandbox for semi-automatic JavaScript malware analysis, deobfuscation, and payload extraction.
A collection of publicly shared Indicators of Compromise (IOCs) from FireEye for threat intelligence and security research.
A lightweight Python wrapper for Censys APIs, enabling search, bulk data access, and ASM asset management.
An open-source toolkit for automated dynamic analysis of Android applications by intercepting and modifying API calls.
A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.
Large hashcat rulesets generated from real-world compromised passwords to improve password cracking effectiveness.
A framework for automated extraction of static and dynamic features from Android APKs for malware detection.
A tool for automatic analysis of malware behavior using machine learning to identify, cluster, and classify malicious software.
A Python toolkit for probabilistic password guessing and analysis using Probabilistic Context-Free Grammar (PCFG) models.
A curated collection of videos, articles, books, tools, and resources focused on ARM architecture exploitation techniques.
A Python library for generating format string exploitation payloads in binary exploitation and CTF challenges.
A Python-based framework for fuzzing Android's Stagefright media engine to discover security vulnerabilities.
A reverse engineering tool that uses DynamoRIO and Capstone to automatically recover data structures from ELF binaries by monitoring memory accesses.
A Python framework and CLI toolkit for exploring, hacking, and developing tools for wireless protocols using compatible hardware.
A configurable sandbox for dynamic analysis of Android malware using Frida hooks to bypass anti-emulation techniques.
A cross-platform TUI tool for generating arbitrary network packets and monitoring traffic on any interface.
Archive mirror of the users section from the historical rootkit.com security research website.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.