A curated collection of 150+ tools and techniques for red teaming and penetration testing, organized by MITRE ATT&CK framework categories covering reconnaissance, initial access, execution, privilege escalation, defense evasion, credential access, lateral movement, command and control, exfiltration, and impact.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONImHex is a feature-rich, cross-platform hex editor built for reverse engineers, programmers, and anyone doing binary analysis. It offers a custom pattern language, data inspector, diffing, disassembler, YARA scanning, node-based data processing, theming, and plugin support.
Maigret is an OSINT command-line tool that builds a dossier on a person from a username alone, checking 3000+ sites, extracting profile data, and exporting reports in HTML, PDF, JSON, CSV and graph formats.
x64dbg is an open-source user-mode debugger for Windows, aimed at reverse engineering and malware analysis of executables whose source code is unavailable. It ships 32-bit and 64-bit builds, a plugin system, and can be compiled from source by users.
An advanced, system-level personal security and anti-coercion suite for Android. Running as a systemless priv-app with LSPosed hooks, it provides duress PINs, hardware tripwires, and remote SMS control.
SafeLine is a self-hosted web application firewall and reverse proxy that sits in front of web apps to filter and block malicious HTTP/S traffic, offering rate limiting, bot and authentication challenges, dynamic HTML/JS encryption and access control lists.
SWE-agent is an autonomous AI agent that uses language models to automatically fix GitHub issues, find cybersecurity vulnerabilities, and solve custom coding challenges. Built by Princeton and Stanford researchers.
Strix is an open-source AI-powered penetration testing tool that uses autonomous agents to identify, validate, and fix application vulnerabilities through real proof-of-concept exploits.
MergeMind is a GitHub Actions and GitLab CI integration that analyzes pull/merge request diffs and maps code changes to SOX, SOC2 and ISO 27001 controls, posting risk level, control gaps and remediation advice as a PR comment. Full compliance output requires a paid license key.
Berty is an open-source, privacy-first peer-to-peer messaging app built on the Wesh Protocol. It offers end-to-end encryption, works offline via BLE and mDNS, requires no phone number or email, and is designed for censorship-resilient communication.
Sherlock is a command-line tool that hunts down social media accounts by username across 400+ networks. It supports multiple usernames, site filtering, proxy use, and output in text, CSV, or XLSX formats, with installation via pip/pipx, Docker, or system packages.
Local-first, zero-egress forensics toolkit for detecting and sanitizing AI watermarks: Unicode steganography visualization, statistical text detectors, C2PA/EXIF/XMP cleaning, SARIF/CI audit and MCP agent tools.
An educational machine learning project that classifies online payment transactions as legitimate or fraudulent. It preprocesses a transaction dataset, encodes and scales features, then trains and evaluates Logistic Regression, Decision Tree, and Random Forest models with Python, pandas, NumPy, and scikit-learn.
WordPress plugin client for ovos console error monitoring and cyberdefense. Reports PHP/JS errors, security events, and scanner probes to a self-hosted console instance. Features CVE matching, traffic rollups, and AI-driven analysis.
A curated list of tools and resources for security incident response, aimed at helping security analysts and DFIR teams.
Shannon is an open-source, autonomous AI pentester for web applications and APIs. It analyzes your source code to find attack paths, then executes real exploits against a running app, reporting only vulnerabilities proven with a working proof of concept.
Anakrisis is an ethics-aware OSINT investigation planning and risk evaluation MCP server. It classifies investigations, scores risk against local YAML doctrine, flags prohibited actions, and scaffolds case documentation, supporting both cloud and local AI models.
Self-hosted security operations stack combining SIEM log collection, endpoint detection with Sigma rules and cross-event correlation, SOAR playbooks, OSV vulnerability scanning and a local Ollama model for AI triage, deployed with a single docker compose up.
IPScout enriches IP addresses from 67 sources (cloud, CDN, threat feeds) via command line, providing threat ratings, caching, and configurable output formats.
Zentra is an AI-powered CLI security scanner for developers, combining SAST, DAST, supply-chain, API, and IaC analysis with LLM orchestration, CI integration, and an authorized pentest mode.